Virus MSN

Fermé
Terendul - 12 mars 2009 à 20:20
totobetourne Messages postés 5592 Date d'inscription dimanche 23 mars 2008 Statut Membre Dernière intervention 6 juin 2012 - 14 mars 2009 à 22:33
Bonjour,

bon voila , je suis le premier a ne pas me faire avoir avec les satanés virus msn , mais ce matin quand je me suis levé la tete dans le C... j'ai faiblit et j'ai cliké sur un message d'une amie :s

le lien etait le suivant : foto?? :P http://msn-gallery.net/profile.php?=Terendul@hotmail.fr

voila suis dans le caca ca me polue mon msn a mort et toutes les fenetres contacts s'ouvrent

helppppppppppppppppppppppp quelqu'un svp
A voir également:

4 réponses

totobetourne Messages postés 5592 Date d'inscription dimanche 23 mars 2008 Statut Membre Dernière intervention 6 juin 2012 65
12 mars 2009 à 20:36
bonjour

on va commencer avec cela , apres dis nous comment se comporte ton pc?
telecharge

http://www.commentcamarche.net/telecharger/telecharger 34055374 msn fix

Décompresse-le (clique droit >> Extraire ici) et place les fichiers dans C:\MSNFix (très important).
Double cliquer sur le fichier MSNFix.bat.
- Exécutez l'option R.
-- Si l'infection est détectée, un message l'indiquera et il suffira de presser une touche pour lancer le nettoyage.

Note :
-Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
- Le rapport sera enregistré dans le même dossier que MSNFix sous forme date_heure.txt
Sauvegardez ce rapport puis faites un copier/coller de ce rapport sur ce forum.
0
Bonsoir ,

alors j'avais fait ce scan y'a 30 min , il mle disait aucunes erreurs ...
j'ai voulu le refaire maintenant pour te mettre le rapport ..... ben ca s'eternise et ca bloque :(((
je crois que c'est la grosse merdouille
0
totobetourne Messages postés 5592 Date d'inscription dimanche 23 mars 2008 Statut Membre Dernière intervention 6 juin 2012 65
12 mars 2009 à 22:21
passe cela on va regarder.
telecharge cela:util pour voir ce que peut etre l infection et agir ensuite.

http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

installe le normallement comme tout autre programme dans c/programme/...............
clique sur do a scan and save a logfile, tu obtiens un rapport que tu colles.


0
Voila le rapport

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:35:28, on 12/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
C:\Program Files\Netlog Music Tool\NetlogMusicTool.exe
C:\Program Files\Globe Software\StatBar\StatBar.exe
C:\Program Files\ManyCam 2.3\ManyCam.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\charles nave\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: UNYKTOOLBAR - {A057A204-BACC-4D26-969F-2CA187E26982} - C:\PROGRA~1\UNYKTO~1\UNYKTO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O3 - Toolbar: UNYKTOOLBAR - {A057A204-BACC-4D26-969F-2CA187E26982} - C:\PROGRA~1\UNYKTO~1\UNYKTO~1.DLL
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [Netlog Music Tool] "C:\Program Files\Netlog Music Tool\NetlogMusicTool.exe"
O4 - HKCU\..\Run: [StatBar] C:\Program Files\Globe Software\StatBar\StatBar.exe
O4 - HKCU\..\Run: [ManyCam] "C:\Program Files\ManyCam 2.3\ManyCam.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\charles nave\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [oovoo.exe] C:\Program Files\ooVoo\oovoo.exe /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (User 'Default user')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\charles nave\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://www.visiogood.com/jalss/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://webalbum.foto.com/ImageUploader5.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {C42B23DF-334C-4AD0-9AB4-91FF53D04239} (AbImporter Class) - http://v.netlogstatic.com/v2.05/600//s/m/oz/OzDesktopImporter.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
0
je vais pas tarder a me coucher car debout a 5h mais si tu sais m'aider je repasse demain sans faute , merci a toi
bonne nuit
0
totobetourne Messages postés 5592 Date d'inscription dimanche 23 mars 2008 Statut Membre Dernière intervention 6 juin 2012 65
13 mars 2009 à 10:06
recu chef je repasse sans faute comme tu me le dis.

Télécharge ToolBar-S&D ( Merci à Eric_71, Angeldark, Sham_Rock et XmichouX )
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

lors du scan coupe ta connection internet.

* Double-clique sur ToolBar-SD afin de lancer l'installation, un raccourci sera ajouté sur le Bureau.
* Double-clique dessus pour démarrer l'outil; choisis la langue.
* Sous Vista, faire un clic droit et "Exécuter en tant qu'administrateur" (Elévation des privilèges), puis -> Continuer.
* Tape 1 puis sur la touche [Entrée] afin de lancer la suppression.
* Patiente jusqu'à la fin de la recherche.
* À la fin du scan, le rapport s'ouvrira dans le Bloc-notes.
* Poste ce rapport, par copier/coller, dans ta prochaine réponse.
* Le rapport se trouve également sous : C:\TB.txt
0
Salut a toi, je rentre du boulot , merci d'etre toujours la ;)

j'ai donc fais ce que tu m'a dit a la lettre
et voici le rapport

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 2800+ )
BIOS : Version 07.00T
USER : charles nave ( Administrator )
BOOT : Normal boot
Antivirus : AntiVir PersonalEdition Classic Virus Protection 0.0.0.0 (Activated)
Firewall : Sunbelt Personal Firewall 4.6.1845 T (Activated)
C:\ (Local Disk) - NTFS - Total:76 Go (Free:11 Go)
D:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( ven. 13/03/2009|18:34 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\DOCUME~1\CHARLE~1\APPLIC~1\alot
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_0
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_1
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_10
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_11
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_2
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_3
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_4
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_5
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_6
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_7
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_8
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_9
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\configurator
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\postInstallLayout
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\products
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\TimerManager
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\toolbar.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\ToolbarSearch
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Updater
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_0\Button_0.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_0\Button_0.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_1\Button_1.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_1\Button_1.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_10\Button_10.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_10\Button_10.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_11\Button_11.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_11\Button_11.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_2\Button_2.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_2\Button_2.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_3\Button_3.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_3\Button_3.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_4\Button_4.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_4\Button_4.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_5\Button_5.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_5\Button_5.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_6\Button_6.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_6\Button_6.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_7\Button_7.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_7\Button_7.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_8\Button_8.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_8\Button_8.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_9\Button_9.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Button_9\Button_9.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\configurator\configurator.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\configurator\configurator.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\postInstallLayout\postInstallLayout.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\postInstallLayout\postInstallLayout.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\products\products.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\products\products.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_0
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_1
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_2
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_3
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_5
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_6
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_7
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_0\images
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_0\images\alot_icon_35x16.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_1\images
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_1\images\alot_search_24x16.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_2\images
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_2\images\default_226_alot_videos_videosearch.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_3\images
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_3\images\default_227_alot_videos_videovault.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\clear.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\cloudy.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\default_281_alot_weather_widget.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\foggy.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG10.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG102.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG186.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG18C.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG18E.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG191.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG1A1.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG1A9.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG1B3.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG1B9.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG1BF.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG1F8.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG20.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG204.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG232.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG237.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG24.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG26.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG26E.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG29.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG2A.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG2B.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG2D1.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG36.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG365.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG38.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG3F.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG40.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG45.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG47.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG4D.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG50.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG59.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG5D.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG64.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG67.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG77.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG78.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG7C.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG7F.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG82.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG90.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMG99.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMGA2.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMGA3.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMGA8.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMGAE.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMGAF.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMGBA.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMGC.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMGD6.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMGDA.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMGF0.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\IMGF7.tmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\mcloud.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\nclear.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\nmcloud.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\npcloud.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\nrain.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\nshower.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\pcloud.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\rain.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\shower.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_4\images\snow.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_5\images
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_5\images\active_default_430_alot_cam_news.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_5\images\default_430_alot_cam_news.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_6\images
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_6\images\default_412_alot_cam_games.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_7\images
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Button_7\images\default_413_alot_mrkt_camfrog.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\domains.dat
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images\alot_brand.png
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images\spinner.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images\widget_bottom.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images\widget_btnclose0.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images\widget_btnclose1.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images\widget_btnmin0.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images\widget_btnmin1.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images\widget_caption.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images\widget_error_bg.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images\widget_error_close.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Resources\Shared\images\widget_error_icon.bmp
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\TimerManager\TimerManager.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\TimerManager\TimerManager.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\ToolbarSearch\ToolbarSearch.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\ToolbarSearch\ToolbarSearch.xml.backup
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Updater\Updater.xml
C:\DOCUME~1\CHARLE~1\APPLIC~1\alot\Updater\Updater.xml.backup
C:\Program Files\alot
C:\Program Files\alot\alotUninst.exe
C:\Program Files\alot\bin
C:\Program Files\alot\bin\alot.dll

-----------\\ Extensions

(charles nave) - {7378B8C2-FC38-41b8-A8C9-875D1F5B0A24} => imageshack
(charles nave) - {7378B8C2-FC38-41b8-A8C9-875D1F5B0A24} => uploadlibrary


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.google.be/?gws_rd=ssl"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"SearchMigratedDefaultURL"="https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Search Bar"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"


--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\CHARLE~1\Application Data\uTorrent\NOD32 Antivirus 3.0.642 + Updates for Life and Crack.torrent
C:\DOCUME~1\CHARLE~1\Application Data\uTorrent\NOD32 Antivirus 3.0.642 - FINAL + CRACK.torrent
C:\DOCUME~1\CHARLE~1\Bureau\Raccourcis Bureau non utilis‚s\maxtor\Maxtor backup\ELENTIR\G\SAUVEGARDE 19oct\WebcamMax 2.3.0.7 - Full Version Crack
C:\DOCUME~1\CHARLE~1\Bureau\Raccourcis Bureau non utilis‚s\maxtor\Maxtor backup\ELENTIR\G\SAUVEGARDE 19oct\WebcamMax 2.3.0.7 - Full Version Crack\WebcamMax v2.3.0.0
C:\DOCUME~1\CHARLE~1\Cookies\charles_nave@www.cracks[2].txt
C:\DOCUME~1\CHARLE~1\Cookies\charles_nave@www.crack[1].txt
C:\DOCUME~1\CHARLE~1\Cookies\charles_nave@www.keygen[1].txt
C:\DOCUME~1\CHARLE~1\Mes documents\NOD32.Antivirus.v2.51.30.FR.(Version.Windows_XP_2000_2003_NT_32-bit_64-bit).Incl-Crack.rar



1 - "C:\ToolBar SD\TB_1.txt" - ven. 13/03/2009|18:37 - Option : [1]

-----------\\ Fin du rapport a 18:37:31,96
0
pas de news :((
0
totobetourne Messages postés 5592 Date d'inscription dimanche 23 mars 2008 Statut Membre Dernière intervention 6 juin 2012 65
14 mars 2009 à 22:33
enleve tes cracks voila le probleme.

ensuite
relance toolbar mais la appuie sur l option 2. tu obtiens un rapport que tu colles.
0