Virus backdoor dl32

Cortez9126 Messages postés 1 Statut Membre -  
loloetseb Messages postés 5684 Statut Membre -
Bonjour,

Mon ordinateur a un virus que je n'arrive pas enlever. Ce virus type « backdoor » est greffé sur le fichier « system 32 », « dll32.dll ».
C’est le logiciel Malwarebytes qui me l’a trouvé. Il me propose de le supprimer mais lorsque je fais la suppression je n’ai plus d’accès à internet. Avec le message suivant à l’ouverture de Windows « SmapLS_IP_EBP_16 est introuvable dans Kernel32.dll ».

Bref ce virus pique mes données et je suis redirigé sur des sites lors des recherches Google. Quelqu’un aurait-il une solution pour moi ?

Merci d’avance.

>>>>Rapport Malwarebytes :

Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1854
Windows 5.1.2600 Service Pack 3

17/03/2009 11:54:48
mbam-log-2009-03-17 (11-54-48).txt

Type de recherche: Examen rapide
Eléments examinés: 1
Temps écoulé: 2 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\WINDOWS\system32\dll32.dll (Backdoor.Bot) -> Delete on reboot.

>>>>> Rapport Hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:22:40, on 21/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
C:\Documents and Settings\Charles Henri\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Fichiers communs\AOL\1169919938\ee\aolsoftware.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
E:\Program Files\AOL 9.0a\waol.exe
E:\Program Files\AOL 9.0a\shellmon.exe
C:\Program Files\Fichiers communs\Aol\aoltpspd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Charles Henri\Local Settings\Temporary Internet Files\Content.IE5\7X0ABSI5\HiJackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Charles Henri\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [dll] rundll32 dll32,sm
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Sam.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - https://myisc.iscparis.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/44.10/uploader2.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://charon777.free.fr/plugins/hardwaredetection_2_0_4_9.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{26C5B780-ADBA-4220-B5D0-9166D661B63D}: NameServer = 205.188.146.145
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
A voir également:

18 réponses

loloetseb Messages postés 5684 Statut Membre 174
 
Télécharge SDFix sur ton bureau :
ici http://downloads.andymanchesta.com/RemovalTools/SDFix.exe.
ou ici http://download.bleepingcomputer.com/andymanchesta/SDFix.exe­
ou ici http://sdfix.net/SDFix.exe

--> Double-clique sur SDFix.exe et choisis "Install" .

( tuto ici : https://www.malekal.com/slenfbot-still-an-other-irc-bot/ )

Puis une fois l'installe faite ,

Impératif : Démarrer en mode sans echec .

/!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

Comment aller en Mode sans échec :
1) Redémarre ton ordi .
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
4) Choisis la première option : Sans Échec , et valide en tapant sur [Entrée] .
5) Choisis ton compte habituel ( et pas Administrateur ).
attention : pas de connexion possible en mode sans échec , donc copie ou imprime bien la manipe pour éviter les erreurs ...

Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double-clique sur RunThis.bat pour lancer l'outil .
-->Tapes Y pour lancer le script ...
Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire , donc :
presses une touche pour redémarrer quand il te le sera demandé .

Le PC va mettre du temps avant de démarrer ( c'est normale ), après le chargement du Bureau presses une touche lorsque "Finished" s'affiche .

Le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier
C:\SDFix sous le nom "Report.txt".

Poste ce dernier dans ta prochaine réponse accompagné d'un nouveau rapport Hijakcthis pour analyse

Je suis en deplacement professionnel jusqu'a vendredi,si tu as des problemes entre temps ,n'hesites pas à me laisser un message.Je m'occuperais de toi samedi.
1
loloetseb Messages postés 5684 Statut Membre 174
 
télécharge Lop S&D.exe sur ton Bureau.https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

* Double-clique dessus pour lancer l'installation
* Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
* Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)
0
cortez9126
 
Voici le rapport, merci de ton aide.

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : BIOS Date: 07/12/04 11:25:28 Ver: 08.00.09
USER : Charles Henri ( Administrator )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:24 Go (Free:2 Go)
D:\ (Local Disk) - NTFS - Total:165 Go (Free:51 Go)
E:\ (Local Disk) - NTFS - Total:74 Go (Free:25 Go)
F:\ (CD or DVD) - UDF - Total:7 Go (Free:0 Go)
H:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
L:\ (CD or DVD)
M:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 22/03/2009| 9:40 )

--------------------\\ Listing des dossiers dans APPLIC~1

[02/02/2007|18:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[02/02/2007|18:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
[02/02/2007|18:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[22/03/2009|00:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
[02/02/2007|18:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[29/11/2008|22:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[11/03/2009|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[31/05/2008|09:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Age of Empires 3
[11/11/2008|16:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[26/10/2007|13:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
[05/10/2008|10:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
[03/12/2007|17:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[03/12/2007|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/11/2007|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ATI
[14/11/2008|14:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Blizzard
[14/08/2008|11:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BT
[28/01/2009|18:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Electronic Arts
[16/12/2008|15:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fallout3
[12/02/2008|12:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[28/01/2007|11:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[11/01/2009|14:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[26/10/2007|13:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[25/11/2007|14:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[16/03/2009|13:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[01/02/2007|18:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/02/2009|20:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/03/2009|00:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[27/01/2007|15:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Network Associates
[23/01/2007|22:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[02/11/2008|23:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[12/03/2009|01:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[05/01/2009|13:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ubisoft
[27/01/2007|16:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[23/01/2007|22:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[17/12/2008|21:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[31/12/2008|17:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[11/03/2009|10:54] C:\DOCUME~1\CHARLE~1\APPLIC~1\Adobe
[08/05/2007|16:14] C:\DOCUME~1\CHARLE~1\APPLIC~1\Ahead
[11/11/2008|16:04] C:\DOCUME~1\CHARLE~1\APPLIC~1\AOL
[03/12/2007|17:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\Apple Computer
[05/02/2007|18:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\Atari
[20/10/2007|23:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\ATI
[14/08/2008|11:22] C:\DOCUME~1\CHARLE~1\APPLIC~1\BT
[20/11/2007|16:52] C:\DOCUME~1\CHARLE~1\APPLIC~1\Classes de site
[25/03/2007|17:57] C:\DOCUME~1\CHARLE~1\APPLIC~1\DivX
[14/03/2008|15:17] C:\DOCUME~1\CHARLE~1\APPLIC~1\dvdcss
[20/11/2007|16:49] C:\DOCUME~1\CHARLE~1\APPLIC~1\Dynamique
[11/07/2008|11:13] C:\DOCUME~1\CHARLE~1\APPLIC~1\fltk.org
[19/03/2009|21:02] C:\DOCUME~1\CHARLE~1\APPLIC~1\FrostWire
[07/06/2008|18:31] C:\DOCUME~1\CHARLE~1\APPLIC~1\Google
[08/11/2007|19:45] C:\DOCUME~1\CHARLE~1\APPLIC~1\Help
[27/10/2007|18:06] C:\DOCUME~1\CHARLE~1\APPLIC~1\Identities
[05/01/2009|13:15] C:\DOCUME~1\CHARLE~1\APPLIC~1\InstallShield
[23/01/2007|22:20] C:\DOCUME~1\CHARLE~1\APPLIC~1\InterVideo
[02/03/2007|18:28] C:\DOCUME~1\CHARLE~1\APPLIC~1\Lavasoft
[01/12/2008|19:03] C:\DOCUME~1\CHARLE~1\APPLIC~1\LimeWire
[20/07/2008|16:41] C:\DOCUME~1\CHARLE~1\APPLIC~1\Macromedia
[16/03/2009|13:16] C:\DOCUME~1\CHARLE~1\APPLIC~1\Malwarebytes
[11/01/2009|13:17] C:\DOCUME~1\CHARLE~1\APPLIC~1\Media Player Classic
[15/02/2009|13:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\Microsoft
[04/02/2009|20:05] C:\DOCUME~1\CHARLE~1\APPLIC~1\Microsoft Games
[21/01/2009|03:09] C:\DOCUME~1\CHARLE~1\APPLIC~1\Mozilla
[11/11/2008|16:00] C:\DOCUME~1\CHARLE~1\APPLIC~1\Notepad++
[07/06/2008|13:06] C:\DOCUME~1\CHARLE~1\APPLIC~1\Real
[22/11/2008|14:47] C:\DOCUME~1\CHARLE~1\APPLIC~1\Red Alert 3
[01/04/2007|11:21] C:\DOCUME~1\CHARLE~1\APPLIC~1\Screenshot Sender
[19/11/2008|18:30] C:\DOCUME~1\CHARLE~1\APPLIC~1\SecuROM
[20/11/2007|16:48] C:\DOCUME~1\CHARLE~1\APPLIC~1\Sites
[06/01/2009|21:46] C:\DOCUME~1\CHARLE~1\APPLIC~1\Skype
[06/01/2009|21:44] C:\DOCUME~1\CHARLE~1\APPLIC~1\skypePM
[31/10/2008|18:53] C:\DOCUME~1\CHARLE~1\APPLIC~1\SoundSpectrum
[12/10/2008|13:42] C:\DOCUME~1\CHARLE~1\APPLIC~1\Spore
[27/01/2007|09:26] C:\DOCUME~1\CHARLE~1\APPLIC~1\Sun
[27/10/2008|14:57] C:\DOCUME~1\CHARLE~1\APPLIC~1\teamspeak2
[01/02/2009|12:13] C:\DOCUME~1\CHARLE~1\APPLIC~1\temp
[03/09/2008|14:03] C:\DOCUME~1\CHARLE~1\APPLIC~1\Viewpoint
[26/02/2007|17:24] C:\DOCUME~1\CHARLE~1\APPLIC~1\vlc
[28/10/2007|12:02] C:\DOCUME~1\CHARLE~1\APPLIC~1\Windows Desktop Search
[27/10/2007|18:05] C:\DOCUME~1\CHARLE~1\APPLIC~1\Windows Live Writer
[27/01/2007|16:44] C:\DOCUME~1\CHARLE~1\APPLIC~1\You've Got Pictures Screensaver

[28/11/2007|21:58] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[27/10/2007|18:11] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[23/01/2007|18:53] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[21/03/2009 22:15][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-2025429265-839522115-1003.job
[21/03/2009 22:17][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[22/03/2009 09:32][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[13/01/2009|17:36] C:\Program Files\Adobe
[27/02/2009|10:10] C:\Program Files\AOL
[02/02/2009|11:33] C:\Program Files\ATI Technologies
[23/01/2007|22:18] C:\Program Files\AVIcodec
[12/03/2009|11:03] C:\Program Files\Bonjour
[23/01/2007|22:14] C:\Program Files\DAEMON Tools
[02/02/2009|13:54] C:\Program Files\DIFX
[24/02/2009|15:59] C:\Program Files\DivX
[24/01/2007|00:08] C:\Program Files\Eidos
[08/01/2009|15:48] C:\Program Files\Fichiers communs
[12/03/2009|20:02] C:\Program Files\FrostWire
[23/01/2007|23:02] C:\Program Files\GameHouse
[11/11/2008|15:59] C:\Program Files\Google
[23/01/2007|22:16] C:\Program Files\Haali
[23/01/2007|22:17] C:\Program Files\illiminable
[02/02/2009|12:18] C:\Program Files\InstallShield Installation Information
[11/02/2009|21:18] C:\Program Files\Internet Explorer
[23/01/2007|22:19] C:\Program Files\InterVideo
[29/11/2008|22:42] C:\Program Files\iPod
[06/12/2008|10:29] C:\Program Files\Java
[15/12/2007|19:42] C:\Program Files\Lavalys
[02/03/2007|18:28] C:\Program Files\Lavasoft
[27/01/2007|16:44] C:\Program Files\Learn2.com
[01/09/2008|20:00] C:\Program Files\LimeWire
[27/01/2007|20:17] C:\Program Files\Logitech
[11/01/2009|14:10] C:\Program Files\ma-config.com
[16/03/2009|13:16] C:\Program Files\Malwarebytes' Anti-Malware
[24/02/2009|15:59] C:\Program Files\Messenger
[11/11/2008|15:59] C:\Program Files\Messenger Plus! Live
[17/12/2008|21:16] C:\Program Files\Microsoft
[13/09/2007|08:54] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[23/01/2007|18:50] C:\Program Files\microsoft frontpage
[26/12/2007|19:03] C:\Program Files\Microsoft Office
[27/10/2007|18:06] C:\Program Files\Microsoft SQL Server Compact Edition
[11/02/2009|20:11] C:\Program Files\Microsoft Visual Studio
[11/02/2009|20:07] C:\Program Files\Microsoft Visual Studio 8
[12/03/2009|01:06] C:\Program Files\Microsoft Windows OneCare Live
[11/02/2009|20:12] C:\Program Files\Microsoft Works
[02/02/2007|16:18] C:\Program Files\Microsoft.NET
[16/11/2007|14:53] C:\Program Files\MKVTOAVI
[30/08/2008|08:41] C:\Program Files\Movie Maker
[21/03/2009|12:11] C:\Program Files\Mozilla Firefox
[11/02/2009|20:12] C:\Program Files\MSBuild
[13/01/2009|17:34] C:\Program Files\MSECache
[30/08/2008|08:41] C:\Program Files\msn
[23/01/2007|18:44] C:\Program Files\MSN Gaming Zone
[12/11/2008|21:49] C:\Program Files\MSXML 4.0
[18/11/2007|23:57] C:\Program Files\MSXML 6.0
[20/05/2007|13:44] C:\Program Files\Multi_Media
[05/05/2007|15:30] C:\Program Files\Nero
[30/08/2008|08:35] C:\Program Files\NetMeeting
[27/01/2007|15:38] C:\Program Files\Network Associates
[14/06/2008|10:37] C:\Program Files\Neuf
[11/11/2008|16:00] C:\Program Files\Notepad++
[30/08/2008|08:35] C:\Program Files\Outlook Express
[16/03/2009|10:48] C:\Program Files\Panda Security
[24/02/2009|15:59] C:\Program Files\QuickTime Alternative
[24/02/2007|22:21] C:\Program Files\Real
[24/02/2009|15:59] C:\Program Files\Real Alternative
[18/11/2007|10:11] C:\Program Files\Reference Assemblies
[11/11/2008|15:59] C:\Program Files\RegSupreme Pro
[23/01/2007|22:15] C:\Program Files\Ripp-It Codec Pack
[11/01/2009|13:17] C:\Program Files\Satsuki Decoder Pack
[23/01/2007|18:48] C:\Program Files\Services en ligne
[11/03/2009|23:03] C:\Program Files\Spybot - Search & Destroy
[29/01/2007|17:22] C:\Program Files\Steam
[06/05/2007|15:14] C:\Program Files\Teamspeak2_RC2
[11/03/2009|22:56] C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[27/01/2007|16:42] C:\Program Files\TechCity Solutions
[27/01/2007|16:44] C:\Program Files\Viewpoint
[21/10/2007|16:02] C:\Program Files\Virtools
[20/11/2007|16:48] C:\Program Files\Visicom Media
[27/10/2007|18:06] C:\Program Files\Windows Desktop Search
[13/01/2009|17:34] C:\Program Files\Windows Installer Clean Up
[31/12/2008|17:24] C:\Program Files\Windows Live
[28/01/2007|13:31] C:\Program Files\Windows Media Connect 2
[12/03/2009|00:15] C:\Program Files\Windows Media Player
[30/08/2008|08:35] C:\Program Files\Windows NT
[12/11/2007|17:35] C:\Program Files\WinRAR
[24/02/2009|15:59] C:\Program Files\x264
[23/01/2007|18:50] C:\Program Files\xerox
[18/11/2008|21:07] C:\Program Files\Xi
[24/02/2009|15:59] C:\Program Files\Xvid

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[30/01/2007|17:58] C:\Program Files\Fichiers communs\3DO Shared
[16/02/2008|11:26] C:\Program Files\Fichiers communs\Adobe
[25/11/2007|14:49] C:\Program Files\Fichiers communs\Adobe Systems Shared
[05/05/2007|15:30] C:\Program Files\Fichiers communs\Ahead
[11/11/2008|16:05] C:\Program Files\Fichiers communs\AOL
[27/01/2007|16:45] C:\Program Files\Fichiers communs\aolback
[11/11/2008|16:04] C:\Program Files\Fichiers communs\aolshare
[29/11/2008|22:42] C:\Program Files\Fichiers communs\Apple
[20/10/2007|16:47] C:\Program Files\Fichiers communs\ATI Technologies
[11/12/2007|17:26] C:\Program Files\Fichiers communs\Blizzard Entertainment
[27/01/2007|15:38] C:\Program Files\Fichiers communs\Cisco Systems
[23/01/2007|22:24] C:\Program Files\Fichiers communs\Designer
[08/01/2009|15:48] C:\Program Files\Fichiers communs\DirectX
[28/01/2007|11:32] C:\Program Files\Fichiers communs\InstallShield
[27/01/2007|09:26] C:\Program Files\Fichiers communs\Java
[27/01/2007|20:17] C:\Program Files\Fichiers communs\Logitech
[05/03/2009|23:25] C:\Program Files\Fichiers communs\Microsoft Shared
[23/01/2007|18:46] C:\Program Files\Fichiers communs\MSSoap
[27/01/2007|15:38] C:\Program Files\Fichiers communs\Network Associates
[27/01/2007|16:44] C:\Program Files\Fichiers communs\Nullsoft
[12/11/2008|21:55] C:\Program Files\Fichiers communs\ODBC
[07/06/2008|13:04] C:\Program Files\Fichiers communs\Real
[23/01/2007|18:46] C:\Program Files\Fichiers communs\Services
[02/11/2008|23:07] C:\Program Files\Fichiers communs\Skype
[23/01/2007|19:01] C:\Program Files\Fichiers communs\SpeechEngines
[14/06/2008|12:49] C:\Program Files\Fichiers communs\SWF Studio
[15/03/2009|00:57] C:\Program Files\Fichiers communs\System
[17/12/2008|20:25] C:\Program Files\Fichiers communs\Windows Live
[31/12/2008|17:27] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[07/06/2008|13:05] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 55 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\Program Files\Multi_Media
C:\Program Files\Multi_Media\INSTALL.LOG
C:\DOCUME~1\CHARLE~1\Cookies\charles_henri@advertising[1].txt

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-22 09:41:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 951

--------------------\\ Recherche d'autres infections

--------------------\\ KoobFace !

C:\WINDOWS\msmark2.dat
C:\WINDOWS\nlmark2.dat

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\CHARLE~1\Mes documents\crack age of empire
C:\DOCUME~1\CHARLE~1\Mes documents\crack age of empire\empires2.exe



[F:3][D:1]-> C:\DOCUME~1\CHARLE~1\LOCALS~1\Temp
[F:29][D:0]-> C:\DOCUME~1\CHARLE~1\Cookies
[F:362][D:5]-> C:\DOCUME~1\CHARLE~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 22/03/2009| 9:43 - Option : [1]

--------------------\\ Fin du rapport a 9:43:35
0
loloetseb Messages postés 5684 Statut Membre 174
 
Suppression + Hosts

double-clique sur le raccourci Lop S&D présent sur ton Bureau
* Séléctionne la langue souhaitée , puis choisis l'option "Suppression + Hosts"
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)
0
cortez9126
 
Voici le nouveau rapport :


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : BIOS Date: 07/12/04 11:25:28 Ver: 08.00.09
USER : Charles Henri ( Administrator )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:24 Go (Free:1 Go)
D:\ (Local Disk) - NTFS - Total:165 Go (Free:51 Go)
E:\ (Local Disk) - NTFS - Total:74 Go (Free:25 Go)
F:\ (CD or DVD) - UDF - Total:7 Go (Free:0 Go)
H:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
L:\ (CD or DVD)
M:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 22/03/2009|12:02 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\Program Files\Multi_Media\INSTALL.LOG
Supprime! - C:\Program Files\Multi_Media

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Supprime! - C:\DOCUME~1\CHARLE~1\APPLIC~1\Viewpoint
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans APPLIC~1

[02/02/2007|18:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[02/02/2007|18:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
[02/02/2007|18:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[22/03/2009|00:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
[02/02/2007|18:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[29/11/2008|22:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[11/03/2009|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[31/05/2008|09:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Age of Empires 3
[11/11/2008|16:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[26/10/2007|13:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
[05/10/2008|10:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
[03/12/2007|17:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[03/12/2007|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/11/2007|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ATI
[14/11/2008|14:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Blizzard
[14/08/2008|11:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BT
[28/01/2009|18:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Electronic Arts
[16/12/2008|15:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fallout3
[12/02/2008|12:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[28/01/2007|11:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[11/01/2009|14:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[26/10/2007|13:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[25/11/2007|14:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[16/03/2009|13:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[01/02/2007|18:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/02/2009|20:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/03/2009|00:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[27/01/2007|15:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Network Associates
[23/01/2007|22:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[02/11/2008|23:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[12/03/2009|01:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[05/01/2009|13:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ubisoft
[23/01/2007|22:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[17/12/2008|21:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[31/12/2008|17:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[11/03/2009|10:54] C:\DOCUME~1\CHARLE~1\APPLIC~1\Adobe
[08/05/2007|16:14] C:\DOCUME~1\CHARLE~1\APPLIC~1\Ahead
[11/11/2008|16:04] C:\DOCUME~1\CHARLE~1\APPLIC~1\AOL
[03/12/2007|17:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\Apple Computer
[05/02/2007|18:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\Atari
[20/10/2007|23:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\ATI
[14/08/2008|11:22] C:\DOCUME~1\CHARLE~1\APPLIC~1\BT
[20/11/2007|16:52] C:\DOCUME~1\CHARLE~1\APPLIC~1\Classes de site
[25/03/2007|17:57] C:\DOCUME~1\CHARLE~1\APPLIC~1\DivX
[14/03/2008|15:17] C:\DOCUME~1\CHARLE~1\APPLIC~1\dvdcss
[20/11/2007|16:49] C:\DOCUME~1\CHARLE~1\APPLIC~1\Dynamique
[11/07/2008|11:13] C:\DOCUME~1\CHARLE~1\APPLIC~1\fltk.org
[19/03/2009|21:02] C:\DOCUME~1\CHARLE~1\APPLIC~1\FrostWire
[07/06/2008|18:31] C:\DOCUME~1\CHARLE~1\APPLIC~1\Google
[08/11/2007|19:45] C:\DOCUME~1\CHARLE~1\APPLIC~1\Help
[27/10/2007|18:06] C:\DOCUME~1\CHARLE~1\APPLIC~1\Identities
[05/01/2009|13:15] C:\DOCUME~1\CHARLE~1\APPLIC~1\InstallShield
[23/01/2007|22:20] C:\DOCUME~1\CHARLE~1\APPLIC~1\InterVideo
[02/03/2007|18:28] C:\DOCUME~1\CHARLE~1\APPLIC~1\Lavasoft
[01/12/2008|19:03] C:\DOCUME~1\CHARLE~1\APPLIC~1\LimeWire
[20/07/2008|16:41] C:\DOCUME~1\CHARLE~1\APPLIC~1\Macromedia
[16/03/2009|13:16] C:\DOCUME~1\CHARLE~1\APPLIC~1\Malwarebytes
[11/01/2009|13:17] C:\DOCUME~1\CHARLE~1\APPLIC~1\Media Player Classic
[15/02/2009|13:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\Microsoft
[04/02/2009|20:05] C:\DOCUME~1\CHARLE~1\APPLIC~1\Microsoft Games
[21/01/2009|03:09] C:\DOCUME~1\CHARLE~1\APPLIC~1\Mozilla
[11/11/2008|16:00] C:\DOCUME~1\CHARLE~1\APPLIC~1\Notepad++
[07/06/2008|13:06] C:\DOCUME~1\CHARLE~1\APPLIC~1\Real
[22/11/2008|14:47] C:\DOCUME~1\CHARLE~1\APPLIC~1\Red Alert 3
[01/04/2007|11:21] C:\DOCUME~1\CHARLE~1\APPLIC~1\Screenshot Sender
[19/11/2008|18:30] C:\DOCUME~1\CHARLE~1\APPLIC~1\SecuROM
[20/11/2007|16:48] C:\DOCUME~1\CHARLE~1\APPLIC~1\Sites
[06/01/2009|21:46] C:\DOCUME~1\CHARLE~1\APPLIC~1\Skype
[06/01/2009|21:44] C:\DOCUME~1\CHARLE~1\APPLIC~1\skypePM
[31/10/2008|18:53] C:\DOCUME~1\CHARLE~1\APPLIC~1\SoundSpectrum
[12/10/2008|13:42] C:\DOCUME~1\CHARLE~1\APPLIC~1\Spore
[27/01/2007|09:26] C:\DOCUME~1\CHARLE~1\APPLIC~1\Sun
[27/10/2008|14:57] C:\DOCUME~1\CHARLE~1\APPLIC~1\teamspeak2
[01/02/2009|12:13] C:\DOCUME~1\CHARLE~1\APPLIC~1\temp
[26/02/2007|17:24] C:\DOCUME~1\CHARLE~1\APPLIC~1\vlc
[28/10/2007|12:02] C:\DOCUME~1\CHARLE~1\APPLIC~1\Windows Desktop Search
[27/10/2007|18:05] C:\DOCUME~1\CHARLE~1\APPLIC~1\Windows Live Writer
[27/01/2007|16:44] C:\DOCUME~1\CHARLE~1\APPLIC~1\You've Got Pictures Screensaver

[28/11/2007|21:58] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[27/10/2007|18:11] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[23/01/2007|18:53] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[22/03/2009 11:36][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-2025429265-839522115-1003.job
[21/03/2009 22:17][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[22/03/2009 09:32][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[13/01/2009|17:36] C:\Program Files\Adobe
[27/02/2009|10:10] C:\Program Files\AOL
[02/02/2009|11:33] C:\Program Files\ATI Technologies
[23/01/2007|22:18] C:\Program Files\AVIcodec
[12/03/2009|11:03] C:\Program Files\Bonjour
[23/01/2007|22:14] C:\Program Files\DAEMON Tools
[02/02/2009|13:54] C:\Program Files\DIFX
[24/02/2009|15:59] C:\Program Files\DivX
[24/01/2007|00:08] C:\Program Files\Eidos
[08/01/2009|15:48] C:\Program Files\Fichiers communs
[12/03/2009|20:02] C:\Program Files\FrostWire
[23/01/2007|23:02] C:\Program Files\GameHouse
[11/11/2008|15:59] C:\Program Files\Google
[23/01/2007|22:16] C:\Program Files\Haali
[23/01/2007|22:17] C:\Program Files\illiminable
[02/02/2009|12:18] C:\Program Files\InstallShield Installation Information
[11/02/2009|21:18] C:\Program Files\Internet Explorer
[23/01/2007|22:19] C:\Program Files\InterVideo
[29/11/2008|22:42] C:\Program Files\iPod
[06/12/2008|10:29] C:\Program Files\Java
[15/12/2007|19:42] C:\Program Files\Lavalys
[02/03/2007|18:28] C:\Program Files\Lavasoft
[27/01/2007|16:44] C:\Program Files\Learn2.com
[01/09/2008|20:00] C:\Program Files\LimeWire
[27/01/2007|20:17] C:\Program Files\Logitech
[11/01/2009|14:10] C:\Program Files\ma-config.com
[16/03/2009|13:16] C:\Program Files\Malwarebytes' Anti-Malware
[24/02/2009|15:59] C:\Program Files\Messenger
[11/11/2008|15:59] C:\Program Files\Messenger Plus! Live
[17/12/2008|21:16] C:\Program Files\Microsoft
[13/09/2007|08:54] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[23/01/2007|18:50] C:\Program Files\microsoft frontpage
[26/12/2007|19:03] C:\Program Files\Microsoft Office
[27/10/2007|18:06] C:\Program Files\Microsoft SQL Server Compact Edition
[11/02/2009|20:11] C:\Program Files\Microsoft Visual Studio
[11/02/2009|20:07] C:\Program Files\Microsoft Visual Studio 8
[12/03/2009|01:06] C:\Program Files\Microsoft Windows OneCare Live
[11/02/2009|20:12] C:\Program Files\Microsoft Works
[02/02/2007|16:18] C:\Program Files\Microsoft.NET
[16/11/2007|14:53] C:\Program Files\MKVTOAVI
[30/08/2008|08:41] C:\Program Files\Movie Maker
[21/03/2009|12:11] C:\Program Files\Mozilla Firefox
[11/02/2009|20:12] C:\Program Files\MSBuild
[13/01/2009|17:34] C:\Program Files\MSECache
[30/08/2008|08:41] C:\Program Files\msn
[23/01/2007|18:44] C:\Program Files\MSN Gaming Zone
[12/11/2008|21:49] C:\Program Files\MSXML 4.0
[18/11/2007|23:57] C:\Program Files\MSXML 6.0
[05/05/2007|15:30] C:\Program Files\Nero
[30/08/2008|08:35] C:\Program Files\NetMeeting
[27/01/2007|15:38] C:\Program Files\Network Associates
[14/06/2008|10:37] C:\Program Files\Neuf
[11/11/2008|16:00] C:\Program Files\Notepad++
[30/08/2008|08:35] C:\Program Files\Outlook Express
[16/03/2009|10:48] C:\Program Files\Panda Security
[24/02/2009|15:59] C:\Program Files\QuickTime Alternative
[24/02/2007|22:21] C:\Program Files\Real
[24/02/2009|15:59] C:\Program Files\Real Alternative
[18/11/2007|10:11] C:\Program Files\Reference Assemblies
[11/11/2008|15:59] C:\Program Files\RegSupreme Pro
[23/01/2007|22:15] C:\Program Files\Ripp-It Codec Pack
[11/01/2009|13:17] C:\Program Files\Satsuki Decoder Pack
[23/01/2007|18:48] C:\Program Files\Services en ligne
[11/03/2009|23:03] C:\Program Files\Spybot - Search & Destroy
[29/01/2007|17:22] C:\Program Files\Steam
[06/05/2007|15:14] C:\Program Files\Teamspeak2_RC2
[11/03/2009|22:56] C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[27/01/2007|16:42] C:\Program Files\TechCity Solutions
[27/01/2007|16:44] C:\Program Files\Viewpoint
[21/10/2007|16:02] C:\Program Files\Virtools
[20/11/2007|16:48] C:\Program Files\Visicom Media
[27/10/2007|18:06] C:\Program Files\Windows Desktop Search
[13/01/2009|17:34] C:\Program Files\Windows Installer Clean Up
[31/12/2008|17:24] C:\Program Files\Windows Live
[28/01/2007|13:31] C:\Program Files\Windows Media Connect 2
[12/03/2009|00:15] C:\Program Files\Windows Media Player
[30/08/2008|08:35] C:\Program Files\Windows NT
[12/11/2007|17:35] C:\Program Files\WinRAR
[24/02/2009|15:59] C:\Program Files\x264
[23/01/2007|18:50] C:\Program Files\xerox
[18/11/2008|21:07] C:\Program Files\Xi
[24/02/2009|15:59] C:\Program Files\Xvid

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[30/01/2007|17:58] C:\Program Files\Fichiers communs\3DO Shared
[16/02/2008|11:26] C:\Program Files\Fichiers communs\Adobe
[25/11/2007|14:49] C:\Program Files\Fichiers communs\Adobe Systems Shared
[05/05/2007|15:30] C:\Program Files\Fichiers communs\Ahead
[11/11/2008|16:05] C:\Program Files\Fichiers communs\AOL
[27/01/2007|16:45] C:\Program Files\Fichiers communs\aolback
[11/11/2008|16:04] C:\Program Files\Fichiers communs\aolshare
[29/11/2008|22:42] C:\Program Files\Fichiers communs\Apple
[20/10/2007|16:47] C:\Program Files\Fichiers communs\ATI Technologies
[11/12/2007|17:26] C:\Program Files\Fichiers communs\Blizzard Entertainment
[27/01/2007|15:38] C:\Program Files\Fichiers communs\Cisco Systems
[23/01/2007|22:24] C:\Program Files\Fichiers communs\Designer
[08/01/2009|15:48] C:\Program Files\Fichiers communs\DirectX
[28/01/2007|11:32] C:\Program Files\Fichiers communs\InstallShield
[27/01/2007|09:26] C:\Program Files\Fichiers communs\Java
[27/01/2007|20:17] C:\Program Files\Fichiers communs\Logitech
[05/03/2009|23:25] C:\Program Files\Fichiers communs\Microsoft Shared
[23/01/2007|18:46] C:\Program Files\Fichiers communs\MSSoap
[27/01/2007|15:38] C:\Program Files\Fichiers communs\Network Associates
[27/01/2007|16:44] C:\Program Files\Fichiers communs\Nullsoft
[12/11/2008|21:55] C:\Program Files\Fichiers communs\ODBC
[07/06/2008|13:04] C:\Program Files\Fichiers communs\Real
[23/01/2007|18:46] C:\Program Files\Fichiers communs\Services
[02/11/2008|23:07] C:\Program Files\Fichiers communs\Skype
[23/01/2007|19:01] C:\Program Files\Fichiers communs\SpeechEngines
[14/06/2008|12:49] C:\Program Files\Fichiers communs\SWF Studio
[15/03/2009|00:57] C:\Program Files\Fichiers communs\System
[17/12/2008|20:25] C:\Program Files\Fichiers communs\Windows Live
[31/12/2008|17:27] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[07/06/2008|13:05] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 52 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\CHARLE~1\Cookies\charles_henri@advertising[2].txt

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-22 12:03:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 951

--------------------\\ Recherche d'autres infections

--------------------\\ KoobFace !

C:\WINDOWS\msmark2.dat
C:\WINDOWS\nlmark2.dat

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\CHARLE~1\Mes documents\crack age of empire
C:\DOCUME~1\CHARLE~1\Mes documents\crack age of empire\empires2.exe


[F:4][D:2]-> C:\DOCUME~1\CHARLE~1\LOCALS~1\Temp
[F:57][D:0]-> C:\DOCUME~1\CHARLE~1\Cookies
[F:1877][D:5]-> C:\DOCUME~1\CHARLE~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 22/03/2009| 9:43 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 22/03/2009|12:04 - Option : [2]

--------------------\\ Fin du rapport a 12:04:50
0
cortez9126
 
Voici le nouveau rapport :


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : BIOS Date: 07/12/04 11:25:28 Ver: 08.00.09
USER : Charles Henri ( Administrator )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:24 Go (Free:1 Go)
D:\ (Local Disk) - NTFS - Total:165 Go (Free:51 Go)
E:\ (Local Disk) - NTFS - Total:74 Go (Free:25 Go)
F:\ (CD or DVD) - UDF - Total:7 Go (Free:0 Go)
H:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
L:\ (CD or DVD)
M:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 22/03/2009|12:02 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\Program Files\Multi_Media\INSTALL.LOG
Supprime! - C:\Program Files\Multi_Media

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Supprime! - C:\DOCUME~1\CHARLE~1\APPLIC~1\Viewpoint
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans APPLIC~1

[02/02/2007|18:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[02/02/2007|18:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
[02/02/2007|18:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[22/03/2009|00:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
[02/02/2007|18:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[29/11/2008|22:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[11/03/2009|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[31/05/2008|09:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Age of Empires 3
[11/11/2008|16:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[26/10/2007|13:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
[05/10/2008|10:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
[03/12/2007|17:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[03/12/2007|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/11/2007|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ATI
[14/11/2008|14:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Blizzard
[14/08/2008|11:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BT
[28/01/2009|18:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Electronic Arts
[16/12/2008|15:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fallout3
[12/02/2008|12:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[28/01/2007|11:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[11/01/2009|14:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[26/10/2007|13:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[25/11/2007|14:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[16/03/2009|13:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[01/02/2007|18:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/02/2009|20:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/03/2009|00:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[27/01/2007|15:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Network Associates
[23/01/2007|22:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[02/11/2008|23:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[12/03/2009|01:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[05/01/2009|13:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ubisoft
[23/01/2007|22:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[17/12/2008|21:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[31/12/2008|17:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[11/03/2009|10:54] C:\DOCUME~1\CHARLE~1\APPLIC~1\Adobe
[08/05/2007|16:14] C:\DOCUME~1\CHARLE~1\APPLIC~1\Ahead
[11/11/2008|16:04] C:\DOCUME~1\CHARLE~1\APPLIC~1\AOL
[03/12/2007|17:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\Apple Computer
[05/02/2007|18:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\Atari
[20/10/2007|23:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\ATI
[14/08/2008|11:22] C:\DOCUME~1\CHARLE~1\APPLIC~1\BT
[20/11/2007|16:52] C:\DOCUME~1\CHARLE~1\APPLIC~1\Classes de site
[25/03/2007|17:57] C:\DOCUME~1\CHARLE~1\APPLIC~1\DivX
[14/03/2008|15:17] C:\DOCUME~1\CHARLE~1\APPLIC~1\dvdcss
[20/11/2007|16:49] C:\DOCUME~1\CHARLE~1\APPLIC~1\Dynamique
[11/07/2008|11:13] C:\DOCUME~1\CHARLE~1\APPLIC~1\fltk.org
[19/03/2009|21:02] C:\DOCUME~1\CHARLE~1\APPLIC~1\FrostWire
[07/06/2008|18:31] C:\DOCUME~1\CHARLE~1\APPLIC~1\Google
[08/11/2007|19:45] C:\DOCUME~1\CHARLE~1\APPLIC~1\Help
[27/10/2007|18:06] C:\DOCUME~1\CHARLE~1\APPLIC~1\Identities
[05/01/2009|13:15] C:\DOCUME~1\CHARLE~1\APPLIC~1\InstallShield
[23/01/2007|22:20] C:\DOCUME~1\CHARLE~1\APPLIC~1\InterVideo
[02/03/2007|18:28] C:\DOCUME~1\CHARLE~1\APPLIC~1\Lavasoft
[01/12/2008|19:03] C:\DOCUME~1\CHARLE~1\APPLIC~1\LimeWire
[20/07/2008|16:41] C:\DOCUME~1\CHARLE~1\APPLIC~1\Macromedia
[16/03/2009|13:16] C:\DOCUME~1\CHARLE~1\APPLIC~1\Malwarebytes
[11/01/2009|13:17] C:\DOCUME~1\CHARLE~1\APPLIC~1\Media Player Classic
[15/02/2009|13:33] C:\DOCUME~1\CHARLE~1\APPLIC~1\Microsoft
[04/02/2009|20:05] C:\DOCUME~1\CHARLE~1\APPLIC~1\Microsoft Games
[21/01/2009|03:09] C:\DOCUME~1\CHARLE~1\APPLIC~1\Mozilla
[11/11/2008|16:00] C:\DOCUME~1\CHARLE~1\APPLIC~1\Notepad++
[07/06/2008|13:06] C:\DOCUME~1\CHARLE~1\APPLIC~1\Real
[22/11/2008|14:47] C:\DOCUME~1\CHARLE~1\APPLIC~1\Red Alert 3
[01/04/2007|11:21] C:\DOCUME~1\CHARLE~1\APPLIC~1\Screenshot Sender
[19/11/2008|18:30] C:\DOCUME~1\CHARLE~1\APPLIC~1\SecuROM
[20/11/2007|16:48] C:\DOCUME~1\CHARLE~1\APPLIC~1\Sites
[06/01/2009|21:46] C:\DOCUME~1\CHARLE~1\APPLIC~1\Skype
[06/01/2009|21:44] C:\DOCUME~1\CHARLE~1\APPLIC~1\skypePM
[31/10/2008|18:53] C:\DOCUME~1\CHARLE~1\APPLIC~1\SoundSpectrum
[12/10/2008|13:42] C:\DOCUME~1\CHARLE~1\APPLIC~1\Spore
[27/01/2007|09:26] C:\DOCUME~1\CHARLE~1\APPLIC~1\Sun
[27/10/2008|14:57] C:\DOCUME~1\CHARLE~1\APPLIC~1\teamspeak2
[01/02/2009|12:13] C:\DOCUME~1\CHARLE~1\APPLIC~1\temp
[26/02/2007|17:24] C:\DOCUME~1\CHARLE~1\APPLIC~1\vlc
[28/10/2007|12:02] C:\DOCUME~1\CHARLE~1\APPLIC~1\Windows Desktop Search
[27/10/2007|18:05] C:\DOCUME~1\CHARLE~1\APPLIC~1\Windows Live Writer
[27/01/2007|16:44] C:\DOCUME~1\CHARLE~1\APPLIC~1\You've Got Pictures Screensaver

[28/11/2007|21:58] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[27/10/2007|18:11] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[23/01/2007|18:53] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[22/03/2009 11:36][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-2025429265-839522115-1003.job
[21/03/2009 22:17][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[22/03/2009 09:32][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[13/01/2009|17:36] C:\Program Files\Adobe
[27/02/2009|10:10] C:\Program Files\AOL
[02/02/2009|11:33] C:\Program Files\ATI Technologies
[23/01/2007|22:18] C:\Program Files\AVIcodec
[12/03/2009|11:03] C:\Program Files\Bonjour
[23/01/2007|22:14] C:\Program Files\DAEMON Tools
[02/02/2009|13:54] C:\Program Files\DIFX
[24/02/2009|15:59] C:\Program Files\DivX
[24/01/2007|00:08] C:\Program Files\Eidos
[08/01/2009|15:48] C:\Program Files\Fichiers communs
[12/03/2009|20:02] C:\Program Files\FrostWire
[23/01/2007|23:02] C:\Program Files\GameHouse
[11/11/2008|15:59] C:\Program Files\Google
[23/01/2007|22:16] C:\Program Files\Haali
[23/01/2007|22:17] C:\Program Files\illiminable
[02/02/2009|12:18] C:\Program Files\InstallShield Installation Information
[11/02/2009|21:18] C:\Program Files\Internet Explorer
[23/01/2007|22:19] C:\Program Files\InterVideo
[29/11/2008|22:42] C:\Program Files\iPod
[06/12/2008|10:29] C:\Program Files\Java
[15/12/2007|19:42] C:\Program Files\Lavalys
[02/03/2007|18:28] C:\Program Files\Lavasoft
[27/01/2007|16:44] C:\Program Files\Learn2.com
[01/09/2008|20:00] C:\Program Files\LimeWire
[27/01/2007|20:17] C:\Program Files\Logitech
[11/01/2009|14:10] C:\Program Files\ma-config.com
[16/03/2009|13:16] C:\Program Files\Malwarebytes' Anti-Malware
[24/02/2009|15:59] C:\Program Files\Messenger
[11/11/2008|15:59] C:\Program Files\Messenger Plus! Live
[17/12/2008|21:16] C:\Program Files\Microsoft
[13/09/2007|08:54] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[23/01/2007|18:50] C:\Program Files\microsoft frontpage
[26/12/2007|19:03] C:\Program Files\Microsoft Office
[27/10/2007|18:06] C:\Program Files\Microsoft SQL Server Compact Edition
[11/02/2009|20:11] C:\Program Files\Microsoft Visual Studio
[11/02/2009|20:07] C:\Program Files\Microsoft Visual Studio 8
[12/03/2009|01:06] C:\Program Files\Microsoft Windows OneCare Live
[11/02/2009|20:12] C:\Program Files\Microsoft Works
[02/02/2007|16:18] C:\Program Files\Microsoft.NET
[16/11/2007|14:53] C:\Program Files\MKVTOAVI
[30/08/2008|08:41] C:\Program Files\Movie Maker
[21/03/2009|12:11] C:\Program Files\Mozilla Firefox
[11/02/2009|20:12] C:\Program Files\MSBuild
[13/01/2009|17:34] C:\Program Files\MSECache
[30/08/2008|08:41] C:\Program Files\msn
[23/01/2007|18:44] C:\Program Files\MSN Gaming Zone
[12/11/2008|21:49] C:\Program Files\MSXML 4.0
[18/11/2007|23:57] C:\Program Files\MSXML 6.0
[05/05/2007|15:30] C:\Program Files\Nero
[30/08/2008|08:35] C:\Program Files\NetMeeting
[27/01/2007|15:38] C:\Program Files\Network Associates
[14/06/2008|10:37] C:\Program Files\Neuf
[11/11/2008|16:00] C:\Program Files\Notepad++
[30/08/2008|08:35] C:\Program Files\Outlook Express
[16/03/2009|10:48] C:\Program Files\Panda Security
[24/02/2009|15:59] C:\Program Files\QuickTime Alternative
[24/02/2007|22:21] C:\Program Files\Real
[24/02/2009|15:59] C:\Program Files\Real Alternative
[18/11/2007|10:11] C:\Program Files\Reference Assemblies
[11/11/2008|15:59] C:\Program Files\RegSupreme Pro
[23/01/2007|22:15] C:\Program Files\Ripp-It Codec Pack
[11/01/2009|13:17] C:\Program Files\Satsuki Decoder Pack
[23/01/2007|18:48] C:\Program Files\Services en ligne
[11/03/2009|23:03] C:\Program Files\Spybot - Search & Destroy
[29/01/2007|17:22] C:\Program Files\Steam
[06/05/2007|15:14] C:\Program Files\Teamspeak2_RC2
[11/03/2009|22:56] C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[27/01/2007|16:42] C:\Program Files\TechCity Solutions
[27/01/2007|16:44] C:\Program Files\Viewpoint
[21/10/2007|16:02] C:\Program Files\Virtools
[20/11/2007|16:48] C:\Program Files\Visicom Media
[27/10/2007|18:06] C:\Program Files\Windows Desktop Search
[13/01/2009|17:34] C:\Program Files\Windows Installer Clean Up
[31/12/2008|17:24] C:\Program Files\Windows Live
[28/01/2007|13:31] C:\Program Files\Windows Media Connect 2
[12/03/2009|00:15] C:\Program Files\Windows Media Player
[30/08/2008|08:35] C:\Program Files\Windows NT
[12/11/2007|17:35] C:\Program Files\WinRAR
[24/02/2009|15:59] C:\Program Files\x264
[23/01/2007|18:50] C:\Program Files\xerox
[18/11/2008|21:07] C:\Program Files\Xi
[24/02/2009|15:59] C:\Program Files\Xvid

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[30/01/2007|17:58] C:\Program Files\Fichiers communs\3DO Shared
[16/02/2008|11:26] C:\Program Files\Fichiers communs\Adobe
[25/11/2007|14:49] C:\Program Files\Fichiers communs\Adobe Systems Shared
[05/05/2007|15:30] C:\Program Files\Fichiers communs\Ahead
[11/11/2008|16:05] C:\Program Files\Fichiers communs\AOL
[27/01/2007|16:45] C:\Program Files\Fichiers communs\aolback
[11/11/2008|16:04] C:\Program Files\Fichiers communs\aolshare
[29/11/2008|22:42] C:\Program Files\Fichiers communs\Apple
[20/10/2007|16:47] C:\Program Files\Fichiers communs\ATI Technologies
[11/12/2007|17:26] C:\Program Files\Fichiers communs\Blizzard Entertainment
[27/01/2007|15:38] C:\Program Files\Fichiers communs\Cisco Systems
[23/01/2007|22:24] C:\Program Files\Fichiers communs\Designer
[08/01/2009|15:48] C:\Program Files\Fichiers communs\DirectX
[28/01/2007|11:32] C:\Program Files\Fichiers communs\InstallShield
[27/01/2007|09:26] C:\Program Files\Fichiers communs\Java
[27/01/2007|20:17] C:\Program Files\Fichiers communs\Logitech
[05/03/2009|23:25] C:\Program Files\Fichiers communs\Microsoft Shared
[23/01/2007|18:46] C:\Program Files\Fichiers communs\MSSoap
[27/01/2007|15:38] C:\Program Files\Fichiers communs\Network Associates
[27/01/2007|16:44] C:\Program Files\Fichiers communs\Nullsoft
[12/11/2008|21:55] C:\Program Files\Fichiers communs\ODBC
[07/06/2008|13:04] C:\Program Files\Fichiers communs\Real
[23/01/2007|18:46] C:\Program Files\Fichiers communs\Services
[02/11/2008|23:07] C:\Program Files\Fichiers communs\Skype
[23/01/2007|19:01] C:\Program Files\Fichiers communs\SpeechEngines
[14/06/2008|12:49] C:\Program Files\Fichiers communs\SWF Studio
[15/03/2009|00:57] C:\Program Files\Fichiers communs\System
[17/12/2008|20:25] C:\Program Files\Fichiers communs\Windows Live
[31/12/2008|17:27] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[07/06/2008|13:05] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 52 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\CHARLE~1\Cookies\charles_henri@advertising[2].txt

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-22 12:03:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 951

--------------------\\ Recherche d'autres infections

--------------------\\ KoobFace !

C:\WINDOWS\msmark2.dat
C:\WINDOWS\nlmark2.dat

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\CHARLE~1\Mes documents\crack age of empire
C:\DOCUME~1\CHARLE~1\Mes documents\crack age of empire\empires2.exe


[F:4][D:2]-> C:\DOCUME~1\CHARLE~1\LOCALS~1\Temp
[F:57][D:0]-> C:\DOCUME~1\CHARLE~1\Cookies
[F:1877][D:5]-> C:\DOCUME~1\CHARLE~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 22/03/2009| 9:43 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 22/03/2009|12:04 - Option : [2]

--------------------\\ Fin du rapport a 12:04:50
0
loloetseb Messages postés 5684 Statut Membre 174
 
Télécharge Superantispyware (SAS)

Choisis "enregistrer" et enregistre-le sur ton bureau.

Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

Créé une icône sur le bureau.

Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
- Sous Configuration and Preferences, clique sur le bouton "Preferences"
- Clique sur l'onglet "Scanning Control "
- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
- Laisse les autres lignes décochées.

- Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

- Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

Dans la colonne de gauche, coche C:\Fixed Drive.

Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

Pour recopier les informations sur le forum, fais ceci :

- après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
- Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

- Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

- Copie son contenu dans ta réponse.

Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.

Ensuite

Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

-> http://images.malwareremoval.com/random/RSIT.exe

! Déconnecte toi et ferme toutes tes applications en cours !

Double-clique sur " RSIT.exe " pour le lancer .

-> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

* Devant l'option "List files/folders created ..." , tu choisis : 2 months

* clique ensuite sur " Continue " pour lancer l'analyse ...

-> laisse faire le scan et ne touche pas au PC ...

Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

Important : poste un rapport, puis l'autre dans la réponse suivante
Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
cortez9126
 
Voici le rapport de Super AntiSpyware, je vais faire le 2e maintenant.

Application Version : 4.25.1014

Core Rules Database Version : 3808
Trace Rules Database Version: 1763

Scan type : Complete Scan
Total Scan Time : 01:05:55

Memory items scanned : 651
Memory threats detected : 0
Registry items scanned : 7045
Registry threats detected : 4
File items scanned : 78773
File threats detected : 22

Trojan.Agent/Gen-Loader
[dll] C:\WINDOWS\SYSTEM32\DLL32.DLL
C:\WINDOWS\SYSTEM32\DLL32.DLL

Adware.Tracking Cookie
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@aolfr.122.2o7[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@bluestreak[2].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@tradedoubler[2].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@msnaccountservices.112.2o7[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@xiti[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@at.atwola[2].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@weborama[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@tacoda[2].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@smartadserver[2].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@atdmt[2].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@adtech[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@cetelem.solution.weborama[2].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@msnportal.112.2o7[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@adserver.aol[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@advertising[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@doubleclick[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@fr.at.atwola[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@atwola[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@mediaplex[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@ads.canalblog[1].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@stats.canalblog[1].txt

Adware.MyWebSearch/FunWebProducts
HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}
HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\TreatAs

Trojan.DNSChanger-Codec
HKU\S-1-5-21-1177238915-2025429265-839522115-1003\Software\fcn
0
cortez9126
 
fichier log :

Logfile of random's system information tool 1.06 (written by random/random)
Run by Charles Henri at 2009-03-22 14:38:01
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 2 GB (8%) free of 25 GB
Total RAM: 1791 MB (63% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-2025429265-839522115-1003.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2008-06-11 61816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-06-07 308856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-06 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C56CB6B0-0D96-11D6-8C65-B2868B609932}]
NTIECatcher Class - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll [2005-09-08 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-06 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-06 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-07-26 77824]
"ShStatEXE"=C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE [2004-09-22 94208]
"McAfeeUpdaterUI"=C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe [2004-08-06 139320]
"Network Associates Error Reporting Service"=C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe [2003-10-07 147514]
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2005-07-19 221184]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-06 136600]
"DAEMON Tools"=D:\Program Files\DAEMON Tools\daemon.exe [2005-12-10 133016]
"QuickTime Task"=C:\Program Files\QuickTime Alternative\qttask.exe [2008-11-04 413696]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe [2005-09-03 94208]
"Google Update"=C:\Documents and Settings\Charles Henri\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-19 133104]
"MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-02-17 1830128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
D:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2008-11-23 203720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Fichiers communs\AOL\1169919938\ee\AOLSoftware.exe [2006-11-17 50736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
D:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Program Files\Logitech\Video\ISStart.exe [2005-06-08 458752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime Alternative\qttask.exe [2008-11-04 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe /nosplash /minimized []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.lnk]
C:\PROGRA~1\FICHIE~1\Adobe\CALIBR~1\ADOBEG~1.EXE [1999-11-04 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AOL 9.0 Icône AOL.lnk]
C:\PROGRA~1\AOL9~1.0A\aoltray.exe -check []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AOL Compagnon.lnk]
C:\PROGRA~1\AOLCOM~1\COMPAN~1.EXE /s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE [2002-05-23 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [2001-02-13 83360]

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Sam.lnk - C:\Program Files\Silicon Image\Sam\sam.jar
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-09-29 122880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 267304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 294400]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Fichiers communs\AOL\ACS\AOLacsd.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL 9.0"
"D:\Program Files\Steam\SteamApps\mcgenetik91\counter-strike source\hl2.exe"="D:\Program Files\Steam\SteamApps\mcgenetik91\counter-strike source\hl2.exe:*:Enabled:hl2"
"D:\Program Files\eMule\emule.exe"="D:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"D:\Program Files\Steam\SteamApps\christophe74\counter-strike\hl.exe"="D:\Program Files\Steam\SteamApps\christophe74\counter-strike\hl.exe:*:Enabled:Half-Life Launcher"
"E:\Program Files\EA Games\Battlefield 1942\BF1942.exe"="E:\Program Files\EA Games\Battlefield 1942\BF1942.exe:*:Enabled:BF1942"
"D:\Program Files\Steam\SteamApps\christophe74\condition zero\hl.exe"="D:\Program Files\Steam\SteamApps\christophe74\condition zero\hl.exe:*:Enabled:Half-Life Launcher"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Exécuter une DLL en tant qu'application"
"C:\Program Files\Fichiers communs\AOL\1169919938\ee\aolsoftware.exe"="C:\Program Files\Fichiers communs\AOL\1169919938\ee\aolsoftware.exe:*:Enabled:AOL Shared Components"
"D:\Program Files\Steam\steam.exe"="D:\Program Files\Steam\steam.exe:*:Enabled:Steam"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AOL 9.0 VR\waol.exe"="C:\Program Files\AOL 9.0 VR\waol.exe:*:Enabled:AOL"
"C:\Program Files\Fichiers communs\AOL\TopSpeed\3.0\aoltpsd3.exe"="C:\Program Files\Fichiers communs\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed"
"C:\Program Files\Fichiers communs\AOL\Loader\aolload.exe"="C:\Program Files\Fichiers communs\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\Fichiers communs\AOL\System Information\sinf.exe"="C:\Program Files\Fichiers communs\AOL\System Information\sinf.exe:*:Enabled:AOL System Information"
"D:\Program Files\Steam\SteamApps\common\lost planet dx9 trial\LostPlanetDX9.exe"="D:\Program Files\Steam\SteamApps\common\lost planet dx9 trial\LostPlanetDX9.exe:*:Enabled:LostPlanetDX9"
"D:\Program Files\Steam\SteamApps\mcgenetik91\day of defeat source\hl2.exe"="D:\Program Files\Steam\SteamApps\mcgenetik91\day of defeat source\hl2.exe:*:Enabled:hl2"
"D:\World of Warcraft\Repair.exe"="D:\World of Warcraft\Repair.exe:*:Enabled:Blizzard Repair Utility"
"E:\Warcraft III\Warcraft III.exe"="E:\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Documents and Settings\Charles Henri\Bureau\Warcraft III.exe"="C:\Documents and Settings\Charles Henri\Bureau\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"D:\World of Warcraft\ssWOWirc\mirc.exe"="D:\World of Warcraft\ssWOWirc\mirc.exe:*:Enabled:mIRC"
"E:\Program Files\Microsoft Games\Age of Empires III\age3.exe"="E:\Program Files\Microsoft Games\Age of Empires III\age3.exe:*:Enabled:Age of Empires 3"
"D:\Program Files\BT Softphone 2\BTSoftphone2.exe"="D:\Program Files\BT Softphone 2\BTSoftphone2.exe:*:Enabled:BTSoftphone2"
"D:\Program Files\LimeWire\LimeWire.exe"="D:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\AOL 9.0a\waol.exe"="C:\Program Files\AOL 9.0a\waol.exe:*:Enabled:AOL"
"D:\Program Files\iTunes\iTunes.exe"="D:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\FrostWire\FrostWire.exe"="C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire"
"C:\Documents and Settings\Charles Henri\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll"="C:\Documents and Settings\Charles Henri\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin"
"C:\Documents and Settings\Charles Henri\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\Charles Henri\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"E:\Program Files\Microsoft Games\Gears Of War\Binaries\WarGame-G4WLive.exe"="E:\Program Files\Microsoft Games\Gears Of War\Binaries\WarGame-G4WLive.exe:*:Enabled:Gears of War"
"C:\Program Files\ma-config.com\maconfservice.exe"="C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"D:\World of Warcraft\Launcher.exe"="D:\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Fichiers communs\AOL\ACS\AOLacsd.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL 9.0"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AOL 9.0a\waol.exe"="C:\Program Files\AOL 9.0a\waol.exe:*:Enabled:AOL"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
shell\AutoRun\command - L:\autorun.exe
shell\directx\command - L:\DirectX9\dxsetup.exe
shell\setup\command - L:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{36fc82af-d672-11dc-a0f7-00112f2afcde}]
shell\Auto\command - G:\AdobeR.exe e
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e7aa3ec7-ab08-11db-8900-806d6172696f}]
shell\AutoRun\command - J:\setup.exe

======List of files/folders created in the last 2 months======

2009-03-22 14:38:01 ----D---- C:\rsit
2009-03-22 14:38:01 ----D---- C:\Program Files\trend micro
2009-03-22 12:51:17 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-03-22 12:51:08 ----D---- C:\Program Files\SUPERAntiSpyware
2009-03-22 12:51:08 ----D---- C:\Documents and Settings\Charles Henri\Application Data\SUPERAntiSpyware.com
2009-03-22 12:50:44 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
2009-03-22 12:02:25 ----D---- C:\Documents and Settings\Charles Henri\Application Data\Viewpoint
2009-03-22 09:40:17 ----A---- C:\lopR.txt
2009-03-22 09:39:20 ----D---- C:\Lop SD
2009-03-22 00:03:36 ----A---- C:\WINDOWS\ntbtlog.txt
2009-03-16 13:16:15 ----D---- C:\Documents and Settings\Charles Henri\Application Data\Malwarebytes
2009-03-16 13:16:09 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-03-16 13:16:09 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-03-16 11:41:10 ----D---- C:\WINDOWS\BDOSCAN8
2009-03-14 15:32:07 ----D---- C:\Program Files\Panda Security
2009-03-12 01:06:22 ----D---- C:\Program Files\Microsoft Windows OneCare Live
2009-03-12 00:15:43 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-03-12 00:15:37 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-03-12 00:15:09 ----HDC---- C:\WINDOWS\$NtUninstallKB959772_WM11$
2009-03-11 22:56:02 ----D---- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2009-02-27 10:10:40 ----D---- C:\Program Files\AOL
2009-02-26 01:32:56 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-02-11 21:19:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
2009-02-11 20:12:44 ----D---- C:\Program Files\Microsoft Works
2009-02-11 20:11:43 ----D---- C:\Program Files\Microsoft Visual Studio
2009-02-11 20:07:45 ----D---- C:\Program Files\Microsoft Visual Studio 8
2009-02-11 20:06:11 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-02-02 14:01:54 ----D---- C:\Documents and Settings\Charles Henri\Application Data\Microsoft Games
2009-02-02 13:54:40 ----D---- C:\Program Files\DIFX
2009-01-28 18:25:50 ----D---- C:\Documents and Settings\All Users\Application Data\Electronic Arts
2009-01-26 00:03:05 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$

======List of files/folders modified in the last 2 months======

2009-03-22 14:38:01 ----D---- C:\Program Files
2009-03-22 14:24:56 ----A---- C:\WINDOWS\win.ini
2009-03-22 14:13:27 ----D---- C:\WINDOWS\Prefetch
2009-03-22 14:12:36 ----D---- C:\WINDOWS\Temp
2009-03-22 14:11:36 ----D---- C:\WINDOWS\system32
2009-03-22 14:10:33 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-03-22 12:52:49 ----D---- C:\WINDOWS\system32\CatRoot2
2009-03-22 12:51:12 ----SHD---- C:\WINDOWS\Installer
2009-03-22 12:50:44 ----D---- C:\Program Files\Fichiers communs
2009-03-22 09:33:22 ----D---- C:\WINDOWS
2009-03-22 00:05:11 ----SHD---- C:\RECYCLER
2009-03-21 22:43:18 ----A---- C:\WINDOWS\NeroDigital.ini
2009-03-21 12:11:04 ----D---- C:\Program Files\Mozilla Firefox
2009-03-19 21:02:52 ----D---- C:\Documents and Settings\Charles Henri\Application Data\FrostWire
2009-03-17 12:12:46 ----SHD---- C:\System Volume Information
2009-03-17 12:12:46 ----D---- C:\WINDOWS\system32\Restore
2009-03-17 11:56:07 ----D---- C:\WINDOWS\system32\drivers
2009-03-16 15:50:59 ----SHD---- C:\WINDOWS\CSC
2009-03-16 11:41:13 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-03-16 11:41:10 ----HD---- C:\WINDOWS\inf
2009-03-15 00:58:07 ----RSD---- C:\WINDOWS\assembly
2009-03-15 00:57:11 ----D---- C:\Program Files\Fichiers communs\System
2009-03-12 21:27:05 ----D---- C:\WINDOWS\Debug
2009-03-12 21:12:34 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-03-12 20:02:52 ----D---- C:\Program Files\FrostWire
2009-03-12 11:03:30 ----D---- C:\Program Files\Bonjour
2009-03-12 01:07:11 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-12 01:06:46 ----SD---- C:\WINDOWS\system32\Microsoft
2009-03-12 00:15:20 ----D---- C:\Program Files\Windows Media Player
2009-03-11 23:03:24 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-03-11 10:54:35 ----D---- C:\Documents and Settings\Charles Henri\Application Data\Adobe
2009-03-11 10:54:35 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-03-11 06:52:19 ----HD---- C:\WINDOWS\$hf_mig$
2009-03-05 23:25:51 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-02-27 22:07:11 ----D---- C:\WINDOWS\system32\wbem
2009-02-27 22:07:10 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-02-25 12:55:00 ----A---- C:\WINDOWS\system32\MRT.exe
2009-02-24 15:59:21 ----D---- C:\Program Files\Xvid
2009-02-24 15:59:21 ----D---- C:\Program Files\x264
2009-02-24 15:59:20 ----D---- C:\Program Files\Real Alternative
2009-02-24 15:59:20 ----D---- C:\Program Files\QuickTime Alternative
2009-02-24 15:59:19 ----D---- C:\Program Files\Messenger
2009-02-24 15:59:18 ----D---- C:\Program Files\DivX
2009-02-15 13:33:31 ----SD---- C:\Documents and Settings\Charles Henri\Application Data\Microsoft
2009-02-11 21:18:37 ----D---- C:\Program Files\Internet Explorer
2009-02-11 21:18:20 ----D---- C:\WINDOWS\ie7updates
2009-02-11 20:16:19 ----D---- C:\WINDOWS\SHELLNEW
2009-02-11 20:13:19 ----D---- C:\WINDOWS\system32\config
2009-02-11 20:12:28 ----D---- C:\WINDOWS\WinSxS
2009-02-11 20:12:23 ----D---- C:\Program Files\MSBuild
2009-02-11 20:10:49 ----RSD---- C:\WINDOWS\Fonts
2009-02-11 20:10:29 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-02-04 16:25:24 ----D---- C:\WINDOWS\system32\DirectX
2009-02-02 14:21:35 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-02-02 14:21:13 ----RSH---- C:\boot.ini
2009-02-02 13:54:34 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-02-02 12:18:10 ----HD---- C:\Program Files\InstallShield Installation Information
2009-02-02 11:33:44 ----D---- C:\Program Files\ATI Technologies
2009-02-01 12:13:19 ----D---- C:\Documents and Settings\Charles Henri\Application Data\temp
2009-01-26 06:59:53 ----D---- C:\WINDOWS\Microsoft.NET
2009-01-26 00:08:49 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-26 00:08:10 ----D---- C:\WINDOWS\system32\en-us
2009-01-26 00:08:07 ----D---- C:\WINDOWS\system32\XPSViewer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;Pilote de processeur AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43520]
R1 NaiAvTdi1;NaiAvTdi1; C:\WINDOWS\system32\drivers\mvstdi5x.sys [2004-09-22 58048]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-07-26 2324160]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-09-29 2456064]
R3 CamDrL;Logitech QuickCam Pro 3000(CamDrl); C:\WINDOWS\system32\DRIVERS\Camdrl.sys [2004-10-08 326656]
R3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2008-11-18 223128]
R3 EntDrv51;EntDrv51; \??\C:\WINDOWS\system32\drivers\EntDrv51.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2005-05-27 22016]
R3 ms_mpu401;Pilote UART MIDI MPU-401 Microsoft; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NaiAvFilter1;NaiAvFilter1; C:\WINDOWS\system32\drivers\naiavf5x.sys [2004-09-22 108256]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-07-26 33280]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-07-26 12928]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
S1 wceusbsh;Pilote d'hôte USB série pour Windows CE; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-14 32128]
S3 arblinew;arblinew; C:\WINDOWS\system32\drivers\arblinew.sys []
S3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 ATIAVAIW;ATI T200 Unified AVStream service; C:\WINDOWS\system32\DRIVERS\atinavt2.sys [2007-01-05 168832]
S3 atinrvxx;ATI WDM Rage Theater Video (Microsoft Corporation); C:\WINDOWS\system32\DRIVERS\atinrvxx.sys [2004-08-03 104960]
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys []
S3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 iatmunin;iatmunin; \??\C:\DOCUME~1\CHARLE~1\LOCALS~1\Temp\iatmunin.sys []
S3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-28 12288]
S3 MPE;Filtre BDA MPE; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-13 15232]
S3 msgame;Activateur de port HID vers manette de jeu Sidewinder; C:\WINDOWS\system32\DRIVERS\msgame.sys [2001-08-17 35200]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 MVDCODEC;ATI WDM Specialized MVD Codec (Microsoft Corporation); C:\WINDOWS\system32\DRIVERS\atinmdxx.sys [2004-08-03 13824]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 sdcplh;sdcplh; C:\WINDOWS\System32\drivers\sdcplh.sys [2008-03-20 72116]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-10-01 32000]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AOL ACS;AOL Connectivity Service; C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe [2006-10-23 46640]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-09-29 483328]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-06 152984]
R2 McAfeeFramework;Service Framework McAfee; C:\Program Files\Network Associates\Common Framework\FrameworkService.exe [2004-08-06 102463]
R2 McShield;Network Associates McShield; C:\Program Files\Network Associates\VirusScan\Mcshield.exe [2004-09-22 221191]
R2 McTaskManager;Network Associates Task Manager; C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe [2004-09-22 28672]
R2 StarWindServiceAE;StarWind AE Service; D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 WANMiniportService;WAN Miniport (ATW) Service; C:\WINDOWS\wanmpsvc.exe [2003-08-27 65536]
R2 WSearch;Recherche Windows; C:\WINDOWS\system32\SearchIndexer.exe [2007-02-05 300032]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2007-09-28 593920]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe [2007-11-25 68096]
S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2009-01-24 216232]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

-----------------EOF-----------------
0
cortez9126
 
fichier info :

info.txt logfile of random's system information tool 1.06 2009-03-22 14:38:04

======Uninstall list======

-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
Ad-Aware SE Personal-->C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Photoshop CS-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe" -l0x40c
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Age of Empires III-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}
AOL - Assistant de désinstallation-->C:\Program Files\Fichiers communs\AOL\uninstaller.exe
AOL (France)-->C:\Program Files\Fichiers communs\aolshare\Aolunins_fr.exe
AOL Auto-diagnostic-->C:\Program Files\TechCity Solutions\AOLSAV\uninstall.exe
AOL Coach Version 1.0(Build:20040229.1 fr)-->"C:\Program Files\Fichiers communs\aolshare\Coach\AolCInUn.exe" -lang="fr-fr"
Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
ATI Catalyst Control Center-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
ATI HydraVision-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}\setup.exe"
ATI Parental Control & Encoder-->MsiExec.exe /I{36CDA33B-909B-4719-97D1-C4B99309BDC7}
AVIcodec (remove only)-->"C:\Program Files\AVIcodec\uninst.exe"
AVIVO Codecs-->MsiExec.exe /X{C941F1F1-25B3-4DF5-83E6-888C51A1AAB6}
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
CCleaner (remove only)-->"D:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Command & Conquer™ Alerte Rouge 3-->MsiExec.exe /X{296D8550-CB06-48E4-9A8B-E5034FB64715}
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
CoreAAC Audio Decoder (remove only)-->"C:\WINDOWS\system32\CoreAAC-uninstall.exe"
Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Counter-Strike: Source-->MsiExec.exe /I{9580813D-94B1-4C28-9426-A441E2BB29A5}
Destinator Console-->C:\DESTIN~1\INSTAL~1\UNWISE.EXE C:\DESTIN~1\INSTAL~1\INSTALL.LOG
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
eMule-->"D:\Program Files\eMule\Uninstall.exe"
EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
Fallout 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{974C4B12-4D02-4879-85E0-61C95CC63E9E}\setup.exe" -l0x40c -removeonly
FrostWire 4.17.2-->C:\Program Files\FrostWire\Uninstall.exe
Gears of War-->C:\Program Files\InstallShield Installation Information\{1170D24F-42B7-40CF-AA1B-6395CE562354}\Setup.exe -runfromtemp -l0x040c
Google Earth-->MsiExec.exe /I{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}
Google Talk (remove only)-->"C:\Program Files\Google\Google Talk\uninstall.exe"
Google Talk Plugin-->MsiExec.exe /I{B279F2F1-3B2F-3A96-AC11-5743CD43DCCB}
Haali Media Splitter-->"C:\Program Files\Haali\MatroskaSplitter\uninstall.exe"
HijackThis 2.0.2-->"C:\Documents and Settings\Charles Henri\Local Settings\Temporary Internet Files\Content.IE5\7X0ABSI5\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
InterVideo WinDVD 4-->"C:\Program Files\InstallShield Installation Information\{98E8A2EF-4EAE-43B8-A172-74842B764777}\setup.exe" REMOVEALL
iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
Ivalice Launcher Version 11-->"D:\Program Files\World of Warcraft\unins000.exe"
J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
Java 2 Runtime Environment, SE v1.4.2_02-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142020}
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Learn2 Player (Uninstall Only)-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
LFP MANAGER 09-->D:\Program Files\EA SPORTS\LFP MANAGER 09\eauninstall.exe
LFP Manager 2004-->D:\Program Files\EA SPORTS\LFP Manager 2004\EAUninstall.exe
Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
Ma-Config.com-->MsiExec.exe /X{EC77A270-FD05-42F8-9E81-ADC3791F5797}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee VirusScan Enterprise-->MsiExec.exe /I{4DCA2739-9D16-4B55-808C-E72CD70A5BD3}
Messenger Plus! Live-->"D:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0 French Language Pack-->MsiExec.exe /X{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}
Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{929CE49F-1CA7-4CF3-A9A1-6D757443C63F}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
MKV TO AVI CONVERTER version 3.1-->"C:\Program Files\MKVTOAVI\unins000.exe"
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0-->C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 French Language Pack\setup.exe
Mozilla Firefox (3.0.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Need for Speed Underground 2-->E:\Program Files\EA GAMES\Need for Speed Underground 2\EAUninstall.exe
Nero 7 Premium-->MsiExec.exe /I{4781569D-5404-1F26-4B2B-6DF444441031}
Net Transport 1.94.282-->"C:\Program Files\Xi\NetTransport 2\unins000.exe"
Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
NVIDIA Drivers-->C:\WINDOWS\system32\NVUninst.exe UninstallGUI
oggcodecs 0.71.0946-->C:\Program Files\illiminable\oggcodecs\uninst.exe
Package de pilotes Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)-->C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\amdk8_1F9DE4E49C97F59EE9F75C34E0E91E568FC9EEB2\amdk8.inf
PL-2303 USB-to-Serial-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\Setup.exe" -l0x9 Installed
Pro Evolution Soccer 6-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{EBB794ED-D282-4334-92FB-254481EFF514} /l1036
Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
QuickTime Alternative 1.76-->"C:\Program Files\QuickTime Alternative\unins000.exe"
QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
Real Alternative 1.51 Lite-->"C:\Program Files\Real Alternative\unins000.exe"
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
RegSupreme Pro-->"C:\Program Files\RegSupreme Pro\unins000.exe"
Ripp-It Codec Pack v 4.2.5-->C:\Program Files\Ripp-It Codec Pack\uninst.exe
Satsuki Decoder Pack 4000-->C:\Program Files\Satsuki Decoder Pack\Uninstall.exe
Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
Security Update for 2007 Microsoft Office System (KB958439)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {6491B8AA-D11C-4648-A461-6234B31EB7E2}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Microsoft Office Excel 2007 (KB958437)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {648FC016-2D6B-4A16-8D87-404533642F4B}
Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
SPORE™-->"C:\Program Files\InstallShield Installation Information\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}\SPORESetup.exe" -runfromtemp -l0x040c -removeonly
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Steam(TM)-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
Update for Office 2007 (KB946691)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb962871)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {297857BF-4011-449B-BD74-DB64D182821C}
VideoLAN VLC media player 0.8.6d-->D:\Program Files\VideoLAN\VLC\uninstall.exe
Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
Virtools 3D Life Player-->C:\Program Files\Virtools\3D Life Player\WebplayerConfig.exe -u
Windows Desktop Search 3.01-->"C:\WINDOWS\$NtUninstallKB917013$\spuninst\spuninst.exe"
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Installer Clean Up-->MsiExec.exe /X{121634B0-2F4B-11D3-ADA3-00C04F52DD52}
Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Presentation Foundation Language Pack (FRA)-->MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation FR Language Pack-->MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
World of Warcraft-->C:\Program Files\Fichiers communs\Blizzard Entertainment\World of Warcraft\Uninstall.exe
x264 Revision 573 x264.nl (remove only)-->"C:\Program Files\x264\x264-uninstall.exe"
XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
Xvid 1.1.2 final uninstall-->"C:\Program Files\Xvid\unins000.exe"
Zune Desktop Theme-->MsiExec.exe /X{7E20EFE6-E604-48C6-8B39-BA4742F2CDB4}

======System event log======

Computer Name: CH_PC
Event Code: 62486
Message: Invalid parameters

Record Number: 108241
Source Name: ati2mtag
Time Written: 20090309211819.000000+060
Event Type: Informations
User:

Computer Name: CH_PC
Event Code: 62486
Message: Invalid parameters

Record Number: 108240
Source Name: ati2mtag
Time Written: 20090309211819.000000+060
Event Type: Informations
User:

Computer Name: CH_PC
Event Code: 62486
Message: Invalid parameters

Record Number: 108239
Source Name: ati2mtag
Time Written: 20090309211819.000000+060
Event Type: Informations
User:

Computer Name: CH_PC
Event Code: 62486
Message: Invalid parameters

Record Number: 108238
Source Name: ati2mtag
Time Written: 20090309211819.000000+060
Event Type: Informations
User:

Computer Name: CH_PC
Event Code: 62486
Message: Invalid parameters

Record Number: 108237
Source Name: ati2mtag
Time Written: 20090309211819.000000+060
Event Type: Informations
User:

=====Application event log=====

Computer Name: CH_PC
Event Code: 103
Message: msnmsgr (3364) \\.\C:\Documents and Settings\Charles Henri\Local Settings\Application Data\Microsoft\Messenger\cortez9126@hotmail.com\SharingMetadata\Working\database_3014_47D7_1447_9EAA\dfsr.db: Le moteur de base de données a arrêté une instance (0).

Record Number: 10941
Source Name: ESENT
Time Written: 20090201133144.000000+060
Event Type: Informations
User:

Computer Name: CH_PC
Event Code: 257
Message: VirusScan Enterprise: Blocage de l'exécution de scripts ('_').(ordinateur source CH_PC, adresse IP 192.168.1.22, utilisateur SYSTEM, exécution de VirusScan Enter 8.0 - OAS)

Record Number: 10940
Source Name: Alert Manager Event Interface
Time Written: 20090201132741.000000+060
Event Type: erreur
User:

Computer Name: CH_PC
Event Code: 257
Message: VirusScan Enterprise: Le fichier C:\Documents and Settings\Charles Henri\Local Settings\Temporary Internet Files\Content.IE5\UXSNFF7A\avrainville_net[1].htm est infecté par le virus JS/Obfuscated (Cheval de Troie). La suppression du fichier a réussi.(ordinateur source CH_PC, adresse IP 192.168.1.22, utilisateur CH_PC, exécution de VirusScan Enter 8.0 - OAS)

Record Number: 10939
Source Name: Alert Manager Event Interface
Time Written: 20090201132741.000000+060
Event Type: erreur
User:

Computer Name: CH_PC
Event Code: 102
Message: msnmsgr (2628) \\.\C:\Documents and Settings\Charles Henri\Local Settings\Application Data\Microsoft\Messenger\pour-avrainville@hotmail.fr\SharingMetadata\Working\database_3014_47D7_1447_9EAA\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

Record Number: 10938
Source Name: ESENT
Time Written: 20090201132000.000000+060
Event Type: Informations
User:

Computer Name: CH_PC
Event Code: 100
Message: msnmsgr (2628) Le moteur de base de données 5.01.2600.5512 est démarré.

Record Number: 10937
Source Name: ESENT
Time Written: 20090201132000.000000+060
Event Type: Informations
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime Alternative\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 12 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=0c00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

-----------------EOF-----------------
0
loloetseb Messages postés 5684 Statut Membre 174
 
Télécharges http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe ( de Cyrildu17 / C_XX ) sur ton bureau :

/!\ Déconnectes toi et fermes toutes applications en cours

? Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
? Double clique sur l'icône Ad-removersituée sur ton bureau
? Au menu principal choisi l'option "Recherche"
? Postes le rapport qui apparait à la fin .

( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

Note :

"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall)
0
cortez9126
 
Mon problème semble résolu mon pc marche très bien, merci dbeaucoup.

Faut-il que je fasse cette autre vérification quand même ?
0
loloetseb Messages postés 5684 Statut Membre 174
 
Ce n'est pas terminé,fais la procedure du post 10
0
cortez9126
 
Et voici :

------- LOGFILE OF AD-REMOVER 1.1.2.0 | ONLY XP/VISTA -------

Updated by C_XX on 22/03/2009 at 10:00
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/FindyKill.Ad.Remover/

Start at: 16:16:57, Dim 22/03/2009 | Boot mode: Normal Boot
Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
Computer Name: CH_PC
Current User: Charles Henri - Administrator
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: NTFS)
- E:\ (File System: NTFS)
- F:\ (File System: UDF)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\

--- Running Processes: 48

+-----------------| Boonty/Boonty Games Elements Found:

.
.

+-----------------| Eorezo Elements Found:

.

+-----------------| Infected Poker Softwares Elements Found:

.

+-----------------| FunWebProducts/MyWay/MyWebSearch Elements Found:

.
.

+-----------------| It's TV Elements Found:

.

+-----------------| Sweetim Elements Found:

.

============ Other Adwares Found ============

.
.
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@atdmt[2].txt
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@atdmt[3].txt

+-----------------| Added Scan:

---- Mozilla FireFox Version 3.0.7 ----

ProfilePath: fphd0xn7.default (Charles Henri)
.
.
.
.
.
.

---- Internet Explorer Version 7.0.5730.11 ----

+-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

Search bar: hxxp://recherche.neuf.fr/ie/default.html
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start page: hxxp://www.google.fr/

+-[HKEY_USERS\S-1-5-21-1177238915-2025429265-839522115-1003\..\Internet Explorer\Main]

Search bar: hxxp://recherche.neuf.fr/ie/default.html
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start page: hxxp://www.google.fr/

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: hxxp://ieframe.dll/tabswelcome.htm

+---------------------------------------------------------------------------+

2433 Byte(s) - C:\Ad-Report-Scan-22.03.2009.log

0 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
0 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

End at: 16:27:11 | 22/03/2009
.
+-----------------| E.O.F - 63 Lines
.
0
loloetseb Messages postés 5684 Statut Membre 174
 
/!\ Déconnecte-toi et ferme toutes applications en cours /!\

Double-clique sur AD-Remover pour le lancer : au menu principal, choisis l'option B.

Choisis A

Puis choisis S, le programme va travailler.

Poste le rapport qui apparaît à la fin.

(Le rapport est sauvegardé aussi sous C:\Ad-report.log)

/!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide) /!\

Note :

"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...)


Les sites ci dessous sont verrolés,il ne faut pas surfer dessus

Bingo Day
Boonty
BoontyGames
Casino DelRio
Casino Lux
Casino Nederland
Casino Tropez
Casino-On-Net
Casino.com
EmpirePoker
EoCalendar
EoClock
EoComputer
EoDesk3d
EoMail
EoMap
EoNet
EoPhoto
EoProgrammeTele
EoRss
EoSudoku
EoTraduction
EoWeather
EoWiki
Europa Casino
Everest Casino
Everest Poker
Flamingo Club Casino
Fun Web Products
Golden Palace Casino
Golden Casino
GV Luxe
It's TV
MySpeedyAlert
MyTotalSearch
MyGlobalSearch
MyQuickSearch
MySearch
MyWay
My Way Speedbar
MyWebSearch
Pacific Poker
PartyPoker
Poker Mile
Poker 770
RoxyPalace
SweetIM
Titan Poker
Vegas Red Casino
888poker
0
loloetseb Messages postés 5684 Statut Membre 174
 
Ensuite

Télécharge Navilog1 depuis-ce lien :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.

Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

Au menu principal, Fais le choix 1 >> Recherche
Laisse toi guider et patiente.
Patiente jusqu'au message :
*** Analyse Termine le ..... *** >>>>> Le fix peut durer une dizaine de minutes ;)
Appuie sur une touche le bloc note va s'ouvrir.
Copie-colle le rapport ici.
0
cortez9126
 
Première analyse :


------- LOGFILE OF AD-REMOVER 1.1.2.0 | ONLY XP/VISTA -------

Updated by C_XX on 22/03/2009 at 10:00
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/FindyKill.Ad.Remover/

**** LIMITED TO ****

Boonty/BoontyGames
Eorezo
Infected Poker Softwares
FunWebProduct/MyWay/MyWebSearch
It's TV
Sweetim
Other Adwares

********************

Start at: 16:55:17, Dim 22/03/2009 | Boot mode: Normal Boot
Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
Computer Name: CH_PC
Current User: Charles Henri - Administrator
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: NTFS)
- E:\ (File System: NTFS)
- F:\ (File System: UDF)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\

--- Running Processes: 48

(!) ---- IE start pages/Tabs reset

+-----------------| Boonty/Boonty Games Elements Deleted :

.
.

+-----------------| Eorezo Elements Deleted :

.

+-----------------| Infected Poker Softwares Elements Deleted :

.

+-----------------| FunWebProducts/MyWay/MyWebSearch Elements Deleted :

.
.

+-----------------| It's TV Elements Deleted :

.

+-----------------| Sweetim Elements Deleted :

.

============ Other Adwares Deleted ============

.
.
C:\Documents and Settings\Charles Henri\Cookies\charles_henri@atdmt[2].txt

(!) ---- Temp files deleted.
(!) ---- Recycle bin emptied in all drives.


+-----------------| Added Scan :

---- Mozilla FireFox Version 3.0.7 ----

ProfilePath: fphd0xn7.default (Charles Henri)
.
.
.
.
.
.

---- Internet Explorer Version 7.0.5730.11 ----

+-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

+-[HKEY_USERS\S-1-5-21-1177238915-2025429265-839522115-1003\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start page: hxxp://fr.msn.com/

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: hxxp://ieframe.dll/tabswelcome.htm

+---------------------------------------------------------------------------+

3164 Byte(s) - C:\Ad-Report-Clean-22.03.2009.log
2673 Byte(s) - C:\Ad-Report-Scan-22.03.2009.log

1 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
1 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

End at: 17:07:11 | 22/03/2009
.
+-----------------| E.O.F - 79 Lines
.
0
cortez9126 > cortez9126
 
Cheval de Troie sur Navilog1 fichier "is-PJQB3.tmp
0
loloetseb Messages postés 5684 Statut Membre 174
 
Non t'inquietes pas navilog est detecté a tord comme un cheval de troie par certains antivirus,mais c'est un faux postif (faux virus),donc retelecharges le,desactives ton antivirus le temps de la procedure,et postes moi le rapport
0
cortez9126
 
Et voila :

Search Navipromo version 3.7.6 commencé le 22/03/2009 à 18:35:55,81

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1

Mise à jour le 14.03.2009 à 18h00 par IL-MAFIOSO

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : BIOS Date: 07/12/04 11:25:28 Ver: 08.00.09
USER : Charles Henri ( Administrator )
BOOT : Normal boot




A:\ (USB)
C:\ (Local Disk) - NTFS - Total:24 Go (Free:2 Go)
D:\ (Local Disk) - NTFS - Total:165 Go (Free:51 Go)
E:\ (Local Disk) - NTFS - Total:74 Go (Free:25 Go)
F:\ (CD or DVD) - UDF - Total:7 Go (Free:0 Go)
H:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
L:\ (CD or DVD)
M:\ (CD or DVD)


Recherche executé en mode normal


*** Recherche dossiers dans "C:\WINDOWS" ***


*** Recherche dossiers dans "C:\Program Files" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\Charles Henri\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\Charles Henri\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\Charles Henri\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans "C:\WINDOWS\system32" *

* Recherche dans "C:\Documents and Settings\Charles Henri\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *



*** Recherche fichiers ***



*** Recherche clés spécifiques dans le Registre ***
!! Les clés trouvées ne sont pas forcément infectées !!

HKEY_CURRENT_USER\Software\mc

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :


2)Recherche Heuristique :

* Dans "C:\WINDOWS\system32" :


* Dans "C:\Documents and Settings\Charles Henri\locals~1\applic~1" :


* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :


3)Recherche Certificats :

Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche autres dossiers et fichiers connus :



*** Analyse terminée le 22/03/2009 à 18:40:56,37 ***
0
loloetseb Messages postés 5684 Statut Membre 174
 
Peux tu supprimes ces deux fichiers

C:\WINDOWS\msmark2.dat
C:\WINDOWS\nlmark2.dat
0
cortez9126
 
C'est supprimé !
0
loloetseb Messages postés 5684 Statut Membre 174
 
Supprimes les logiciels de desinfection inutiles avec tool cleaner

http://www.commentcamarche.net/telecharger/telechargement 34055291 toolscleaner
---> Télécharge ToolsCleaner2 sur ton Bureau.
* Double-clique sur ToolsCleaner2.exe pour le lancer.
* Clique sur Recherche et laisse le scan agir.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options Facultatives.
* Clique sur Quitter pour obtenir le rapport.
* Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
_________________________________________________

Puis fais un scan en ligne avec bitdefender

-> Scan BitDefender

Fais une analyse antivirus en ligne sur BitDefender avec Internet Explorer.:

http://www.bitdefender.fr/bd/site/page.php?tab=0#

* Clique en bas à gauche sur Scan on line.
* Accepte la licence et laisse-le installer l'Active x..
* Laisse-toi guider. Colle son rapport ici.
* Poste un nouveau rapport Hijackthis.

Aide : https://forum.pcastuces.com/sujet.asp?f=25&s=31584&page=1&
0
cortez9126
 
[ Rapport ToolsCleaner version 2.3.2 (par A.Rothstein & dj QUIOU) ]

-->- Recherche:

C:\fixnavi.txt: trouvé !
C:\rapport_clean.txt: trouvé !
C:\lopR.txt: trouvé !
C:\Lop SD: trouvé !
C:\Rsit: trouvé !
C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
C:\Documents and Settings\Charles Henri\Bureau\LopSD.exe: trouvé !
C:\Documents and Settings\Charles Henri\Bureau\Navilog1.exe: trouvé !
C:\Documents and Settings\Charles Henri\Bureau\hijackthis.log: trouvé !
C:\Documents and Settings\Charles Henri\Bureau\Rsit.exe: trouvé !
C:\Program Files\Navilog1: trouvé !
C:\Program Files\Navilog1\Navilog1.bat: trouvé !

---------------------------------
-->- Suppression:

C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
C:\Documents and Settings\Charles Henri\Bureau\LopSD.exe: supprimé !
C:\Documents and Settings\Charles Henri\Bureau\Navilog1.exe: supprimé !
C:\Program Files\Navilog1\Navilog1.bat: supprimé !
C:\fixnavi.txt: supprimé !
C:\rapport_clean.txt: supprimé !
C:\lopR.txt: supprimé !
C:\Documents and Settings\Charles Henri\Bureau\hijackthis.log: supprimé !
C:\Documents and Settings\Charles Henri\Bureau\Rsit.exe: supprimé !
C:\Lop SD: supprimé !
C:\Rsit: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
C:\Program Files\Navilog1: supprimé !
0
loloetseb Messages postés 5684 Statut Membre 174
 
oK tu peux faire bitdefender
0
cortez9126
 
BitDefender Online Scanner - Rapport virus en temps réel



Généré à: Sun, Mar 22, 2009 - 21:13:27


--------------------------------------------------------------------------------





Info d'analyse



Fichiers scannés
137326

Infectés Fichiers
3


Virus Détectés



Trojan.Generic.1556754
1

Application.Motherboardmon.A
1

Adware.Whenu.BSR
1
0
cortez9126
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:18:01, on 22/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
C:\Documents and Settings\Charles Henri\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\AOL\1169919938\ee\aolsoftware.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
E:\Program Files\AOL 9.0a\waol.exe
E:\Program Files\AOL 9.0a\shellmon.exe
C:\Program Files\Fichiers communs\Aol\aoltpspd.exe
C:\Documents and Settings\Charles Henri\Local Settings\Temporary Internet Files\Content.IE5\CSF68EVF\HiJackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Charles Henri\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Sam.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://www.myisc.com/qp2.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/44.10/uploader2.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://charon777.free.fr/plugins/hardwaredetection_2_0_4_9.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{26C5B780-ADBA-4220-B5D0-9166D661B63D}: NameServer = 205.188.146.145
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
0
loloetseb Messages postés 5684 Statut Membre 174
 
Il a supprimé les 3 virus,tu n'as pas eu le detail des fichiers concernés?
0
cortez9126
 
Nouveau scan BitDefender ce matin :

Fichier analysé
Statut

D:\Program Files\DAEMON Tools\SetupDTSB.exe=>(CAB Sfx r)=>VVSN.exe
Détecté avec: Adware.Whenu.BSR

D:\World of Warcraft\système\system.dll
Détecté avec: Application.Motherboardmon.A
0