Help!! j'ai un virus!!!
Résolu
amyann
-
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité -
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité -
Bonjour,
je pense avoir un virus!!!
merci de m'aider!!
avast ne le détecte pas et je n'arrive pas à le supprimer ac spybot!!!
je vien s de faire un rapport hijack :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:34:31, on 01/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\HomePlayer\HomePlayer.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\amélie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ST291DH5\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
je pense avoir un virus!!!
merci de m'aider!!
avast ne le détecte pas et je n'arrive pas à le supprimer ac spybot!!!
je vien s de faire un rapport hijack :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:34:31, on 01/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\HomePlayer\HomePlayer.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\amélie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ST291DH5\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
A voir également:
- Help!! j'ai un virus!!!
- Virus mcafee - Accueil - Piratage
- Virus facebook demande d'amis - Accueil - Facebook
- Virus informatique - Guide
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
- Undisclosed-recipients virus - Guide
24 réponses
Fait ceci et poste moi le rapport à la suite de la question êtes vous aider par quelqu'un. Merci.
Télécharge GenProc sur ton bureau (Attention le fichier est un fichier zip)
Dézippe le dossier, double-clique sur GenProc.bat
En final, poste le contenu du rapport qui s'affiche.
Comment utiliser GenProc
Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs
Télécharge GenProc sur ton bureau (Attention le fichier est un fichier zip)
Dézippe le dossier, double-clique sur GenProc.bat
En final, poste le contenu du rapport qui s'affiche.
Comment utiliser GenProc
Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs
Tu peux faire ce qui est indiqué et me poster les rapports.
VOICI LES 3 RAPPORTS :
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Basique ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Celeron(R) D CPU 3.46GHz )
BIOS : BIOS Date: 03/09/07 18:46:32 Ver: 08.00.13
USER : amélie ( Not Administrator ! )
BOOT : Fail-safe boot
Antivirus : avast! antivirus 4.8.1335 [VPS 090302-0] 4.8.1335 (Activated)
C:\ (Local Disk) - NTFS - Total:227 Go (Free:158 Go)
D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 02/03/2009|22:09 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertstream[1].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adultfriendfinder[2].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertising[1].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@ero-advertising[1].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adopt.euroclick[2].txt
Supprime! - C:\Program Files\Circle Developement
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[23/08/2007|17:14] C:\Users\AMLIE~1\AppData\Local\Adobe
[29/09/2007|16:13] C:\Users\AMLIE~1\AppData\Local\Ahead
[21/08/2007|18:35] C:\Users\AMLIE~1\AppData\Local\Application Data
[23/10/2007|21:03] C:\Users\AMLIE~1\AppData\Local\Codemasters
[22/11/2007|00:16] C:\Users\AMLIE~1\AppData\Local\d3d8caps.dat
[13/12/2007|21:10] C:\Users\AMLIE~1\AppData\Local\d3d9caps.dat
[01/03/2009|22:42] C:\Users\AMLIE~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[16/02/2008|17:25] C:\Users\AMLIE~1\AppData\Local\DNA
[03/05/2008|09:16] C:\Users\AMLIE~1\AppData\Local\DVDPlay
[18/10/2008|15:40] C:\Users\AMLIE~1\AppData\Local\GDIPFONTCACHEV1.DAT
[18/01/2009|16:43] C:\Users\AMLIE~1\AppData\Local\Google
[21/08/2007|18:35] C:\Users\AMLIE~1\AppData\Local\Historique
[02/03/2009|22:00] C:\Users\AMLIE~1\AppData\Local\IconCache.db
[31/10/2007|13:59] C:\Users\AMLIE~1\AppData\Local\IM
[10/09/2007|14:34] C:\Users\AMLIE~1\AppData\Local\Lphant
[11/11/2007|20:38] C:\Users\AMLIE~1\AppData\Local\Magentic
[29/10/2008|22:47] C:\Users\AMLIE~1\AppData\Local\Microsoft
[24/08/2007|23:35] C:\Users\AMLIE~1\AppData\Local\Microsoft Games
[22/09/2007|13:29] C:\Users\AMLIE~1\AppData\Local\Mozilla
[24/11/2008|17:46] C:\Users\AMLIE~1\AppData\Local\PowerCinema
[02/03/2009|22:09] C:\Users\AMLIE~1\AppData\Local\Temp
[21/08/2007|18:35] C:\Users\AMLIE~1\AppData\Local\Temporary Internet Files
[23/08/2007|17:00] C:\Users\AMLIE~1\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[02/03/2009 11:38][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{B7D7C3D9-A772-409F-8943-DB61DE2FAEC5}.job
[02/03/2009 22:01][--ah-----] C:\Windows\tasks\SA.DAT
[02/03/2009 22:01][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[08/03/2007|06:14] C:\ProgramData\Adobe
[02/11/2006|13:59] C:\ProgramData\Application Data
[29/10/2007|11:34] C:\ProgramData\AVS4YOU
[21/08/2007|18:31] C:\ProgramData\Bureau
[21/07/2008|09:25] C:\ProgramData\CyberLink
[02/11/2006|13:59] C:\ProgramData\Desktop
[02/11/2006|13:59] C:\ProgramData\Documents
[11/09/2007|15:56] C:\ProgramData\eMule
[10/01/2008|22:20] C:\ProgramData\EPSON
[21/08/2007|18:31] C:\ProgramData\Favoris
[02/11/2006|13:59] C:\ProgramData\Favorites
[18/01/2009|16:24] C:\ProgramData\Google
[17/01/2008|18:32] C:\ProgramData\Grisoft
[08/03/2007|06:39] C:\ProgramData\Hewlett-Packard
[08/03/2007|06:20] C:\ProgramData\InstallShield
[15/02/2009|21:17] C:\ProgramData\Kaspersky Lab Setup Files
[17/01/2008|13:47] C:\ProgramData\Lavasoft
[25/09/2007|10:45] C:\ProgramData\LightScribe
[21/08/2007|18:31] C:\ProgramData\Menu D‚marrer
[22/12/2008|17:54] C:\ProgramData\Messenger Plus!
[17/10/2008|20:32] C:\ProgramData\Microsoft
[21/08/2007|18:31] C:\ProgramData\ModŠles
[22/09/2007|13:28] C:\ProgramData\Mozilla
[25/09/2007|10:32] C:\ProgramData\Nero
[13/12/2007|21:51] C:\ProgramData\NFS Underground
[17/05/2008|17:39] C:\ProgramData\RoboForm
[24/09/2007|21:21] C:\ProgramData\Roxio
[26/08/2007|17:49] C:\ProgramData\Sonic
[15/02/2009|23:11] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|13:59] C:\ProgramData\Start Menu
[28/10/2007|10:17] C:\ProgramData\Symantec
[02/11/2006|13:59] C:\ProgramData\Templates
[10/01/2008|22:27] C:\ProgramData\UDL
[30/10/2007|09:13] C:\ProgramData\vsosdk
--------------------\\ Listing des dossiers dans C:\Program Files
[08/03/2007|06:14] C:\Program Files\Adobe
[27/11/2007|14:26] C:\Program Files\Alwil Software
[16/01/2008|15:46] C:\Program Files\a-squared Anti-Malware
[23/12/2007|18:56] C:\Program Files\AVS4YOU
[14/12/2008|23:22] C:\Program Files\BarreConfCMCIC
[28/10/2007|11:15] C:\Program Files\BitDefender
[16/02/2008|17:25] C:\Program Files\BitTorrent
[22/08/2008|16:53] C:\Program Files\CCleaner
[26/12/2007|20:43] C:\Program Files\Codemasters
[30/12/2008|18:01] C:\Program Files\Common Files
[30/12/2008|17:52] C:\Program Files\Computer Artworks
[08/03/2007|06:04] C:\Program Files\CyberLink
[17/11/2008|21:58] C:\Program Files\Dactylo
[17/10/2007|20:35] C:\Program Files\DAEMON Tools
[26/12/2007|20:36] C:\Program Files\DivX
[30/08/2008|08:57] C:\Program Files\DNA
[11/09/2007|15:56] C:\Program Files\eMule
[10/01/2008|22:24] C:\Program Files\epson
[21/08/2007|18:31] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[14/01/2009|21:21] C:\Program Files\Freeplayer
[18/01/2009|16:37] C:\Program Files\Google
[08/03/2007|06:20] C:\Program Files\Hewlett-Packard
[15/01/2009|20:55] C:\Program Files\HomePlayer
[08/03/2007|06:15] C:\Program Files\HP
[16/01/2008|15:44] C:\Program Files\IncrediMail
[30/12/2008|17:52] C:\Program Files\InstallShield Installation Information
[13/02/2009|14:35] C:\Program Files\Internet Explorer
[01/08/2008|23:08] C:\Program Files\Java
[11/09/2007|16:23] C:\Program Files\K-Lite Codec Pack
[25/03/2008|17:19] C:\Program Files\LimeWire
[15/01/2008|15:02] C:\Program Files\Macrogaming
[23/12/2007|18:56] C:\Program Files\Magentic
[22/08/2008|16:47] C:\Program Files\Messenger Plus! Live
[02/11/2006|13:35] C:\Program Files\Microsoft Games
[17/10/2007|12:51] C:\Program Files\Microsoft LifeCam
[17/10/2008|20:33] C:\Program Files\Microsoft Office
[08/03/2007|06:16] C:\Program Files\Microsoft Works
[17/10/2008|20:32] C:\Program Files\Microsoft.NET
[08/03/2007|14:42] C:\Program Files\Movie Maker
[22/09/2007|13:29] C:\Program Files\Mozilla Firefox
[02/11/2006|13:35] C:\Program Files\MSBuild
[02/11/2006|13:35] C:\Program Files\MSN
[22/08/2008|16:47] C:\Program Files\MSN Messenger
[12/09/2007|02:02] C:\Program Files\MSXML 4.0
[25/09/2007|10:32] C:\Program Files\Nero
[30/12/2007|13:13] C:\Program Files\NovaLogic
[08/10/2008|20:46] C:\Program Files\OpenOffice.org 2.4
[14/01/2008|21:47] C:\Program Files\PC-Doctor 5 for Windows
[01/11/2007|20:22] C:\Program Files\QuickTime
[17/11/2008|22:07] C:\Program Files\RapidTyping
[08/03/2007|06:13] C:\Program Files\Real
[08/03/2007|06:01] C:\Program Files\Realtek
[02/11/2006|13:35] C:\Program Files\Reference Assemblies
[08/03/2007|06:12] C:\Program Files\Roxio
[08/03/2007|06:23] C:\Program Files\Services en ligne
[17/05/2008|17:38] C:\Program Files\Siber Systems
[15/02/2009|22:03] C:\Program Files\Spybot - Search & Destroy
[17/01/2008|14:52] C:\Program Files\Trend Micro
[02/11/2006|13:58] C:\Program Files\Uninstall Information
[09/01/2009|20:49] C:\Program Files\uTorrent
[05/09/2007|18:04] C:\Program Files\VideoLAN
[29/03/2008|22:52] C:\Program Files\VSO
[12/09/2007|02:18] C:\Program Files\Windows Calendar
[08/03/2007|14:42] C:\Program Files\Windows Collaboration
[12/09/2007|02:18] C:\Program Files\Windows Defender
[22/08/2008|16:47] C:\Program Files\Windows Live
[12/02/2009|23:11] C:\Program Files\Windows Mail
[10/10/2007|14:27] C:\Program Files\Windows Media Player
[21/08/2007|18:31] C:\Program Files\Windows NT
[08/03/2007|14:42] C:\Program Files\Windows Photo Gallery
[09/01/2008|14:59] C:\Program Files\Windows Sidebar
[25/09/2007|13:15] C:\Program Files\WinRAR
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[08/03/2007|06:14] C:\Program Files\Common Files\Adobe
[25/09/2007|10:38] C:\Program Files\Common Files\Ahead
[23/12/2007|18:56] C:\Program Files\Common Files\AVSMedia
[27/11/2007|14:12] C:\Program Files\Common Files\BitDefender
[17/10/2008|20:33] C:\Program Files\Common Files\DESIGNER
[15/01/2008|15:02] C:\Program Files\Common Files\DisqudurProtection
[08/03/2007|06:20] C:\Program Files\Common Files\InstallShield
[22/03/2008|20:11] C:\Program Files\Common Files\Java
[08/03/2007|06:05] C:\Program Files\Common Files\LightScribe
[08/03/2007|06:04] C:\Program Files\Common Files\LS Getting Started
[17/10/2008|20:35] C:\Program Files\Common Files\microsoft shared
[22/09/2007|13:28] C:\Program Files\Common Files\PX Storage Engine
[08/03/2007|06:13] C:\Program Files\Common Files\Real
[08/03/2007|06:03] C:\Program Files\Common Files\Roxio Shared
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[08/03/2007|06:11] C:\Program Files\Common Files\Sonic Shared
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[08/03/2007|06:03] C:\Program Files\Common Files\SureThing Shared
[30/12/2008|18:01] C:\Program Files\Common Files\SWF Studio
[28/10/2007|10:17] C:\Program Files\Common Files\Symantec Shared
[17/10/2008|20:32] C:\Program Files\Common Files\System
[08/03/2007|06:13] C:\Program Files\Common Files\xing shared
--------------------\\ Process
( 21 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-02 22:09:37
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 134
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:51][D:11]-> C:\Users\AMLIE~1\AppData\Local\Temp
[F:260][D:1]-> C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies
[F:6283][D:9]-> C:\Users\AMLIE~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:29][D:6]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 02/03/2009|22:11 - Option : [2]
--------------------\\ Fin du rapport a 22:11:18
[ UAC => 1 ]
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Basique ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Celeron(R) D CPU 3.46GHz )
BIOS : BIOS Date: 03/09/07 18:46:32 Ver: 08.00.13
USER : amélie ( Not Administrator ! )
BOOT : Fail-safe boot
Antivirus : avast! antivirus 4.8.1335 [VPS 090302-0] 4.8.1335 (Activated)
C:\ (Local Disk) - NTFS - Total:227 Go (Free:158 Go)
D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 02/03/2009|22:05 )
[ UAC => 0 ]
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.fr/?gws_rd=ssl"
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Url"="https://www.msn.com/fr-fr/actualite/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 02/03/2009|22:06 - Option : [2]
-----------\\ Fin du rapport a 22:06:36,89
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:42, on 02/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Basique ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Celeron(R) D CPU 3.46GHz )
BIOS : BIOS Date: 03/09/07 18:46:32 Ver: 08.00.13
USER : amélie ( Not Administrator ! )
BOOT : Fail-safe boot
Antivirus : avast! antivirus 4.8.1335 [VPS 090302-0] 4.8.1335 (Activated)
C:\ (Local Disk) - NTFS - Total:227 Go (Free:158 Go)
D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 02/03/2009|22:09 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertstream[1].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adultfriendfinder[2].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertising[1].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@ero-advertising[1].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adopt.euroclick[2].txt
Supprime! - C:\Program Files\Circle Developement
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[23/08/2007|17:14] C:\Users\AMLIE~1\AppData\Local\Adobe
[29/09/2007|16:13] C:\Users\AMLIE~1\AppData\Local\Ahead
[21/08/2007|18:35] C:\Users\AMLIE~1\AppData\Local\Application Data
[23/10/2007|21:03] C:\Users\AMLIE~1\AppData\Local\Codemasters
[22/11/2007|00:16] C:\Users\AMLIE~1\AppData\Local\d3d8caps.dat
[13/12/2007|21:10] C:\Users\AMLIE~1\AppData\Local\d3d9caps.dat
[01/03/2009|22:42] C:\Users\AMLIE~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[16/02/2008|17:25] C:\Users\AMLIE~1\AppData\Local\DNA
[03/05/2008|09:16] C:\Users\AMLIE~1\AppData\Local\DVDPlay
[18/10/2008|15:40] C:\Users\AMLIE~1\AppData\Local\GDIPFONTCACHEV1.DAT
[18/01/2009|16:43] C:\Users\AMLIE~1\AppData\Local\Google
[21/08/2007|18:35] C:\Users\AMLIE~1\AppData\Local\Historique
[02/03/2009|22:00] C:\Users\AMLIE~1\AppData\Local\IconCache.db
[31/10/2007|13:59] C:\Users\AMLIE~1\AppData\Local\IM
[10/09/2007|14:34] C:\Users\AMLIE~1\AppData\Local\Lphant
[11/11/2007|20:38] C:\Users\AMLIE~1\AppData\Local\Magentic
[29/10/2008|22:47] C:\Users\AMLIE~1\AppData\Local\Microsoft
[24/08/2007|23:35] C:\Users\AMLIE~1\AppData\Local\Microsoft Games
[22/09/2007|13:29] C:\Users\AMLIE~1\AppData\Local\Mozilla
[24/11/2008|17:46] C:\Users\AMLIE~1\AppData\Local\PowerCinema
[02/03/2009|22:09] C:\Users\AMLIE~1\AppData\Local\Temp
[21/08/2007|18:35] C:\Users\AMLIE~1\AppData\Local\Temporary Internet Files
[23/08/2007|17:00] C:\Users\AMLIE~1\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[02/03/2009 11:38][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{B7D7C3D9-A772-409F-8943-DB61DE2FAEC5}.job
[02/03/2009 22:01][--ah-----] C:\Windows\tasks\SA.DAT
[02/03/2009 22:01][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[08/03/2007|06:14] C:\ProgramData\Adobe
[02/11/2006|13:59] C:\ProgramData\Application Data
[29/10/2007|11:34] C:\ProgramData\AVS4YOU
[21/08/2007|18:31] C:\ProgramData\Bureau
[21/07/2008|09:25] C:\ProgramData\CyberLink
[02/11/2006|13:59] C:\ProgramData\Desktop
[02/11/2006|13:59] C:\ProgramData\Documents
[11/09/2007|15:56] C:\ProgramData\eMule
[10/01/2008|22:20] C:\ProgramData\EPSON
[21/08/2007|18:31] C:\ProgramData\Favoris
[02/11/2006|13:59] C:\ProgramData\Favorites
[18/01/2009|16:24] C:\ProgramData\Google
[17/01/2008|18:32] C:\ProgramData\Grisoft
[08/03/2007|06:39] C:\ProgramData\Hewlett-Packard
[08/03/2007|06:20] C:\ProgramData\InstallShield
[15/02/2009|21:17] C:\ProgramData\Kaspersky Lab Setup Files
[17/01/2008|13:47] C:\ProgramData\Lavasoft
[25/09/2007|10:45] C:\ProgramData\LightScribe
[21/08/2007|18:31] C:\ProgramData\Menu D‚marrer
[22/12/2008|17:54] C:\ProgramData\Messenger Plus!
[17/10/2008|20:32] C:\ProgramData\Microsoft
[21/08/2007|18:31] C:\ProgramData\ModŠles
[22/09/2007|13:28] C:\ProgramData\Mozilla
[25/09/2007|10:32] C:\ProgramData\Nero
[13/12/2007|21:51] C:\ProgramData\NFS Underground
[17/05/2008|17:39] C:\ProgramData\RoboForm
[24/09/2007|21:21] C:\ProgramData\Roxio
[26/08/2007|17:49] C:\ProgramData\Sonic
[15/02/2009|23:11] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|13:59] C:\ProgramData\Start Menu
[28/10/2007|10:17] C:\ProgramData\Symantec
[02/11/2006|13:59] C:\ProgramData\Templates
[10/01/2008|22:27] C:\ProgramData\UDL
[30/10/2007|09:13] C:\ProgramData\vsosdk
--------------------\\ Listing des dossiers dans C:\Program Files
[08/03/2007|06:14] C:\Program Files\Adobe
[27/11/2007|14:26] C:\Program Files\Alwil Software
[16/01/2008|15:46] C:\Program Files\a-squared Anti-Malware
[23/12/2007|18:56] C:\Program Files\AVS4YOU
[14/12/2008|23:22] C:\Program Files\BarreConfCMCIC
[28/10/2007|11:15] C:\Program Files\BitDefender
[16/02/2008|17:25] C:\Program Files\BitTorrent
[22/08/2008|16:53] C:\Program Files\CCleaner
[26/12/2007|20:43] C:\Program Files\Codemasters
[30/12/2008|18:01] C:\Program Files\Common Files
[30/12/2008|17:52] C:\Program Files\Computer Artworks
[08/03/2007|06:04] C:\Program Files\CyberLink
[17/11/2008|21:58] C:\Program Files\Dactylo
[17/10/2007|20:35] C:\Program Files\DAEMON Tools
[26/12/2007|20:36] C:\Program Files\DivX
[30/08/2008|08:57] C:\Program Files\DNA
[11/09/2007|15:56] C:\Program Files\eMule
[10/01/2008|22:24] C:\Program Files\epson
[21/08/2007|18:31] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[14/01/2009|21:21] C:\Program Files\Freeplayer
[18/01/2009|16:37] C:\Program Files\Google
[08/03/2007|06:20] C:\Program Files\Hewlett-Packard
[15/01/2009|20:55] C:\Program Files\HomePlayer
[08/03/2007|06:15] C:\Program Files\HP
[16/01/2008|15:44] C:\Program Files\IncrediMail
[30/12/2008|17:52] C:\Program Files\InstallShield Installation Information
[13/02/2009|14:35] C:\Program Files\Internet Explorer
[01/08/2008|23:08] C:\Program Files\Java
[11/09/2007|16:23] C:\Program Files\K-Lite Codec Pack
[25/03/2008|17:19] C:\Program Files\LimeWire
[15/01/2008|15:02] C:\Program Files\Macrogaming
[23/12/2007|18:56] C:\Program Files\Magentic
[22/08/2008|16:47] C:\Program Files\Messenger Plus! Live
[02/11/2006|13:35] C:\Program Files\Microsoft Games
[17/10/2007|12:51] C:\Program Files\Microsoft LifeCam
[17/10/2008|20:33] C:\Program Files\Microsoft Office
[08/03/2007|06:16] C:\Program Files\Microsoft Works
[17/10/2008|20:32] C:\Program Files\Microsoft.NET
[08/03/2007|14:42] C:\Program Files\Movie Maker
[22/09/2007|13:29] C:\Program Files\Mozilla Firefox
[02/11/2006|13:35] C:\Program Files\MSBuild
[02/11/2006|13:35] C:\Program Files\MSN
[22/08/2008|16:47] C:\Program Files\MSN Messenger
[12/09/2007|02:02] C:\Program Files\MSXML 4.0
[25/09/2007|10:32] C:\Program Files\Nero
[30/12/2007|13:13] C:\Program Files\NovaLogic
[08/10/2008|20:46] C:\Program Files\OpenOffice.org 2.4
[14/01/2008|21:47] C:\Program Files\PC-Doctor 5 for Windows
[01/11/2007|20:22] C:\Program Files\QuickTime
[17/11/2008|22:07] C:\Program Files\RapidTyping
[08/03/2007|06:13] C:\Program Files\Real
[08/03/2007|06:01] C:\Program Files\Realtek
[02/11/2006|13:35] C:\Program Files\Reference Assemblies
[08/03/2007|06:12] C:\Program Files\Roxio
[08/03/2007|06:23] C:\Program Files\Services en ligne
[17/05/2008|17:38] C:\Program Files\Siber Systems
[15/02/2009|22:03] C:\Program Files\Spybot - Search & Destroy
[17/01/2008|14:52] C:\Program Files\Trend Micro
[02/11/2006|13:58] C:\Program Files\Uninstall Information
[09/01/2009|20:49] C:\Program Files\uTorrent
[05/09/2007|18:04] C:\Program Files\VideoLAN
[29/03/2008|22:52] C:\Program Files\VSO
[12/09/2007|02:18] C:\Program Files\Windows Calendar
[08/03/2007|14:42] C:\Program Files\Windows Collaboration
[12/09/2007|02:18] C:\Program Files\Windows Defender
[22/08/2008|16:47] C:\Program Files\Windows Live
[12/02/2009|23:11] C:\Program Files\Windows Mail
[10/10/2007|14:27] C:\Program Files\Windows Media Player
[21/08/2007|18:31] C:\Program Files\Windows NT
[08/03/2007|14:42] C:\Program Files\Windows Photo Gallery
[09/01/2008|14:59] C:\Program Files\Windows Sidebar
[25/09/2007|13:15] C:\Program Files\WinRAR
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[08/03/2007|06:14] C:\Program Files\Common Files\Adobe
[25/09/2007|10:38] C:\Program Files\Common Files\Ahead
[23/12/2007|18:56] C:\Program Files\Common Files\AVSMedia
[27/11/2007|14:12] C:\Program Files\Common Files\BitDefender
[17/10/2008|20:33] C:\Program Files\Common Files\DESIGNER
[15/01/2008|15:02] C:\Program Files\Common Files\DisqudurProtection
[08/03/2007|06:20] C:\Program Files\Common Files\InstallShield
[22/03/2008|20:11] C:\Program Files\Common Files\Java
[08/03/2007|06:05] C:\Program Files\Common Files\LightScribe
[08/03/2007|06:04] C:\Program Files\Common Files\LS Getting Started
[17/10/2008|20:35] C:\Program Files\Common Files\microsoft shared
[22/09/2007|13:28] C:\Program Files\Common Files\PX Storage Engine
[08/03/2007|06:13] C:\Program Files\Common Files\Real
[08/03/2007|06:03] C:\Program Files\Common Files\Roxio Shared
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[08/03/2007|06:11] C:\Program Files\Common Files\Sonic Shared
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[08/03/2007|06:03] C:\Program Files\Common Files\SureThing Shared
[30/12/2008|18:01] C:\Program Files\Common Files\SWF Studio
[28/10/2007|10:17] C:\Program Files\Common Files\Symantec Shared
[17/10/2008|20:32] C:\Program Files\Common Files\System
[08/03/2007|06:13] C:\Program Files\Common Files\xing shared
--------------------\\ Process
( 21 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-02 22:09:37
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 134
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:51][D:11]-> C:\Users\AMLIE~1\AppData\Local\Temp
[F:260][D:1]-> C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies
[F:6283][D:9]-> C:\Users\AMLIE~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:29][D:6]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 02/03/2009|22:11 - Option : [2]
--------------------\\ Fin du rapport a 22:11:18
[ UAC => 1 ]
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Basique ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Celeron(R) D CPU 3.46GHz )
BIOS : BIOS Date: 03/09/07 18:46:32 Ver: 08.00.13
USER : amélie ( Not Administrator ! )
BOOT : Fail-safe boot
Antivirus : avast! antivirus 4.8.1335 [VPS 090302-0] 4.8.1335 (Activated)
C:\ (Local Disk) - NTFS - Total:227 Go (Free:158 Go)
D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 02/03/2009|22:05 )
[ UAC => 0 ]
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.fr/?gws_rd=ssl"
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Url"="https://www.msn.com/fr-fr/actualite/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 02/03/2009|22:06 - Option : [2]
-----------\\ Fin du rapport a 22:06:36,89
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:42, on 02/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
Bien maintenant fait ceci :
Telecharge malwarebytes
NB : S'il te manque COMCTL32.OCX alors télécharge le ici
Tu l´instale; le programme va se mettre automatiquement a jour.
Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".
Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".
Puis click sur "rechercher".
Laisse le scanner le pc...
Si des elements on ete trouvés > click sur supprimer la selection.
si il t´es demandé de redemarrer > click sur "yes".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.
PS : les rapport sont aussi rangé dans l onglet rapport/log
Tutoriaux
Telecharge malwarebytes
NB : S'il te manque COMCTL32.OCX alors télécharge le ici
Tu l´instale; le programme va se mettre automatiquement a jour.
Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".
Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".
Puis click sur "rechercher".
Laisse le scanner le pc...
Si des elements on ete trouvés > click sur supprimer la selection.
si il t´es demandé de redemarrer > click sur "yes".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.
PS : les rapport sont aussi rangé dans l onglet rapport/log
Tutoriaux
VOICI LE RAPPORT :
Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1815
Windows 6.0.6000
03/03/2009 22:45:05
mbam-log-2009-03-03 (22-45-05).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 192194
Temps écoulé: 1 hour(s), 0 minute(s), 5 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 3
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\DomainService (Trojan.Agent) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Users\amélie\Desktop\GenProc\outil\curl.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1815
Windows 6.0.6000
03/03/2009 22:45:05
mbam-log-2009-03-03 (22-45-05).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 192194
Temps écoulé: 1 hour(s), 0 minute(s), 5 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 3
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\DomainService (Trojan.Agent) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Users\amélie\Desktop\GenProc\outil\curl.exe (Trojan.Agent) -> Quarantined and deleted successfully.
pas mal ensuite vide la quarantaine de malware et fait ceci :
Pour commencer : faire un petit nettoyage de l'ordi et du registre avec Ccleaner, regarde bien le Tuto CCleaner
Télécharge Superantispyware (SAS)
Choisis "enregistrer" et enregistre-le sur ton bureau.
Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.
Créé une icône sur le bureau.
Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.
- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
- Sous Configuration and Preferences, clique sur le bouton "Preferences"
- Clique sur l'onglet "Scanning Control "
- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :
Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
- Laisse les autres lignes décochées.
- Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.
- Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".
Dans la colonne de gauche, coche C:\Fixed Drive.
Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"
Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.
A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.
Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".
Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.
Pour recopier les informations sur le forum, fais ceci :
- après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
- Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.
- Le rapport va s'ouvrir dans ton éditeur de texte par défaut.
- Copie son contenu dans ta réponse.
Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
Pour commencer : faire un petit nettoyage de l'ordi et du registre avec Ccleaner, regarde bien le Tuto CCleaner
Télécharge Superantispyware (SAS)
Choisis "enregistrer" et enregistre-le sur ton bureau.
Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.
Créé une icône sur le bureau.
Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.
- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
- Sous Configuration and Preferences, clique sur le bouton "Preferences"
- Clique sur l'onglet "Scanning Control "
- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :
Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
- Laisse les autres lignes décochées.
- Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.
- Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".
Dans la colonne de gauche, coche C:\Fixed Drive.
Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"
Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.
A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.
Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".
Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.
Pour recopier les informations sur le forum, fais ceci :
- après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
- Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.
- Le rapport va s'ouvrir dans ton éditeur de texte par défaut.
- Copie son contenu dans ta réponse.
Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
j'ai arrété le scan car il allait depuis plusieurs jours!!
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/
Generated 03/09/2009 at 10:20 PM
Application Version : 4.25.1014
Core Rules Database Version : 3784
Trace Rules Database Version: 1741
Scan type : Complete Scan
Total Scan Time : 23:53:34
Memory items scanned : 725
Memory threats detected : 0
Registry items scanned : 8444
Registry threats detected : 1
File items scanned : 7395352
File threats detected : 365
Adware.Vundo Variant
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{7555906D-70F1-4FD6-8250-4FBE75252F58}
Adware.Tracking Cookie
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@smartadserver[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@smartadserver[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@mediaplex[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Documents and Settings\amélie\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Cookies\amélie@smartadserver[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adrevolver[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@ads.monster[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@mediaplex[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@serving-sys[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@yourmedia[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@ad.wedoo[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@ad.zanox[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@adserver.aol[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@adv.surinter[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@advertstream[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@cdiscount[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@clickintext[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@d2.advertserve[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@proximedia[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@roiservice[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@track.effiliation[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@tracker.affistats[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.googleadservices[4].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.googleadservices[5].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.googleadservices[6].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.proximedia[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@xiti[1].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adopt.euroclick[2].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adultfriendfinder[2].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertising[1].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertstream[1].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@ero-advertising[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@smartadserver[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@2o7[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.caradisiac[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.zanox[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adopt.euroclick[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ads-dev.youporn[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@boursoramabanque.solution.weborama[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ero-advertising[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@www.googleadservices[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@youporn[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@zedo[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\amélie@smartadserver[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@2o7[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.caradisiac[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.zanox[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adopt.euroclick[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ads-dev.youporn[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@advertising[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bluestreak[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@boursoramabanque.solution.weborama[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ero-advertising[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@smartadserver[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@www.googleadservices[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@youporn[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@zedo[1].txt
C:\Users\amélie\Cookies\amélie@atdmt[2].txt
C:\Users\amélie\Cookies\amélie@doubleclick[1].txt
C:\Users\amélie\Cookies\amélie@smartadserver[2].txt
C:\Users\amélie\Cookies\Low\amélie@2o7[1].txt
C:\Users\amélie\Cookies\Low\amélie@ad.caradisiac[2].txt
C:\Users\amélie\Cookies\Low\amélie@ad.proxad[1].txt
C:\Users\amélie\Cookies\Low\amélie@ad.zanox[1].txt
C:\Users\amélie\Cookies\Low\amélie@adopt.euroclick[2].txt
C:\Users\amélie\Cookies\Low\amélie@adrevolver[2].txt
C:\Users\amélie\Cookies\Low\amélie@ads-dev.youporn[1].txt
C:\Users\amélie\Cookies\Low\amélie@ads.monster[1].txt
C:\Users\amélie\Cookies\Low\amélie@adserver.aol[1].txt
C:\Users\amélie\Cookies\Low\amélie@adtech[1].txt
C:\Users\amélie\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Users\amélie\Cookies\Low\amélie@advertising[1].txt
C:\Users\amélie\Cookies\Low\amélie@apmebf[1].txt
C:\Users\amélie\Cookies\Low\amélie@atdmt[2].txt
C:\Users\amélie\Cookies\Low\amélie@bluestreak[2].txt
C:\Users\amélie\Cookies\Low\amélie@boursoramabanque.solution.weborama[2].txt
C:\Users\amélie\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Users\amélie\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Users\amélie\Cookies\Low\amélie@doubleclick[1].txt
C:\Users\amélie\Cookies\Low\amélie@ero-advertising[1].txt
C:\Users\amélie\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Users\amélie\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Users\amélie\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Users\amélie\Cookies\Low\amélie@mediaplex[1].txt
C:\Users\amélie\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Users\amélie\Cookies\Low\amélie@serving-sys[2].txt
C:\Users\amélie\Cookies\Low\amélie@smartadserver[1].txt
C:\Users\amélie\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Users\amélie\Cookies\Low\amélie@tradedoubler[2].txt
C:\Users\amélie\Cookies\Low\amélie@weborama[1].txt
C:\Users\amélie\Cookies\Low\amélie@www.googleadservices[1].txt
C:\Users\amélie\Cookies\Low\amélie@xiti[1].txt
C:\Users\amélie\Cookies\Low\amélie@youporn[1].txt
C:\Users\amélie\Cookies\Low\amélie@yourmedia[1].txt
C:\Users\amélie\Cookies\Low\amélie@zedo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Users\yann\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Users\yann\Cookies\Low\yann@ad.wedoo[1].txt
C:\Users\yann\Cookies\Low\yann@ad.zanox[2].txt
C:\Users\yann\Cookies\Low\yann@adserver.aol[1].txt
C:\Users\yann\Cookies\Low\yann@adv.surinter[2].txt
C:\Users\yann\Cookies\Low\yann@advertstream[1].txt
C:\Users\yann\Cookies\Low\yann@cdiscount[1].txt
C:\Users\yann\Cookies\Low\yann@clickintext[2].txt
C:\Users\yann\Cookies\Low\yann@d2.advertserve[1].txt
C:\Users\yann\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Users\yann\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Users\yann\Cookies\Low\yann@proximedia[1].txt
C:\Users\yann\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Users\yann\Cookies\Low\yann@roiservice[1].txt
C:\Users\yann\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Users\yann\Cookies\Low\yann@track.effiliation[1].txt
C:\Users\yann\Cookies\Low\yann@tracker.affistats[2].txt
C:\Users\yann\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Users\yann\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Users\yann\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Users\yann\Cookies\Low\yann@www.googleadservices[4].txt
C:\Users\yann\Cookies\Low\yann@www.googleadservices[5].txt
C:\Users\yann\Cookies\Low\yann@www.googleadservices[6].txt
C:\Users\yann\Cookies\Low\yann@www.proximedia[2].txt
C:\Users\yann\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Users\yann\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Users\yann\Cookies\Low\yann@xiti[1].txt
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/
Generated 03/05/2009 at 10:25 PM
Application Version : 4.25.1014
Core Rules Database Version : 3784
Trace Rules Database Version: 1741
Scan type : Complete Scan
Total Scan Time : 02:39:24
Memory items scanned : 715
Memory threats detected : 0
Registry items scanned : 8444
Registry threats detected : 1
File items scanned : 2021264
File threats detected : 63
Adware.Vundo Variant
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{7555906D-70F1-4FD6-8250-4FBE75252F58}
Adware.Tracking Cookie
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@serving-sys[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@mediaplex[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@serving-sys[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@xiti[1].txt
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/
Generated 03/09/2009 at 10:20 PM
Application Version : 4.25.1014
Core Rules Database Version : 3784
Trace Rules Database Version: 1741
Scan type : Complete Scan
Total Scan Time : 23:53:34
Memory items scanned : 725
Memory threats detected : 0
Registry items scanned : 8444
Registry threats detected : 1
File items scanned : 7395352
File threats detected : 365
Adware.Vundo Variant
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{7555906D-70F1-4FD6-8250-4FBE75252F58}
Adware.Tracking Cookie
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@smartadserver[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@smartadserver[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@mediaplex[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Documents and Settings\amélie\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Cookies\amélie@smartadserver[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adrevolver[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@ads.monster[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@mediaplex[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@serving-sys[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@yourmedia[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@ad.wedoo[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@ad.zanox[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@adserver.aol[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@adv.surinter[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@advertstream[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@cdiscount[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@clickintext[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@d2.advertserve[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@proximedia[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@roiservice[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@track.effiliation[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@tracker.affistats[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.googleadservices[4].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.googleadservices[5].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.googleadservices[6].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.proximedia[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@xiti[1].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adopt.euroclick[2].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adultfriendfinder[2].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertising[1].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertstream[1].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@ero-advertising[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@smartadserver[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@2o7[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.caradisiac[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.zanox[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adopt.euroclick[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ads-dev.youporn[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@boursoramabanque.solution.weborama[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ero-advertising[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@www.googleadservices[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@youporn[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@zedo[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\amélie@smartadserver[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@2o7[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.caradisiac[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.zanox[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adopt.euroclick[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ads-dev.youporn[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@advertising[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bluestreak[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@boursoramabanque.solution.weborama[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ero-advertising[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@smartadserver[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@www.googleadservices[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@youporn[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@zedo[1].txt
C:\Users\amélie\Cookies\amélie@atdmt[2].txt
C:\Users\amélie\Cookies\amélie@doubleclick[1].txt
C:\Users\amélie\Cookies\amélie@smartadserver[2].txt
C:\Users\amélie\Cookies\Low\amélie@2o7[1].txt
C:\Users\amélie\Cookies\Low\amélie@ad.caradisiac[2].txt
C:\Users\amélie\Cookies\Low\amélie@ad.proxad[1].txt
C:\Users\amélie\Cookies\Low\amélie@ad.zanox[1].txt
C:\Users\amélie\Cookies\Low\amélie@adopt.euroclick[2].txt
C:\Users\amélie\Cookies\Low\amélie@adrevolver[2].txt
C:\Users\amélie\Cookies\Low\amélie@ads-dev.youporn[1].txt
C:\Users\amélie\Cookies\Low\amélie@ads.monster[1].txt
C:\Users\amélie\Cookies\Low\amélie@adserver.aol[1].txt
C:\Users\amélie\Cookies\Low\amélie@adtech[1].txt
C:\Users\amélie\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Users\amélie\Cookies\Low\amélie@advertising[1].txt
C:\Users\amélie\Cookies\Low\amélie@apmebf[1].txt
C:\Users\amélie\Cookies\Low\amélie@atdmt[2].txt
C:\Users\amélie\Cookies\Low\amélie@bluestreak[2].txt
C:\Users\amélie\Cookies\Low\amélie@boursoramabanque.solution.weborama[2].txt
C:\Users\amélie\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Users\amélie\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Users\amélie\Cookies\Low\amélie@doubleclick[1].txt
C:\Users\amélie\Cookies\Low\amélie@ero-advertising[1].txt
C:\Users\amélie\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Users\amélie\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Users\amélie\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Users\amélie\Cookies\Low\amélie@mediaplex[1].txt
C:\Users\amélie\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Users\amélie\Cookies\Low\amélie@serving-sys[2].txt
C:\Users\amélie\Cookies\Low\amélie@smartadserver[1].txt
C:\Users\amélie\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Users\amélie\Cookies\Low\amélie@tradedoubler[2].txt
C:\Users\amélie\Cookies\Low\amélie@weborama[1].txt
C:\Users\amélie\Cookies\Low\amélie@www.googleadservices[1].txt
C:\Users\amélie\Cookies\Low\amélie@xiti[1].txt
C:\Users\amélie\Cookies\Low\amélie@youporn[1].txt
C:\Users\amélie\Cookies\Low\amélie@yourmedia[1].txt
C:\Users\amélie\Cookies\Low\amélie@zedo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Users\yann\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Users\yann\Cookies\Low\yann@ad.wedoo[1].txt
C:\Users\yann\Cookies\Low\yann@ad.zanox[2].txt
C:\Users\yann\Cookies\Low\yann@adserver.aol[1].txt
C:\Users\yann\Cookies\Low\yann@adv.surinter[2].txt
C:\Users\yann\Cookies\Low\yann@advertstream[1].txt
C:\Users\yann\Cookies\Low\yann@cdiscount[1].txt
C:\Users\yann\Cookies\Low\yann@clickintext[2].txt
C:\Users\yann\Cookies\Low\yann@d2.advertserve[1].txt
C:\Users\yann\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Users\yann\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Users\yann\Cookies\Low\yann@proximedia[1].txt
C:\Users\yann\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Users\yann\Cookies\Low\yann@roiservice[1].txt
C:\Users\yann\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Users\yann\Cookies\Low\yann@track.effiliation[1].txt
C:\Users\yann\Cookies\Low\yann@tracker.affistats[2].txt
C:\Users\yann\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Users\yann\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Users\yann\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Users\yann\Cookies\Low\yann@www.googleadservices[4].txt
C:\Users\yann\Cookies\Low\yann@www.googleadservices[5].txt
C:\Users\yann\Cookies\Low\yann@www.googleadservices[6].txt
C:\Users\yann\Cookies\Low\yann@www.proximedia[2].txt
C:\Users\yann\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Users\yann\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Users\yann\Cookies\Low\yann@xiti[1].txt
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/
Generated 03/05/2009 at 10:25 PM
Application Version : 4.25.1014
Core Rules Database Version : 3784
Trace Rules Database Version: 1741
Scan type : Complete Scan
Total Scan Time : 02:39:24
Memory items scanned : 715
Memory threats detected : 0
Registry items scanned : 8444
Registry threats detected : 1
File items scanned : 2021264
File threats detected : 63
Adware.Vundo Variant
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{7555906D-70F1-4FD6-8250-4FBE75252F58}
Adware.Tracking Cookie
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@serving-sys[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@mediaplex[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@serving-sys[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@xiti[1].txt
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Supprimer déjà en regardant bien le tuto ce qu'à trouvé SAS, ensuite fait moi unn dernier hijackthis, puis ceci :
https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:42, on 02/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
Scan saved at 22:33:42, on 02/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
Résultats : 17 virus ou logiciels espions détectés.
Eléments suspects: Aucun fichier suspect détecté.
Vulnérabilités : Aucune vulnérabilité détectée.
Eléments suspects: Aucun fichier suspect détecté.
Vulnérabilités : Aucune vulnérabilité détectée.
je dois recommencer le scan car j'ai dû m'absenter et je n'ai pas le rapport!!
il ne comporte qu'une ligne :
<div class="decalage1"><img src="GenProcPage/1.gif" />Poste un rapport <a href="https://www.micro-astuce.com/securite/NanoScan-Panda.php" target="_blank"><em>NanoScan</em></a><br /><br /></div>
il ne comporte qu'une ligne :
<div class="decalage1"><img src="GenProcPage/1.gif" />Poste un rapport <a href="https://www.micro-astuce.com/securite/NanoScan-Panda.php" target="_blank"><em>NanoScan</em></a><br /><br /></div>
;***********************************************************************************************************************************************************************************
ANALYSIS: 2009-03-11 07:05:22
PROTECTIONS: 5
MALWARE: 17
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
avast! antivirus 4.8.1335 [VPS 090309-0] 4.8.1335 Yes Yes
Spybot - Search and Destroy 1.0.0.6 No No
Windows Defender 1.1.1505.0 No Yes
SUPERAntiSpyware 4, 25, 0, 1014 No Yes
avast! antivirus 4.8.1335 [VPS 090309-0] 4.8.1335 No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[2].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@doubleclick[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@247realmedia[1].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@bs.serving-sys[2].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[3].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[2].txt
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[1].txt
00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
00207936 Cookie/Adviva TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adviva[2].txt
00207936 Cookie/Adviva TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adviva[3].txt
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
;===================================================================================================================================================================================
SUSPECTS
Sent Location ��&W���39
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description ��&W���39
;===================================================================================================================================================================================
;===================================================================================================================================================================================
ANALYSIS: 2009-03-11 07:05:22
PROTECTIONS: 5
MALWARE: 17
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
avast! antivirus 4.8.1335 [VPS 090309-0] 4.8.1335 Yes Yes
Spybot - Search and Destroy 1.0.0.6 No No
Windows Defender 1.1.1505.0 No Yes
SUPERAntiSpyware 4, 25, 0, 1014 No Yes
avast! antivirus 4.8.1335 [VPS 090309-0] 4.8.1335 No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[2].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@doubleclick[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@247realmedia[1].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@bs.serving-sys[2].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[3].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[2].txt
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[1].txt
00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
00207936 Cookie/Adviva TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adviva[2].txt
00207936 Cookie/Adviva TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adviva[3].txt
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
;===================================================================================================================================================================================
SUSPECTS
Sent Location ��&W���39
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description ��&W���39
;===================================================================================================================================================================================
;===================================================================================================================================================================================
plus de virus que des cookies à supprimer avec ccleaner.
Maintenant un dernier hiajckthis.
Maintenant un dernier hiajckthis.
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:42, on 02/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
Scan saved at 22:33:42, on 02/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
Tu relance hijackthis, mais là tu clique juste sur faire un scan, ensuite tu sélectionne les lignes puis,
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
Tu cliques en bas sur le bouton FIX CHECKED et valides .
2- Redémarres l'ordi .
( important pour que certaines modifs faites avec hijakthis soient prises en compte )
Ensuite ceci :
Télécharge Toolscleaner sur ton Bureau :
* Double-clique sur ToolsCleaner2.exe et laisse le travailler
* Clique sur Recherche et laisse le scan se terminer.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options facultatives.
* Clique sur Quitter, pour que le rapport puisse se créer.
* Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse
Et enfin comme ton pc n'est pas à jour, il va faloir télécharger le service pack trois de windows et faire ceci pour mettre à jour ton pc :
pour voir si ton pc est à jour :
http://www.filehippo.com/updatechecker/UpdateChecker.exe (attention certain logiciels mis en lien pour les mises à jour peuvent être en anglais, rechercher à ce moment là celui en français)
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
Tu cliques en bas sur le bouton FIX CHECKED et valides .
2- Redémarres l'ordi .
( important pour que certaines modifs faites avec hijakthis soient prises en compte )
Ensuite ceci :
Télécharge Toolscleaner sur ton Bureau :
* Double-clique sur ToolsCleaner2.exe et laisse le travailler
* Clique sur Recherche et laisse le scan se terminer.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options facultatives.
* Clique sur Quitter, pour que le rapport puisse se créer.
* Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse
Et enfin comme ton pc n'est pas à jour, il va faloir télécharger le service pack trois de windows et faire ceci pour mettre à jour ton pc :
pour voir si ton pc est à jour :
http://www.filehippo.com/updatechecker/UpdateChecker.exe (attention certain logiciels mis en lien pour les mises à jour peuvent être en anglais, rechercher à ce moment là celui en français)
j'ai fait un copier/coller car pas possible d'enregister le rapport : acces refusé!!
C:\Users\amélie\Desktop\LopSD.exe: supprimé !
C:\Users\amélie\Desktop\HJTInstall.exe: supprimé !
C:\Users\amélie\Desktop\ToolBarSD.exe: supprimé !
C:\Users\amélie\Downloads\GenProc.zip: supprimé !
C:\VundoFix.txt: ERREUR DE SUPPRESSION !!
C:\lopR.txt: ERREUR DE SUPPRESSION !!
C:\TB.txt: ERREUR DE SUPPRESSION !!
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Users\amélie\Desktop\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
C:\Lop SD: supprimé !
C:\Vundofix backups: supprimé !
C:\Toolbar SD: supprimé !
C:\Program Files\Trend Micro\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\amélie\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: supprimé !
C:\Users\amélie\Desktop\GenProc: supprimé !
C:\Users\amélie\Desktop\LopSD.exe: supprimé !
C:\Users\amélie\Desktop\HJTInstall.exe: supprimé !
C:\Users\amélie\Desktop\ToolBarSD.exe: supprimé !
C:\Users\amélie\Downloads\GenProc.zip: supprimé !
C:\VundoFix.txt: ERREUR DE SUPPRESSION !!
C:\lopR.txt: ERREUR DE SUPPRESSION !!
C:\TB.txt: ERREUR DE SUPPRESSION !!
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Users\amélie\Desktop\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
C:\Lop SD: supprimé !
C:\Vundofix backups: supprimé !
C:\Toolbar SD: supprimé !
C:\Program Files\Trend Micro\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\amélie\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: supprimé !
C:\Users\amélie\Desktop\GenProc: supprimé !
Il va y avoir ça à supprimer manuellement :
C:\VundoFix.txt: ERREUR DE SUPPRESSION !!
C:\lopR.txt: ERREUR DE SUPPRESSION !!
C:\TB.txt: ERREUR DE SUPPRESSION !!
C:\Users\amélie\Desktop\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
C:\Program Files\Trend Micro\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
C:\VundoFix.txt: ERREUR DE SUPPRESSION !!
C:\lopR.txt: ERREUR DE SUPPRESSION !!
C:\TB.txt: ERREUR DE SUPPRESSION !!
C:\Users\amélie\Desktop\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
C:\Program Files\Trend Micro\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
il y a tt ça!!!
13 Updates Detected
CCleaner 2.17.853
Installed Version: 2.10.0.618 3.04MB
DAEMON Tools Lite 4.30.3
Installed Version: 4.10.0.0 6.98MB
eMule 0.49c
Installed Version: 0.48.0.8 3.19MB
Firefox 3.0.7
Installed Version: 2.0.0.2 7.17MB
Flash Player 10.0.22.87 (IE)
Installed Version: 9.0.124.0 1.83MB
Java Runtime Environment 1.6.0.12
Installed Version: 1.6.0.7 15.52MB
LimeWire Basic 5.1.2
Installed Version: 4.16.6.0 15.74MB
OpenOffice.org 3.0.1 Final
Installed Version: 2.4.1 128.05MB
QuickTime Player 7.60.92.0
Installed Version: 7.2.0.240 20.86MB
RealPlayer 11.0.0.581
Installed Version: 6.0.12.1741 12.72MB
uTorrent 1.8.2 Build 14458
Installed Version: 1.8.1.12639 264KB
Windows Live Messenger 2009 (14.0.8064)
Installed Version: 8.1.178.0 1.09MB
WinRAR 3.80
Installed Version: 3.50.0.0 1.18MB
Total size: 217.63MB
2 Beta Updates Detected
Firefox 3.1 Beta 3
Installed Version: 2.0.0.2 7.55MB
uTorrent 1.8.3 Beta 14755
Installed Version: 1.8.1.12639 275KB
Total size: 7.82MB
Computer scan time: 5.436 secs
FileHippo processing time: 0.003 secs
Update Checker version: 1.030
Clear results - Report a Problem
13 Updates Detected
CCleaner 2.17.853
Installed Version: 2.10.0.618 3.04MB
DAEMON Tools Lite 4.30.3
Installed Version: 4.10.0.0 6.98MB
eMule 0.49c
Installed Version: 0.48.0.8 3.19MB
Firefox 3.0.7
Installed Version: 2.0.0.2 7.17MB
Flash Player 10.0.22.87 (IE)
Installed Version: 9.0.124.0 1.83MB
Java Runtime Environment 1.6.0.12
Installed Version: 1.6.0.7 15.52MB
LimeWire Basic 5.1.2
Installed Version: 4.16.6.0 15.74MB
OpenOffice.org 3.0.1 Final
Installed Version: 2.4.1 128.05MB
QuickTime Player 7.60.92.0
Installed Version: 7.2.0.240 20.86MB
RealPlayer 11.0.0.581
Installed Version: 6.0.12.1741 12.72MB
uTorrent 1.8.2 Build 14458
Installed Version: 1.8.1.12639 264KB
Windows Live Messenger 2009 (14.0.8064)
Installed Version: 8.1.178.0 1.09MB
WinRAR 3.80
Installed Version: 3.50.0.0 1.18MB
Total size: 217.63MB
2 Beta Updates Detected
Firefox 3.1 Beta 3
Installed Version: 2.0.0.2 7.55MB
uTorrent 1.8.3 Beta 14755
Installed Version: 1.8.1.12639 275KB
Total size: 7.82MB
Computer scan time: 5.436 secs
FileHippo processing time: 0.003 secs
Update Checker version: 1.030
Clear results - Report a Problem
voici le rapport :
Rapport GenProc 2.398 [1] - 02/03/2009 à 19:31:04,55 - Windows Vista
Il est impératif de désactiver le résident TeaTimer de Spybot pendant l'ensemble des manipulations qui vont suivre. Aide Tea-Timer : http://ww11.genproc.com/spybot/spybot.html
Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
Par la suite, laisse-le avec ses réglages par défaut. C'est tout.
# Etape 1/ Télécharge :
- Lop S&D https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2 (Eric 71 & Angeldark) sur ton Bureau.
- Toolbar-S&D https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2 (Team IDN) sur ton Bureau.
Redémarre en mode sans échec comme indiqué ici https://www.wekyo.com/demarrer-le-pc-en-mode-sans-echec-windows-7-et-8/ ; pour retrouver le rapport, clique sur le raccourci "GenProc" sur ton bureau. Choisis ta session courante *** amélie ***
# Etape 2/
Lance Toolbar-S&D situé sur le Bureau.
Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression.
# Etape 3/
Double-clique sur Lop S&D pour lancer l'installation, séléctionne la langue souhaitée, puis choisis l'Option 2 - Suppression - et patiente jusqu'à ce qu'il ait terminé.
# Etape 4/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 5/
Redémarre normalement et poste, dans la même réponse :
- Le contenu du rapport C:\TB.txt ;
- Le contenu du rapport C:\lopR.txt ;
- Un nouveau rapport HijackThis http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/hijackthis-version-install-sujet_199100_1.htm ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
----------------------------------------------------------------------
Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
----------------------------------------------------------------------
~~ Arguments ~~
# Détections GenProc 2.398 02/03/2009 à 19:30:17,80
Lop:le 02/03/2009 à 19:30:21,27 "C:\Program Files\Circle Developement"
Toolbar:le 02/03/2009 à 19:30:26,52 "C:\Program Files\MSN Messenger\msimg32.dll"