Malware defender : info ou intox ?
NoProbs
Messages postés
34
Statut
Membre
-
anthony5151 Messages postés 10927 Statut Contributeur sécurité -
anthony5151 Messages postés 10927 Statut Contributeur sécurité -
Bonjour,
Je rencontre un problème avec mon PC :
Impossible de mettre à jour mon antivirus Bit Defender (message serveur invalide) et le centre de sécurité Windows est désactivé avec impossibilité de le réactiver
J'ai de temps en temps une fenetre malware defender qui apparait et me dit que mon PC est infecté et comme un crétin il me semble que j'ai accepté de faire un scan à partir de cette fenetre.
Je suis allé voir sur le net et ce malware defender est à priori un faux anti malware, le problème c'est que je ne sais même pas si c'est vrai !!
J'ai essayé de télécharger Ccleaner : résultat : échec !!
N'étant pas un spécialiste, qqn peut il me dire quoi faire svp ?
Je colle dessous le rapport Hijackthis.
Merci par avance à tous !!!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:36:42, on 26/03/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Interwrite Learning\Interwrite Workspace\IWStarter.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Users\darty\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\darty\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4PS6HSDD\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Smartorrent Toolbar - {2f3a94fd-c89e-41c4-bbd6-18b11705e7f3} - C:\Program Files\Smartorrent\tbSmar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: Smartorrent Toolbar - {2f3a94fd-c89e-41c4-bbd6-18b11705e7f3} - C:\Program Files\Smartorrent\tbSmar.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: mysidesearch search enhancer - {8349BC85-7239-B526-7D30-9CBDD2B35008} - C:\Windows\system32\mhhewwywbyspgz.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O3 - Toolbar: Smartorrent Toolbar - {2f3a94fd-c89e-41c4-bbd6-18b11705e7f3} - C:\Program Files\Smartorrent\tbSmar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InterWrite Device Manager] "C:\Program Files\Interwrite Learning\Interwrite Workspace\IWStarter.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\darty\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [A00F1C5C9BD.exe] C:\Windows\TEMP\_A00F1C5C9BD.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [A00F1C5C9BD.exe] C:\Windows\TEMP\_A00F1C5C9BD.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: *.canalplay.com
O15 - Trusted Zone: *.canalplusactive.com
O15 - Trusted Zone: *.canalplay.com (HKLM)
O15 - Trusted Zone: *.canalplusactive.com (HKLM)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{36ABEDAD-47D5-42BE-A889-6FD9457E357A}: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4A88FA0-0DB8-4556-AB74-DB8D3F31A6DF}: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CS1\Services\Tcpip\..\{36ABEDAD-47D5-42BE-A889-6FD9457E357A}: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CS2\Services\Tcpip\..\{36ABEDAD-47D5-42BE-A889-6FD9457E357A}: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.62,85.255.112.231
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1c98a09a93c69c9) (gupdate1c98a09a93c69c9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: SAMSUNG WiselinkPro Service (WiselinkPro) - Unknown owner - C:\Program Files\SAMSUNG\SAMSUNG PC Share Manager\WiselinkPro.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
Je rencontre un problème avec mon PC :
Impossible de mettre à jour mon antivirus Bit Defender (message serveur invalide) et le centre de sécurité Windows est désactivé avec impossibilité de le réactiver
J'ai de temps en temps une fenetre malware defender qui apparait et me dit que mon PC est infecté et comme un crétin il me semble que j'ai accepté de faire un scan à partir de cette fenetre.
Je suis allé voir sur le net et ce malware defender est à priori un faux anti malware, le problème c'est que je ne sais même pas si c'est vrai !!
J'ai essayé de télécharger Ccleaner : résultat : échec !!
N'étant pas un spécialiste, qqn peut il me dire quoi faire svp ?
Je colle dessous le rapport Hijackthis.
Merci par avance à tous !!!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:36:42, on 26/03/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Interwrite Learning\Interwrite Workspace\IWStarter.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Users\darty\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\darty\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4PS6HSDD\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Smartorrent Toolbar - {2f3a94fd-c89e-41c4-bbd6-18b11705e7f3} - C:\Program Files\Smartorrent\tbSmar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: Smartorrent Toolbar - {2f3a94fd-c89e-41c4-bbd6-18b11705e7f3} - C:\Program Files\Smartorrent\tbSmar.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: mysidesearch search enhancer - {8349BC85-7239-B526-7D30-9CBDD2B35008} - C:\Windows\system32\mhhewwywbyspgz.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O3 - Toolbar: Smartorrent Toolbar - {2f3a94fd-c89e-41c4-bbd6-18b11705e7f3} - C:\Program Files\Smartorrent\tbSmar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InterWrite Device Manager] "C:\Program Files\Interwrite Learning\Interwrite Workspace\IWStarter.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\darty\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [A00F1C5C9BD.exe] C:\Windows\TEMP\_A00F1C5C9BD.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [A00F1C5C9BD.exe] C:\Windows\TEMP\_A00F1C5C9BD.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: *.canalplay.com
O15 - Trusted Zone: *.canalplusactive.com
O15 - Trusted Zone: *.canalplay.com (HKLM)
O15 - Trusted Zone: *.canalplusactive.com (HKLM)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{36ABEDAD-47D5-42BE-A889-6FD9457E357A}: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4A88FA0-0DB8-4556-AB74-DB8D3F31A6DF}: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CS1\Services\Tcpip\..\{36ABEDAD-47D5-42BE-A889-6FD9457E357A}: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CS2\Services\Tcpip\..\{36ABEDAD-47D5-42BE-A889-6FD9457E357A}: NameServer = 85.255.112.62,85.255.112.231
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.62,85.255.112.231
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1c98a09a93c69c9) (gupdate1c98a09a93c69c9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: SAMSUNG WiselinkPro Service (WiselinkPro) - Unknown owner - C:\Program Files\SAMSUNG\SAMSUNG PC Share Manager\WiselinkPro.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
A voir également:
- Malware defender : info ou intox ?
- Malwarebytes anti-malware - Télécharger - Antivirus & Antimalwares
- Windows defender windows 7 - Télécharger - Antivirus & Antimalwares
- Mcafee malware - Accueil - Piratage
- Supprimer malware - Guide
- Desactiver windows defender - Guide
50 réponses
J'ai quand même effectué un dernier essai avant d'aller me coucher.
Je suis passé en mode sans echec et j'ai fait glisser CFScipt sur C-FIx.
Oh surprise, il continue à me dire qu'il a détecté un scanner en temps réel actif nommé.... BitDefender !!
Même en mode sans échec il continue à être présent alors qu'en cherchant sur C: , je ne le trouve nulle part !!!
Allez, bonne nuit et à demain.
Merci encore.
Je suis passé en mode sans echec et j'ai fait glisser CFScipt sur C-FIx.
Oh surprise, il continue à me dire qu'il a détecté un scanner en temps réel actif nommé.... BitDefender !!
Même en mode sans échec il continue à être présent alors qu'en cherchant sur C: , je ne le trouve nulle part !!!
Allez, bonne nuit et à demain.
Merci encore.
Ah donc tu n'as pas encore fait le nettoyage avec le script ?
Est-ce qu'il y a la possibilité de passer outre l'avertissement qui apparait pour utiliser le script malgré tout ? (en mode sans échec)
Est-ce qu'il y a la possibilité de passer outre l'avertissement qui apparait pour utiliser le script malgré tout ? (en mode sans échec)
Nouveau problème : il me dit qu'il lui est impossible de renommer combofix ern C Fix, alors qur j'ai refait exactement la meme chose qu'hier !! du coup je ne peux plus lancer le script.
Donc lui un nom différent, par exemple Rambo ;)
Si ça ne va pas, supprime le, et télécharge le à nouveau (en le renommant avant, pas une fois qu'il est sur ton Bureau)
Si ça ne va pas, supprime le, et télécharge le à nouveau (en le renommant avant, pas une fois qu'il est sur ton Bureau)
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Bonjour à toi,
Voila le rapport :
ComboFix 09-03-28.06 - darty 2009-03-29 10:01:30.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.1088 [GMT 2:00]
Lancé depuis: c:\users\darty\Desktop\rambo.exe
Commutateurs utilisés :: c:\users\darty\Desktop\CFScript.txt
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
FW: Bitdefender Firewall *disabled*
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\System32\mhhewwywbyspgz.dll
c:\windows\System32\ovfsthkrrpfqowegytoyhnnblvvfolrqnsqxvd.dat
c:\windows\System32\ovfsthwoeanqfcibtprejrmpwbhedeftvjimur.dat
.
---- Exécution préalable -------
.
c:\program files\BoontyGames
c:\program files\BoontyGames\Components\bureau.url
c:\program files\BoontyGames\Components\Joystick.ico
c:\program files\BoontyGames\Components\start.url
c:\program files\BoontyGames\Discovery\Discovery.exe
c:\program files\BoontyGames\Discovery\fmodex.dll
c:\program files\BoontyGames\Discovery\trial.ini
c:\program files\BoontyGames\Flower Stand Tycoon\FlowerStandTycoon.exe
c:\program files\BoontyGames\Flower Stand Tycoon\trial.ini
c:\program files\BoontyGames\Mystery PI The Vegas Heist\bass.dll
c:\program files\BoontyGames\Mystery PI The Vegas Heist\config.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\distributor.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\drm.xml
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\drm.xml.sig
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\_Arial10.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\_Arial10Bold.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\_Arial12Bold.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\_Arial9.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\_Arial9Bold.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\Arial10.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\Arial10Bold.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\Arial12Bold.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\Arial9.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\Arial9Bold.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\help.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\bbb.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_buynow.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_buynow2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_cancel.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_cancel2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_close.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_close2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_continue.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_continue2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_finish.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_finish2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_help.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_help_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_help2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_help2_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_mask.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_play.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_play2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_play3.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_privacy.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_privacy_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_privacy2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_privacy2_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_register.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_register2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_retry.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_retry2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_security.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_security_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_security2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_security2_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_sendreceipt.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_sendreceipt2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\ecomm_wrapper_background.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\ecomm_wrapper_background_centered.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\icon_complete.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\icon_connected.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\icon_connecting.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\ssframe.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\textlet.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\privacy.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Bullets.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\ClassLink.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Common.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Consts.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Default.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\DProps.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\DRMApp.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\DRMButtonWidget.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Layout.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\LuaApp.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\LuaCommonWidgets.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\LuaWidget.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\main.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Screen.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\TextletWidget.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\security.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\drm.xml
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\drm.xml.sig
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet1.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet1_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet2.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet2_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet3.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet3_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\game.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\game_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\logo.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\logo_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drmss.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\eula.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\Fenetre.bmp
c:\program files\BoontyGames\Mystery PI The Vegas Heist\fenetrepop.bmp
c:\program files\BoontyGames\Mystery PI The Vegas Heist\FLEXnet Activation Service Installer.dll
c:\program files\BoontyGames\Mystery PI The Vegas Heist\lisez-moi.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\MysteryPIVegas.exe
c:\program files\BoontyGames\Mystery PI The Vegas Heist\MysteryPIVegas.exe.manifest
c:\program files\BoontyGames\Mystery PI The Vegas Heist\properties\partner.xml
c:\program files\BoontyGames\Mystery PI The Vegas Heist\properties\partner.xml.sig
c:\program files\BoontyGames\Mystery PI The Vegas Heist\publisher.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\Resources.dll
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\~pleasewait.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\buy_connectionrequired.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\connectionrequired.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_br.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_de.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_en.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_fr.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_it.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_nb.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_nl.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_po.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_sp.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_us.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bg_nomjeu.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bg_table.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgDELOCK.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgERROR.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgERROR_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgERROR_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgERROR_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgERROR_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgOK.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgOK_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgOK_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgOK_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgOK_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgREDUC.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgREDUC_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgREDUC_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgREDUC_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgREDUC_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSECURE.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSECURE_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSECURE_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSECURE_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSECURE_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSUPPORT.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBkg.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottomLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottomLeftC.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottomLeftCN.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottomLeftCR.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottomRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocCoinCadenas.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocError.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocExpiredTop.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocJouezMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocJouezTop.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocTop.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocTopLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocTopRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\boontysecure.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomLeftEast.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomLeftNorth.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomRightNorth.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomRightWest.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btAcheterLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btAcheterMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btAcheterRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtBlueLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtBlueMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtBlueRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btJouerLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btJouerMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btJouerRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_acheter.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_fermer.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_infos.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_jouer.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_nomjeu2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_reactiver.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_reduc.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_suivant.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_suivant2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtnBuyExit.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtYellowLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtYellowMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtYellowQuestion.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtYellowRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgLeft_Off.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgLeft_On.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgMiddle_Off.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgMiddle_On.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgRight_Off.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgRight_On.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\CacheImgJeu.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\caddie.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\cadenas.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\CloseOff.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\CloseOn.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\fleche.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\flechetrial.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\greypoint.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\jeu.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\jouer_gratuitement.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\MaximizeOff.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\MaximizeOn.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\MinimizeOff.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\MinimizeOn.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopBottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopBottomLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopBottomRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopTop.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopTopLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopTopRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\scroll.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\scroll_bkg.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\separator2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\separatorEnd.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\separatorMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\separatorStart.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Shell_popup_03.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Shell_popup_06.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Shell_popup_08.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Shell_popup_09.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\spacer.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\test.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Top.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\TopLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\TopLeftSouth.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\TopRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\TopRightWest.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\transp.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\wait.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\js\ShellScripts.js
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\manualtransaction.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\pageerror.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\pleasewait.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\repairstart.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\thankyou.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\transfailure.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\trialexit.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\trialexpired.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\trialstart.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SpMU.lnk
c:\program files\BoontyGames\Mystery PI The Vegas Heist\trial.ini
c:\program files\BoontyGames\Mystery PI The Vegas Heist\unins000.dat
c:\program files\BoontyGames\Mystery PI The Vegas Heist\unins000.exe
c:\program files\BoontyGames\Supermarket Mania\bass.dll
c:\program files\BoontyGames\Supermarket Mania\SupermarketMania.exe
c:\program files\BoontyGames\Supermarket Mania\trial.ini
c:\program files\Smartorrent
c:\program files\Smartorrent\INSTALL.LOG
c:\program files\Smartorrent\SmartorrentToolbarHelper.exe
c:\program files\Smartorrent\tbSmar.dll
c:\program files\Smartorrent\toolbar.cfg
c:\program files\Smartorrent\UNWISE.EXE
c:\program files\Smartorrent\UNWISE.INI
c:\programdata\ApeZone
c:\programdata\ApeZone\Loco Mogul\err.log
c:\programdata\ApeZone\Loco Mogul\out.log
c:\programdata\ApeZone\Loco Mogul\unwise.save
c:\programdata\ApeZone\Loco Mogul\unwise.sco
c:\programdata\ApeZone\Loco Mogul\user.prof
c:\programdata\ApeZone\Loco Mogul\video.ini
c:\programdata\BigFish
c:\programdata\BigFish\The Wizard's Pen\cached\audio\bonus.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\boom.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\click.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\correct.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\drip.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\emblem.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\flash.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\hot.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\ice.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\incorrect.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\ingame_1_body.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\ingame_2_body.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\ingame_3_body.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\ingame_4_body.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\lightning.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\lock_complete.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\lock_shake.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\minigame_unlocked.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\mosaic.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pageturn.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pageturn2.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\panel.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pen_motion.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\PEN_POOF.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pen_write.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pen_write_single.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pic_click.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\poof.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pop.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\rise.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\shelf.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\sorcerer_free.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\stats.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\stats2.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\swirl.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\title_music.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\tower_done.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\whisk.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\whoosh.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\x_draw.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\zoom.wav
c:\programdata\BigFish\The Wizard's Pen\userdata\profiles.dat
c:\programdata\BigFish\The Wizard's Pen\userdata\save_0_0
c:\programdata\Sortasoft
c:\programdata\ZEMNOTT
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\bonus.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\boom.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\click.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\correct.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\drip.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\emblem.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\flash.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\hot.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\ice.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\incorrect.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\ingame_1_body.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\ingame_2_body.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\ingame_3_body.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\ingame_4_body.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\lightning.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\lock_complete.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\lock_shake.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\minigame_unlocked.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\mosaic.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pageturn.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pageturn2.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\panel.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pen_motion.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\PEN_POOF.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pen_write.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pen_write_single.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pic_click.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\poof.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pop.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\rise.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\shelf.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\sorcerer_free.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\stats.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\stats2.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\swirl.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\title_music.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\tower_done.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\whisk.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\whoosh.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\x_draw.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\zoom.wav
c:\users\All Users\BigFish\The Wizard's Pen\userdata\profiles.dat
c:\users\All Users\BigFish\The Wizard's Pen\userdata\save_0_0
c:\users\darty\AppData\Roaming\Big Fish
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\log.txt
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\Save-1.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\Save-2.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\Save-3.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\Save-4.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\Save-5.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\UserData.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\WinmodController.dat
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-28 au 2009-03-29 ))))))))))))))))))))))))))))))))))))
.
2009-03-28 01:35 . 2009-03-28 01:35 <REP> d-------- C:\C-Fix
2009-03-27 21:01 . 2009-03-27 22:28 121 --a------ c:\windows\bdagent.INI
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\users\darty\AppData\Roaming\Be a King
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\program files\Be a King
2009-03-26 22:50 . 2009-03-26 22:50 <REP> d-------- c:\program files\Insider Tales - Stolen Venus
2009-03-26 22:28 . 2009-03-26 22:28 <REP> d-------- c:\program files\Mystery PI - The New York Fortune
2009-03-25 22:25 . 2009-03-25 22:25 <REP> d-------- c:\windows\BDOSCAN8
2009-03-22 23:02 . 2009-03-22 23:02 <REP> d-------- c:\program files\Tropical Mania
2009-03-22 18:45 . 2009-03-22 18:45 35,840 --a------ c:\windows\System32\gldx.exe
2009-03-22 01:19 . 2009-03-22 01:19 0 --a------ c:\windows\System32\drivers\ovfsth.sys
2009-03-22 00:22 . 2009-03-22 00:22 <REP> d-------- c:\program files\DigitalHQ
2009-03-22 00:19 . 2009-03-22 00:19 <REP> d-------- c:\windows\Delicious - Emily's Tea Garden
2009-03-22 00:19 . 2009-03-22 00:22 <REP> d-------- c:\program files\Delicious - Emily's Tea Garden
2009-03-21 22:35 . 2009-03-22 00:12 <REP> d-------- c:\program files\Hidden Mysteries - Buckingham Palace
2009-03-21 18:36 . 2009-03-21 18:36 59 --a------ c:\windows\RUNAWAY.INI
2009-03-21 18:32 . 2009-03-21 18:32 <REP> d-------- c:\program files\PENDULO Studios
2009-03-21 14:31 . 2009-03-22 11:23 <REP> d-------- c:\program files\Cossacks
2009-03-21 14:31 . 2009-03-21 14:31 53,248 --a------ c:\windows\System32\unrar.dll
2009-03-20 20:01 . 2009-03-20 20:01 <REP> d-------- c:\users\darty\AppData\Roaming\BrandX Games
2009-03-18 15:56 . 2009-03-18 16:04 <REP> d-------- c:\program files\Téléchargeur de amerzone
2009-03-16 21:47 . 2009-03-16 21:47 <REP> d-------- c:\users\darty\AppData\Roaming\Sortasoft
2009-03-15 12:18 . 2009-03-15 12:18 <REP> d-------- c:\program files\Lost in the City
2009-03-15 11:47 . 2009-03-15 11:47 <REP> d-------- c:\users\darty\AppData\Roaming\Anabel
2009-03-15 00:53 . 2009-03-15 00:54 <REP> d-------- c:\program files\The Hidden Object Show - Season 2
2009-03-14 11:24 . 2009-03-14 11:24 <REP> d-------- c:\windows\Hidden Wonders of the Depths
2009-03-13 21:07 . 2009-03-13 21:07 <REP> d-------- c:\users\darty\AppData\Roaming\Boolat Games
2009-03-11 22:31 . 2009-03-11 22:31 <REP> d-------- c:\program files\Angela Young's Dream Adventure
2009-03-11 21:55 . 2008-12-16 05:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 21:55 . 2008-12-16 07:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-11 21:54 . 2009-02-09 05:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 21:54 . 2008-11-27 06:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\users\All Users\Friday's games
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\programdata\Friday's games
2009-03-08 20:09 . 2009-03-08 20:09 <REP> d-------- c:\program files\Curse of the Pharaoh - Napoleons Secret
2009-03-08 17:18 . 2009-03-08 17:18 <REP> d-------- c:\program files\Geoplan-Geospace
2009-03-08 17:10 . 2009-03-08 17:10 <REP> d-------- c:\program files\Interwrite Learning
2009-03-05 23:57 . 2009-03-05 23:57 <REP> d-------- c:\users\darty\AppData\Roaming\ZEMNOTT
2009-03-05 23:55 . 2009-03-05 23:55 <REP> d-------- c:\windows\Nanny Mania 2
2009-03-05 23:53 . 2009-03-06 00:57 <REP> d-------- c:\program files\Eco-Match
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\windows\Romopolis
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\program files\Romopolis
2009-03-01 22:58 . 2009-03-02 00:03 <REP> d-------- c:\program files\Party Down
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 08:13 --------- d-----w c:\users\darty\AppData\Roaming\OpenOffice.org2
2009-03-29 08:12 --------- d-----w c:\users\darty\AppData\Roaming\DNA
2009-03-29 07:52 --------- d-----w c:\programdata\Google Updater
2009-03-28 22:02 27,839 ----a-w c:\users\All Users\nvModes.dat
2009-03-28 22:02 27,839 ----a-w c:\programdata\nvModes.dat
2009-03-28 22:02 --------- d---a-w c:\programdata\TEMP
2009-03-28 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Gold Casual Games
2009-03-28 21:02 --------- d-----w c:\programdata\Gold Casual Games
2009-03-28 20:01 --------- d-----w c:\programdata\Intenium
2009-03-28 19:41 --------- d-----w c:\users\darty\AppData\Roaming\PlayFirst
2009-03-28 19:41 --------- d-----w c:\programdata\PlayFirst
2009-03-27 23:02 --------- d-----w c:\program files\Common Files\BitDefender
2009-03-27 22:21 630,784 ----a-w c:\windows\System32\mhhewwywbyspgz.dll
2009-03-27 20:53 --------- d-----w c:\program files\DNA
2009-03-25 20:36 81,984 ----a-w c:\windows\System32\bdod.bin
2009-03-25 19:49 --------- d-----w c:\program files\Java
2009-03-23 19:07 --------- d-----w c:\users\darty\AppData\Roaming\BitTorrent
2009-03-23 18:26 69,194 ----a-w c:\windows\System32\mhhewwywbyspgz.dll-uninst.exe
2009-03-22 08:16 --------- d-----w c:\programdata\NVIDIA
2009-03-21 20:35 --------- d-----w c:\users\darty\AppData\Roaming\Zylom
2009-03-21 16:32 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-20 22:22 --------- d-----w c:\program files\Oberon Media
2009-03-19 19:45 --------- d-----w c:\program files\HP Games
2009-03-19 19:21 --------- d-----w c:\programdata\WildTangent
2009-03-19 14:29 --------- d-----w c:\users\darty\AppData\Roaming\Flood Light Games
2009-03-19 14:29 --------- d-----w c:\programdata\Flood Light Games
2009-03-18 14:11 --------- d-----w c:\programdata\GameXzone
2009-03-18 14:04 --------- d-----w c:\program files\Téléchargeur de amerzone
2009-03-12 19:17 --------- d-----w c:\program files\Windows Mail
2009-03-09 04:19 410,984 ----a-w c:\windows\System32\deploytk.dll
2009-03-04 21:30 --------- d-----w c:\programdata\Gogii
2009-03-03 21:01 --------- d-----w c:\users\darty\AppData\Roaming\MysteryStudio
2009-03-01 21:00 --------- d-----w c:\users\darty\AppData\Roaming\EleFun Games
2009-02-28 20:28 --------- d-----w c:\users\darty\AppData\Roaming\SerpentOfIsis
2009-02-28 20:25 --------- d-----w c:\program files\The Serpent of Isis
2009-02-28 20:18 --------- d-----w c:\users\darty\AppData\Roaming\panoramik
2009-02-27 20:48 --------- d-----w c:\users\darty\AppData\Roaming\World-LooM
2009-02-27 19:13 --------- d-----w c:\program files\The Wizard's Pen
2009-02-25 12:36 --------- d-----w c:\users\darty\AppData\Roaming\Tropical Dream Underwater Odyssey
2009-02-22 09:39 --------- d-----w c:\programdata\Enkord
2009-02-22 09:03 --------- d-----w c:\programdata\Big Fish Games Vancouver
2009-02-21 14:55 --------- d-----w c:\program files\Costume Chaos
2009-02-21 14:54 --------- d-----w c:\program files\Herods Lost Tomb
2009-02-21 09:32 --------- d-----w c:\programdata\FarmFrenzy-PizzaParty
2009-02-21 08:14 --------- d-----w c:\programdata\HoverBee Studios
2009-02-20 20:34 --------- d-----w c:\program files\Restoring Rhonda
2009-02-20 19:52 --------- d-----w c:\users\darty\AppData\Roaming\Skunk Studios
2009-02-20 14:57 --------- d-----w c:\users\darty\AppData\Roaming\blg
2009-02-20 14:57 --------- d-----w c:\programdata\blg
2009-02-18 12:49 --------- d-----w c:\users\darty\AppData\Roaming\FirstColony
2009-02-17 19:55 --------- d-----w c:\programdata\Mandragora
2009-02-16 18:46 --------- d-----w c:\program files\Google
2009-02-11 21:20 --------- d-----w c:\program files\BigfishGames
2009-02-11 20:05 --------- d-----w c:\programdata\SugarGames
2009-02-05 17:12 --------- d-----w c:\program files\Cradle Of Rome
2009-02-05 14:10 --------- d-----w c:\users\darty\AppData\Roaming\dvdcss
2009-02-04 12:41 --------- d-----w c:\users\darty\AppData\Roaming\Playrix Entertainment
2009-02-03 20:51 --------- d-----w c:\users\darty\AppData\Roaming\HSA
2009-02-02 22:07 --------- d-----w c:\users\darty\AppData\Roaming\Friday's games
2009-02-02 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Coyotes Tale
2009-02-02 18:42 --------- d-----w c:\program files\Samsung
2009-02-02 12:43 --------- d-----w c:\users\darty\AppData\Roaming\Island
2009-02-01 20:10 --------- d-----w c:\programdata\Meridian93
2009-02-01 20:09 --------- d-----w c:\users\darty\AppData\Roaming\Meridian93
2009-02-01 19:54 --------- d-----w c:\users\darty\AppData\Roaming\RobinsonCrusoe
2009-02-01 16:44 --------- d-----w c:\users\darty\AppData\Roaming\ViquaSoft
2009-01-30 08:41 --------- d-----w c:\program files\Lecteur CANALPLAY
2009-01-29 22:05 --------- d-----w c:\users\darty\AppData\Roaming\TimeQuest
2009-01-29 22:03 --------- d-----w c:\program files\Totem Tribe
2009-01-29 21:42 --------- d-----w c:\program files\Vogue Tales
2009-01-28 19:48 --------- d-----w c:\programdata\VogueTales
2009-01-28 15:51 --------- d-----w c:\program files\Sallys Salon
2009-01-28 11:26 --------- d-----w c:\programdata\Vogue Tales
2009-01-28 11:02 --------- d-----w c:\programdata\InterAction studios
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2008-10-11 18:52 27,335 ----a-w c:\users\darty\AppData\Roaming\nvModes.dat
2008-08-23 18:13 174 --sha-w c:\program files\desktop.ini
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-24 06:32 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-10-23 22:35 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-03-27_22.04.44.78 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
- 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2000-08-31 07:00:00 89,504 ----a-w c:\windows\fdsv.exe
+ 2000-08-31 06:00:00 89,504 ----a-w c:\windows\fdsv.exe
- 2000-08-31 07:00:00 80,412 ----a-w c:\windows\grep.exe
+ 2000-08-31 06:00:00 80,412 ----a-w c:\windows\grep.exe
- 2009-03-25 20:42:49 51,200 ----a-w c:\windows\inf\infpub.dat
+ 2009-03-29 07:59:20 51,200 ----a-w c:\windows\inf\infpub.dat
- 2009-03-25 20:42:09 86,016 ----a-w c:\windows\inf\infstor.dat
+ 2009-03-27 22:06:52 86,016 ----a-w c:\windows\inf\infstor.dat
- 2009-03-25 20:42:49 143,360 ----a-w c:\windows\inf\infstrng.dat
+ 2009-03-29 07:59:20 143,360 ----a-w c:\windows\inf\infstrng.dat
- 2000-08-31 07:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
+ 2000-08-31 06:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
- 2000-08-31 07:00:00 98,816 ----a-w c:\windows\sed.exe
+ 2000-08-31 06:00:00 98,816 ----a-w c:\windows\sed.exe
- 2009-03-27 20:51:53 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-03-29 08:11:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-03-27 20:51:53 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-03-29 08:11:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-03-27 20:46:10 262,144 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2009-03-27 21:06:59 262,144 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2009-03-27 20:52:30 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 08:11:57 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 08:11:57 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-27 20:53:15 262,144 ----a-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2009-03-27 21:52:42 262,144 ----a-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2009-03-27 20:52:30 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 08:11:57 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 08:11:57 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2000-08-31 07:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 06:00:00 161,792 ----a-w c:\windows\SWREG.exe
- 2000-08-31 07:00:00 136,704 ----a-w c:\windows\SWSC.exe
+ 2000-08-31 06:00:00 136,704 ----a-w c:\windows\SWSC.exe
- 2000-08-31 07:00:00 212,480 ----a-w c:\windows\SWXCACLS.exe
+ 2000-08-31 06:00:00 212,480 ----a-w c:\windows\SWXCACLS.exe
- 2009-03-27 19:06:12 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-29 07:52:11 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-27 19:06:12 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-29 07:52:11 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-27 19:06:12 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-29 07:52:11 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-03-27 20:22:54 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-03-29 07:59:54 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2009-02-05 07:03:01 101,250 ----a-w c:\windows\System32\perfc009.dat
+ 2009-03-29 07:57:29 101,250 ----a-w c:\windows\System32\perfc009.dat
- 2009-02-05 07:03:01 123,556 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-03-29 07:57:29 123,556 ----a-w c:\windows\System32\perfc00C.dat
- 2009-02-05 07:03:01 587,178 ----a-w c:\windows\System32\perfh009.dat
+ 2009-03-29 07:57:29 587,178 ----a-w c:\windows\System32\perfh009.dat
- 2009-02-05 07:03:01 669,566 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-03-29 07:57:29 669,566 ----a-w c:\windows\System32\perfh00C.dat
- 2009-03-27 20:54:13 13,138 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
+ 2009-03-29 08:13:34 13,294 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
- 2009-03-27 20:54:13 76,122 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-29 08:13:34 76,890 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-27 20:32:25 57,944 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-29 07:51:51 58,564 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2000-08-31 07:00:00 49,152 ----a-w c:\windows\VFIND.exe
+ 2000-08-31 06:00:00 49,152 ----a-w c:\windows\VFIND.exe
- 2000-08-31 07:00:00 68,096 ----a-w c:\windows\zip.exe
+ 2000-08-31 06:00:00 68,096 ----a-w c:\windows\zip.exe
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-22 149040]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-26 39408]
"BitTorrent DNA"="c:\users\darty\Program Files\DNA\btdna.exe" [2008-12-19 342848]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2007-09-20 671744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-15 153136]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-27 13515296]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-27 92704]
"InterWrite Device Manager"="c:\program files\Interwrite Learning\Interwrite Workspace\IWStarter.exe" [2007-09-21 1122304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 c:\windows\RtHDVCpl.exe]
c:\users\darty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4757DF27-BB99-458F-80CB-DB0364C8F28F}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{419E922C-2259-4F5C-8434-B5F1D2E96D3A}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{E0F9C7C3-CA1A-416F-A34C-0862127D6393}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EB55CB69-2800-4DE8-A74E-01C74B7C84E3}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{ECCE1CEF-E35A-4D98-B328-225A47D70E75}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{31501F90-C592-4D85-9438-33EFD5D13D23}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{C3B4693F-2000-437E-B074-E9B72031798A}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{E661D763-1AD9-4680-B994-3BA0E48E3AC9}"= UDP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{E911C296-A208-4414-B72B-16FF9588005C}"= TCP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{F447015E-E82D-4B8F-8956-A39F6478AFFA}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{C88D7A4F-D46E-48CD-96D0-BA1ECFBD1E6B}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{F3B89985-7BF5-44B5-9D4E-EE2A42062761}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{E31F4E8A-0769-4B1A-9E31-4114195CBB25}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{8068D17E-06FF-480A-9AC1-C3F0676BEAD7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{1298C032-B160-458E-A3C8-BC7331CE56F9}"= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{018B64A2-15D3-495C-8582-C77D800E1665}"= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{F7A98888-0FC7-49F5-BE51-8FD6C7784EFE}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{4C65ADFC-9C57-4D87-976C-9C5943C4C2E2}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\Hp\QuickPlay\[u]0/u00.fcl [2008-01-16 01:22:44 39408]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [2008-12-15 185640]
R2 X4HSX32Ex;X4HSX32Ex;c:\program files\Player Metaboli\X4HSX32Ex.sys [2008-04-25 29856]
S2 gupdate1c98a09a93c69c9;Google Update Service (gupdate1c98a09a93c69c9);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [2008-04-21 436096]
S3 WiselinkPro;SAMSUNG WiselinkPro Service;c:\program files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2009-02-02 4014080]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - sptd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e9b063f-d10a-11dc-8d37-806e6f6e6963}]
\shell\AutoRun\command - F:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a915f3ae-9f32-11dd-a158-001e68056457}]
\shell\AutoRun\command - H:\LaunchU3.exe
.
Contenu du dossier 'Tâches planifiées'
2009-03-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-26 23:20]
2009-03-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 18:22]
2009-03-29 c:\windows\Tasks\User_Feed_Synchronization-{683B7A7C-3607-42F0-AF40-80427994F3E7}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 09:33]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://fr.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=81&bd=Pavilion&pf=laptop
IE: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-29 10:14:14
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(744)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(3552)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\conime.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\windows\ehome\ehsched.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\windows\ehome\ehrecvr.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
.
**************************************************************************
.
Heure de fin: 2009-03-29 10:25:11 - La machine a redémarré [darty]
ComboFix-quarantined-files.txt 2009-03-29 08:24:44
ComboFix2.txt 2009-03-27 21:06:21
Avant-CF: 31 038 754 816 octets libres
Après-CF: 32,587,096,064 octets libres
756 --- E O F --- 2009-03-29 07:55:19
Voila le rapport :
ComboFix 09-03-28.06 - darty 2009-03-29 10:01:30.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.1088 [GMT 2:00]
Lancé depuis: c:\users\darty\Desktop\rambo.exe
Commutateurs utilisés :: c:\users\darty\Desktop\CFScript.txt
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
FW: Bitdefender Firewall *disabled*
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\System32\mhhewwywbyspgz.dll
c:\windows\System32\ovfsthkrrpfqowegytoyhnnblvvfolrqnsqxvd.dat
c:\windows\System32\ovfsthwoeanqfcibtprejrmpwbhedeftvjimur.dat
.
---- Exécution préalable -------
.
c:\program files\BoontyGames
c:\program files\BoontyGames\Components\bureau.url
c:\program files\BoontyGames\Components\Joystick.ico
c:\program files\BoontyGames\Components\start.url
c:\program files\BoontyGames\Discovery\Discovery.exe
c:\program files\BoontyGames\Discovery\fmodex.dll
c:\program files\BoontyGames\Discovery\trial.ini
c:\program files\BoontyGames\Flower Stand Tycoon\FlowerStandTycoon.exe
c:\program files\BoontyGames\Flower Stand Tycoon\trial.ini
c:\program files\BoontyGames\Mystery PI The Vegas Heist\bass.dll
c:\program files\BoontyGames\Mystery PI The Vegas Heist\config.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\distributor.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\drm.xml
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\drm.xml.sig
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\_Arial10.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\_Arial10Bold.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\_Arial12Bold.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\_Arial9.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\_Arial9Bold.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\Arial10.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\Arial10Bold.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\Arial12Bold.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\Arial9.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\fonts\Arial9Bold.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\help.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\bbb.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_buynow.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_buynow2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_cancel.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_cancel2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_close.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_close2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_continue.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_continue2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_finish.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_finish2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_help.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_help_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_help2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_help2_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_mask.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_play.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_play2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_play3.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_privacy.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_privacy_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_privacy2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_privacy2_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_register.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_register2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_retry.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_retry2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_security.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_security_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_security2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_security2_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_sendreceipt.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\btn_sendreceipt2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\ecomm_wrapper_background.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\ecomm_wrapper_background_centered.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\icon_complete.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\icon_connected.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\icon_connecting.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\ssframe.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\images\textlet.png
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\privacy.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Bullets.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\ClassLink.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Common.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Consts.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Default.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\DProps.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\DRMApp.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\DRMButtonWidget.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Layout.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\LuaApp.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\LuaCommonWidgets.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\LuaWidget.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\main.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\Screen.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\scripts\TextletWidget.luc
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\common\security.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\drm.xml
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\drm.xml.sig
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet1.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet1_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet2.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet2_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet3.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\custom\images\bullet3_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\game.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\game_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\logo.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drm\logo_.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\drmss.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\eula.txt
c:\program files\BoontyGames\Mystery PI The Vegas Heist\Fenetre.bmp
c:\program files\BoontyGames\Mystery PI The Vegas Heist\fenetrepop.bmp
c:\program files\BoontyGames\Mystery PI The Vegas Heist\FLEXnet Activation Service Installer.dll
c:\program files\BoontyGames\Mystery PI The Vegas Heist\lisez-moi.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\MysteryPIVegas.exe
c:\program files\BoontyGames\Mystery PI The Vegas Heist\MysteryPIVegas.exe.manifest
c:\program files\BoontyGames\Mystery PI The Vegas Heist\properties\partner.xml
c:\program files\BoontyGames\Mystery PI The Vegas Heist\properties\partner.xml.sig
c:\program files\BoontyGames\Mystery PI The Vegas Heist\publisher.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\Resources.dll
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\~pleasewait.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\buy_connectionrequired.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\connectionrequired.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_br.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_de.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_en.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_fr.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_it.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_nb.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_nl.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_po.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_sp.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\css\ShellStyle_us.css
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bg_nomjeu.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bg_table.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgDELOCK.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgERROR.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgERROR_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgERROR_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgERROR_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgERROR_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgOK.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgOK_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgOK_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgOK_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgOK_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgREDUC.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgREDUC_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgREDUC_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgREDUC_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgREDUC_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSECURE.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSECURE_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSECURE_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSECURE_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSECURE_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSUPPORT.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Coin.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBkg.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottomLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottomLeftC.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottomLeftCN.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottomLeftCR.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocBottomRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocCoinCadenas.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocError.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocExpiredTop.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocJouezMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocJouezTop.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocTop.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocTopLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\blocTopRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\boontysecure.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Bottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomLeftEast.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomLeftNorth.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomRightNorth.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BottomRightWest.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btAcheterLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btAcheterMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btAcheterRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtBlueLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtBlueMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtBlueRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btJouerLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btJouerMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btJouerRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_acheter.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_fermer.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_infos.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_jouer.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_nomjeu2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_reactiver.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_reduc.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_suivant.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\btn_suivant2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtnBuyExit.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtYellowLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtYellowMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtYellowQuestion.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\BtYellowRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgLeft_Off.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgLeft_On.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgMiddle_Off.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgMiddle_On.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgRight_Off.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\ButtonBkgRight_On.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\CacheImgJeu.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\caddie.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\cadenas.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\CloseOff.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\CloseOn.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\fleche.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\flechetrial.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\greypoint.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\jeu.jpg
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\jouer_gratuitement.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Left.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\MaximizeOff.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\MaximizeOn.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\MinimizeOff.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\MinimizeOn.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopBottom.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopBottomLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopBottomRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopTop.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopTopLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\PopTopRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Right.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\scroll.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\scroll_bkg.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\separator2.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\separatorEnd.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\separatorMiddle.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\separatorStart.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Shell_popup_03.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Shell_popup_06.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Shell_popup_08.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Shell_popup_09.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\spacer.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\test.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\Top.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\TopLeft.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\TopLeftSouth.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\TopRight.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\TopRightWest.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\transp.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\Images\wait.gif
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\js\ShellScripts.js
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\manualtransaction.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\pageerror.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\pleasewait.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\repairstart.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\thankyou.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\transfailure.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\trialexit.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\trialexpired.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SHELL_DEFAULT_HTML\trialstart.html
c:\program files\BoontyGames\Mystery PI The Vegas Heist\SpMU.lnk
c:\program files\BoontyGames\Mystery PI The Vegas Heist\trial.ini
c:\program files\BoontyGames\Mystery PI The Vegas Heist\unins000.dat
c:\program files\BoontyGames\Mystery PI The Vegas Heist\unins000.exe
c:\program files\BoontyGames\Supermarket Mania\bass.dll
c:\program files\BoontyGames\Supermarket Mania\SupermarketMania.exe
c:\program files\BoontyGames\Supermarket Mania\trial.ini
c:\program files\Smartorrent
c:\program files\Smartorrent\INSTALL.LOG
c:\program files\Smartorrent\SmartorrentToolbarHelper.exe
c:\program files\Smartorrent\tbSmar.dll
c:\program files\Smartorrent\toolbar.cfg
c:\program files\Smartorrent\UNWISE.EXE
c:\program files\Smartorrent\UNWISE.INI
c:\programdata\ApeZone
c:\programdata\ApeZone\Loco Mogul\err.log
c:\programdata\ApeZone\Loco Mogul\out.log
c:\programdata\ApeZone\Loco Mogul\unwise.save
c:\programdata\ApeZone\Loco Mogul\unwise.sco
c:\programdata\ApeZone\Loco Mogul\user.prof
c:\programdata\ApeZone\Loco Mogul\video.ini
c:\programdata\BigFish
c:\programdata\BigFish\The Wizard's Pen\cached\audio\bonus.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\boom.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\click.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\correct.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\drip.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\emblem.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\flash.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\hot.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\ice.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\incorrect.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\ingame_1_body.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\ingame_2_body.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\ingame_3_body.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\ingame_4_body.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\lightning.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\lock_complete.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\lock_shake.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\minigame_unlocked.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\mosaic.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pageturn.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pageturn2.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\panel.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pen_motion.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\PEN_POOF.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pen_write.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pen_write_single.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pic_click.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\poof.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\pop.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\rise.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\shelf.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\sorcerer_free.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\stats.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\stats2.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\swirl.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\title_music.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\tower_done.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\whisk.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\whoosh.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\x_draw.wav
c:\programdata\BigFish\The Wizard's Pen\cached\audio\zoom.wav
c:\programdata\BigFish\The Wizard's Pen\userdata\profiles.dat
c:\programdata\BigFish\The Wizard's Pen\userdata\save_0_0
c:\programdata\Sortasoft
c:\programdata\ZEMNOTT
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\bonus.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\boom.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\click.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\correct.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\drip.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\emblem.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\flash.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\hot.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\ice.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\incorrect.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\ingame_1_body.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\ingame_2_body.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\ingame_3_body.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\ingame_4_body.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\lightning.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\lock_complete.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\lock_shake.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\minigame_unlocked.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\mosaic.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pageturn.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pageturn2.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\panel.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pen_motion.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\PEN_POOF.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pen_write.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pen_write_single.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pic_click.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\poof.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\pop.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\rise.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\shelf.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\sorcerer_free.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\stats.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\stats2.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\swirl.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\title_music.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\tower_done.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\whisk.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\whoosh.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\x_draw.wav
c:\users\All Users\BigFish\The Wizard's Pen\cached\audio\zoom.wav
c:\users\All Users\BigFish\The Wizard's Pen\userdata\profiles.dat
c:\users\All Users\BigFish\The Wizard's Pen\userdata\save_0_0
c:\users\darty\AppData\Roaming\Big Fish
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\log.txt
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\Save-1.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\Save-2.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\Save-3.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\Save-4.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\Save-5.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\UserData.dat
c:\users\darty\AppData\Roaming\Big Fish\Sea Journey\WinmodController.dat
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-28 au 2009-03-29 ))))))))))))))))))))))))))))))))))))
.
2009-03-28 01:35 . 2009-03-28 01:35 <REP> d-------- C:\C-Fix
2009-03-27 21:01 . 2009-03-27 22:28 121 --a------ c:\windows\bdagent.INI
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\users\darty\AppData\Roaming\Be a King
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\program files\Be a King
2009-03-26 22:50 . 2009-03-26 22:50 <REP> d-------- c:\program files\Insider Tales - Stolen Venus
2009-03-26 22:28 . 2009-03-26 22:28 <REP> d-------- c:\program files\Mystery PI - The New York Fortune
2009-03-25 22:25 . 2009-03-25 22:25 <REP> d-------- c:\windows\BDOSCAN8
2009-03-22 23:02 . 2009-03-22 23:02 <REP> d-------- c:\program files\Tropical Mania
2009-03-22 18:45 . 2009-03-22 18:45 35,840 --a------ c:\windows\System32\gldx.exe
2009-03-22 01:19 . 2009-03-22 01:19 0 --a------ c:\windows\System32\drivers\ovfsth.sys
2009-03-22 00:22 . 2009-03-22 00:22 <REP> d-------- c:\program files\DigitalHQ
2009-03-22 00:19 . 2009-03-22 00:19 <REP> d-------- c:\windows\Delicious - Emily's Tea Garden
2009-03-22 00:19 . 2009-03-22 00:22 <REP> d-------- c:\program files\Delicious - Emily's Tea Garden
2009-03-21 22:35 . 2009-03-22 00:12 <REP> d-------- c:\program files\Hidden Mysteries - Buckingham Palace
2009-03-21 18:36 . 2009-03-21 18:36 59 --a------ c:\windows\RUNAWAY.INI
2009-03-21 18:32 . 2009-03-21 18:32 <REP> d-------- c:\program files\PENDULO Studios
2009-03-21 14:31 . 2009-03-22 11:23 <REP> d-------- c:\program files\Cossacks
2009-03-21 14:31 . 2009-03-21 14:31 53,248 --a------ c:\windows\System32\unrar.dll
2009-03-20 20:01 . 2009-03-20 20:01 <REP> d-------- c:\users\darty\AppData\Roaming\BrandX Games
2009-03-18 15:56 . 2009-03-18 16:04 <REP> d-------- c:\program files\Téléchargeur de amerzone
2009-03-16 21:47 . 2009-03-16 21:47 <REP> d-------- c:\users\darty\AppData\Roaming\Sortasoft
2009-03-15 12:18 . 2009-03-15 12:18 <REP> d-------- c:\program files\Lost in the City
2009-03-15 11:47 . 2009-03-15 11:47 <REP> d-------- c:\users\darty\AppData\Roaming\Anabel
2009-03-15 00:53 . 2009-03-15 00:54 <REP> d-------- c:\program files\The Hidden Object Show - Season 2
2009-03-14 11:24 . 2009-03-14 11:24 <REP> d-------- c:\windows\Hidden Wonders of the Depths
2009-03-13 21:07 . 2009-03-13 21:07 <REP> d-------- c:\users\darty\AppData\Roaming\Boolat Games
2009-03-11 22:31 . 2009-03-11 22:31 <REP> d-------- c:\program files\Angela Young's Dream Adventure
2009-03-11 21:55 . 2008-12-16 05:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 21:55 . 2008-12-16 07:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-11 21:54 . 2009-02-09 05:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 21:54 . 2008-11-27 06:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\users\All Users\Friday's games
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\programdata\Friday's games
2009-03-08 20:09 . 2009-03-08 20:09 <REP> d-------- c:\program files\Curse of the Pharaoh - Napoleons Secret
2009-03-08 17:18 . 2009-03-08 17:18 <REP> d-------- c:\program files\Geoplan-Geospace
2009-03-08 17:10 . 2009-03-08 17:10 <REP> d-------- c:\program files\Interwrite Learning
2009-03-05 23:57 . 2009-03-05 23:57 <REP> d-------- c:\users\darty\AppData\Roaming\ZEMNOTT
2009-03-05 23:55 . 2009-03-05 23:55 <REP> d-------- c:\windows\Nanny Mania 2
2009-03-05 23:53 . 2009-03-06 00:57 <REP> d-------- c:\program files\Eco-Match
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\windows\Romopolis
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\program files\Romopolis
2009-03-01 22:58 . 2009-03-02 00:03 <REP> d-------- c:\program files\Party Down
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 08:13 --------- d-----w c:\users\darty\AppData\Roaming\OpenOffice.org2
2009-03-29 08:12 --------- d-----w c:\users\darty\AppData\Roaming\DNA
2009-03-29 07:52 --------- d-----w c:\programdata\Google Updater
2009-03-28 22:02 27,839 ----a-w c:\users\All Users\nvModes.dat
2009-03-28 22:02 27,839 ----a-w c:\programdata\nvModes.dat
2009-03-28 22:02 --------- d---a-w c:\programdata\TEMP
2009-03-28 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Gold Casual Games
2009-03-28 21:02 --------- d-----w c:\programdata\Gold Casual Games
2009-03-28 20:01 --------- d-----w c:\programdata\Intenium
2009-03-28 19:41 --------- d-----w c:\users\darty\AppData\Roaming\PlayFirst
2009-03-28 19:41 --------- d-----w c:\programdata\PlayFirst
2009-03-27 23:02 --------- d-----w c:\program files\Common Files\BitDefender
2009-03-27 22:21 630,784 ----a-w c:\windows\System32\mhhewwywbyspgz.dll
2009-03-27 20:53 --------- d-----w c:\program files\DNA
2009-03-25 20:36 81,984 ----a-w c:\windows\System32\bdod.bin
2009-03-25 19:49 --------- d-----w c:\program files\Java
2009-03-23 19:07 --------- d-----w c:\users\darty\AppData\Roaming\BitTorrent
2009-03-23 18:26 69,194 ----a-w c:\windows\System32\mhhewwywbyspgz.dll-uninst.exe
2009-03-22 08:16 --------- d-----w c:\programdata\NVIDIA
2009-03-21 20:35 --------- d-----w c:\users\darty\AppData\Roaming\Zylom
2009-03-21 16:32 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-20 22:22 --------- d-----w c:\program files\Oberon Media
2009-03-19 19:45 --------- d-----w c:\program files\HP Games
2009-03-19 19:21 --------- d-----w c:\programdata\WildTangent
2009-03-19 14:29 --------- d-----w c:\users\darty\AppData\Roaming\Flood Light Games
2009-03-19 14:29 --------- d-----w c:\programdata\Flood Light Games
2009-03-18 14:11 --------- d-----w c:\programdata\GameXzone
2009-03-18 14:04 --------- d-----w c:\program files\Téléchargeur de amerzone
2009-03-12 19:17 --------- d-----w c:\program files\Windows Mail
2009-03-09 04:19 410,984 ----a-w c:\windows\System32\deploytk.dll
2009-03-04 21:30 --------- d-----w c:\programdata\Gogii
2009-03-03 21:01 --------- d-----w c:\users\darty\AppData\Roaming\MysteryStudio
2009-03-01 21:00 --------- d-----w c:\users\darty\AppData\Roaming\EleFun Games
2009-02-28 20:28 --------- d-----w c:\users\darty\AppData\Roaming\SerpentOfIsis
2009-02-28 20:25 --------- d-----w c:\program files\The Serpent of Isis
2009-02-28 20:18 --------- d-----w c:\users\darty\AppData\Roaming\panoramik
2009-02-27 20:48 --------- d-----w c:\users\darty\AppData\Roaming\World-LooM
2009-02-27 19:13 --------- d-----w c:\program files\The Wizard's Pen
2009-02-25 12:36 --------- d-----w c:\users\darty\AppData\Roaming\Tropical Dream Underwater Odyssey
2009-02-22 09:39 --------- d-----w c:\programdata\Enkord
2009-02-22 09:03 --------- d-----w c:\programdata\Big Fish Games Vancouver
2009-02-21 14:55 --------- d-----w c:\program files\Costume Chaos
2009-02-21 14:54 --------- d-----w c:\program files\Herods Lost Tomb
2009-02-21 09:32 --------- d-----w c:\programdata\FarmFrenzy-PizzaParty
2009-02-21 08:14 --------- d-----w c:\programdata\HoverBee Studios
2009-02-20 20:34 --------- d-----w c:\program files\Restoring Rhonda
2009-02-20 19:52 --------- d-----w c:\users\darty\AppData\Roaming\Skunk Studios
2009-02-20 14:57 --------- d-----w c:\users\darty\AppData\Roaming\blg
2009-02-20 14:57 --------- d-----w c:\programdata\blg
2009-02-18 12:49 --------- d-----w c:\users\darty\AppData\Roaming\FirstColony
2009-02-17 19:55 --------- d-----w c:\programdata\Mandragora
2009-02-16 18:46 --------- d-----w c:\program files\Google
2009-02-11 21:20 --------- d-----w c:\program files\BigfishGames
2009-02-11 20:05 --------- d-----w c:\programdata\SugarGames
2009-02-05 17:12 --------- d-----w c:\program files\Cradle Of Rome
2009-02-05 14:10 --------- d-----w c:\users\darty\AppData\Roaming\dvdcss
2009-02-04 12:41 --------- d-----w c:\users\darty\AppData\Roaming\Playrix Entertainment
2009-02-03 20:51 --------- d-----w c:\users\darty\AppData\Roaming\HSA
2009-02-02 22:07 --------- d-----w c:\users\darty\AppData\Roaming\Friday's games
2009-02-02 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Coyotes Tale
2009-02-02 18:42 --------- d-----w c:\program files\Samsung
2009-02-02 12:43 --------- d-----w c:\users\darty\AppData\Roaming\Island
2009-02-01 20:10 --------- d-----w c:\programdata\Meridian93
2009-02-01 20:09 --------- d-----w c:\users\darty\AppData\Roaming\Meridian93
2009-02-01 19:54 --------- d-----w c:\users\darty\AppData\Roaming\RobinsonCrusoe
2009-02-01 16:44 --------- d-----w c:\users\darty\AppData\Roaming\ViquaSoft
2009-01-30 08:41 --------- d-----w c:\program files\Lecteur CANALPLAY
2009-01-29 22:05 --------- d-----w c:\users\darty\AppData\Roaming\TimeQuest
2009-01-29 22:03 --------- d-----w c:\program files\Totem Tribe
2009-01-29 21:42 --------- d-----w c:\program files\Vogue Tales
2009-01-28 19:48 --------- d-----w c:\programdata\VogueTales
2009-01-28 15:51 --------- d-----w c:\program files\Sallys Salon
2009-01-28 11:26 --------- d-----w c:\programdata\Vogue Tales
2009-01-28 11:02 --------- d-----w c:\programdata\InterAction studios
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2008-10-11 18:52 27,335 ----a-w c:\users\darty\AppData\Roaming\nvModes.dat
2008-08-23 18:13 174 --sha-w c:\program files\desktop.ini
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-24 06:32 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-10-23 22:35 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-03-27_22.04.44.78 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
- 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2000-08-31 07:00:00 89,504 ----a-w c:\windows\fdsv.exe
+ 2000-08-31 06:00:00 89,504 ----a-w c:\windows\fdsv.exe
- 2000-08-31 07:00:00 80,412 ----a-w c:\windows\grep.exe
+ 2000-08-31 06:00:00 80,412 ----a-w c:\windows\grep.exe
- 2009-03-25 20:42:49 51,200 ----a-w c:\windows\inf\infpub.dat
+ 2009-03-29 07:59:20 51,200 ----a-w c:\windows\inf\infpub.dat
- 2009-03-25 20:42:09 86,016 ----a-w c:\windows\inf\infstor.dat
+ 2009-03-27 22:06:52 86,016 ----a-w c:\windows\inf\infstor.dat
- 2009-03-25 20:42:49 143,360 ----a-w c:\windows\inf\infstrng.dat
+ 2009-03-29 07:59:20 143,360 ----a-w c:\windows\inf\infstrng.dat
- 2000-08-31 07:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
+ 2000-08-31 06:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
- 2000-08-31 07:00:00 98,816 ----a-w c:\windows\sed.exe
+ 2000-08-31 06:00:00 98,816 ----a-w c:\windows\sed.exe
- 2009-03-27 20:51:53 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-03-29 08:11:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-03-27 20:51:53 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-03-29 08:11:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-03-27 20:46:10 262,144 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2009-03-27 21:06:59 262,144 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2009-03-27 20:52:30 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 08:11:57 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 08:11:57 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-27 20:53:15 262,144 ----a-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2009-03-27 21:52:42 262,144 ----a-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2009-03-27 20:52:30 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 08:11:57 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 08:11:57 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2000-08-31 07:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 06:00:00 161,792 ----a-w c:\windows\SWREG.exe
- 2000-08-31 07:00:00 136,704 ----a-w c:\windows\SWSC.exe
+ 2000-08-31 06:00:00 136,704 ----a-w c:\windows\SWSC.exe
- 2000-08-31 07:00:00 212,480 ----a-w c:\windows\SWXCACLS.exe
+ 2000-08-31 06:00:00 212,480 ----a-w c:\windows\SWXCACLS.exe
- 2009-03-27 19:06:12 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-29 07:52:11 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-27 19:06:12 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-29 07:52:11 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-27 19:06:12 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-29 07:52:11 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-03-27 20:22:54 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-03-29 07:59:54 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2009-02-05 07:03:01 101,250 ----a-w c:\windows\System32\perfc009.dat
+ 2009-03-29 07:57:29 101,250 ----a-w c:\windows\System32\perfc009.dat
- 2009-02-05 07:03:01 123,556 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-03-29 07:57:29 123,556 ----a-w c:\windows\System32\perfc00C.dat
- 2009-02-05 07:03:01 587,178 ----a-w c:\windows\System32\perfh009.dat
+ 2009-03-29 07:57:29 587,178 ----a-w c:\windows\System32\perfh009.dat
- 2009-02-05 07:03:01 669,566 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-03-29 07:57:29 669,566 ----a-w c:\windows\System32\perfh00C.dat
- 2009-03-27 20:54:13 13,138 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
+ 2009-03-29 08:13:34 13,294 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
- 2009-03-27 20:54:13 76,122 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-29 08:13:34 76,890 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-27 20:32:25 57,944 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-29 07:51:51 58,564 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2000-08-31 07:00:00 49,152 ----a-w c:\windows\VFIND.exe
+ 2000-08-31 06:00:00 49,152 ----a-w c:\windows\VFIND.exe
- 2000-08-31 07:00:00 68,096 ----a-w c:\windows\zip.exe
+ 2000-08-31 06:00:00 68,096 ----a-w c:\windows\zip.exe
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-22 149040]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-26 39408]
"BitTorrent DNA"="c:\users\darty\Program Files\DNA\btdna.exe" [2008-12-19 342848]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2007-09-20 671744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-15 153136]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-27 13515296]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-27 92704]
"InterWrite Device Manager"="c:\program files\Interwrite Learning\Interwrite Workspace\IWStarter.exe" [2007-09-21 1122304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 c:\windows\RtHDVCpl.exe]
c:\users\darty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4757DF27-BB99-458F-80CB-DB0364C8F28F}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{419E922C-2259-4F5C-8434-B5F1D2E96D3A}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{E0F9C7C3-CA1A-416F-A34C-0862127D6393}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EB55CB69-2800-4DE8-A74E-01C74B7C84E3}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{ECCE1CEF-E35A-4D98-B328-225A47D70E75}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{31501F90-C592-4D85-9438-33EFD5D13D23}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{C3B4693F-2000-437E-B074-E9B72031798A}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{E661D763-1AD9-4680-B994-3BA0E48E3AC9}"= UDP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{E911C296-A208-4414-B72B-16FF9588005C}"= TCP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{F447015E-E82D-4B8F-8956-A39F6478AFFA}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{C88D7A4F-D46E-48CD-96D0-BA1ECFBD1E6B}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{F3B89985-7BF5-44B5-9D4E-EE2A42062761}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{E31F4E8A-0769-4B1A-9E31-4114195CBB25}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{8068D17E-06FF-480A-9AC1-C3F0676BEAD7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{1298C032-B160-458E-A3C8-BC7331CE56F9}"= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{018B64A2-15D3-495C-8582-C77D800E1665}"= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{F7A98888-0FC7-49F5-BE51-8FD6C7784EFE}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{4C65ADFC-9C57-4D87-976C-9C5943C4C2E2}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\Hp\QuickPlay\[u]0/u00.fcl [2008-01-16 01:22:44 39408]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [2008-12-15 185640]
R2 X4HSX32Ex;X4HSX32Ex;c:\program files\Player Metaboli\X4HSX32Ex.sys [2008-04-25 29856]
S2 gupdate1c98a09a93c69c9;Google Update Service (gupdate1c98a09a93c69c9);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [2008-04-21 436096]
S3 WiselinkPro;SAMSUNG WiselinkPro Service;c:\program files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2009-02-02 4014080]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - sptd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e9b063f-d10a-11dc-8d37-806e6f6e6963}]
\shell\AutoRun\command - F:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a915f3ae-9f32-11dd-a158-001e68056457}]
\shell\AutoRun\command - H:\LaunchU3.exe
.
Contenu du dossier 'Tâches planifiées'
2009-03-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-26 23:20]
2009-03-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 18:22]
2009-03-29 c:\windows\Tasks\User_Feed_Synchronization-{683B7A7C-3607-42F0-AF40-80427994F3E7}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 09:33]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://fr.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=81&bd=Pavilion&pf=laptop
IE: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-29 10:14:14
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(744)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(3552)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\conime.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\windows\ehome\ehsched.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\windows\ehome\ehrecvr.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
.
**************************************************************************
.
Heure de fin: 2009-03-29 10:25:11 - La machine a redémarré [darty]
ComboFix-quarantined-files.txt 2009-03-29 08:24:44
ComboFix2.txt 2009-03-27 21:06:21
Avant-CF: 31 038 754 816 octets libres
Après-CF: 32,587,096,064 octets libres
756 --- E O F --- 2009-03-29 07:55:19
Tu as plein de jeux téléchargés je crois ? Je ne serai pas surpris que l'infection vienne de là
Il va falloir faire un nouveau script. Ouvre le bloc-notes et fais un copié/collé de ce qui suit :
File::
c:\windows\System32\mhhewwywbyspgz.dll
Folder::
c:\programdata\GameXzone
Enregistre le sur ton Bureau sous le nom CFScript.txt
Puis fais le glisser sur Combofix comme pour l'autre, et poste le rapport stp
Il va falloir faire un nouveau script. Ouvre le bloc-notes et fais un copié/collé de ce qui suit :
File::
c:\windows\System32\mhhewwywbyspgz.dll
Folder::
c:\programdata\GameXzone
Enregistre le sur ton Bureau sous le nom CFScript.txt
Puis fais le glisser sur Combofix comme pour l'autre, et poste le rapport stp
Effectivement pour les jeux !
Jecrois que je vais faire un gros nettoyage après !!
Voila le rapport :
ComboFix 09-03-29.02 - darty 2009-03-29 23:10:20.3 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.1025 [GMT 2:00]
Lancé depuis: c:\users\darty\Desktop\rambo.exe
Commutateurs utilisés :: c:\users\darty\Desktop\CfScript.txt
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
FW: Bitdefender Firewall *disabled*
* Un nouveau point de restauration a été créé
FILE ::
c:\windows\System32\mhhewwywbyspgz.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\GameXzone
c:\programdata\GameXzone\ElDorado Quest\ElDoradoQuest.cfg
c:\programdata\GameXzone\ElDorado Quest\ElDoradoQuest.log
c:\programdata\GameXzone\Tibet Quest\TibetQuest.cfg
c:\programdata\GameXzone\Tibet Quest\TibetQuest.log
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-28 au 2009-03-29 ))))))))))))))))))))))))))))))))))))
.
2009-03-29 20:56 . 2009-03-29 20:56 <REP> d-------- c:\users\darty\AppData\Roaming\BigFishv1002fr
2009-03-28 01:35 . 2009-03-28 01:35 <REP> d-------- C:\C-Fix
2009-03-27 21:01 . 2009-03-27 22:28 121 --a------ c:\windows\bdagent.INI
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\users\darty\AppData\Roaming\Be a King
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\program files\Be a King
2009-03-26 22:50 . 2009-03-26 22:50 <REP> d-------- c:\program files\Insider Tales - Stolen Venus
2009-03-25 22:25 . 2009-03-25 22:25 <REP> d-------- c:\windows\BDOSCAN8
2009-03-22 23:02 . 2009-03-22 23:02 <REP> d-------- c:\program files\Tropical Mania
2009-03-22 18:45 . 2009-03-22 18:45 35,840 --a------ c:\windows\System32\gldx.exe
2009-03-22 01:19 . 2009-03-22 01:19 0 --a------ c:\windows\System32\drivers\ovfsth.sys
2009-03-22 00:22 . 2009-03-22 00:22 <REP> d-------- c:\program files\DigitalHQ
2009-03-22 00:19 . 2009-03-22 00:19 <REP> d-------- c:\windows\Delicious - Emily's Tea Garden
2009-03-22 00:19 . 2009-03-22 00:22 <REP> d-------- c:\program files\Delicious - Emily's Tea Garden
2009-03-21 22:35 . 2009-03-22 00:12 <REP> d-------- c:\program files\Hidden Mysteries - Buckingham Palace
2009-03-21 18:36 . 2009-03-21 18:36 59 --a------ c:\windows\RUNAWAY.INI
2009-03-21 18:32 . 2009-03-21 18:32 <REP> d-------- c:\program files\PENDULO Studios
2009-03-21 14:31 . 2009-03-22 11:23 <REP> d-------- c:\program files\Cossacks
2009-03-21 14:31 . 2009-03-21 14:31 53,248 --a------ c:\windows\System32\unrar.dll
2009-03-20 20:01 . 2009-03-20 20:01 <REP> d-------- c:\users\darty\AppData\Roaming\BrandX Games
2009-03-18 15:56 . 2009-03-18 16:04 <REP> d-------- c:\program files\Téléchargeur de amerzone
2009-03-16 21:47 . 2009-03-16 21:47 <REP> d-------- c:\users\darty\AppData\Roaming\Sortasoft
2009-03-15 12:18 . 2009-03-15 12:18 <REP> d-------- c:\program files\Lost in the City
2009-03-15 11:47 . 2009-03-15 11:47 <REP> d-------- c:\users\darty\AppData\Roaming\Anabel
2009-03-15 00:53 . 2009-03-15 00:54 <REP> d-------- c:\program files\The Hidden Object Show - Season 2
2009-03-14 11:24 . 2009-03-14 11:24 <REP> d-------- c:\windows\Hidden Wonders of the Depths
2009-03-13 21:07 . 2009-03-13 21:07 <REP> d-------- c:\users\darty\AppData\Roaming\Boolat Games
2009-03-11 22:31 . 2009-03-11 22:31 <REP> d-------- c:\program files\Angela Young's Dream Adventure
2009-03-11 21:55 . 2008-12-16 05:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 21:55 . 2008-12-16 07:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-11 21:54 . 2009-02-09 05:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 21:54 . 2008-11-27 06:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\users\All Users\Friday's games
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\programdata\Friday's games
2009-03-08 20:09 . 2009-03-08 20:09 <REP> d-------- c:\program files\Curse of the Pharaoh - Napoleons Secret
2009-03-08 17:18 . 2009-03-08 17:18 <REP> d-------- c:\program files\Geoplan-Geospace
2009-03-08 17:10 . 2009-03-08 17:10 <REP> d-------- c:\program files\Interwrite Learning
2009-03-05 23:57 . 2009-03-05 23:57 <REP> d-------- c:\users\darty\AppData\Roaming\ZEMNOTT
2009-03-05 23:55 . 2009-03-05 23:55 <REP> d-------- c:\windows\Nanny Mania 2
2009-03-05 23:53 . 2009-03-06 00:57 <REP> d-------- c:\program files\Eco-Match
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\windows\Romopolis
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\program files\Romopolis
2009-03-01 22:58 . 2009-03-02 00:03 <REP> d-------- c:\program files\Party Down
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 21:19 --------- d-----w c:\users\darty\AppData\Roaming\OpenOffice.org2
2009-03-29 21:18 --------- d-----w c:\users\darty\AppData\Roaming\DNA
2009-03-29 20:57 27,839 ----a-w c:\users\All Users\nvModes.dat
2009-03-29 20:57 27,839 ----a-w c:\programdata\nvModes.dat
2009-03-29 20:57 --------- d---a-w c:\programdata\TEMP
2009-03-29 16:40 --------- d-----w c:\programdata\Microsoft Help
2009-03-29 07:52 --------- d-----w c:\programdata\Google Updater
2009-03-28 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Gold Casual Games
2009-03-28 21:02 --------- d-----w c:\programdata\Gold Casual Games
2009-03-28 20:01 --------- d-----w c:\programdata\Intenium
2009-03-28 19:41 --------- d-----w c:\users\darty\AppData\Roaming\PlayFirst
2009-03-28 19:41 --------- d-----w c:\programdata\PlayFirst
2009-03-27 23:02 --------- d-----w c:\program files\Common Files\BitDefender
2009-03-27 20:53 --------- d-----w c:\program files\DNA
2009-03-25 20:36 81,984 ----a-w c:\windows\System32\bdod.bin
2009-03-25 19:49 --------- d-----w c:\program files\Java
2009-03-23 19:07 --------- d-----w c:\users\darty\AppData\Roaming\BitTorrent
2009-03-23 18:26 69,194 ----a-w c:\windows\System32\mhhewwywbyspgz.dll-uninst.exe
2009-03-22 08:16 --------- d-----w c:\programdata\NVIDIA
2009-03-21 20:35 --------- d-----w c:\users\darty\AppData\Roaming\Zylom
2009-03-21 16:32 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-20 22:22 --------- d-----w c:\program files\Oberon Media
2009-03-19 19:45 --------- d-----w c:\program files\HP Games
2009-03-19 19:21 --------- d-----w c:\programdata\WildTangent
2009-03-19 14:29 --------- d-----w c:\users\darty\AppData\Roaming\Flood Light Games
2009-03-19 14:29 --------- d-----w c:\programdata\Flood Light Games
2009-03-18 14:04 --------- d-----w c:\program files\Téléchargeur de amerzone
2009-03-12 19:17 --------- d-----w c:\program files\Windows Mail
2009-03-09 04:19 410,984 ----a-w c:\windows\System32\deploytk.dll
2009-03-04 21:30 --------- d-----w c:\programdata\Gogii
2009-03-03 21:01 --------- d-----w c:\users\darty\AppData\Roaming\MysteryStudio
2009-03-01 21:00 --------- d-----w c:\users\darty\AppData\Roaming\EleFun Games
2009-02-28 20:28 --------- d-----w c:\users\darty\AppData\Roaming\SerpentOfIsis
2009-02-28 20:25 --------- d-----w c:\program files\The Serpent of Isis
2009-02-28 20:18 --------- d-----w c:\users\darty\AppData\Roaming\panoramik
2009-02-27 20:48 --------- d-----w c:\users\darty\AppData\Roaming\World-LooM
2009-02-27 19:13 --------- d-----w c:\program files\The Wizard's Pen
2009-02-25 12:36 --------- d-----w c:\users\darty\AppData\Roaming\Tropical Dream Underwater Odyssey
2009-02-22 09:39 --------- d-----w c:\programdata\Enkord
2009-02-22 09:03 --------- d-----w c:\programdata\Big Fish Games Vancouver
2009-02-21 14:55 --------- d-----w c:\program files\Costume Chaos
2009-02-21 14:54 --------- d-----w c:\program files\Herods Lost Tomb
2009-02-21 09:32 --------- d-----w c:\programdata\FarmFrenzy-PizzaParty
2009-02-21 08:14 --------- d-----w c:\programdata\HoverBee Studios
2009-02-20 20:34 --------- d-----w c:\program files\Restoring Rhonda
2009-02-20 19:52 --------- d-----w c:\users\darty\AppData\Roaming\Skunk Studios
2009-02-20 14:57 --------- d-----w c:\users\darty\AppData\Roaming\blg
2009-02-20 14:57 --------- d-----w c:\programdata\blg
2009-02-18 12:49 --------- d-----w c:\users\darty\AppData\Roaming\FirstColony
2009-02-17 19:55 --------- d-----w c:\programdata\Mandragora
2009-02-16 18:46 --------- d-----w c:\program files\Google
2009-02-11 21:20 --------- d-----w c:\program files\BigfishGames
2009-02-11 20:05 --------- d-----w c:\programdata\SugarGames
2009-02-05 17:12 --------- d-----w c:\program files\Cradle Of Rome
2009-02-05 14:10 --------- d-----w c:\users\darty\AppData\Roaming\dvdcss
2009-02-04 12:41 --------- d-----w c:\users\darty\AppData\Roaming\Playrix Entertainment
2009-02-03 20:51 --------- d-----w c:\users\darty\AppData\Roaming\HSA
2009-02-02 22:07 --------- d-----w c:\users\darty\AppData\Roaming\Friday's games
2009-02-02 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Coyotes Tale
2009-02-02 18:42 --------- d-----w c:\program files\Samsung
2009-02-02 12:43 --------- d-----w c:\users\darty\AppData\Roaming\Island
2009-02-01 20:10 --------- d-----w c:\programdata\Meridian93
2009-02-01 20:09 --------- d-----w c:\users\darty\AppData\Roaming\Meridian93
2009-02-01 19:54 --------- d-----w c:\users\darty\AppData\Roaming\RobinsonCrusoe
2009-02-01 16:44 --------- d-----w c:\users\darty\AppData\Roaming\ViquaSoft
2009-01-30 08:41 --------- d-----w c:\program files\Lecteur CANALPLAY
2009-01-29 22:05 --------- d-----w c:\users\darty\AppData\Roaming\TimeQuest
2009-01-29 22:03 --------- d-----w c:\program files\Totem Tribe
2009-01-29 21:42 --------- d-----w c:\program files\Vogue Tales
2009-01-28 19:48 --------- d-----w c:\programdata\VogueTales
2009-01-28 15:51 --------- d-----w c:\program files\Sallys Salon
2009-01-28 11:26 --------- d-----w c:\programdata\Vogue Tales
2009-01-28 11:02 --------- d-----w c:\programdata\InterAction studios
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2008-10-11 18:52 27,335 ----a-w c:\users\darty\AppData\Roaming\nvModes.dat
2008-08-23 18:13 174 --sha-w c:\program files\desktop.ini
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-24 06:32 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-10-23 22:35 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( SnapShot_2009-03-29_10.23.26.57 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-18 21:07:41 217,864 ----a-r c:\windows\Installer\{90120000-006E-040C-0000-0000000FF1CE}\misc.exe
+ 2009-03-29 16:39:46 217,864 ----a-r c:\windows\Installer\{90120000-006E-040C-0000-0000000FF1CE}\misc.exe
- 2008-12-12 22:50:57 20,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-03-29 16:40:27 20,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-12-12 22:50:57 184,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-03-29 16:40:27 184,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2008-12-12 22:50:57 217,864 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-29 16:40:27 217,864 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2008-12-12 22:50:57 18,704 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-03-29 16:40:27 18,704 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-12-12 22:50:57 35,088 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-03-29 16:40:27 35,088 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-12-12 22:50:57 922,384 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-03-29 16:40:27 922,384 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2008-12-12 22:50:57 888,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-03-29 16:40:27 888,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-12-12 22:50:57 1,172,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-03-29 16:40:27 1,172,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-03-29 08:11:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-03-29 21:16:20 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-03-29 08:11:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-03-29 21:16:20 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-03-29 08:11:57 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 21:17:25 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 21:17:25 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-29 08:11:57 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 21:18:33 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 21:18:33 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-03-29 07:59:54 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-03-29 21:06:36 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-03-29 21:06:36 262,144 ---ha-w c:\windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2009-03-12 19:19:09 373,936 ----a-w c:\windows\System32\FNTCACHE.DAT
+ 2009-03-29 21:16:45 376,056 ----a-w c:\windows\System32\FNTCACHE.DAT
- 2009-03-29 07:57:29 101,250 ----a-w c:\windows\System32\perfc009.dat
+ 2009-03-29 21:24:44 101,250 ----a-w c:\windows\System32\perfc009.dat
- 2009-03-29 07:57:29 123,556 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-03-29 21:24:44 123,556 ----a-w c:\windows\System32\perfc00C.dat
- 2009-03-29 07:57:29 587,178 ----a-w c:\windows\System32\perfh009.dat
+ 2009-03-29 21:24:44 587,178 ----a-w c:\windows\System32\perfh009.dat
- 2009-03-29 07:57:29 669,566 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-03-29 21:24:44 669,566 ----a-w c:\windows\System32\perfh00C.dat
- 2009-03-29 08:13:34 13,294 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
+ 2009-03-29 21:18:47 13,318 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
- 2009-03-29 08:13:34 76,890 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-29 21:18:47 76,944 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-22 149040]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-26 39408]
"BitTorrent DNA"="c:\users\darty\Program Files\DNA\btdna.exe" [2008-12-19 342848]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2007-09-20 671744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-15 153136]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-27 13515296]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-27 92704]
"InterWrite Device Manager"="c:\program files\Interwrite Learning\Interwrite Workspace\IWStarter.exe" [2007-09-21 1122304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 c:\windows\RtHDVCpl.exe]
c:\users\darty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4757DF27-BB99-458F-80CB-DB0364C8F28F}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{419E922C-2259-4F5C-8434-B5F1D2E96D3A}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{E0F9C7C3-CA1A-416F-A34C-0862127D6393}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EB55CB69-2800-4DE8-A74E-01C74B7C84E3}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{ECCE1CEF-E35A-4D98-B328-225A47D70E75}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{31501F90-C592-4D85-9438-33EFD5D13D23}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{C3B4693F-2000-437E-B074-E9B72031798A}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{E661D763-1AD9-4680-B994-3BA0E48E3AC9}"= UDP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{E911C296-A208-4414-B72B-16FF9588005C}"= TCP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{F447015E-E82D-4B8F-8956-A39F6478AFFA}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{C88D7A4F-D46E-48CD-96D0-BA1ECFBD1E6B}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{F3B89985-7BF5-44B5-9D4E-EE2A42062761}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{E31F4E8A-0769-4B1A-9E31-4114195CBB25}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{8068D17E-06FF-480A-9AC1-C3F0676BEAD7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{1298C032-B160-458E-A3C8-BC7331CE56F9}"= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{018B64A2-15D3-495C-8582-C77D800E1665}"= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{F7A98888-0FC7-49F5-BE51-8FD6C7784EFE}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{4C65ADFC-9C57-4D87-976C-9C5943C4C2E2}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{41D03603-6BAB-4E75-8BAC-CC2C99172636}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3AFC9A16-A99D-4AC2-AAC0-B66A8716CE4F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{465BA8EE-172A-4F28-9AB5-4354EDDC76B3}c:\\users\\darty\\program files\\dna\\btdna.exe"= UDP:c:\users\darty\program files\dna\btdna.exe:btdna.exe
"UDP Query User{871BD6DC-C592-4923-81CE-1154534DCA68}c:\\users\\darty\\program files\\dna\\btdna.exe"= TCP:c:\users\darty\program files\dna\btdna.exe:btdna.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\Hp\QuickPlay\[u]0/u00.fcl [2008-01-16 01:22:44 39408]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [2008-12-15 185640]
R2 X4HSX32Ex;X4HSX32Ex;c:\program files\Player Metaboli\X4HSX32Ex.sys [2008-04-25 29856]
S2 gupdate1c98a09a93c69c9;Google Update Service (gupdate1c98a09a93c69c9);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [2008-04-21 436096]
S3 WiselinkPro;SAMSUNG WiselinkPro Service;c:\program files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2009-02-02 4014080]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - sptd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e9b063f-d10a-11dc-8d37-806e6f6e6963}]
\shell\AutoRun\command - F:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a915f3ae-9f32-11dd-a158-001e68056457}]
\shell\AutoRun\command - H:\LaunchU3.exe
.
Contenu du dossier 'Tâches planifiées'
2009-03-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-26 23:20]
2009-03-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 18:22]
2009-03-29 c:\windows\Tasks\User_Feed_Synchronization-{683B7A7C-3607-42F0-AF40-80427994F3E7}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 09:33]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://fr.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=81&bd=Pavilion&pf=laptop
IE: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-29 23:26:50
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(748)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(1808)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\windows\System32\rundll32.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\System32\conime.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\windows\ehome\ehsched.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\windows\ehome\ehrecvr.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
.
**************************************************************************
.
Heure de fin: 2009-03-29 23:33:20 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-29 21:32:54
ComboFix2.txt 2009-03-29 08:25:12
ComboFix3.txt 2009-03-27 21:06:21
Avant-CF: 32 337 432 576 octets libres
Après-CF: 32,211,030,016 octets libres
365 --- E O F --- 2009-03-29 07:55:19
Jecrois que je vais faire un gros nettoyage après !!
Voila le rapport :
ComboFix 09-03-29.02 - darty 2009-03-29 23:10:20.3 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.1025 [GMT 2:00]
Lancé depuis: c:\users\darty\Desktop\rambo.exe
Commutateurs utilisés :: c:\users\darty\Desktop\CfScript.txt
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
FW: Bitdefender Firewall *disabled*
* Un nouveau point de restauration a été créé
FILE ::
c:\windows\System32\mhhewwywbyspgz.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\GameXzone
c:\programdata\GameXzone\ElDorado Quest\ElDoradoQuest.cfg
c:\programdata\GameXzone\ElDorado Quest\ElDoradoQuest.log
c:\programdata\GameXzone\Tibet Quest\TibetQuest.cfg
c:\programdata\GameXzone\Tibet Quest\TibetQuest.log
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-28 au 2009-03-29 ))))))))))))))))))))))))))))))))))))
.
2009-03-29 20:56 . 2009-03-29 20:56 <REP> d-------- c:\users\darty\AppData\Roaming\BigFishv1002fr
2009-03-28 01:35 . 2009-03-28 01:35 <REP> d-------- C:\C-Fix
2009-03-27 21:01 . 2009-03-27 22:28 121 --a------ c:\windows\bdagent.INI
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\users\darty\AppData\Roaming\Be a King
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\program files\Be a King
2009-03-26 22:50 . 2009-03-26 22:50 <REP> d-------- c:\program files\Insider Tales - Stolen Venus
2009-03-25 22:25 . 2009-03-25 22:25 <REP> d-------- c:\windows\BDOSCAN8
2009-03-22 23:02 . 2009-03-22 23:02 <REP> d-------- c:\program files\Tropical Mania
2009-03-22 18:45 . 2009-03-22 18:45 35,840 --a------ c:\windows\System32\gldx.exe
2009-03-22 01:19 . 2009-03-22 01:19 0 --a------ c:\windows\System32\drivers\ovfsth.sys
2009-03-22 00:22 . 2009-03-22 00:22 <REP> d-------- c:\program files\DigitalHQ
2009-03-22 00:19 . 2009-03-22 00:19 <REP> d-------- c:\windows\Delicious - Emily's Tea Garden
2009-03-22 00:19 . 2009-03-22 00:22 <REP> d-------- c:\program files\Delicious - Emily's Tea Garden
2009-03-21 22:35 . 2009-03-22 00:12 <REP> d-------- c:\program files\Hidden Mysteries - Buckingham Palace
2009-03-21 18:36 . 2009-03-21 18:36 59 --a------ c:\windows\RUNAWAY.INI
2009-03-21 18:32 . 2009-03-21 18:32 <REP> d-------- c:\program files\PENDULO Studios
2009-03-21 14:31 . 2009-03-22 11:23 <REP> d-------- c:\program files\Cossacks
2009-03-21 14:31 . 2009-03-21 14:31 53,248 --a------ c:\windows\System32\unrar.dll
2009-03-20 20:01 . 2009-03-20 20:01 <REP> d-------- c:\users\darty\AppData\Roaming\BrandX Games
2009-03-18 15:56 . 2009-03-18 16:04 <REP> d-------- c:\program files\Téléchargeur de amerzone
2009-03-16 21:47 . 2009-03-16 21:47 <REP> d-------- c:\users\darty\AppData\Roaming\Sortasoft
2009-03-15 12:18 . 2009-03-15 12:18 <REP> d-------- c:\program files\Lost in the City
2009-03-15 11:47 . 2009-03-15 11:47 <REP> d-------- c:\users\darty\AppData\Roaming\Anabel
2009-03-15 00:53 . 2009-03-15 00:54 <REP> d-------- c:\program files\The Hidden Object Show - Season 2
2009-03-14 11:24 . 2009-03-14 11:24 <REP> d-------- c:\windows\Hidden Wonders of the Depths
2009-03-13 21:07 . 2009-03-13 21:07 <REP> d-------- c:\users\darty\AppData\Roaming\Boolat Games
2009-03-11 22:31 . 2009-03-11 22:31 <REP> d-------- c:\program files\Angela Young's Dream Adventure
2009-03-11 21:55 . 2008-12-16 05:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 21:55 . 2008-12-16 07:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-11 21:54 . 2009-02-09 05:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 21:54 . 2008-11-27 06:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\users\All Users\Friday's games
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\programdata\Friday's games
2009-03-08 20:09 . 2009-03-08 20:09 <REP> d-------- c:\program files\Curse of the Pharaoh - Napoleons Secret
2009-03-08 17:18 . 2009-03-08 17:18 <REP> d-------- c:\program files\Geoplan-Geospace
2009-03-08 17:10 . 2009-03-08 17:10 <REP> d-------- c:\program files\Interwrite Learning
2009-03-05 23:57 . 2009-03-05 23:57 <REP> d-------- c:\users\darty\AppData\Roaming\ZEMNOTT
2009-03-05 23:55 . 2009-03-05 23:55 <REP> d-------- c:\windows\Nanny Mania 2
2009-03-05 23:53 . 2009-03-06 00:57 <REP> d-------- c:\program files\Eco-Match
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\windows\Romopolis
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\program files\Romopolis
2009-03-01 22:58 . 2009-03-02 00:03 <REP> d-------- c:\program files\Party Down
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 21:19 --------- d-----w c:\users\darty\AppData\Roaming\OpenOffice.org2
2009-03-29 21:18 --------- d-----w c:\users\darty\AppData\Roaming\DNA
2009-03-29 20:57 27,839 ----a-w c:\users\All Users\nvModes.dat
2009-03-29 20:57 27,839 ----a-w c:\programdata\nvModes.dat
2009-03-29 20:57 --------- d---a-w c:\programdata\TEMP
2009-03-29 16:40 --------- d-----w c:\programdata\Microsoft Help
2009-03-29 07:52 --------- d-----w c:\programdata\Google Updater
2009-03-28 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Gold Casual Games
2009-03-28 21:02 --------- d-----w c:\programdata\Gold Casual Games
2009-03-28 20:01 --------- d-----w c:\programdata\Intenium
2009-03-28 19:41 --------- d-----w c:\users\darty\AppData\Roaming\PlayFirst
2009-03-28 19:41 --------- d-----w c:\programdata\PlayFirst
2009-03-27 23:02 --------- d-----w c:\program files\Common Files\BitDefender
2009-03-27 20:53 --------- d-----w c:\program files\DNA
2009-03-25 20:36 81,984 ----a-w c:\windows\System32\bdod.bin
2009-03-25 19:49 --------- d-----w c:\program files\Java
2009-03-23 19:07 --------- d-----w c:\users\darty\AppData\Roaming\BitTorrent
2009-03-23 18:26 69,194 ----a-w c:\windows\System32\mhhewwywbyspgz.dll-uninst.exe
2009-03-22 08:16 --------- d-----w c:\programdata\NVIDIA
2009-03-21 20:35 --------- d-----w c:\users\darty\AppData\Roaming\Zylom
2009-03-21 16:32 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-20 22:22 --------- d-----w c:\program files\Oberon Media
2009-03-19 19:45 --------- d-----w c:\program files\HP Games
2009-03-19 19:21 --------- d-----w c:\programdata\WildTangent
2009-03-19 14:29 --------- d-----w c:\users\darty\AppData\Roaming\Flood Light Games
2009-03-19 14:29 --------- d-----w c:\programdata\Flood Light Games
2009-03-18 14:04 --------- d-----w c:\program files\Téléchargeur de amerzone
2009-03-12 19:17 --------- d-----w c:\program files\Windows Mail
2009-03-09 04:19 410,984 ----a-w c:\windows\System32\deploytk.dll
2009-03-04 21:30 --------- d-----w c:\programdata\Gogii
2009-03-03 21:01 --------- d-----w c:\users\darty\AppData\Roaming\MysteryStudio
2009-03-01 21:00 --------- d-----w c:\users\darty\AppData\Roaming\EleFun Games
2009-02-28 20:28 --------- d-----w c:\users\darty\AppData\Roaming\SerpentOfIsis
2009-02-28 20:25 --------- d-----w c:\program files\The Serpent of Isis
2009-02-28 20:18 --------- d-----w c:\users\darty\AppData\Roaming\panoramik
2009-02-27 20:48 --------- d-----w c:\users\darty\AppData\Roaming\World-LooM
2009-02-27 19:13 --------- d-----w c:\program files\The Wizard's Pen
2009-02-25 12:36 --------- d-----w c:\users\darty\AppData\Roaming\Tropical Dream Underwater Odyssey
2009-02-22 09:39 --------- d-----w c:\programdata\Enkord
2009-02-22 09:03 --------- d-----w c:\programdata\Big Fish Games Vancouver
2009-02-21 14:55 --------- d-----w c:\program files\Costume Chaos
2009-02-21 14:54 --------- d-----w c:\program files\Herods Lost Tomb
2009-02-21 09:32 --------- d-----w c:\programdata\FarmFrenzy-PizzaParty
2009-02-21 08:14 --------- d-----w c:\programdata\HoverBee Studios
2009-02-20 20:34 --------- d-----w c:\program files\Restoring Rhonda
2009-02-20 19:52 --------- d-----w c:\users\darty\AppData\Roaming\Skunk Studios
2009-02-20 14:57 --------- d-----w c:\users\darty\AppData\Roaming\blg
2009-02-20 14:57 --------- d-----w c:\programdata\blg
2009-02-18 12:49 --------- d-----w c:\users\darty\AppData\Roaming\FirstColony
2009-02-17 19:55 --------- d-----w c:\programdata\Mandragora
2009-02-16 18:46 --------- d-----w c:\program files\Google
2009-02-11 21:20 --------- d-----w c:\program files\BigfishGames
2009-02-11 20:05 --------- d-----w c:\programdata\SugarGames
2009-02-05 17:12 --------- d-----w c:\program files\Cradle Of Rome
2009-02-05 14:10 --------- d-----w c:\users\darty\AppData\Roaming\dvdcss
2009-02-04 12:41 --------- d-----w c:\users\darty\AppData\Roaming\Playrix Entertainment
2009-02-03 20:51 --------- d-----w c:\users\darty\AppData\Roaming\HSA
2009-02-02 22:07 --------- d-----w c:\users\darty\AppData\Roaming\Friday's games
2009-02-02 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Coyotes Tale
2009-02-02 18:42 --------- d-----w c:\program files\Samsung
2009-02-02 12:43 --------- d-----w c:\users\darty\AppData\Roaming\Island
2009-02-01 20:10 --------- d-----w c:\programdata\Meridian93
2009-02-01 20:09 --------- d-----w c:\users\darty\AppData\Roaming\Meridian93
2009-02-01 19:54 --------- d-----w c:\users\darty\AppData\Roaming\RobinsonCrusoe
2009-02-01 16:44 --------- d-----w c:\users\darty\AppData\Roaming\ViquaSoft
2009-01-30 08:41 --------- d-----w c:\program files\Lecteur CANALPLAY
2009-01-29 22:05 --------- d-----w c:\users\darty\AppData\Roaming\TimeQuest
2009-01-29 22:03 --------- d-----w c:\program files\Totem Tribe
2009-01-29 21:42 --------- d-----w c:\program files\Vogue Tales
2009-01-28 19:48 --------- d-----w c:\programdata\VogueTales
2009-01-28 15:51 --------- d-----w c:\program files\Sallys Salon
2009-01-28 11:26 --------- d-----w c:\programdata\Vogue Tales
2009-01-28 11:02 --------- d-----w c:\programdata\InterAction studios
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2008-10-11 18:52 27,335 ----a-w c:\users\darty\AppData\Roaming\nvModes.dat
2008-08-23 18:13 174 --sha-w c:\program files\desktop.ini
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-24 06:32 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-10-23 22:35 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( SnapShot_2009-03-29_10.23.26.57 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-18 21:07:41 217,864 ----a-r c:\windows\Installer\{90120000-006E-040C-0000-0000000FF1CE}\misc.exe
+ 2009-03-29 16:39:46 217,864 ----a-r c:\windows\Installer\{90120000-006E-040C-0000-0000000FF1CE}\misc.exe
- 2008-12-12 22:50:57 20,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-03-29 16:40:27 20,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-12-12 22:50:57 184,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-03-29 16:40:27 184,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2008-12-12 22:50:57 217,864 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-29 16:40:27 217,864 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2008-12-12 22:50:57 18,704 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-03-29 16:40:27 18,704 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-12-12 22:50:57 35,088 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-03-29 16:40:27 35,088 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-12-12 22:50:57 922,384 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-03-29 16:40:27 922,384 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2008-12-12 22:50:57 888,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-03-29 16:40:27 888,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-12-12 22:50:57 1,172,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-03-29 16:40:27 1,172,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-03-29 08:11:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-03-29 21:16:20 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-03-29 08:11:27 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-03-29 21:16:20 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-03-29 08:11:57 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 21:17:25 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 21:17:25 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-29 08:11:57 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 21:18:33 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 21:18:33 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-03-29 07:59:54 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-03-29 21:06:36 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-03-29 21:06:36 262,144 ---ha-w c:\windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2009-03-12 19:19:09 373,936 ----a-w c:\windows\System32\FNTCACHE.DAT
+ 2009-03-29 21:16:45 376,056 ----a-w c:\windows\System32\FNTCACHE.DAT
- 2009-03-29 07:57:29 101,250 ----a-w c:\windows\System32\perfc009.dat
+ 2009-03-29 21:24:44 101,250 ----a-w c:\windows\System32\perfc009.dat
- 2009-03-29 07:57:29 123,556 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-03-29 21:24:44 123,556 ----a-w c:\windows\System32\perfc00C.dat
- 2009-03-29 07:57:29 587,178 ----a-w c:\windows\System32\perfh009.dat
+ 2009-03-29 21:24:44 587,178 ----a-w c:\windows\System32\perfh009.dat
- 2009-03-29 07:57:29 669,566 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-03-29 21:24:44 669,566 ----a-w c:\windows\System32\perfh00C.dat
- 2009-03-29 08:13:34 13,294 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
+ 2009-03-29 21:18:47 13,318 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
- 2009-03-29 08:13:34 76,890 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-29 21:18:47 76,944 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-22 149040]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-26 39408]
"BitTorrent DNA"="c:\users\darty\Program Files\DNA\btdna.exe" [2008-12-19 342848]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2007-09-20 671744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-15 153136]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-27 13515296]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-27 92704]
"InterWrite Device Manager"="c:\program files\Interwrite Learning\Interwrite Workspace\IWStarter.exe" [2007-09-21 1122304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 c:\windows\RtHDVCpl.exe]
c:\users\darty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4757DF27-BB99-458F-80CB-DB0364C8F28F}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{419E922C-2259-4F5C-8434-B5F1D2E96D3A}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{E0F9C7C3-CA1A-416F-A34C-0862127D6393}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EB55CB69-2800-4DE8-A74E-01C74B7C84E3}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{ECCE1CEF-E35A-4D98-B328-225A47D70E75}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{31501F90-C592-4D85-9438-33EFD5D13D23}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{C3B4693F-2000-437E-B074-E9B72031798A}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{E661D763-1AD9-4680-B994-3BA0E48E3AC9}"= UDP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{E911C296-A208-4414-B72B-16FF9588005C}"= TCP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{F447015E-E82D-4B8F-8956-A39F6478AFFA}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{C88D7A4F-D46E-48CD-96D0-BA1ECFBD1E6B}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{F3B89985-7BF5-44B5-9D4E-EE2A42062761}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{E31F4E8A-0769-4B1A-9E31-4114195CBB25}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{8068D17E-06FF-480A-9AC1-C3F0676BEAD7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{1298C032-B160-458E-A3C8-BC7331CE56F9}"= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{018B64A2-15D3-495C-8582-C77D800E1665}"= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{F7A98888-0FC7-49F5-BE51-8FD6C7784EFE}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{4C65ADFC-9C57-4D87-976C-9C5943C4C2E2}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{41D03603-6BAB-4E75-8BAC-CC2C99172636}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3AFC9A16-A99D-4AC2-AAC0-B66A8716CE4F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{465BA8EE-172A-4F28-9AB5-4354EDDC76B3}c:\\users\\darty\\program files\\dna\\btdna.exe"= UDP:c:\users\darty\program files\dna\btdna.exe:btdna.exe
"UDP Query User{871BD6DC-C592-4923-81CE-1154534DCA68}c:\\users\\darty\\program files\\dna\\btdna.exe"= TCP:c:\users\darty\program files\dna\btdna.exe:btdna.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\Hp\QuickPlay\[u]0/u00.fcl [2008-01-16 01:22:44 39408]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [2008-12-15 185640]
R2 X4HSX32Ex;X4HSX32Ex;c:\program files\Player Metaboli\X4HSX32Ex.sys [2008-04-25 29856]
S2 gupdate1c98a09a93c69c9;Google Update Service (gupdate1c98a09a93c69c9);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [2008-04-21 436096]
S3 WiselinkPro;SAMSUNG WiselinkPro Service;c:\program files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2009-02-02 4014080]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - sptd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e9b063f-d10a-11dc-8d37-806e6f6e6963}]
\shell\AutoRun\command - F:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a915f3ae-9f32-11dd-a158-001e68056457}]
\shell\AutoRun\command - H:\LaunchU3.exe
.
Contenu du dossier 'Tâches planifiées'
2009-03-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-26 23:20]
2009-03-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 18:22]
2009-03-29 c:\windows\Tasks\User_Feed_Synchronization-{683B7A7C-3607-42F0-AF40-80427994F3E7}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 09:33]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://fr.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=81&bd=Pavilion&pf=laptop
IE: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-29 23:26:50
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(748)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(1808)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\windows\System32\rundll32.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\System32\conime.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\windows\ehome\ehsched.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\windows\ehome\ehrecvr.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
.
**************************************************************************
.
Heure de fin: 2009-03-29 23:33:20 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-29 21:32:54
ComboFix2.txt 2009-03-29 08:25:12
ComboFix3.txt 2009-03-27 21:06:21
Avant-CF: 32 337 432 576 octets libres
Après-CF: 32,211,030,016 octets libres
365 --- E O F --- 2009-03-29 07:55:19
Ok ;)
J'avais oublié que tu avais un problème avec BitDefender : est-ce que c'est toujours d'actualité ?
J'avais oublié que tu avais un problème avec BitDefender : est-ce que c'est toujours d'actualité ?
Poste un nouveau rapport hijackthis stp, je te proposerai ensuite un script de suppression des restes de BitDefender
et voila le rapport Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:05:59, on 31/03/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Interwrite Learning\Interwrite Workspace\IWStarter.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\darty\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\SearchFilterHost.exe
c:\Users\darty\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InterWrite Device Manager] "C:\Program Files\Interwrite Learning\Interwrite Workspace\IWStarter.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\darty\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: *.canalplay.com
O15 - Trusted Zone: *.canalplusactive.com
O15 - Trusted Zone: *.canalplay.com (HKLM)
O15 - Trusted Zone: *.canalplusactive.com (HKLM)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1c98a09a93c69c9) (gupdate1c98a09a93c69c9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: SAMSUNG WiselinkPro Service (WiselinkPro) - Unknown owner - C:\Program Files\SAMSUNG\SAMSUNG PC Share Manager\WiselinkPro.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:05:59, on 31/03/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Interwrite Learning\Interwrite Workspace\IWStarter.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\darty\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\SearchFilterHost.exe
c:\Users\darty\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InterWrite Device Manager] "C:\Program Files\Interwrite Learning\Interwrite Workspace\IWStarter.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\darty\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: *.canalplay.com
O15 - Trusted Zone: *.canalplusactive.com
O15 - Trusted Zone: *.canalplay.com (HKLM)
O15 - Trusted Zone: *.canalplusactive.com (HKLM)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1c98a09a93c69c9) (gupdate1c98a09a93c69c9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: SAMSUNG WiselinkPro Service (WiselinkPro) - Unknown owner - C:\Program Files\SAMSUNG\SAMSUNG PC Share Manager\WiselinkPro.exe
/!\ ATTENTION /!\ Le script qui suit a été écrit spécialement pour NoProbs, il n'est pas transposable sur un autre ordinateur !
• Télécharge ce dossier SuppressionBitDef.zip
• Fais un clic-droit dessus --> Extraire tout --> choisis le Bureau comme destination
• Un autre dossier va apparaitre, prends le fichier CFScript.txt qui se trouve à l'intérieur et place le sur le Bureau.
• Désactive tes logiciels de protection
• Fais un glisser/déposer de ce fichier CFScript.txt sur le fichier Combofix.exe
• Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
• Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
• Si le fichier ne s'ouvre pas, il se trouve ici → C:\ComboFix.txt
• Télécharge ce dossier SuppressionBitDef.zip
• Fais un clic-droit dessus --> Extraire tout --> choisis le Bureau comme destination
• Un autre dossier va apparaitre, prends le fichier CFScript.txt qui se trouve à l'intérieur et place le sur le Bureau.
• Désactive tes logiciels de protection
• Fais un glisser/déposer de ce fichier CFScript.txt sur le fichier Combofix.exe
• Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
• Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
• Si le fichier ne s'ouvre pas, il se trouve ici → C:\ComboFix.txt
Avant de t'envoyer le rapport je fais un test car je n'arrive pas à le poster et je me demande si ca n'est pas parce qu'il est trop long.
Je t'envoie le message en 3 fois car il ne passe pas sinon.
Une petite précision tout de même :
Après que le PC ait redémarré et avant qu'il m'affiche le rapport, j'ai eu un message me disant que Bit Defender était toujours actif. Ce que je vois également quand je regarde dans le centre de sécurité Windows !!
ComboFix 09-03-31.02 - darty 2009-04-01 12:46:00.4 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.869 [GMT 2:00]
Lancé depuis: c:\users\darty\Desktop\rambo.exe
Commutateurs utilisés :: c:\users\darty\Desktop\CFScript.txt
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
FW: Bitdefender Firewall *disabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\BitDefender
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\aphblack.cas
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\aphblack.ias
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\aphwhite.cas
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\aphwhite.ias
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_adg.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_adn.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_bgu.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_bit.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_fun.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_ipx.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_mdo.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_nmd.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_vda.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2himgdb.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2more.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2nn.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2nndata.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2sign.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2std.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2urldbc.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2urldbi.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2wl.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\asnnmap.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\aspdict.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\asversion.txt
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\bayescsf.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\pcdic.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\prlblk.cas
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\prlwht.cas
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\spoofcsf.dat
c:\program files\BitDefender\BitDefender 2008\NAG\Trial\expired.html
c:\program files\BitDefender\BitDefender 2008\NAG\Trial\expired.jpg
c:\program files\BitDefender\BitDefender 2008\tbextension\chrome.manifest
c:\program files\BitDefender\BitDefender 2008\tbextension\content\addenemy.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\addFriend.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\bdToolbar.js
c:\program files\BitDefender\BitDefender 2008\tbextension\content\bdToolbar.xul
c:\program files\BitDefender\BitDefender 2008\tbextension\content\isspam.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\logo.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\manageenemies.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\managefriends.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\notspam.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\settings.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\wizard.png
c:\program files\BitDefender\BitDefender 2008\tbextension\install.rdf
c:\program files\BitDefender\BitDefender 2008\tbextension\locale\en-US\bdtoolbar.dtd
c:\program files\Common Files\BitDefender
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\avxs.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\avxt.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\bdc.exe
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\bdc.ini
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\bdcore.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\bdupd.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\libfn.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\plugins.htm
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\7zip.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\access.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ace.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\adsntfs.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\alz.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\arc.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\arj.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\aspy_emu.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\bach.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\boot.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\bzip2.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cab.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ceva_dll.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ceva_emu.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ceva_vfs.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ceva_vfs.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cevakrnl.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cevakrnl.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cevakrnl.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\chm.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cookie.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cookie.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cpio.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cran.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cran.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\dbx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\docfile.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i01
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i02
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i03
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i04
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i05
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i06
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i07
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i08
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i09
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i10
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i11
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i12
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i13
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i14
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i15
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i16
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i17
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i18
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i19
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i20
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i21
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i22
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i23
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i24
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i25
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i26
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i27
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i28
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i29
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i30
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i31
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i32
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i33
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i34
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i35
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i36
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i37
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i38
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i39
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i40
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i41
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i42
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i43
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i44
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i45
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i46
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i47
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i48
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i49
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.001
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.002
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.003
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.004
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.005
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.006
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.007
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.008
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.009
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.010
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.011
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.012
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.013
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.014
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.015
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.016
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.017
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.018
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.019
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.020
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.021
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.022
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.023
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.024
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.025
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.026
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.027
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.028
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.029
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.030
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.031
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.032
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.033
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.034
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.035
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.036
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.037
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.038
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.039
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.040
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.041
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.042
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.043
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.044
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.045
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.046
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.047
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.048
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.049
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.050
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.051
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.052
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.053
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.054
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.055
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.056
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.057
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.058
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.059
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.060
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.061
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.062
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.063
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.064
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.065
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.066
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.067
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.068
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.069
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.070
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.071
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.072
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.073
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.074
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.075
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.076
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.077
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.078
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.079
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.080
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.081
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.082
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.083
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.084
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.085
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.086
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.087
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.088
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.089
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.090
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.091
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.092
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.093
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.094
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.095
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.096
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.097
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.098
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.099
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.100
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.101
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.102
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.103
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.104
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.105
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.106
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.107
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.108
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.109
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.110
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.111
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.112
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.113
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.114
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.115
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.116
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.117
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.118
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.119
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.120
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.121
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.122
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.123
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.124
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.125
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.126
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.127
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.128
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.129
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.130
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.131
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.132
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.133
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.134
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.135
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.136
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.137
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.138
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.139
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.140
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.141
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.142
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.143
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.144
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.145
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.146
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.147
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.148
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.149
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.150
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.151
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.152
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.153
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.154
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.155
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.156
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.157
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.158
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.159
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.160
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.161
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.162
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.163
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.164
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.165
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.166
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.167
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.168
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.169
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.170
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.171
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.172
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.173
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.174
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.175
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.176
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.177
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.178
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.179
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.180
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.181
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.182
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.183
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.184
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.185
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.186
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.187
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.188
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.189
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.190
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.191
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.192
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.193
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.194
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.195
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.196
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.197
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.198
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.199
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.200
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.201
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.202
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.203
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.204
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.205
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.206
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.207
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.208
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.209
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.210
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.211
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.212
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.213
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.214
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.215
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.216
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.217
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.218
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.219
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.220
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.221
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.222
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.223
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.224
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.225
Une petite précision tout de même :
Après que le PC ait redémarré et avant qu'il m'affiche le rapport, j'ai eu un message me disant que Bit Defender était toujours actif. Ce que je vois également quand je regarde dans le centre de sécurité Windows !!
ComboFix 09-03-31.02 - darty 2009-04-01 12:46:00.4 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.869 [GMT 2:00]
Lancé depuis: c:\users\darty\Desktop\rambo.exe
Commutateurs utilisés :: c:\users\darty\Desktop\CFScript.txt
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
FW: Bitdefender Firewall *disabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\BitDefender
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\aphblack.cas
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\aphblack.ias
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\aphwhite.cas
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\aphwhite.ias
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_adg.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_adn.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_bgu.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_bit.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_fun.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_ipx.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_mdo.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_nmd.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2_vda.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2himgdb.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2more.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2nn.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2nndata.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2sign.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2std.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2urldbc.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2urldbi.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\as2wl.slf
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\asnnmap.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\aspdict.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\asversion.txt
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\bayescsf.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\pcdic.dat
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\prlblk.cas
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\prlwht.cas
c:\program files\BitDefender\BitDefender 2008\as2core\antispam_sig\spoofcsf.dat
c:\program files\BitDefender\BitDefender 2008\NAG\Trial\expired.html
c:\program files\BitDefender\BitDefender 2008\NAG\Trial\expired.jpg
c:\program files\BitDefender\BitDefender 2008\tbextension\chrome.manifest
c:\program files\BitDefender\BitDefender 2008\tbextension\content\addenemy.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\addFriend.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\bdToolbar.js
c:\program files\BitDefender\BitDefender 2008\tbextension\content\bdToolbar.xul
c:\program files\BitDefender\BitDefender 2008\tbextension\content\isspam.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\logo.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\manageenemies.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\managefriends.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\notspam.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\settings.png
c:\program files\BitDefender\BitDefender 2008\tbextension\content\wizard.png
c:\program files\BitDefender\BitDefender 2008\tbextension\install.rdf
c:\program files\BitDefender\BitDefender 2008\tbextension\locale\en-US\bdtoolbar.dtd
c:\program files\Common Files\BitDefender
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\avxs.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\avxt.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\bdc.exe
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\bdc.ini
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\bdcore.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\bdupd.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\libfn.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\plugins.htm
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\7zip.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\access.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ace.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\adsntfs.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\alz.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\arc.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\arj.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\aspy_emu.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\bach.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\boot.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\bzip2.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cab.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ceva_dll.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ceva_emu.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ceva_vfs.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ceva_vfs.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cevakrnl.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cevakrnl.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cevakrnl.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\chm.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cookie.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cookie.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cpio.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cran.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\cran.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\dbx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\docfile.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i01
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i02
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i03
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i04
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i05
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i06
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i07
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i08
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i09
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i10
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i11
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i12
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i13
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i14
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i15
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i16
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i17
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i18
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i19
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i20
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i21
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i22
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i23
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i24
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i25
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i26
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i27
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i28
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i29
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i30
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i31
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i32
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i33
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i34
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i35
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i36
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i37
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i38
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i39
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i40
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i41
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i42
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i43
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i44
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i45
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i46
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i47
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i48
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.i49
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\e_spyw.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.001
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.002
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.003
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.004
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.005
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.006
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.007
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.008
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.009
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.010
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.011
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.012
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.013
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.014
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.015
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.016
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.017
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.018
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.019
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.020
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.021
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.022
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.023
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.024
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.025
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.026
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.027
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.028
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.029
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.030
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.031
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.032
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.033
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.034
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.035
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.036
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.037
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.038
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.039
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.040
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.041
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.042
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.043
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.044
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.045
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.046
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.047
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.048
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.049
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.050
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.051
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.052
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.053
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.054
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.055
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.056
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.057
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.058
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.059
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.060
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.061
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.062
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.063
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.064
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.065
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.066
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.067
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.068
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.069
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.070
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.071
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.072
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.073
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.074
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.075
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.076
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.077
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.078
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.079
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.080
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.081
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.082
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.083
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.084
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.085
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.086
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.087
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.088
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.089
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.090
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.091
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.092
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.093
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.094
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.095
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.096
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.097
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.098
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.099
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.100
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.101
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.102
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.103
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.104
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.105
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.106
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.107
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.108
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.109
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.110
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.111
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.112
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.113
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.114
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.115
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.116
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.117
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.118
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.119
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.120
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.121
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.122
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.123
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.124
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.125
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.126
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.127
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.128
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.129
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.130
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.131
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.132
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.133
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.134
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.135
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.136
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.137
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.138
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.139
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.140
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.141
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.142
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.143
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.144
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.145
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.146
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.147
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.148
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.149
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.150
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.151
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.152
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.153
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.154
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.155
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.156
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.157
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.158
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.159
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.160
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.161
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.162
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.163
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.164
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.165
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.166
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.167
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.168
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.169
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.170
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.171
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.172
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.173
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.174
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.175
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.176
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.177
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.178
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.179
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.180
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.181
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.182
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.183
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.184
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.185
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.186
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.187
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.188
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.189
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.190
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.191
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.192
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.193
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.194
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.195
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.196
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.197
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.198
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.199
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.200
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.201
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.202
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.203
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.204
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.205
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.206
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.207
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.208
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.209
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.210
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.211
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.212
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.213
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.214
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.215
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.216
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.217
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.218
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.219
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.220
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.221
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.222
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.223
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.224
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.225
Deuxième message !
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.226
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.227
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.228
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.229
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.230
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.231
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.232
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.233
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.234
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.235
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.236
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.237
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.238
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.239
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.240
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.241
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.242
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.243
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.244
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.245
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.246
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.247
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.248
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.249
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.250
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.251
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.252
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.253
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.254
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.255
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.256
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.257
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.258
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.259
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.260
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.261
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.262
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.263
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.264
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.265
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.266
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.267
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.268
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.269
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.270
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.271
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.272
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.273
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.274
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.275
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.276
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.277
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.278
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.279
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.280
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.281
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.282
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.283
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.284
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.285
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.286
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.287
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.288
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.289
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.290
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.291
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.292
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.293
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.294
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.295
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.296
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.297
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.298
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.299
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.300
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.301
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.302
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.303
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.304
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.305
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.306
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.307
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.308
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.309
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.310
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.311
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.312
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.313
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.314
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.315
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.316
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.317
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.318
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.319
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.320
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.321
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.322
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.323
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.324
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.325
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.326
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.327
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.328
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.329
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i01
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i02
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i03
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i04
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i05
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i06
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i07
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i08
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i09
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i10
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i11
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i12
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i13
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i14
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i15
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i16
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i17
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i18
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i19
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i20
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i21
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i22
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i23
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i24
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i25
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i26
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i27
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i28
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i29
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i30
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i31
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i32
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i33
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i34
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i35
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i36
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i37
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i38
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i39
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i40
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i41
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i42
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i43
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i44
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i45
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i46
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i47
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i48
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i49
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i50
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i51
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i52
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i53
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i54
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i55
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i56
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i57
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i58
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i59
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i60
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i61
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i62
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i63
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i64
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i65
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i66
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i67
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i68
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i69
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i70
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i71
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i72
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i73
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i74
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i75
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i76
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i77
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i78
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i79
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i80
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i81
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i82
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i83
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i84
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i85
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i86
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i87
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i88
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i89
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i90
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i91
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i92
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i93
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i94
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i95
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i96
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i97
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i98
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i99
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\epoc.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\gvmscripts.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\gzip.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ha.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\hlp.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\hpe.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\hqx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\html.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\imp.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\inno.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\instyler.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\iso.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\java.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\java.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\jpeg.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\lha.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\lnk.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mbox.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mbx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx_97.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx_97.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx_w95.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx_x95.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx_xf.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mime.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mobmalware.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mobmalware.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mso.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\na.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\nelf.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\nelf.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\nsis.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\objd.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\orice.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\pdf.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\proc.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\pst.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\rar.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\regarch.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\regarch.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\regscan.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\regscan.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\rpm.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\rtf.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\rup.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\rup.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\sdx.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\sdx.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\sdx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\sfx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\swf.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\tar.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\td0.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\thebat.xm
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.226
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.227
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.228
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.229
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.230
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.231
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.232
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.233
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.234
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.235
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.236
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.237
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.238
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.239
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.240
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.241
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.242
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.243
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.244
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.245
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.246
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.247
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.248
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.249
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.250
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.251
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.252
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.253
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.254
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.255
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.256
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.257
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.258
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.259
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.260
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.261
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.262
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.263
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.264
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.265
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.266
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.267
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.268
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.269
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.270
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.271
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.272
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.273
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.274
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.275
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.276
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.277
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.278
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.279
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.280
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.281
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.282
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.283
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.284
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.285
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.286
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.287
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.288
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.289
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.290
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.291
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.292
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.293
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.294
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.295
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.296
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.297
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.298
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.299
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.300
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.301
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.302
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.303
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.304
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.305
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.306
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.307
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.308
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.309
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.310
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.311
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.312
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.313
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.314
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.315
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.316
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.317
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.318
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.319
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.320
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.321
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.322
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.323
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.324
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.325
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.326
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.327
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.328
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.329
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i01
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i02
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i03
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i04
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i05
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i06
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i07
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i08
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i09
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i10
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i11
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i12
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i13
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i14
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i15
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i16
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i17
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i18
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i19
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i20
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i21
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i22
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i23
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i24
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i25
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i26
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i27
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i28
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i29
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i30
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i31
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i32
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i33
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i34
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i35
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i36
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i37
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i38
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i39
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i40
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i41
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i42
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i43
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i44
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i45
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i46
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i47
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i48
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i49
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i50
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i51
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i52
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i53
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i54
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i55
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i56
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i57
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i58
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i59
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i60
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i61
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i62
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i63
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i64
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i65
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i66
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i67
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i68
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i69
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i70
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i71
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i72
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i73
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i74
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i75
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i76
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i77
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i78
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i79
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i80
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i81
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i82
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i83
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i84
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i85
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i86
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i87
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i88
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i89
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i90
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i91
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i92
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i93
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i94
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i95
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i96
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i97
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i98
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.i99
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\emalware.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\epoc.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\gvmscripts.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\gzip.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ha.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\hlp.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\hpe.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\hqx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\html.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\imp.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\inno.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\instyler.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\iso.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\java.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\java.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\jpeg.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\lha.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\lnk.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mbox.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mbx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx_97.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx_97.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx_w95.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx_x95.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mdx_xf.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mime.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mobmalware.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mobmalware.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\mso.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\na.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\nelf.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\nelf.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\nsis.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\objd.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\orice.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\pdf.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\proc.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\pst.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\rar.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\regarch.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\regarch.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\regscan.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\regscan.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\rpm.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\rtf.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\rup.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\rup.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\sdx.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\sdx.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\sdx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\sfx.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\swf.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\tar.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\td0.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\thebat.xm
Troisième message !
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\tnef.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\uif.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\unpack.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\unpack.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\unpack.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\update.txt
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\uudecode.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ve.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ve.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ve.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\vedata.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\viza.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\wise.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\xcookies.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\xishield.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\xlmrd.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\xlmrd.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\z.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\zip.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\zoo.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5255\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5275\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5291\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5301\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5309\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5318\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5326\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5338\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5347\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5349\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5368\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5388\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5420\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5432\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5441\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5447\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5468\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5527\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5542\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5548\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5570\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5584\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5594\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5608\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5631\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5725\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5742\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5761\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5765\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5799\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5814\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5824\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5833\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5854\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5877\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5900\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5939\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5949\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5975\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6005\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6030\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6046\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6067\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6077\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6084\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6107\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6136\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6171\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6178\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6230\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6259\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7714\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7725\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7728\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7728\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7738\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7738\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7740\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7740\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7741\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7741\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7742\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7742\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7757\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7757\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7769\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7769\Plugins\cevakrnl.rvd
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-01 au 2009-04-01 ))))))))))))))))))))))))))))))))))))
.
2009-03-31 20:51 . 2009-03-31 20:51 <REP> d-------- c:\users\darty\AppData\Roaming\Lost in the City
2009-03-29 20:56 . 2009-03-29 20:56 <REP> d-------- c:\users\darty\AppData\Roaming\BigFishv1002fr
2009-03-28 01:35 . 2009-03-28 01:35 <REP> d-------- C:\C-Fix
2009-03-27 21:01 . 2009-03-27 22:28 121 --a------ c:\windows\bdagent.INI
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\users\darty\AppData\Roaming\Be a King
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\program files\Be a King
2009-03-26 22:50 . 2009-03-26 22:50 <REP> d-------- c:\program files\Insider Tales - Stolen Venus
2009-03-25 22:25 . 2009-03-25 22:25 <REP> d-------- c:\windows\BDOSCAN8
2009-03-22 23:02 . 2009-03-22 23:02 <REP> d-------- c:\program files\Tropical Mania
2009-03-22 18:45 . 2009-03-22 18:45 35,840 --a------ c:\windows\System32\gldx.exe
2009-03-22 01:19 . 2009-03-22 01:19 0 --a------ c:\windows\System32\drivers\ovfsth.sys
2009-03-22 00:22 . 2009-03-22 00:22 <REP> d-------- c:\program files\DigitalHQ
2009-03-22 00:19 . 2009-03-22 00:19 <REP> d-------- c:\windows\Delicious - Emily's Tea Garden
2009-03-22 00:19 . 2009-03-22 00:22 <REP> d-------- c:\program files\Delicious - Emily's Tea Garden
2009-03-21 22:35 . 2009-03-22 00:12 <REP> d-------- c:\program files\Hidden Mysteries - Buckingham Palace
2009-03-21 18:36 . 2009-03-21 18:36 59 --a------ c:\windows\RUNAWAY.INI
2009-03-21 18:32 . 2009-03-21 18:32 <REP> d-------- c:\program files\PENDULO Studios
2009-03-21 14:31 . 2009-03-22 11:23 <REP> d-------- c:\program files\Cossacks
2009-03-21 14:31 . 2009-03-21 14:31 53,248 --a------ c:\windows\System32\unrar.dll
2009-03-20 20:01 . 2009-03-20 20:01 <REP> d-------- c:\users\darty\AppData\Roaming\BrandX Games
2009-03-18 15:56 . 2009-03-18 16:04 <REP> d-------- c:\program files\Téléchargeur de amerzone
2009-03-16 21:47 . 2009-03-16 21:47 <REP> d-------- c:\users\darty\AppData\Roaming\Sortasoft
2009-03-15 12:18 . 2009-03-15 12:18 <REP> d-------- c:\program files\Lost in the City
2009-03-15 11:47 . 2009-03-15 11:47 <REP> d-------- c:\users\darty\AppData\Roaming\Anabel
2009-03-14 11:24 . 2009-03-14 11:24 <REP> d-------- c:\windows\Hidden Wonders of the Depths
2009-03-13 21:07 . 2009-03-13 21:07 <REP> d-------- c:\users\darty\AppData\Roaming\Boolat Games
2009-03-11 21:55 . 2008-12-16 05:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 21:55 . 2008-12-16 07:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-11 21:54 . 2009-02-09 05:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 21:54 . 2008-11-27 06:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\users\All Users\Friday's games
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\programdata\Friday's games
2009-03-08 20:09 . 2009-03-08 20:09 <REP> d-------- c:\program files\Curse of the Pharaoh - Napoleons Secret
2009-03-08 17:18 . 2009-03-08 17:18 <REP> d-------- c:\program files\Geoplan-Geospace
2009-03-08 17:10 . 2009-03-08 17:10 <REP> d-------- c:\program files\Interwrite Learning
2009-03-05 23:57 . 2009-03-05 23:57 <REP> d-------- c:\users\darty\AppData\Roaming\ZEMNOTT
2009-03-05 23:55 . 2009-03-05 23:55 <REP> d-------- c:\windows\Nanny Mania 2
2009-03-05 23:53 . 2009-03-06 00:57 <REP> d-------- c:\program files\Eco-Match
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\windows\Romopolis
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\program files\Romopolis
2009-03-01 22:58 . 2009-03-02 00:03 <REP> d-------- c:\program files\Party Down
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-01 10:58 --------- d-----w c:\users\darty\AppData\Roaming\OpenOffice.org2
2009-04-01 10:57 --------- d-----w c:\users\darty\AppData\Roaming\DNA
2009-03-31 19:53 27,839 ----a-w c:\users\All Users\nvModes.dat
2009-03-31 19:53 27,839 ----a-w c:\programdata\nvModes.dat
2009-03-31 19:53 --------- d---a-w c:\programdata\TEMP
2009-03-31 19:33 --------- d-----w c:\programdata\Google Updater
2009-03-31 18:53 --------- d-----w c:\programdata\Gogii
2009-03-29 16:40 --------- d-----w c:\programdata\Microsoft Help
2009-03-28 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Gold Casual Games
2009-03-28 21:02 --------- d-----w c:\programdata\Gold Casual Games
2009-03-28 20:01 --------- d-----w c:\programdata\Intenium
2009-03-28 19:41 --------- d-----w c:\users\darty\AppData\Roaming\PlayFirst
2009-03-28 19:41 --------- d-----w c:\programdata\PlayFirst
2009-03-27 20:53 --------- d-----w c:\program files\DNA
2009-03-25 20:36 81,984 ----a-w c:\windows\System32\bdod.bin
2009-03-25 19:49 --------- d-----w c:\program files\Java
2009-03-23 19:07 --------- d-----w c:\users\darty\AppData\Roaming\BitTorrent
2009-03-23 18:26 69,194 ----a-w c:\windows\System32\mhhewwywbyspgz.dll-uninst.exe
2009-03-22 08:16 --------- d-----w c:\programdata\NVIDIA
2009-03-21 20:35 --------- d-----w c:\users\darty\AppData\Roaming\Zylom
2009-03-21 16:32 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-20 22:22 --------- d-----w c:\program files\Oberon Media
2009-03-19 19:45 --------- d-----w c:\program files\HP Games
2009-03-19 19:21 --------- d-----w c:\programdata\WildTangent
2009-03-19 14:29 --------- d-----w c:\users\darty\AppData\Roaming\Flood Light Games
2009-03-19 14:29 --------- d-----w c:\programdata\Flood Light Games
2009-03-18 14:04 --------- d-----w c:\program files\Téléchargeur de amerzone
2009-03-12 19:17 --------- d-----w c:\program files\Windows Mail
2009-03-09 04:19 410,984 ----a-w c:\windows\System32\deploytk.dll
2009-03-03 21:01 --------- d-----w c:\users\darty\AppData\Roaming\MysteryStudio
2009-03-01 21:00 --------- d-----w c:\users\darty\AppData\Roaming\EleFun Games
2009-02-28 20:28 --------- d-----w c:\users\darty\AppData\Roaming\SerpentOfIsis
2009-02-28 20:25 --------- d-----w c:\program files\The Serpent of Isis
2009-02-28 20:18 --------- d-----w c:\users\darty\AppData\Roaming\panoramik
2009-02-27 20:48 --------- d-----w c:\users\darty\AppData\Roaming\World-LooM
2009-02-27 19:13 --------- d-----w c:\program files\The Wizard's Pen
2009-02-25 12:36 --------- d-----w c:\users\darty\AppData\Roaming\Tropical Dream Underwater Odyssey
2009-02-22 09:39 --------- d-----w c:\programdata\Enkord
2009-02-22 09:03 --------- d-----w c:\programdata\Big Fish Games Vancouver
2009-02-21 14:55 --------- d-----w c:\program files\Costume Chaos
2009-02-21 14:54 --------- d-----w c:\program files\Herods Lost Tomb
2009-02-21 09:32 --------- d-----w c:\programdata\FarmFrenzy-PizzaParty
2009-02-21 08:14 --------- d-----w c:\programdata\HoverBee Studios
2009-02-20 20:34 --------- d-----w c:\program files\Restoring Rhonda
2009-02-20 19:52 --------- d-----w c:\users\darty\AppData\Roaming\Skunk Studios
2009-02-20 14:57 --------- d-----w c:\users\darty\AppData\Roaming\blg
2009-02-20 14:57 --------- d-----w c:\programdata\blg
2009-02-18 12:49 --------- d-----w c:\users\darty\AppData\Roaming\FirstColony
2009-02-17 19:55 --------- d-----w c:\programdata\Mandragora
2009-02-16 18:46 --------- d-----w c:\program files\Google
2009-02-11 21:20 --------- d-----w c:\program files\BigfishGames
2009-02-11 20:05 --------- d-----w c:\programdata\SugarGames
2009-02-05 17:12 --------- d-----w c:\program files\Cradle Of Rome
2009-02-05 14:10 --------- d-----w c:\users\darty\AppData\Roaming\dvdcss
2009-02-04 12:41 --------- d-----w c:\users\darty\AppData\Roaming\Playrix Entertainment
2009-02-03 20:51 --------- d-----w c:\users\darty\AppData\Roaming\HSA
2009-02-02 22:07 --------- d-----w c:\users\darty\AppData\Roaming\Friday's games
2009-02-02 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Coyotes Tale
2009-02-02 18:42 --------- d-----w c:\program files\Samsung
2009-02-02 12:43 --------- d-----w c:\users\darty\AppData\Roaming\Island
2009-02-01 20:10 --------- d-----w c:\programdata\Meridian93
2009-02-01 20:09 --------- d-----w c:\users\darty\AppData\Roaming\Meridian93
2009-02-01 19:54 --------- d-----w c:\users\darty\AppData\Roaming\RobinsonCrusoe
2009-02-01 16:44 --------- d-----w c:\users\darty\AppData\Roaming\ViquaSoft
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2008-10-11 18:52 27,335 ----a-w c:\users\darty\AppData\Roaming\nvModes.dat
2008-08-23 18:13 174 --sha-w c:\program files\desktop.ini
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-24 06:32 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-10-23 22:35 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( SnapShot_2009-03-29_23.31.39.66 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-29 21:16:20 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-04-01 10:53:29 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-03-29 21:16:20 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-04-01 10:53:29 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-03-29 21:17:25 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-04-01 10:57:17 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-04-01 10:57:17 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-29 21:18:33 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-04-01 10:58:01 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2009-03-29 07:52:11 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-04-01 10:43:14 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-29 07:52:11 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-01 10:43:14 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-29 07:52:11 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-04-01 10:43:14 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-03-29 21:06:36 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-04-01 10:45:24 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-04-01 10:45:24 262,144 ---ha-w c:\windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2009-03-29 21:24:44 101,250 ----a-w c:\windows\System32\perfc009.dat
+ 2009-04-01 08:41:35 101,250 ----a-w c:\windows\System32\perfc009.dat
- 2009-03-29 21:24:44 123,556 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-04-01 08:41:35 123,556 ----a-w c:\windows\System32\perfc00C.dat
- 2009-03-29 21:24:44 587,178 ----a-w c:\windows\System32\perfh009.dat
+ 2009-04-01 08:41:35 587,178 ----a-w c:\windows\System32\perfh009.dat
- 2009-03-29 21:24:44 669,566 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-04-01 08:41:35 669,566 ----a-w c:\windows\System32\perfh00C.dat
- 2009-03-29 21:18:47 13,318 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
+ 2009-04-01 10:58:40 13,386 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
- 2009-03-29 21:18:47 76,944 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-04-01 10:58:39 77,240 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-29 07:51:51 58,564 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-04-01 08:37:59 58,564 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\tnef.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\uif.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\unpack.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\unpack.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\unpack.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\update.txt
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\uudecode.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ve.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ve.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\ve.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\vedata.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\viza.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\wise.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\xcookies.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\xishield.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\xlmrd.cvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\xlmrd.ivd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\z.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\zip.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit\Plugins\zoo.xmd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5255\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5275\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5291\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5301\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5309\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5318\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5326\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5338\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5347\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5349\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5368\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5388\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5420\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5432\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5441\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5447\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5468\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5527\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5542\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5548\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5570\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5584\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5594\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5608\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5631\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5725\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5742\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5761\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5765\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5799\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5814\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5824\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5833\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5854\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5877\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5900\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5939\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5949\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_5975\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6005\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6030\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6046\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6067\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6077\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6084\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6107\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6136\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6171\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6178\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6230\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_6259\avxdisk.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7714\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7725\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7728\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7728\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7738\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7738\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7740\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7740\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7741\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7741\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7742\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7742\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7757\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7757\Plugins\cevakrnl.rvd
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7769\Plugins\cevakrnl.rv0
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_7769\Plugins\cevakrnl.rvd
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-01 au 2009-04-01 ))))))))))))))))))))))))))))))))))))
.
2009-03-31 20:51 . 2009-03-31 20:51 <REP> d-------- c:\users\darty\AppData\Roaming\Lost in the City
2009-03-29 20:56 . 2009-03-29 20:56 <REP> d-------- c:\users\darty\AppData\Roaming\BigFishv1002fr
2009-03-28 01:35 . 2009-03-28 01:35 <REP> d-------- C:\C-Fix
2009-03-27 21:01 . 2009-03-27 22:28 121 --a------ c:\windows\bdagent.INI
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\users\darty\AppData\Roaming\Be a King
2009-03-27 19:05 . 2009-03-27 19:05 <REP> d-------- c:\program files\Be a King
2009-03-26 22:50 . 2009-03-26 22:50 <REP> d-------- c:\program files\Insider Tales - Stolen Venus
2009-03-25 22:25 . 2009-03-25 22:25 <REP> d-------- c:\windows\BDOSCAN8
2009-03-22 23:02 . 2009-03-22 23:02 <REP> d-------- c:\program files\Tropical Mania
2009-03-22 18:45 . 2009-03-22 18:45 35,840 --a------ c:\windows\System32\gldx.exe
2009-03-22 01:19 . 2009-03-22 01:19 0 --a------ c:\windows\System32\drivers\ovfsth.sys
2009-03-22 00:22 . 2009-03-22 00:22 <REP> d-------- c:\program files\DigitalHQ
2009-03-22 00:19 . 2009-03-22 00:19 <REP> d-------- c:\windows\Delicious - Emily's Tea Garden
2009-03-22 00:19 . 2009-03-22 00:22 <REP> d-------- c:\program files\Delicious - Emily's Tea Garden
2009-03-21 22:35 . 2009-03-22 00:12 <REP> d-------- c:\program files\Hidden Mysteries - Buckingham Palace
2009-03-21 18:36 . 2009-03-21 18:36 59 --a------ c:\windows\RUNAWAY.INI
2009-03-21 18:32 . 2009-03-21 18:32 <REP> d-------- c:\program files\PENDULO Studios
2009-03-21 14:31 . 2009-03-22 11:23 <REP> d-------- c:\program files\Cossacks
2009-03-21 14:31 . 2009-03-21 14:31 53,248 --a------ c:\windows\System32\unrar.dll
2009-03-20 20:01 . 2009-03-20 20:01 <REP> d-------- c:\users\darty\AppData\Roaming\BrandX Games
2009-03-18 15:56 . 2009-03-18 16:04 <REP> d-------- c:\program files\Téléchargeur de amerzone
2009-03-16 21:47 . 2009-03-16 21:47 <REP> d-------- c:\users\darty\AppData\Roaming\Sortasoft
2009-03-15 12:18 . 2009-03-15 12:18 <REP> d-------- c:\program files\Lost in the City
2009-03-15 11:47 . 2009-03-15 11:47 <REP> d-------- c:\users\darty\AppData\Roaming\Anabel
2009-03-14 11:24 . 2009-03-14 11:24 <REP> d-------- c:\windows\Hidden Wonders of the Depths
2009-03-13 21:07 . 2009-03-13 21:07 <REP> d-------- c:\users\darty\AppData\Roaming\Boolat Games
2009-03-11 21:55 . 2008-12-16 05:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 21:55 . 2008-12-16 07:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 21:55 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-11 21:54 . 2009-02-09 05:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 21:54 . 2008-11-27 06:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\users\All Users\Friday's games
2009-03-10 22:36 . 2009-03-10 22:36 <REP> d-------- c:\programdata\Friday's games
2009-03-08 20:09 . 2009-03-08 20:09 <REP> d-------- c:\program files\Curse of the Pharaoh - Napoleons Secret
2009-03-08 17:18 . 2009-03-08 17:18 <REP> d-------- c:\program files\Geoplan-Geospace
2009-03-08 17:10 . 2009-03-08 17:10 <REP> d-------- c:\program files\Interwrite Learning
2009-03-05 23:57 . 2009-03-05 23:57 <REP> d-------- c:\users\darty\AppData\Roaming\ZEMNOTT
2009-03-05 23:55 . 2009-03-05 23:55 <REP> d-------- c:\windows\Nanny Mania 2
2009-03-05 23:53 . 2009-03-06 00:57 <REP> d-------- c:\program files\Eco-Match
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\windows\Romopolis
2009-03-03 21:35 . 2009-03-03 21:35 <REP> d-------- c:\program files\Romopolis
2009-03-01 22:58 . 2009-03-02 00:03 <REP> d-------- c:\program files\Party Down
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-01 10:58 --------- d-----w c:\users\darty\AppData\Roaming\OpenOffice.org2
2009-04-01 10:57 --------- d-----w c:\users\darty\AppData\Roaming\DNA
2009-03-31 19:53 27,839 ----a-w c:\users\All Users\nvModes.dat
2009-03-31 19:53 27,839 ----a-w c:\programdata\nvModes.dat
2009-03-31 19:53 --------- d---a-w c:\programdata\TEMP
2009-03-31 19:33 --------- d-----w c:\programdata\Google Updater
2009-03-31 18:53 --------- d-----w c:\programdata\Gogii
2009-03-29 16:40 --------- d-----w c:\programdata\Microsoft Help
2009-03-28 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Gold Casual Games
2009-03-28 21:02 --------- d-----w c:\programdata\Gold Casual Games
2009-03-28 20:01 --------- d-----w c:\programdata\Intenium
2009-03-28 19:41 --------- d-----w c:\users\darty\AppData\Roaming\PlayFirst
2009-03-28 19:41 --------- d-----w c:\programdata\PlayFirst
2009-03-27 20:53 --------- d-----w c:\program files\DNA
2009-03-25 20:36 81,984 ----a-w c:\windows\System32\bdod.bin
2009-03-25 19:49 --------- d-----w c:\program files\Java
2009-03-23 19:07 --------- d-----w c:\users\darty\AppData\Roaming\BitTorrent
2009-03-23 18:26 69,194 ----a-w c:\windows\System32\mhhewwywbyspgz.dll-uninst.exe
2009-03-22 08:16 --------- d-----w c:\programdata\NVIDIA
2009-03-21 20:35 --------- d-----w c:\users\darty\AppData\Roaming\Zylom
2009-03-21 16:32 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-20 22:22 --------- d-----w c:\program files\Oberon Media
2009-03-19 19:45 --------- d-----w c:\program files\HP Games
2009-03-19 19:21 --------- d-----w c:\programdata\WildTangent
2009-03-19 14:29 --------- d-----w c:\users\darty\AppData\Roaming\Flood Light Games
2009-03-19 14:29 --------- d-----w c:\programdata\Flood Light Games
2009-03-18 14:04 --------- d-----w c:\program files\Téléchargeur de amerzone
2009-03-12 19:17 --------- d-----w c:\program files\Windows Mail
2009-03-09 04:19 410,984 ----a-w c:\windows\System32\deploytk.dll
2009-03-03 21:01 --------- d-----w c:\users\darty\AppData\Roaming\MysteryStudio
2009-03-01 21:00 --------- d-----w c:\users\darty\AppData\Roaming\EleFun Games
2009-02-28 20:28 --------- d-----w c:\users\darty\AppData\Roaming\SerpentOfIsis
2009-02-28 20:25 --------- d-----w c:\program files\The Serpent of Isis
2009-02-28 20:18 --------- d-----w c:\users\darty\AppData\Roaming\panoramik
2009-02-27 20:48 --------- d-----w c:\users\darty\AppData\Roaming\World-LooM
2009-02-27 19:13 --------- d-----w c:\program files\The Wizard's Pen
2009-02-25 12:36 --------- d-----w c:\users\darty\AppData\Roaming\Tropical Dream Underwater Odyssey
2009-02-22 09:39 --------- d-----w c:\programdata\Enkord
2009-02-22 09:03 --------- d-----w c:\programdata\Big Fish Games Vancouver
2009-02-21 14:55 --------- d-----w c:\program files\Costume Chaos
2009-02-21 14:54 --------- d-----w c:\program files\Herods Lost Tomb
2009-02-21 09:32 --------- d-----w c:\programdata\FarmFrenzy-PizzaParty
2009-02-21 08:14 --------- d-----w c:\programdata\HoverBee Studios
2009-02-20 20:34 --------- d-----w c:\program files\Restoring Rhonda
2009-02-20 19:52 --------- d-----w c:\users\darty\AppData\Roaming\Skunk Studios
2009-02-20 14:57 --------- d-----w c:\users\darty\AppData\Roaming\blg
2009-02-20 14:57 --------- d-----w c:\programdata\blg
2009-02-18 12:49 --------- d-----w c:\users\darty\AppData\Roaming\FirstColony
2009-02-17 19:55 --------- d-----w c:\programdata\Mandragora
2009-02-16 18:46 --------- d-----w c:\program files\Google
2009-02-11 21:20 --------- d-----w c:\program files\BigfishGames
2009-02-11 20:05 --------- d-----w c:\programdata\SugarGames
2009-02-05 17:12 --------- d-----w c:\program files\Cradle Of Rome
2009-02-05 14:10 --------- d-----w c:\users\darty\AppData\Roaming\dvdcss
2009-02-04 12:41 --------- d-----w c:\users\darty\AppData\Roaming\Playrix Entertainment
2009-02-03 20:51 --------- d-----w c:\users\darty\AppData\Roaming\HSA
2009-02-02 22:07 --------- d-----w c:\users\darty\AppData\Roaming\Friday's games
2009-02-02 21:02 --------- d-----w c:\users\darty\AppData\Roaming\Coyotes Tale
2009-02-02 18:42 --------- d-----w c:\program files\Samsung
2009-02-02 12:43 --------- d-----w c:\users\darty\AppData\Roaming\Island
2009-02-01 20:10 --------- d-----w c:\programdata\Meridian93
2009-02-01 20:09 --------- d-----w c:\users\darty\AppData\Roaming\Meridian93
2009-02-01 19:54 --------- d-----w c:\users\darty\AppData\Roaming\RobinsonCrusoe
2009-02-01 16:44 --------- d-----w c:\users\darty\AppData\Roaming\ViquaSoft
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2008-10-11 18:52 27,335 ----a-w c:\users\darty\AppData\Roaming\nvModes.dat
2008-08-23 18:13 174 --sha-w c:\program files\desktop.ini
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-24 06:32 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-24 06:32 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-10-23 22:35 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-10-23 22:35 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( SnapShot_2009-03-29_23.31.39.66 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-29 21:16:20 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-04-01 10:53:29 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-03-29 21:16:20 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-04-01 10:53:29 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-03-29 21:17:25 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-04-01 10:57:17 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-04-01 10:57:17 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-29 21:18:33 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-04-01 10:58:01 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2009-03-29 07:52:11 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-04-01 10:43:14 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-29 07:52:11 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-01 10:43:14 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-29 07:52:11 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-04-01 10:43:14 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-03-29 21:06:36 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-04-01 10:45:24 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-04-01 10:45:24 262,144 ---ha-w c:\windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2009-03-29 21:24:44 101,250 ----a-w c:\windows\System32\perfc009.dat
+ 2009-04-01 08:41:35 101,250 ----a-w c:\windows\System32\perfc009.dat
- 2009-03-29 21:24:44 123,556 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-04-01 08:41:35 123,556 ----a-w c:\windows\System32\perfc00C.dat
- 2009-03-29 21:24:44 587,178 ----a-w c:\windows\System32\perfh009.dat
+ 2009-04-01 08:41:35 587,178 ----a-w c:\windows\System32\perfh009.dat
- 2009-03-29 21:24:44 669,566 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-04-01 08:41:35 669,566 ----a-w c:\windows\System32\perfh00C.dat
- 2009-03-29 21:18:47 13,318 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
+ 2009-04-01 10:58:40 13,386 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1939369795-1135893550-788158429-1000_UserData.bin
- 2009-03-29 21:18:47 76,944 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-04-01 10:58:39 77,240 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-29 07:51:51 58,564 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-04-01 08:37:59 58,564 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
Et enfin quatrième et dernier message !!(ouf)
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-22 149040]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-26 39408]
"BitTorrent DNA"="c:\users\darty\Program Files\DNA\btdna.exe" [2008-12-19 342848]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2007-09-20 671744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-15 153136]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-27 13515296]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-27 92704]
"InterWrite Device Manager"="c:\program files\Interwrite Learning\Interwrite Workspace\IWStarter.exe" [2007-09-21 1122304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 c:\windows\RtHDVCpl.exe]
c:\users\darty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4757DF27-BB99-458F-80CB-DB0364C8F28F}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{419E922C-2259-4F5C-8434-B5F1D2E96D3A}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{E0F9C7C3-CA1A-416F-A34C-0862127D6393}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EB55CB69-2800-4DE8-A74E-01C74B7C84E3}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{ECCE1CEF-E35A-4D98-B328-225A47D70E75}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{31501F90-C592-4D85-9438-33EFD5D13D23}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{C3B4693F-2000-437E-B074-E9B72031798A}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{E661D763-1AD9-4680-B994-3BA0E48E3AC9}"= UDP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{E911C296-A208-4414-B72B-16FF9588005C}"= TCP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{F447015E-E82D-4B8F-8956-A39F6478AFFA}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{C88D7A4F-D46E-48CD-96D0-BA1ECFBD1E6B}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{F3B89985-7BF5-44B5-9D4E-EE2A42062761}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{E31F4E8A-0769-4B1A-9E31-4114195CBB25}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{8068D17E-06FF-480A-9AC1-C3F0676BEAD7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{1298C032-B160-458E-A3C8-BC7331CE56F9}"= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{018B64A2-15D3-495C-8582-C77D800E1665}"= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{F7A98888-0FC7-49F5-BE51-8FD6C7784EFE}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{4C65ADFC-9C57-4D87-976C-9C5943C4C2E2}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{41D03603-6BAB-4E75-8BAC-CC2C99172636}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3AFC9A16-A99D-4AC2-AAC0-B66A8716CE4F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{465BA8EE-172A-4F28-9AB5-4354EDDC76B3}c:\\users\\darty\\program files\\dna\\btdna.exe"= UDP:c:\users\darty\program files\dna\btdna.exe:btdna.exe
"UDP Query User{871BD6DC-C592-4923-81CE-1154534DCA68}c:\\users\\darty\\program files\\dna\\btdna.exe"= TCP:c:\users\darty\program files\dna\btdna.exe:btdna.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\Hp\QuickPlay\[u]0/u00.fcl [2008-01-16 01:22:44 39408]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [2008-12-15 185640]
R2 X4HSX32Ex;X4HSX32Ex;c:\program files\Player Metaboli\X4HSX32Ex.sys [2008-04-25 29856]
S2 gupdate1c98a09a93c69c9;Google Update Service (gupdate1c98a09a93c69c9);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [2008-04-21 436096]
S3 WiselinkPro;SAMSUNG WiselinkPro Service;c:\program files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2009-02-02 4014080]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - sptd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e9b063f-d10a-11dc-8d37-806e6f6e6963}]
\shell\AutoRun\command - F:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a915f3ae-9f32-11dd-a158-001e68056457}]
\shell\AutoRun\command - H:\LaunchU3.exe
.
Contenu du dossier 'Tâches planifiées'
2009-04-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-26 23:20]
2009-04-01 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 18:22]
2009-03-31 c:\windows\Tasks\User_Feed_Synchronization-{683B7A7C-3607-42F0-AF40-80427994F3E7}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 09:33]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://fr.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=81&bd=Pavilion&pf=laptop
IE: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-01 12:59:19
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(744)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(3948)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehsched.exe
c:\windows\ehome\ehrecvr.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Heure de fin: 2009-04-01 13:07:20 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-01 11:07:17
ComboFix2.txt 2009-03-29 21:33:21
ComboFix3.txt 2009-03-29 08:25:12
ComboFix4.txt 2009-03-27 21:06:21
Avant-CF: 33 391 992 832 octets libres
Après-CF: 33,284,505,600 octets libres
1045 --- E O F --- 2009-04-01 08:41:46
Bon courage !
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-22 149040]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-26 39408]
"BitTorrent DNA"="c:\users\darty\Program Files\DNA\btdna.exe" [2008-12-19 342848]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2007-09-20 671744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-15 153136]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-27 13515296]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-27 92704]
"InterWrite Device Manager"="c:\program files\Interwrite Learning\Interwrite Workspace\IWStarter.exe" [2007-09-21 1122304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 c:\windows\RtHDVCpl.exe]
c:\users\darty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4757DF27-BB99-458F-80CB-DB0364C8F28F}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{419E922C-2259-4F5C-8434-B5F1D2E96D3A}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{E0F9C7C3-CA1A-416F-A34C-0862127D6393}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EB55CB69-2800-4DE8-A74E-01C74B7C84E3}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{ECCE1CEF-E35A-4D98-B328-225A47D70E75}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{31501F90-C592-4D85-9438-33EFD5D13D23}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{C3B4693F-2000-437E-B074-E9B72031798A}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{E661D763-1AD9-4680-B994-3BA0E48E3AC9}"= UDP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{E911C296-A208-4414-B72B-16FF9588005C}"= TCP:c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{F447015E-E82D-4B8F-8956-A39F6478AFFA}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{C88D7A4F-D46E-48CD-96D0-BA1ECFBD1E6B}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{F3B89985-7BF5-44B5-9D4E-EE2A42062761}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{E31F4E8A-0769-4B1A-9E31-4114195CBB25}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{8068D17E-06FF-480A-9AC1-C3F0676BEAD7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{1298C032-B160-458E-A3C8-BC7331CE56F9}"= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{018B64A2-15D3-495C-8582-C77D800E1665}"= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{F7A98888-0FC7-49F5-BE51-8FD6C7784EFE}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{4C65ADFC-9C57-4D87-976C-9C5943C4C2E2}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{41D03603-6BAB-4E75-8BAC-CC2C99172636}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3AFC9A16-A99D-4AC2-AAC0-B66A8716CE4F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{465BA8EE-172A-4F28-9AB5-4354EDDC76B3}c:\\users\\darty\\program files\\dna\\btdna.exe"= UDP:c:\users\darty\program files\dna\btdna.exe:btdna.exe
"UDP Query User{871BD6DC-C592-4923-81CE-1154534DCA68}c:\\users\\darty\\program files\\dna\\btdna.exe"= TCP:c:\users\darty\program files\dna\btdna.exe:btdna.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\Hp\QuickPlay\[u]0/u00.fcl [2008-01-16 01:22:44 39408]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [2008-12-15 185640]
R2 X4HSX32Ex;X4HSX32Ex;c:\program files\Player Metaboli\X4HSX32Ex.sys [2008-04-25 29856]
S2 gupdate1c98a09a93c69c9;Google Update Service (gupdate1c98a09a93c69c9);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [2008-04-21 436096]
S3 WiselinkPro;SAMSUNG WiselinkPro Service;c:\program files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2009-02-02 4014080]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - sptd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e9b063f-d10a-11dc-8d37-806e6f6e6963}]
\shell\AutoRun\command - F:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a915f3ae-9f32-11dd-a158-001e68056457}]
\shell\AutoRun\command - H:\LaunchU3.exe
.
Contenu du dossier 'Tâches planifiées'
2009-04-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-26 23:20]
2009-04-01 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 18:22]
2009-03-31 c:\windows\Tasks\User_Feed_Synchronization-{683B7A7C-3607-42F0-AF40-80427994F3E7}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 09:33]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://fr.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=81&bd=Pavilion&pf=laptop
IE: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-01 12:59:19
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(744)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(3948)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\Hp\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehsched.exe
c:\windows\ehome\ehrecvr.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Heure de fin: 2009-04-01 13:07:20 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-01 11:07:17
ComboFix2.txt 2009-03-29 21:33:21
ComboFix3.txt 2009-03-29 08:25:12
ComboFix4.txt 2009-03-27 21:06:21
Avant-CF: 33 391 992 832 octets libres
Après-CF: 33,284,505,600 octets libres
1045 --- E O F --- 2009-04-01 08:41:46
Bon courage !
Re,
Télécharge et installe CCleaner (si ce n’est pas déjà fait) : https://www.ccleaner.com/ccleaner/download
Lance CCleaner
Clique sur Option --> avancé --> décoche « effacer uniquement les fichiers plus vieux que 48h »
Puis Nettoyeur --> Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s' affiche.
Enfin, Registre --> corrige toutes les erreurs, et recommence jusqu'à ce qu'il ne trouve plus d'erreurs.
(Tu peux garder ce logiciel et l'utiliser régulièrement).
Puis redémarre ton ordinateur.
Encore des traces de BitDefender après ça ? :(
Télécharge et installe CCleaner (si ce n’est pas déjà fait) : https://www.ccleaner.com/ccleaner/download
Lance CCleaner
Clique sur Option --> avancé --> décoche « effacer uniquement les fichiers plus vieux que 48h »
Puis Nettoyeur --> Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s' affiche.
Enfin, Registre --> corrige toutes les erreurs, et recommence jusqu'à ce qu'il ne trouve plus d'erreurs.
(Tu peux garder ce logiciel et l'utiliser régulièrement).
Puis redémarre ton ordinateur.
Encore des traces de BitDefender après ça ? :(
Toujours là !!!!
J'ai relancé deux fois le ccleaner en redémarrant à chaque fois.
A chaque fois il ne me met plus rien à corriger dans CCleaner, mais Bit Defender est toujours actif (antivirus et antispam !!
Le pire c'est que je n'en trouve aucune trace quand je fais une recherche !!!
C'est pire qu'un virus ce truc !!!!
J'ai relancé deux fois le ccleaner en redémarrant à chaque fois.
A chaque fois il ne me met plus rien à corriger dans CCleaner, mais Bit Defender est toujours actif (antivirus et antispam !!
Le pire c'est que je n'en trouve aucune trace quand je fais une recherche !!!
C'est pire qu'un virus ce truc !!!!
A part dans le centre de sécurité Windows, rien n'indique qu'il est encore actif, il n'y a plus de traces nulle part ?
Ce n'est pas très grave, le centre de sécurité donne souvent de fausses informations...
Est-ce que tu comptes réinstaller BitDefender ?
J'ai trouvé une manip' qui pourrait régler ce problème, je te l'envoie telle que je l'ai trouvée :
Il arrive parfois que le "centre de sécurité" vous renvoie de fausses informations,telles que : votre antivirus est désactivé, ou indique qu'un ancien ativirus soit installé, etc...
le centre de sécurité affiche des informations en fonctions de ce qu'indique le système de gestion interne de Windows WMI (Windows Management Instrumentation). Il est possible que celui soit partiellement endommagé, la solution consiste a le réinitialiser.
Pour cela, deroulez le menu Démarrer, Programmes, Accessoires puis cliquez sur Invite de comandes. dans la fenêtre tapez les commandes en respectant les espaces et en appuyant sur la touche Entrée à la fin de chaque ligne :
C:
net stop winmgmt
cd /d %windir%\system32\wbem
ren repository repository.old
net start winmgmt
Redémarrez votre PC.
Est-ce que tu comptes réinstaller BitDefender ?
J'ai trouvé une manip' qui pourrait régler ce problème, je te l'envoie telle que je l'ai trouvée :
Il arrive parfois que le "centre de sécurité" vous renvoie de fausses informations,telles que : votre antivirus est désactivé, ou indique qu'un ancien ativirus soit installé, etc...
le centre de sécurité affiche des informations en fonctions de ce qu'indique le système de gestion interne de Windows WMI (Windows Management Instrumentation). Il est possible que celui soit partiellement endommagé, la solution consiste a le réinitialiser.
Pour cela, deroulez le menu Démarrer, Programmes, Accessoires puis cliquez sur Invite de comandes. dans la fenêtre tapez les commandes en respectant les espaces et en appuyant sur la touche Entrée à la fin de chaque ligne :
C:
net stop winmgmt
cd /d %windir%\system32\wbem
ren repository repository.old
net start winmgmt
Redémarrez votre PC.