Virus, besoin d'aide pour HijackThis
Céline2828
Messages postés
9
Statut
Membre
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
Depuis peu de temps, le message "Il y a trop de mails identiques envoyés dans un faible intervalle de temps" apparait sur mon ordinateur dans un court intervalle.
Je me suis donc renseignée sur internet, sur des forums et j'ai téléchargé "HijackThis" mais ensuite je ne sais pas du tout quoi faire !
Je vous colle le résultat
_______________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:57:47, on 15/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\LocalService\Application Data\Microsoft\zylany.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\AOL\1171204510\ee\AOLSoftware.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Malice\Bureau\Scanner.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: My Search BHO - {014da6c1-189f-421a-88cd-07cfe51cff10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {35E78239-811E-4c3f-B37D-F339AC16C2C0} - C:\PROGRA~1\Comet\bin\autosearch.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Helper Class - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - C:\Program Files\NavExcel Search Toolbar\NavExcelBar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {fe6bc4ef-5676-484b-88ae-883323913256} - (no file)
O3 - Toolbar: My &Search Bar - {014da6c9-189f-421a-88cd-07cfe51cff10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1171204510\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [couzoosou] C:\WINDOWS\system32\kycoot.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [flap admin] C:\DOCUME~1\Malice\APPLIC~1\BIBDEN~1\Kind Junk Data.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB5; (R1 1.3); MSN Optimized;FR; .NET CLR 1.1.4322; Creative ZENcast v1.02.10; .NET CLR 2.0.50727; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)" -"https://www.justinnozuka.fr/"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [couzoosou] C:\Documents and Settings\LocalService\Application Data\Microsoft\kycoot.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 4.0\resources\fr-FR\local\search.html
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Zip Backup to CD (aofx8oe3wo) - Unknown owner - C:\Documents and Settings\LocalService\Application Data\Microsoft\zylany.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
_______________________________________
Voilà, j'espère que vous pourrez m'aider !
Depuis peu de temps, le message "Il y a trop de mails identiques envoyés dans un faible intervalle de temps" apparait sur mon ordinateur dans un court intervalle.
Je me suis donc renseignée sur internet, sur des forums et j'ai téléchargé "HijackThis" mais ensuite je ne sais pas du tout quoi faire !
Je vous colle le résultat
_______________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:57:47, on 15/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\LocalService\Application Data\Microsoft\zylany.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\AOL\1171204510\ee\AOLSoftware.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Malice\Bureau\Scanner.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: My Search BHO - {014da6c1-189f-421a-88cd-07cfe51cff10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {35E78239-811E-4c3f-B37D-F339AC16C2C0} - C:\PROGRA~1\Comet\bin\autosearch.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Helper Class - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - C:\Program Files\NavExcel Search Toolbar\NavExcelBar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {fe6bc4ef-5676-484b-88ae-883323913256} - (no file)
O3 - Toolbar: My &Search Bar - {014da6c9-189f-421a-88cd-07cfe51cff10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1171204510\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [couzoosou] C:\WINDOWS\system32\kycoot.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [flap admin] C:\DOCUME~1\Malice\APPLIC~1\BIBDEN~1\Kind Junk Data.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB5; (R1 1.3); MSN Optimized;FR; .NET CLR 1.1.4322; Creative ZENcast v1.02.10; .NET CLR 2.0.50727; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)" -"https://www.justinnozuka.fr/"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [couzoosou] C:\Documents and Settings\LocalService\Application Data\Microsoft\kycoot.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 4.0\resources\fr-FR\local\search.html
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Zip Backup to CD (aofx8oe3wo) - Unknown owner - C:\Documents and Settings\LocalService\Application Data\Microsoft\zylany.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
_______________________________________
Voilà, j'espère que vous pourrez m'aider !
A voir également:
- Virus, besoin d'aide pour HijackThis
- Hijackthis - Télécharger - Antivirus & Antimalwares
- Virus mcafee - Accueil - Piratage
- Virus facebook demande d'amis - Accueil - Facebook
- Virus informatique - Guide
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
24 réponses
Re,
▶ Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.
▶ Double clique sur RSIT.exe pour lancer l'outil.
▶ Clique sur ' continue ' à l'écran Disclaimer.
▶ Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports séparément.
( log.txt & info.txt )
(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
▶ Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.
▶ Double clique sur RSIT.exe pour lancer l'outil.
▶ Clique sur ' continue ' à l'écran Disclaimer.
▶ Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports séparément.
( log.txt & info.txt )
(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
Salut,
Télécharge Lop S&D
▶ Double-clique dessus pour lancer l'installation
▶ Puis double-clique sur le raccourci Lop S&D présent sur ton bureau
▶ Séléctionne la langue souhaitée
▶ Puis choisis l'Option 1 ( Recherche )
▶ Patiente jusqu'à la fin du scan
▶ Poste le rapport généré ( C:lopR.txt )
Tutoriel
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
Télécharge Lop S&D
▶ Double-clique dessus pour lancer l'installation
▶ Puis double-clique sur le raccourci Lop S&D présent sur ton bureau
▶ Séléctionne la langue souhaitée
▶ Puis choisis l'Option 1 ( Recherche )
▶ Patiente jusqu'à la fin du scan
▶ Poste le rapport généré ( C:lopR.txt )
Tutoriel
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Bonjour,
Tu peux déjà fixer celle ci:
O2 - BHO: My Search BHO - {014da6c1-189f-421a-88cd-07cfe51cff10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {35E78239-811E-4c3f-B37D-F339AC16C2C0} - C:\PROGRA~1\Comet\bin\autosearch.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Helper Class - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - C:\Program Files\NavExcel Search Toolbar\NavExcelBar.dll (file missing)
Ensuite
Télécharges:
https://www.commentcamarche.net/telecharger/ 34055379 malwarebytes anti malware
Fais une mise à jour, dans Paramètres coches tout
Actives tous des périphériques de stockages (externes compris).
Fermes toutes tesapplications.
Fait 1 scan complet.
Redémarres.
Tu peux déjà fixer celle ci:
O2 - BHO: My Search BHO - {014da6c1-189f-421a-88cd-07cfe51cff10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {35E78239-811E-4c3f-B37D-F339AC16C2C0} - C:\PROGRA~1\Comet\bin\autosearch.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Helper Class - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - C:\Program Files\NavExcel Search Toolbar\NavExcelBar.dll (file missing)
Ensuite
Télécharges:
https://www.commentcamarche.net/telecharger/ 34055379 malwarebytes anti malware
Fais une mise à jour, dans Paramètres coches tout
Actives tous des périphériques de stockages (externes compris).
Fermes toutes tesapplications.
Fait 1 scan complet.
Redémarres.
voilà le résultat
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 3000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Malice ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090108-0] 4.8.1296 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:145 Go (Free:20 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 16/04/2009| 0:24 )
--------------------\\ Listing des dossiers dans APPLIC~1
[07/02/2009|19:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[15/04/2007|15:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[15/04/2007|15:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe(2)
[08/09/2007|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[26/03/2008|21:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AlawarGameBox
[01/01/2009|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[22/07/2007|23:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
[28/09/2008|16:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
[07/02/2009|19:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[07/02/2009|19:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[10/09/2008|17:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[10/03/2007|16:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[24/03/2008|15:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[21/02/2008|19:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[26/09/2008|17:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Escape From Paradise
[26/03/2008|21:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fugazo
[26/03/2008|22:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Go Go Gourmet
[01/01/2009|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[01/10/2006|21:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin
[05/05/2007|22:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Legacy Interactive
[22/07/2007|23:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[02/09/2007|00:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[22/02/2009|00:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[26/12/2004|15:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[11/07/2006|17:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Newsoft
[05/05/2008|14:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games
[10/08/2008|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[26/12/2004|02:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[26/09/2008|17:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[26/12/2004|02:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[05/01/2006|17:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[12/08/2008|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[05/05/2007|21:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[21/02/2009|17:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[12/12/2007|07:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[07/07/2006|11:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[17/11/2006|18:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[31/12/2008|18:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[30/11/2007|14:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/03/2008|01:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[26/12/2004|02:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[04/07/2007|12:32] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[26/12/2004|02:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[23/01/2008|14:44] C:\DOCUME~1\Florence\APPLIC~1\Adobe
[23/07/2007|14:36] C:\DOCUME~1\Florence\APPLIC~1\AOL
[20/02/2005|19:41] C:\DOCUME~1\Florence\APPLIC~1\ArcSoft
[28/07/2008|15:46] C:\DOCUME~1\Florence\APPLIC~1\Atari
[18/09/2008|19:59] C:\DOCUME~1\Florence\APPLIC~1\AVS4YOU
[16/05/2007|13:56] C:\DOCUME~1\Florence\APPLIC~1\BFGTOOLBAR
[29/01/2006|16:16] C:\DOCUME~1\Florence\APPLIC~1\CyberLink
[12/01/2008|14:36] C:\DOCUME~1\Florence\APPLIC~1\DivX
[07/07/2007|15:43] C:\DOCUME~1\Florence\APPLIC~1\Google
[20/02/2005|20:11] C:\DOCUME~1\Florence\APPLIC~1\Help
[26/12/2004|02:27] C:\DOCUME~1\Florence\APPLIC~1\Identities
[23/10/2006|21:16] C:\DOCUME~1\Florence\APPLIC~1\Logitech
[03/07/2007|12:47] C:\DOCUME~1\Florence\APPLIC~1\Macromedia
[31/12/2008|18:06] C:\DOCUME~1\Florence\APPLIC~1\Microsoft
[30/01/2005|18:37] C:\DOCUME~1\Florence\APPLIC~1\MSN6
[29/01/2006|16:24] C:\DOCUME~1\Florence\APPLIC~1\Real
[25/05/2008|15:05] C:\DOCUME~1\Florence\APPLIC~1\Sonic
[06/08/2006|18:37] C:\DOCUME~1\Florence\APPLIC~1\Sun
[23/01/2006|17:14] C:\DOCUME~1\Florence\APPLIC~1\Ulead Systems
[12/12/2007|14:39] C:\DOCUME~1\Florence\APPLIC~1\Viewpoint
[19/10/2008|20:38] C:\DOCUME~1\Florence\APPLIC~1\Yahoo!
[25/12/2004|18:32] C:\DOCUME~1\Florence\APPLIC~1\You've Got Pictures Screensaver
[20/06/2007|00:11] C:\DOCUME~1\LOCALS~1\APPLIC~1\Help
[15/04/2009|23:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[13/03/2009|22:23] C:\DOCUME~1\Malice\APPLIC~1\Adobe
[16/06/2006|14:03] C:\DOCUME~1\Malice\APPLIC~1\AdobeUM
[08/09/2007|17:21] C:\DOCUME~1\Malice\APPLIC~1\Ahead
[24/07/2007|20:13] C:\DOCUME~1\Malice\APPLIC~1\AOL
[07/02/2009|19:49] C:\DOCUME~1\Malice\APPLIC~1\Apple Computer
[03/03/2005|14:07] C:\DOCUME~1\Malice\APPLIC~1\ArcSoft
[10/09/2008|17:46] C:\DOCUME~1\Malice\APPLIC~1\AVS4YOU
[08/06/2007|20:46] C:\DOCUME~1\Malice\APPLIC~1\BFGTOOLBAR
[13/08/2007|21:50] C:\DOCUME~1\Malice\APPLIC~1\Bib dent road
[23/09/2007|15:17] C:\DOCUME~1\Malice\APPLIC~1\BitTorrent
[19/08/2007|23:26] C:\DOCUME~1\Malice\APPLIC~1\Creative
[30/12/2004|18:15] C:\DOCUME~1\Malice\APPLIC~1\CyberLink
[10/05/2008|22:45] C:\DOCUME~1\Malice\APPLIC~1\DivX
[07/08/2005|14:15] C:\DOCUME~1\Malice\APPLIC~1\Ecran de veille
[21/03/2007|12:04] C:\DOCUME~1\Malice\APPLIC~1\Google
[17/01/2007|16:08] C:\DOCUME~1\Malice\APPLIC~1\Identities
[22/09/2006|21:23] C:\DOCUME~1\Malice\APPLIC~1\LimeWire
[17/12/2006|18:10] C:\DOCUME~1\Malice\APPLIC~1\Logitech
[06/07/2007|13:32] C:\DOCUME~1\Malice\APPLIC~1\Macromedia
[01/02/2009|21:33] C:\DOCUME~1\Malice\APPLIC~1\Microsoft
[30/10/2007|02:17] C:\DOCUME~1\Malice\APPLIC~1\MSN6
[23/03/2008|20:46] C:\DOCUME~1\Malice\APPLIC~1\PlayFirst
[25/01/2005|23:11] C:\DOCUME~1\Malice\APPLIC~1\Real
[31/07/2007|20:57] C:\DOCUME~1\Malice\APPLIC~1\Screenshot Sender
[02/01/2008|21:12] C:\DOCUME~1\Malice\APPLIC~1\Sonic
[29/04/2006|18:21] C:\DOCUME~1\Malice\APPLIC~1\Sun
[30/07/2005|00:34] C:\DOCUME~1\Malice\APPLIC~1\Symantec
[04/04/2006|12:00] C:\DOCUME~1\Malice\APPLIC~1\Ulead Systems
[12/12/2007|07:30] C:\DOCUME~1\Malice\APPLIC~1\Viewpoint
[22/02/2009|00:43] C:\DOCUME~1\Malice\APPLIC~1\Windows Live Writer
[14/10/2008|23:02] C:\DOCUME~1\Malice\APPLIC~1\Yahoo!
[17/01/2007|16:08] C:\DOCUME~1\Malice\APPLIC~1\Zylom
[11/03/2008|03:41] C:\DOCUME~1\Michel\APPLIC~1\Adobe
[11/10/2006|18:55] C:\DOCUME~1\Michel\APPLIC~1\AdobeUM
[24/07/2007|05:21] C:\DOCUME~1\Michel\APPLIC~1\AOL
[15/02/2009|18:02] C:\DOCUME~1\Michel\APPLIC~1\Apple Computer
[06/01/2005|17:12] C:\DOCUME~1\Michel\APPLIC~1\ArcSoft
[02/06/2007|04:27] C:\DOCUME~1\Michel\APPLIC~1\BFGTOOLBAR
[23/09/2006|13:50] C:\DOCUME~1\Michel\APPLIC~1\CyberLink
[15/10/2006|04:41] C:\DOCUME~1\Michel\APPLIC~1\DivX
[16/09/2007|12:42] C:\DOCUME~1\Michel\APPLIC~1\Google
[05/06/2006|11:04] C:\DOCUME~1\Michel\APPLIC~1\Help
[17/09/2006|12:34] C:\DOCUME~1\Michel\APPLIC~1\Identities
[17/12/2006|18:10] C:\DOCUME~1\Michel\APPLIC~1\Logitech
[16/09/2007|12:44] C:\DOCUME~1\Michel\APPLIC~1\Macromedia
[05/02/2009|13:53] C:\DOCUME~1\Michel\APPLIC~1\Microsoft
[07/03/2009|09:20] C:\DOCUME~1\Michel\APPLIC~1\MSN6
[04/11/2006|04:41] C:\DOCUME~1\Michel\APPLIC~1\Real
[21/08/2006|18:21] C:\DOCUME~1\Michel\APPLIC~1\Sun
[16/10/2005|12:32] C:\DOCUME~1\Michel\APPLIC~1\Symantec
[13/12/2007|04:05] C:\DOCUME~1\Michel\APPLIC~1\Viewpoint
[01/01/2009|19:09] C:\DOCUME~1\Michel\APPLIC~1\Yahoo!
[19/02/2006|19:49] C:\DOCUME~1\Michel\APPLIC~1\You've Got Pictures Screensaver
[17/09/2006|12:34] C:\DOCUME~1\Michel\APPLIC~1\Zylom
[26/12/2004|02:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[16/03/2005|18:33] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec
[30/11/2008|19:55] C:\DOCUME~1\Winnie\APPLIC~1\Adobe
[02/12/2005|21:25] C:\DOCUME~1\Winnie\APPLIC~1\AdobeUM
[08/09/2007|20:57] C:\DOCUME~1\Winnie\APPLIC~1\Ahead
[09/10/2007|12:06] C:\DOCUME~1\Winnie\APPLIC~1\Anuman Interactive
[24/08/2006|16:59] C:\DOCUME~1\Winnie\APPLIC~1\AOL
[06/01/2005|19:43] C:\DOCUME~1\Winnie\APPLIC~1\ArcSoft
[28/07/2008|16:01] C:\DOCUME~1\Winnie\APPLIC~1\Atari
[30/05/2007|22:08] C:\DOCUME~1\Winnie\APPLIC~1\BFGTOOLBAR
[17/03/2008|01:38] C:\DOCUME~1\Winnie\APPLIC~1\Creative
[30/12/2004|16:02] C:\DOCUME~1\Winnie\APPLIC~1\CyberLink
[26/01/2008|16:47] C:\DOCUME~1\Winnie\APPLIC~1\DAEMON Tools
[06/10/2006|20:57] C:\DOCUME~1\Winnie\APPLIC~1\DivX
[09/10/2005|20:00] C:\DOCUME~1\Winnie\APPLIC~1\Ecran de veille
[12/08/2008|15:50] C:\DOCUME~1\Winnie\APPLIC~1\Gaijin Ent
[05/03/2008|02:30] C:\DOCUME~1\Winnie\APPLIC~1\Gamelab
[13/03/2008|23:57] C:\DOCUME~1\Winnie\APPLIC~1\GetRightToGo
[15/01/2007|20:00] C:\DOCUME~1\Winnie\APPLIC~1\Google
[12/04/2005|22:41] C:\DOCUME~1\Winnie\APPLIC~1\Help
[22/01/2008|17:30] C:\DOCUME~1\Winnie\APPLIC~1\Identities
[29/06/2006|19:05] C:\DOCUME~1\Winnie\APPLIC~1\iScreensaver
[01/10/2006|21:26] C:\DOCUME~1\Winnie\APPLIC~1\iWin
[28/12/2004|21:59] C:\DOCUME~1\Winnie\APPLIC~1\Leadertech
[03/03/2008|18:13] C:\DOCUME~1\Winnie\APPLIC~1\LimeWire
[17/12/2006|18:10] C:\DOCUME~1\Winnie\APPLIC~1\Logitech
[04/07/2007|21:35] C:\DOCUME~1\Winnie\APPLIC~1\Macromedia
[05/01/2009|17:13] C:\DOCUME~1\Winnie\APPLIC~1\Microsoft
[16/01/2006|11:39] C:\DOCUME~1\Winnie\APPLIC~1\MSN6
[17/07/2008|14:56] C:\DOCUME~1\Winnie\APPLIC~1\My Stitch
[26/03/2008|22:36] C:\DOCUME~1\Winnie\APPLIC~1\Oberon Games
[10/08/2008|21:37] C:\DOCUME~1\Winnie\APPLIC~1\PlayFirst
[19/01/2005|21:15] C:\DOCUME~1\Winnie\APPLIC~1\Real
[15/10/2006|20:40] C:\DOCUME~1\Winnie\APPLIC~1\Samsung
[26/09/2008|17:14] C:\DOCUME~1\Winnie\APPLIC~1\Sandlot Games
[26/09/2008|17:13] C:\DOCUME~1\Winnie\APPLIC~1\SecuROM
[28/12/2004|21:59] C:\DOCUME~1\Winnie\APPLIC~1\Sonic
[19/02/2006|16:19] C:\DOCUME~1\Winnie\APPLIC~1\Sun
[19/04/2005|17:29] C:\DOCUME~1\Winnie\APPLIC~1\Symantec
[17/01/2006|22:48] C:\DOCUME~1\Winnie\APPLIC~1\Ulead Systems
[12/12/2007|19:07] C:\DOCUME~1\Winnie\APPLIC~1\Viewpoint
[01/07/2007|19:42] C:\DOCUME~1\Winnie\APPLIC~1\Vso
[13/10/2008|18:23] C:\DOCUME~1\Winnie\APPLIC~1\Yahoo!
[15/01/2007|18:58] C:\DOCUME~1\Winnie\APPLIC~1\You've Got Pictures Screensaver
[22/01/2008|17:30] C:\DOCUME~1\Winnie\APPLIC~1\Zylom
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/04/2009 19:47][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[25/01/2008 14:20][--a------] C:\WINDOWS\tasks\At6.job
[25/03/2009 21:00][--a------] C:\WINDOWS\tasks\At5.job
[25/10/2008 14:00][--a------] C:\WINDOWS\tasks\At4.job
[25/01/2008 14:18][--a------] C:\WINDOWS\tasks\At3.job
[25/03/2009 21:00][--a------] C:\WINDOWS\tasks\At2.job
[25/10/2008 14:00][--a------] C:\WINDOWS\tasks\At1.job
[15/04/2009 20:41][--a------] C:\WINDOWS\tasks\Symantec NetDetect.job
[08/01/2005 21:35][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 3.job
[02/01/2005 00:50][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 2.job
[27/12/2004 00:35][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 1.job
[15/04/2009 23:37][--ah-----] C:\WINDOWS\tasks\SA.DAT
[30/08/2002 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[12/08/2008|15:46] C:\Program Files\7788xyx
[19/02/2008|22:23] C:\Program Files\A123 AVI WMV ASF MOV MP4 FLV to MPEG Converter
[12/02/2008|14:06] C:\Program Files\Adobe
[03/01/2005|19:16] C:\Program Files\Agfa
[16/10/2005|18:21] C:\Program Files\Ahead
[12/04/2005|17:06] C:\Program Files\AimOne_AlltoMP3
[01/07/2007|19:38] C:\Program Files\Akimania
[26/03/2008|21:55] C:\Program Files\Alawar
[05/01/2006|17:19] C:\Program Files\Alwil Software
[18/10/2008|11:36] C:\Program Files\Anuman Interactive
[01/01/2009|19:12] C:\Program Files\AOL
[01/01/2009|19:08] C:\Program Files\AOL 9.0b
[01/01/2009|19:08] C:\Program Files\AOL Toolbar
[07/02/2009|19:46] C:\Program Files\Apple Software Update
[01/01/2009|19:15] C:\Program Files\ArcSoft
[14/03/2008|00:10] C:\Program Files\Audacity
[29/10/2007|14:46] C:\Program Files\Audible
[12/04/2005|17:20] C:\Program Files\AudioCDMagic
[01/01/2009|19:10] C:\Program Files\AVS4YOU
[31/05/2007|00:45] C:\Program Files\BFG
[23/09/2007|18:11] C:\Program Files\BitTorrent
[07/02/2009|20:56] C:\Program Files\Bonjour
[05/05/2007|21:43] C:\Program Files\Boonty
[27/09/2008|17:16] C:\Program Files\BoontyGames
[30/03/2008|19:03] C:\Program Files\Burger Shop
[26/01/2009|19:28] C:\Program Files\CCleaner
[15/08/2007|10:48] C:\Program Files\CDBurnerXP Pro 3
[03/08/2008|16:01] C:\Program Files\Common Files
[24/03/2008|15:51] C:\Program Files\Creative
[15/04/2007|14:58] C:\Program Files\Creative Installation Information
[26/12/2004|02:27] C:\Program Files\CyberLink
[05/03/2008|13:10] C:\Program Files\Delicious 2 Deluxe
[02/01/2008|21:36] C:\Program Files\Disc2Phone
[13/10/2008|18:21] C:\Program Files\DivX
[27/04/2005|18:02] C:\Program Files\DVD Shrink
[16/12/2008|20:50] C:\Program Files\EA GAMES
[15/04/2009|23:38] C:\Program Files\eMule
[02/09/2007|18:14] C:\Program Files\eMulee
[03/03/2008|18:57] C:\Program Files\eMuleplus
[22/01/2008|15:42] C:\Program Files\eToro
[22/03/2008|22:41] C:\Program Files\Everest Poker
[26/03/2008|20:39] C:\Program Files\Farm Frenzy
[26/03/2008|21:54] C:\Program Files\Fashion Fits
[07/02/2009|19:45] C:\Program Files\Fichiers communs
[30/07/2008|20:59] C:\Program Files\Fish Tycoon
[12/04/2005|22:41] C:\Program Files\FreeRIP2
[10/03/2007|17:54] C:\Program Files\Gamenext
[31/12/2008|18:08] C:\Program Files\Google
[31/07/2008|21:14] C:\Program Files\Gpotato.eu
[17/12/2006|18:12] C:\Program Files\Hamster Blocks
[11/08/2008|01:11] C:\Program Files\Ice Cream Craze
[12/04/2005|18:16] C:\Program Files\Illustrate
[01/01/2009|19:12] C:\Program Files\Imikimi
[17/03/2005|19:28] C:\Program Files\IncrediMail
[26/12/2004|11:07] C:\Program Files\Infogrames
[21/02/2009|17:36] C:\Program Files\InstallShield Installation Information
[27/03/2009|20:28] C:\Program Files\Internet Explorer
[07/02/2009|19:48] C:\Program Files\iPod
[02/02/2005|12:22] C:\Program Files\ISTsvc
[07/02/2009|19:48] C:\Program Files\iTunes
[10/01/2009|14:21] C:\Program Files\Java
[26/12/2004|14:35] C:\Program Files\Labtec
[25/12/2004|18:32] C:\Program Files\Learn2.com
[09/10/2007|12:04] C:\Program Files\LiveCAD
[19/12/2006|15:10] C:\Program Files\Logitech
[12/08/2008|15:30] C:\Program Files\M6 Jeux
[01/01/2009|19:08] C:\Program Files\Maxis
[05/05/2007|21:31] C:\Program Files\Mes Jeux T‚l‚charg‚s
[19/09/2008|15:25] C:\Program Files\Messenger
[07/02/2009|13:31] C:\Program Files\Messenger Plus! Live
[19/08/2007|00:39] C:\Program Files\MessengerPlus! 3
[22/02/2009|00:42] C:\Program Files\Microsoft
[15/04/2009|23:18] C:\Program Files\Microsoft ActiveSync
[09/05/2007|00:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[26/12/2004|02:27] C:\Program Files\microsoft frontpage
[23/10/2007|16:01] C:\Program Files\Microsoft Games
[30/01/2005|18:27] C:\Program Files\microsoft office
[27/02/2009|07:45] C:\Program Files\Microsoft Silverlight
[14/11/2007|15:22] C:\Program Files\Microsoft SQL Server Compact Edition
[27/12/2008|22:16] C:\Program Files\Microsoft Sync Framework
[26/12/2004|02:27] C:\Program Files\Microsoft Visual Studio
[19/09/2008|15:20] C:\Program Files\Movie Maker
[15/04/2007|15:00] C:\Program Files\Mozilla Firefox
[25/08/2005|12:14] C:\Program Files\MP3 Player Utilities
[06/08/2008|14:04] C:\Program Files\MP3 Player Utilities 3.68
[29/03/2008|14:21] C:\Program Files\MP3 Player Utilities 4.18
[02/08/2007|11:08] C:\Program Files\MSN
[21/05/2008|16:48] C:\Program Files\MSN Games
[26/12/2004|02:27] C:\Program Files\MSN Gaming Zone
[18/08/2007|21:48] C:\Program Files\MSN Messenger
[15/08/2007|14:00] C:\Program Files\MSXML 4.0
[23/10/2006|17:25] C:\Program Files\MUSICMATCH
[12/04/2005|22:38] C:\Program Files\MySearch
[26/03/2008|20:39] C:\Program Files\Nanny Mania
[02/02/2005|12:21] C:\Program Files\NavExcel
[05/01/2006|17:31] C:\Program Files\NavExcel Search Toolbar
[19/09/2008|15:14] C:\Program Files\NetMeeting
[05/07/2007|16:51] C:\Program Files\Neuf
[26/12/2004|02:27] C:\Program Files\Nullsoft
[19/09/2008|15:14] C:\Program Files\Outlook Express
[15/12/2005|17:48] C:\Program Files\PAN vision
[01/01/2009|19:12] C:\Program Files\Photo Story 3 for Windows
[01/01/2009|19:12] C:\Program Files\Photo Viewer
[25/02/2009|20:14] C:\Program Files\PhotoFiltre
[30/11/2005|13:17] C:\Program Files\PIXELA
[26/03/2008|19:19] C:\Program Files\PlayFirst
[23/01/2005|22:46] C:\Program Files\Plus!
[07/02/2009|19:47] C:\Program Files\QuickTime
[26/12/2004|02:27] C:\Program Files\Real
[10/12/2006|22:19] C:\Program Files\ReflexiveArcade
[12/12/2006|21:13] C:\Program Files\Samsung
[26/12/2004|02:29] C:\Program Files\Services en ligne
[12/02/2009|16:47] C:\Program Files\Sierra On-Line
[18/01/2007|22:20] C:\Program Files\SnowyLunchRush_at
[26/12/2004|02:27] C:\Program Files\Sonic
[03/08/2008|16:30] C:\Program Files\Sony
[07/03/2006|16:36] C:\Program Files\Sony Corporation
[17/09/2008|09:57] C:\Program Files\Sun
[05/01/2006|17:06] C:\Program Files\Symantec
[26/10/2007|19:23] C:\Program Files\Ubi Soft
[11/02/2008|23:04] C:\Program Files\Ulead Systems
[26/12/2004|02:27] C:\Program Files\Uninstall Information
[06/11/2008|11:11] C:\Program Files\VGA USB Camera
[26/12/2004|02:27] C:\Program Files\Viewpoint
[26/12/2004|02:27] C:\Program Files\Virtual CD v4 SDK
[26/03/2008|20:39] C:\Program Files\Wedding Dash
[22/02/2009|00:41] C:\Program Files\Windows Live
[01/01/2009|19:13] C:\Program Files\Windows Live SkyDrive
[01/01/2009|19:10] C:\Program Files\Windows Live Toolbar
[25/01/2008|14:19] C:\Program Files\Windows Media Connect 2
[19/09/2008|15:14] C:\Program Files\Windows Media Player
[19/09/2008|15:14] C:\Program Files\Windows NT
[15/04/2007|13:37] C:\Program Files\WinRAR
[18/08/2008|20:42] C:\Program Files\WMA-MP3.com
[28/07/2008|20:59] C:\Program Files\World of Warcraft Trial
[26/12/2004|02:27] C:\Program Files\xerox
[01/01/2009|19:10] C:\Program Files\Yahoo!
[01/01/2009|19:08] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[01/01/2009|19:08] C:\Program Files\Fichiers communs\Adobe
[01/01/2009|19:12] C:\Program Files\Fichiers communs\AOL
[25/12/2004|18:32] C:\Program Files\Fichiers communs\aolback
[07/02/2009|19:48] C:\Program Files\Fichiers communs\Apple
[10/09/2008|17:45] C:\Program Files\Fichiers communs\AVSMedia
[08/07/2008|15:12] C:\Program Files\Fichiers communs\Blizzard Entertainment
[10/03/2007|16:43] C:\Program Files\Fichiers communs\BOONTY Shared
[15/04/2007|15:00] C:\Program Files\Fichiers communs\Creative
[26/12/2004|02:28] C:\Program Files\Fichiers communs\Designer
[16/08/2006|19:15] C:\Program Files\Fichiers communs\Digi338
[11/02/2008|22:30] C:\Program Files\Fichiers communs\FotoNation
[03/04/2007|18:52] C:\Program Files\Fichiers communs\InstallShield
[15/01/2006|18:50] C:\Program Files\Fichiers communs\Java
[26/12/2004|14:35] C:\Program Files\Fichiers communs\Logitech
[22/02/2009|00:37] C:\Program Files\Fichiers communs\Microsoft Shared
[26/12/2004|02:27] C:\Program Files\Fichiers communs\MSSoap
[16/08/2006|19:18] C:\Program Files\Fichiers communs\NewSoft
[25/12/2004|18:32] C:\Program Files\Fichiers communs\Nullsoft
[10/08/2008|21:07] C:\Program Files\Fichiers communs\Oberon Media
[10/10/2007|03:04] C:\Program Files\Fichiers communs\ODBC
[26/12/2004|02:27] C:\Program Files\Fichiers communs\Real
[16/04/2007|13:32] C:\Program Files\Fichiers communs\Scanner
[26/12/2004|02:29] C:\Program Files\Fichiers communs\Services
[03/08/2008|16:02] C:\Program Files\Fichiers communs\Sony Shared
[26/12/2004|02:27] C:\Program Files\Fichiers communs\SpeechEngines
[26/12/2004|02:29] C:\Program Files\Fichiers communs\SureThing Shared
[05/12/2008|21:11] C:\Program Files\Fichiers communs\Symantec Shared
[19/09/2008|15:14] C:\Program Files\Fichiers communs\System
[26/12/2004|02:29] C:\Program Files\Fichiers communs\TVNavigTechnologies Shared
[06/04/2007|16:20] C:\Program Files\Fichiers communs\Ulead Systems
[17/12/2008|21:36] C:\Program Files\Fichiers communs\Windows Live
[14/11/2007|15:14] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[26/12/2004|02:27] C:\Program Files\Fichiers communs\xing shared
--------------------\\ Process
( 56 Processes )
IEXPLORE.EXE ~ [PID:3724]
IEXPLORE.EXE ~ [PID:184]
--------------------\\ Recherche avec S_Lop
C:\DOCUME~1\Malice\APPLIC~1\BIBDEN~1
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\Malice\LOCALS~1\Temp\NSSstub.txt
C:\DOCUME~1\Malice\Cookies\malice@advertstream[2].txt
C:\DOCUME~1\Malice\Cookies\malice@advertising[1].txt
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FRAGSAFEFILM]
"DisplayName"="CiD Help"
"UninstallString"="C:\\DOCUME~1\\Malice\\APPLIC~1\\BIBDEN~1\\Kind Junk Data.exe -uninstall"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"flap admin"="C:\\DOCUME~1\\Malice\\APPLIC~1\\BIBDEN~1\\Kind Junk Data.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------\\ Verification du fichier Hosts
Fichier Hosts MODIFIE
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD
-> 72 [ 70 ## added by CiD ]
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-16 00:26:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 37
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Malice\Application Data\Microsoft\Office\Fichiers r‚cents\Hospital Tycoon crack NoCD - patch activation Multilanguage garanted by eMule inside.lnk
[F:220][D:27]-> C:\DOCUME~1\Malice\LOCALS~1\Temp
[F:649][D:0]-> C:\DOCUME~1\Malice\Cookies
[F:1494][D:49]-> C:\DOCUME~1\Malice\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 16/04/2009| 0:28 - Option : [1]
--------------------\\ Fin du rapport a 0:28:49
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 3000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Malice ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090108-0] 4.8.1296 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:145 Go (Free:20 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 16/04/2009| 0:24 )
--------------------\\ Listing des dossiers dans APPLIC~1
[07/02/2009|19:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[15/04/2007|15:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[15/04/2007|15:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe(2)
[08/09/2007|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[26/03/2008|21:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AlawarGameBox
[01/01/2009|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[22/07/2007|23:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
[28/09/2008|16:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
[07/02/2009|19:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[07/02/2009|19:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[10/09/2008|17:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[10/03/2007|16:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[24/03/2008|15:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[21/02/2008|19:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[26/09/2008|17:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Escape From Paradise
[26/03/2008|21:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fugazo
[26/03/2008|22:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Go Go Gourmet
[01/01/2009|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[01/10/2006|21:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin
[05/05/2007|22:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Legacy Interactive
[22/07/2007|23:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[02/09/2007|00:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[22/02/2009|00:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[26/12/2004|15:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[11/07/2006|17:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Newsoft
[05/05/2008|14:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games
[10/08/2008|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[26/12/2004|02:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[26/09/2008|17:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[26/12/2004|02:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[05/01/2006|17:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[12/08/2008|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[05/05/2007|21:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[21/02/2009|17:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[12/12/2007|07:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[07/07/2006|11:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[17/11/2006|18:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[31/12/2008|18:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[30/11/2007|14:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/03/2008|01:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[26/12/2004|02:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[04/07/2007|12:32] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[26/12/2004|02:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[23/01/2008|14:44] C:\DOCUME~1\Florence\APPLIC~1\Adobe
[23/07/2007|14:36] C:\DOCUME~1\Florence\APPLIC~1\AOL
[20/02/2005|19:41] C:\DOCUME~1\Florence\APPLIC~1\ArcSoft
[28/07/2008|15:46] C:\DOCUME~1\Florence\APPLIC~1\Atari
[18/09/2008|19:59] C:\DOCUME~1\Florence\APPLIC~1\AVS4YOU
[16/05/2007|13:56] C:\DOCUME~1\Florence\APPLIC~1\BFGTOOLBAR
[29/01/2006|16:16] C:\DOCUME~1\Florence\APPLIC~1\CyberLink
[12/01/2008|14:36] C:\DOCUME~1\Florence\APPLIC~1\DivX
[07/07/2007|15:43] C:\DOCUME~1\Florence\APPLIC~1\Google
[20/02/2005|20:11] C:\DOCUME~1\Florence\APPLIC~1\Help
[26/12/2004|02:27] C:\DOCUME~1\Florence\APPLIC~1\Identities
[23/10/2006|21:16] C:\DOCUME~1\Florence\APPLIC~1\Logitech
[03/07/2007|12:47] C:\DOCUME~1\Florence\APPLIC~1\Macromedia
[31/12/2008|18:06] C:\DOCUME~1\Florence\APPLIC~1\Microsoft
[30/01/2005|18:37] C:\DOCUME~1\Florence\APPLIC~1\MSN6
[29/01/2006|16:24] C:\DOCUME~1\Florence\APPLIC~1\Real
[25/05/2008|15:05] C:\DOCUME~1\Florence\APPLIC~1\Sonic
[06/08/2006|18:37] C:\DOCUME~1\Florence\APPLIC~1\Sun
[23/01/2006|17:14] C:\DOCUME~1\Florence\APPLIC~1\Ulead Systems
[12/12/2007|14:39] C:\DOCUME~1\Florence\APPLIC~1\Viewpoint
[19/10/2008|20:38] C:\DOCUME~1\Florence\APPLIC~1\Yahoo!
[25/12/2004|18:32] C:\DOCUME~1\Florence\APPLIC~1\You've Got Pictures Screensaver
[20/06/2007|00:11] C:\DOCUME~1\LOCALS~1\APPLIC~1\Help
[15/04/2009|23:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[13/03/2009|22:23] C:\DOCUME~1\Malice\APPLIC~1\Adobe
[16/06/2006|14:03] C:\DOCUME~1\Malice\APPLIC~1\AdobeUM
[08/09/2007|17:21] C:\DOCUME~1\Malice\APPLIC~1\Ahead
[24/07/2007|20:13] C:\DOCUME~1\Malice\APPLIC~1\AOL
[07/02/2009|19:49] C:\DOCUME~1\Malice\APPLIC~1\Apple Computer
[03/03/2005|14:07] C:\DOCUME~1\Malice\APPLIC~1\ArcSoft
[10/09/2008|17:46] C:\DOCUME~1\Malice\APPLIC~1\AVS4YOU
[08/06/2007|20:46] C:\DOCUME~1\Malice\APPLIC~1\BFGTOOLBAR
[13/08/2007|21:50] C:\DOCUME~1\Malice\APPLIC~1\Bib dent road
[23/09/2007|15:17] C:\DOCUME~1\Malice\APPLIC~1\BitTorrent
[19/08/2007|23:26] C:\DOCUME~1\Malice\APPLIC~1\Creative
[30/12/2004|18:15] C:\DOCUME~1\Malice\APPLIC~1\CyberLink
[10/05/2008|22:45] C:\DOCUME~1\Malice\APPLIC~1\DivX
[07/08/2005|14:15] C:\DOCUME~1\Malice\APPLIC~1\Ecran de veille
[21/03/2007|12:04] C:\DOCUME~1\Malice\APPLIC~1\Google
[17/01/2007|16:08] C:\DOCUME~1\Malice\APPLIC~1\Identities
[22/09/2006|21:23] C:\DOCUME~1\Malice\APPLIC~1\LimeWire
[17/12/2006|18:10] C:\DOCUME~1\Malice\APPLIC~1\Logitech
[06/07/2007|13:32] C:\DOCUME~1\Malice\APPLIC~1\Macromedia
[01/02/2009|21:33] C:\DOCUME~1\Malice\APPLIC~1\Microsoft
[30/10/2007|02:17] C:\DOCUME~1\Malice\APPLIC~1\MSN6
[23/03/2008|20:46] C:\DOCUME~1\Malice\APPLIC~1\PlayFirst
[25/01/2005|23:11] C:\DOCUME~1\Malice\APPLIC~1\Real
[31/07/2007|20:57] C:\DOCUME~1\Malice\APPLIC~1\Screenshot Sender
[02/01/2008|21:12] C:\DOCUME~1\Malice\APPLIC~1\Sonic
[29/04/2006|18:21] C:\DOCUME~1\Malice\APPLIC~1\Sun
[30/07/2005|00:34] C:\DOCUME~1\Malice\APPLIC~1\Symantec
[04/04/2006|12:00] C:\DOCUME~1\Malice\APPLIC~1\Ulead Systems
[12/12/2007|07:30] C:\DOCUME~1\Malice\APPLIC~1\Viewpoint
[22/02/2009|00:43] C:\DOCUME~1\Malice\APPLIC~1\Windows Live Writer
[14/10/2008|23:02] C:\DOCUME~1\Malice\APPLIC~1\Yahoo!
[17/01/2007|16:08] C:\DOCUME~1\Malice\APPLIC~1\Zylom
[11/03/2008|03:41] C:\DOCUME~1\Michel\APPLIC~1\Adobe
[11/10/2006|18:55] C:\DOCUME~1\Michel\APPLIC~1\AdobeUM
[24/07/2007|05:21] C:\DOCUME~1\Michel\APPLIC~1\AOL
[15/02/2009|18:02] C:\DOCUME~1\Michel\APPLIC~1\Apple Computer
[06/01/2005|17:12] C:\DOCUME~1\Michel\APPLIC~1\ArcSoft
[02/06/2007|04:27] C:\DOCUME~1\Michel\APPLIC~1\BFGTOOLBAR
[23/09/2006|13:50] C:\DOCUME~1\Michel\APPLIC~1\CyberLink
[15/10/2006|04:41] C:\DOCUME~1\Michel\APPLIC~1\DivX
[16/09/2007|12:42] C:\DOCUME~1\Michel\APPLIC~1\Google
[05/06/2006|11:04] C:\DOCUME~1\Michel\APPLIC~1\Help
[17/09/2006|12:34] C:\DOCUME~1\Michel\APPLIC~1\Identities
[17/12/2006|18:10] C:\DOCUME~1\Michel\APPLIC~1\Logitech
[16/09/2007|12:44] C:\DOCUME~1\Michel\APPLIC~1\Macromedia
[05/02/2009|13:53] C:\DOCUME~1\Michel\APPLIC~1\Microsoft
[07/03/2009|09:20] C:\DOCUME~1\Michel\APPLIC~1\MSN6
[04/11/2006|04:41] C:\DOCUME~1\Michel\APPLIC~1\Real
[21/08/2006|18:21] C:\DOCUME~1\Michel\APPLIC~1\Sun
[16/10/2005|12:32] C:\DOCUME~1\Michel\APPLIC~1\Symantec
[13/12/2007|04:05] C:\DOCUME~1\Michel\APPLIC~1\Viewpoint
[01/01/2009|19:09] C:\DOCUME~1\Michel\APPLIC~1\Yahoo!
[19/02/2006|19:49] C:\DOCUME~1\Michel\APPLIC~1\You've Got Pictures Screensaver
[17/09/2006|12:34] C:\DOCUME~1\Michel\APPLIC~1\Zylom
[26/12/2004|02:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[16/03/2005|18:33] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec
[30/11/2008|19:55] C:\DOCUME~1\Winnie\APPLIC~1\Adobe
[02/12/2005|21:25] C:\DOCUME~1\Winnie\APPLIC~1\AdobeUM
[08/09/2007|20:57] C:\DOCUME~1\Winnie\APPLIC~1\Ahead
[09/10/2007|12:06] C:\DOCUME~1\Winnie\APPLIC~1\Anuman Interactive
[24/08/2006|16:59] C:\DOCUME~1\Winnie\APPLIC~1\AOL
[06/01/2005|19:43] C:\DOCUME~1\Winnie\APPLIC~1\ArcSoft
[28/07/2008|16:01] C:\DOCUME~1\Winnie\APPLIC~1\Atari
[30/05/2007|22:08] C:\DOCUME~1\Winnie\APPLIC~1\BFGTOOLBAR
[17/03/2008|01:38] C:\DOCUME~1\Winnie\APPLIC~1\Creative
[30/12/2004|16:02] C:\DOCUME~1\Winnie\APPLIC~1\CyberLink
[26/01/2008|16:47] C:\DOCUME~1\Winnie\APPLIC~1\DAEMON Tools
[06/10/2006|20:57] C:\DOCUME~1\Winnie\APPLIC~1\DivX
[09/10/2005|20:00] C:\DOCUME~1\Winnie\APPLIC~1\Ecran de veille
[12/08/2008|15:50] C:\DOCUME~1\Winnie\APPLIC~1\Gaijin Ent
[05/03/2008|02:30] C:\DOCUME~1\Winnie\APPLIC~1\Gamelab
[13/03/2008|23:57] C:\DOCUME~1\Winnie\APPLIC~1\GetRightToGo
[15/01/2007|20:00] C:\DOCUME~1\Winnie\APPLIC~1\Google
[12/04/2005|22:41] C:\DOCUME~1\Winnie\APPLIC~1\Help
[22/01/2008|17:30] C:\DOCUME~1\Winnie\APPLIC~1\Identities
[29/06/2006|19:05] C:\DOCUME~1\Winnie\APPLIC~1\iScreensaver
[01/10/2006|21:26] C:\DOCUME~1\Winnie\APPLIC~1\iWin
[28/12/2004|21:59] C:\DOCUME~1\Winnie\APPLIC~1\Leadertech
[03/03/2008|18:13] C:\DOCUME~1\Winnie\APPLIC~1\LimeWire
[17/12/2006|18:10] C:\DOCUME~1\Winnie\APPLIC~1\Logitech
[04/07/2007|21:35] C:\DOCUME~1\Winnie\APPLIC~1\Macromedia
[05/01/2009|17:13] C:\DOCUME~1\Winnie\APPLIC~1\Microsoft
[16/01/2006|11:39] C:\DOCUME~1\Winnie\APPLIC~1\MSN6
[17/07/2008|14:56] C:\DOCUME~1\Winnie\APPLIC~1\My Stitch
[26/03/2008|22:36] C:\DOCUME~1\Winnie\APPLIC~1\Oberon Games
[10/08/2008|21:37] C:\DOCUME~1\Winnie\APPLIC~1\PlayFirst
[19/01/2005|21:15] C:\DOCUME~1\Winnie\APPLIC~1\Real
[15/10/2006|20:40] C:\DOCUME~1\Winnie\APPLIC~1\Samsung
[26/09/2008|17:14] C:\DOCUME~1\Winnie\APPLIC~1\Sandlot Games
[26/09/2008|17:13] C:\DOCUME~1\Winnie\APPLIC~1\SecuROM
[28/12/2004|21:59] C:\DOCUME~1\Winnie\APPLIC~1\Sonic
[19/02/2006|16:19] C:\DOCUME~1\Winnie\APPLIC~1\Sun
[19/04/2005|17:29] C:\DOCUME~1\Winnie\APPLIC~1\Symantec
[17/01/2006|22:48] C:\DOCUME~1\Winnie\APPLIC~1\Ulead Systems
[12/12/2007|19:07] C:\DOCUME~1\Winnie\APPLIC~1\Viewpoint
[01/07/2007|19:42] C:\DOCUME~1\Winnie\APPLIC~1\Vso
[13/10/2008|18:23] C:\DOCUME~1\Winnie\APPLIC~1\Yahoo!
[15/01/2007|18:58] C:\DOCUME~1\Winnie\APPLIC~1\You've Got Pictures Screensaver
[22/01/2008|17:30] C:\DOCUME~1\Winnie\APPLIC~1\Zylom
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/04/2009 19:47][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[25/01/2008 14:20][--a------] C:\WINDOWS\tasks\At6.job
[25/03/2009 21:00][--a------] C:\WINDOWS\tasks\At5.job
[25/10/2008 14:00][--a------] C:\WINDOWS\tasks\At4.job
[25/01/2008 14:18][--a------] C:\WINDOWS\tasks\At3.job
[25/03/2009 21:00][--a------] C:\WINDOWS\tasks\At2.job
[25/10/2008 14:00][--a------] C:\WINDOWS\tasks\At1.job
[15/04/2009 20:41][--a------] C:\WINDOWS\tasks\Symantec NetDetect.job
[08/01/2005 21:35][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 3.job
[02/01/2005 00:50][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 2.job
[27/12/2004 00:35][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 1.job
[15/04/2009 23:37][--ah-----] C:\WINDOWS\tasks\SA.DAT
[30/08/2002 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[12/08/2008|15:46] C:\Program Files\7788xyx
[19/02/2008|22:23] C:\Program Files\A123 AVI WMV ASF MOV MP4 FLV to MPEG Converter
[12/02/2008|14:06] C:\Program Files\Adobe
[03/01/2005|19:16] C:\Program Files\Agfa
[16/10/2005|18:21] C:\Program Files\Ahead
[12/04/2005|17:06] C:\Program Files\AimOne_AlltoMP3
[01/07/2007|19:38] C:\Program Files\Akimania
[26/03/2008|21:55] C:\Program Files\Alawar
[05/01/2006|17:19] C:\Program Files\Alwil Software
[18/10/2008|11:36] C:\Program Files\Anuman Interactive
[01/01/2009|19:12] C:\Program Files\AOL
[01/01/2009|19:08] C:\Program Files\AOL 9.0b
[01/01/2009|19:08] C:\Program Files\AOL Toolbar
[07/02/2009|19:46] C:\Program Files\Apple Software Update
[01/01/2009|19:15] C:\Program Files\ArcSoft
[14/03/2008|00:10] C:\Program Files\Audacity
[29/10/2007|14:46] C:\Program Files\Audible
[12/04/2005|17:20] C:\Program Files\AudioCDMagic
[01/01/2009|19:10] C:\Program Files\AVS4YOU
[31/05/2007|00:45] C:\Program Files\BFG
[23/09/2007|18:11] C:\Program Files\BitTorrent
[07/02/2009|20:56] C:\Program Files\Bonjour
[05/05/2007|21:43] C:\Program Files\Boonty
[27/09/2008|17:16] C:\Program Files\BoontyGames
[30/03/2008|19:03] C:\Program Files\Burger Shop
[26/01/2009|19:28] C:\Program Files\CCleaner
[15/08/2007|10:48] C:\Program Files\CDBurnerXP Pro 3
[03/08/2008|16:01] C:\Program Files\Common Files
[24/03/2008|15:51] C:\Program Files\Creative
[15/04/2007|14:58] C:\Program Files\Creative Installation Information
[26/12/2004|02:27] C:\Program Files\CyberLink
[05/03/2008|13:10] C:\Program Files\Delicious 2 Deluxe
[02/01/2008|21:36] C:\Program Files\Disc2Phone
[13/10/2008|18:21] C:\Program Files\DivX
[27/04/2005|18:02] C:\Program Files\DVD Shrink
[16/12/2008|20:50] C:\Program Files\EA GAMES
[15/04/2009|23:38] C:\Program Files\eMule
[02/09/2007|18:14] C:\Program Files\eMulee
[03/03/2008|18:57] C:\Program Files\eMuleplus
[22/01/2008|15:42] C:\Program Files\eToro
[22/03/2008|22:41] C:\Program Files\Everest Poker
[26/03/2008|20:39] C:\Program Files\Farm Frenzy
[26/03/2008|21:54] C:\Program Files\Fashion Fits
[07/02/2009|19:45] C:\Program Files\Fichiers communs
[30/07/2008|20:59] C:\Program Files\Fish Tycoon
[12/04/2005|22:41] C:\Program Files\FreeRIP2
[10/03/2007|17:54] C:\Program Files\Gamenext
[31/12/2008|18:08] C:\Program Files\Google
[31/07/2008|21:14] C:\Program Files\Gpotato.eu
[17/12/2006|18:12] C:\Program Files\Hamster Blocks
[11/08/2008|01:11] C:\Program Files\Ice Cream Craze
[12/04/2005|18:16] C:\Program Files\Illustrate
[01/01/2009|19:12] C:\Program Files\Imikimi
[17/03/2005|19:28] C:\Program Files\IncrediMail
[26/12/2004|11:07] C:\Program Files\Infogrames
[21/02/2009|17:36] C:\Program Files\InstallShield Installation Information
[27/03/2009|20:28] C:\Program Files\Internet Explorer
[07/02/2009|19:48] C:\Program Files\iPod
[02/02/2005|12:22] C:\Program Files\ISTsvc
[07/02/2009|19:48] C:\Program Files\iTunes
[10/01/2009|14:21] C:\Program Files\Java
[26/12/2004|14:35] C:\Program Files\Labtec
[25/12/2004|18:32] C:\Program Files\Learn2.com
[09/10/2007|12:04] C:\Program Files\LiveCAD
[19/12/2006|15:10] C:\Program Files\Logitech
[12/08/2008|15:30] C:\Program Files\M6 Jeux
[01/01/2009|19:08] C:\Program Files\Maxis
[05/05/2007|21:31] C:\Program Files\Mes Jeux T‚l‚charg‚s
[19/09/2008|15:25] C:\Program Files\Messenger
[07/02/2009|13:31] C:\Program Files\Messenger Plus! Live
[19/08/2007|00:39] C:\Program Files\MessengerPlus! 3
[22/02/2009|00:42] C:\Program Files\Microsoft
[15/04/2009|23:18] C:\Program Files\Microsoft ActiveSync
[09/05/2007|00:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[26/12/2004|02:27] C:\Program Files\microsoft frontpage
[23/10/2007|16:01] C:\Program Files\Microsoft Games
[30/01/2005|18:27] C:\Program Files\microsoft office
[27/02/2009|07:45] C:\Program Files\Microsoft Silverlight
[14/11/2007|15:22] C:\Program Files\Microsoft SQL Server Compact Edition
[27/12/2008|22:16] C:\Program Files\Microsoft Sync Framework
[26/12/2004|02:27] C:\Program Files\Microsoft Visual Studio
[19/09/2008|15:20] C:\Program Files\Movie Maker
[15/04/2007|15:00] C:\Program Files\Mozilla Firefox
[25/08/2005|12:14] C:\Program Files\MP3 Player Utilities
[06/08/2008|14:04] C:\Program Files\MP3 Player Utilities 3.68
[29/03/2008|14:21] C:\Program Files\MP3 Player Utilities 4.18
[02/08/2007|11:08] C:\Program Files\MSN
[21/05/2008|16:48] C:\Program Files\MSN Games
[26/12/2004|02:27] C:\Program Files\MSN Gaming Zone
[18/08/2007|21:48] C:\Program Files\MSN Messenger
[15/08/2007|14:00] C:\Program Files\MSXML 4.0
[23/10/2006|17:25] C:\Program Files\MUSICMATCH
[12/04/2005|22:38] C:\Program Files\MySearch
[26/03/2008|20:39] C:\Program Files\Nanny Mania
[02/02/2005|12:21] C:\Program Files\NavExcel
[05/01/2006|17:31] C:\Program Files\NavExcel Search Toolbar
[19/09/2008|15:14] C:\Program Files\NetMeeting
[05/07/2007|16:51] C:\Program Files\Neuf
[26/12/2004|02:27] C:\Program Files\Nullsoft
[19/09/2008|15:14] C:\Program Files\Outlook Express
[15/12/2005|17:48] C:\Program Files\PAN vision
[01/01/2009|19:12] C:\Program Files\Photo Story 3 for Windows
[01/01/2009|19:12] C:\Program Files\Photo Viewer
[25/02/2009|20:14] C:\Program Files\PhotoFiltre
[30/11/2005|13:17] C:\Program Files\PIXELA
[26/03/2008|19:19] C:\Program Files\PlayFirst
[23/01/2005|22:46] C:\Program Files\Plus!
[07/02/2009|19:47] C:\Program Files\QuickTime
[26/12/2004|02:27] C:\Program Files\Real
[10/12/2006|22:19] C:\Program Files\ReflexiveArcade
[12/12/2006|21:13] C:\Program Files\Samsung
[26/12/2004|02:29] C:\Program Files\Services en ligne
[12/02/2009|16:47] C:\Program Files\Sierra On-Line
[18/01/2007|22:20] C:\Program Files\SnowyLunchRush_at
[26/12/2004|02:27] C:\Program Files\Sonic
[03/08/2008|16:30] C:\Program Files\Sony
[07/03/2006|16:36] C:\Program Files\Sony Corporation
[17/09/2008|09:57] C:\Program Files\Sun
[05/01/2006|17:06] C:\Program Files\Symantec
[26/10/2007|19:23] C:\Program Files\Ubi Soft
[11/02/2008|23:04] C:\Program Files\Ulead Systems
[26/12/2004|02:27] C:\Program Files\Uninstall Information
[06/11/2008|11:11] C:\Program Files\VGA USB Camera
[26/12/2004|02:27] C:\Program Files\Viewpoint
[26/12/2004|02:27] C:\Program Files\Virtual CD v4 SDK
[26/03/2008|20:39] C:\Program Files\Wedding Dash
[22/02/2009|00:41] C:\Program Files\Windows Live
[01/01/2009|19:13] C:\Program Files\Windows Live SkyDrive
[01/01/2009|19:10] C:\Program Files\Windows Live Toolbar
[25/01/2008|14:19] C:\Program Files\Windows Media Connect 2
[19/09/2008|15:14] C:\Program Files\Windows Media Player
[19/09/2008|15:14] C:\Program Files\Windows NT
[15/04/2007|13:37] C:\Program Files\WinRAR
[18/08/2008|20:42] C:\Program Files\WMA-MP3.com
[28/07/2008|20:59] C:\Program Files\World of Warcraft Trial
[26/12/2004|02:27] C:\Program Files\xerox
[01/01/2009|19:10] C:\Program Files\Yahoo!
[01/01/2009|19:08] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[01/01/2009|19:08] C:\Program Files\Fichiers communs\Adobe
[01/01/2009|19:12] C:\Program Files\Fichiers communs\AOL
[25/12/2004|18:32] C:\Program Files\Fichiers communs\aolback
[07/02/2009|19:48] C:\Program Files\Fichiers communs\Apple
[10/09/2008|17:45] C:\Program Files\Fichiers communs\AVSMedia
[08/07/2008|15:12] C:\Program Files\Fichiers communs\Blizzard Entertainment
[10/03/2007|16:43] C:\Program Files\Fichiers communs\BOONTY Shared
[15/04/2007|15:00] C:\Program Files\Fichiers communs\Creative
[26/12/2004|02:28] C:\Program Files\Fichiers communs\Designer
[16/08/2006|19:15] C:\Program Files\Fichiers communs\Digi338
[11/02/2008|22:30] C:\Program Files\Fichiers communs\FotoNation
[03/04/2007|18:52] C:\Program Files\Fichiers communs\InstallShield
[15/01/2006|18:50] C:\Program Files\Fichiers communs\Java
[26/12/2004|14:35] C:\Program Files\Fichiers communs\Logitech
[22/02/2009|00:37] C:\Program Files\Fichiers communs\Microsoft Shared
[26/12/2004|02:27] C:\Program Files\Fichiers communs\MSSoap
[16/08/2006|19:18] C:\Program Files\Fichiers communs\NewSoft
[25/12/2004|18:32] C:\Program Files\Fichiers communs\Nullsoft
[10/08/2008|21:07] C:\Program Files\Fichiers communs\Oberon Media
[10/10/2007|03:04] C:\Program Files\Fichiers communs\ODBC
[26/12/2004|02:27] C:\Program Files\Fichiers communs\Real
[16/04/2007|13:32] C:\Program Files\Fichiers communs\Scanner
[26/12/2004|02:29] C:\Program Files\Fichiers communs\Services
[03/08/2008|16:02] C:\Program Files\Fichiers communs\Sony Shared
[26/12/2004|02:27] C:\Program Files\Fichiers communs\SpeechEngines
[26/12/2004|02:29] C:\Program Files\Fichiers communs\SureThing Shared
[05/12/2008|21:11] C:\Program Files\Fichiers communs\Symantec Shared
[19/09/2008|15:14] C:\Program Files\Fichiers communs\System
[26/12/2004|02:29] C:\Program Files\Fichiers communs\TVNavigTechnologies Shared
[06/04/2007|16:20] C:\Program Files\Fichiers communs\Ulead Systems
[17/12/2008|21:36] C:\Program Files\Fichiers communs\Windows Live
[14/11/2007|15:14] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[26/12/2004|02:27] C:\Program Files\Fichiers communs\xing shared
--------------------\\ Process
( 56 Processes )
IEXPLORE.EXE ~ [PID:3724]
IEXPLORE.EXE ~ [PID:184]
--------------------\\ Recherche avec S_Lop
C:\DOCUME~1\Malice\APPLIC~1\BIBDEN~1
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\Malice\LOCALS~1\Temp\NSSstub.txt
C:\DOCUME~1\Malice\Cookies\malice@advertstream[2].txt
C:\DOCUME~1\Malice\Cookies\malice@advertising[1].txt
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FRAGSAFEFILM]
"DisplayName"="CiD Help"
"UninstallString"="C:\\DOCUME~1\\Malice\\APPLIC~1\\BIBDEN~1\\Kind Junk Data.exe -uninstall"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"flap admin"="C:\\DOCUME~1\\Malice\\APPLIC~1\\BIBDEN~1\\Kind Junk Data.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------\\ Verification du fichier Hosts
Fichier Hosts MODIFIE
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD
-> 72 [ 70 ## added by CiD ]
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-16 00:26:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 37
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Malice\Application Data\Microsoft\Office\Fichiers r‚cents\Hospital Tycoon crack NoCD - patch activation Multilanguage garanted by eMule inside.lnk
[F:220][D:27]-> C:\DOCUME~1\Malice\LOCALS~1\Temp
[F:649][D:0]-> C:\DOCUME~1\Malice\Cookies
[F:1494][D:49]-> C:\DOCUME~1\Malice\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 16/04/2009| 0:28 - Option : [1]
--------------------\\ Fin du rapport a 0:28:49
Re,
▶ Relance Lop S&D
▶ Choisis cette fois ci l'Option 2 ( Suppression )
▶ Ne ferme pas la fenêtre lors de la suppression !
▶ Poste le rapport généré ( C:\lopR.txt )
( Si le Bureau ne réapparaît pas presse Ctrl + Alt + Suppr, Onglet Fichier,
Nouvelle tâche, tape explorer.exe et valide )
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
▶ Relance Lop S&D
▶ Choisis cette fois ci l'Option 2 ( Suppression )
▶ Ne ferme pas la fenêtre lors de la suppression !
▶ Poste le rapport généré ( C:\lopR.txt )
( Si le Bureau ne réapparaît pas presse Ctrl + Alt + Suppr, Onglet Fichier,
Nouvelle tâche, tape explorer.exe et valide )
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
Voilà le résultat
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 3000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Malice ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090108-0] 4.8.1296 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:145 Go (Free:20 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 16/04/2009| 0:35 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\Malice\LOCALS~1\Temp\NSSstub.txt
Supprime! - C:\DOCUME~1\Malice\Cookies\malice@advertstream[2].txt
Supprime! - C:\DOCUME~1\Malice\Cookies\malice@advertising[1].txt
Supprime! - C:\DOCUME~1\Malice\APPLIC~1\BIBDEN~1
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
Supprime! - C:\Program Files\Viewpoint
Supprime! - C:\DOCUME~1\Malice\APPLIC~1\Viewpoint
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[07/02/2009|19:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[15/04/2007|15:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[15/04/2007|15:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe(2)
[08/09/2007|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[26/03/2008|21:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AlawarGameBox
[01/01/2009|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[22/07/2007|23:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
[28/09/2008|16:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
[07/02/2009|19:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[07/02/2009|19:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[10/09/2008|17:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[10/03/2007|16:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[24/03/2008|15:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[21/02/2008|19:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[26/09/2008|17:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Escape From Paradise
[26/03/2008|21:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fugazo
[26/03/2008|22:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Go Go Gourmet
[01/01/2009|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[01/10/2006|21:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin
[05/05/2007|22:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Legacy Interactive
[22/07/2007|23:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[02/09/2007|00:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[22/02/2009|00:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[26/12/2004|15:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[11/07/2006|17:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Newsoft
[05/05/2008|14:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games
[10/08/2008|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[26/12/2004|02:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[26/09/2008|17:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[26/12/2004|02:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[05/01/2006|17:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[12/08/2008|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[05/05/2007|21:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[21/02/2009|17:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[07/07/2006|11:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[17/11/2006|18:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[31/12/2008|18:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[30/11/2007|14:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/03/2008|01:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[26/12/2004|02:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[04/07/2007|12:32] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[26/12/2004|02:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[23/01/2008|14:44] C:\DOCUME~1\Florence\APPLIC~1\Adobe
[23/07/2007|14:36] C:\DOCUME~1\Florence\APPLIC~1\AOL
[20/02/2005|19:41] C:\DOCUME~1\Florence\APPLIC~1\ArcSoft
[28/07/2008|15:46] C:\DOCUME~1\Florence\APPLIC~1\Atari
[18/09/2008|19:59] C:\DOCUME~1\Florence\APPLIC~1\AVS4YOU
[16/05/2007|13:56] C:\DOCUME~1\Florence\APPLIC~1\BFGTOOLBAR
[29/01/2006|16:16] C:\DOCUME~1\Florence\APPLIC~1\CyberLink
[12/01/2008|14:36] C:\DOCUME~1\Florence\APPLIC~1\DivX
[07/07/2007|15:43] C:\DOCUME~1\Florence\APPLIC~1\Google
[20/02/2005|20:11] C:\DOCUME~1\Florence\APPLIC~1\Help
[26/12/2004|02:27] C:\DOCUME~1\Florence\APPLIC~1\Identities
[23/10/2006|21:16] C:\DOCUME~1\Florence\APPLIC~1\Logitech
[03/07/2007|12:47] C:\DOCUME~1\Florence\APPLIC~1\Macromedia
[31/12/2008|18:06] C:\DOCUME~1\Florence\APPLIC~1\Microsoft
[30/01/2005|18:37] C:\DOCUME~1\Florence\APPLIC~1\MSN6
[29/01/2006|16:24] C:\DOCUME~1\Florence\APPLIC~1\Real
[25/05/2008|15:05] C:\DOCUME~1\Florence\APPLIC~1\Sonic
[06/08/2006|18:37] C:\DOCUME~1\Florence\APPLIC~1\Sun
[23/01/2006|17:14] C:\DOCUME~1\Florence\APPLIC~1\Ulead Systems
[12/12/2007|14:39] C:\DOCUME~1\Florence\APPLIC~1\Viewpoint
[19/10/2008|20:38] C:\DOCUME~1\Florence\APPLIC~1\Yahoo!
[25/12/2004|18:32] C:\DOCUME~1\Florence\APPLIC~1\You've Got Pictures Screensaver
[20/06/2007|00:11] C:\DOCUME~1\LOCALS~1\APPLIC~1\Help
[15/04/2009|23:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[13/03/2009|22:23] C:\DOCUME~1\Malice\APPLIC~1\Adobe
[16/06/2006|14:03] C:\DOCUME~1\Malice\APPLIC~1\AdobeUM
[08/09/2007|17:21] C:\DOCUME~1\Malice\APPLIC~1\Ahead
[24/07/2007|20:13] C:\DOCUME~1\Malice\APPLIC~1\AOL
[07/02/2009|19:49] C:\DOCUME~1\Malice\APPLIC~1\Apple Computer
[03/03/2005|14:07] C:\DOCUME~1\Malice\APPLIC~1\ArcSoft
[10/09/2008|17:46] C:\DOCUME~1\Malice\APPLIC~1\AVS4YOU
[08/06/2007|20:46] C:\DOCUME~1\Malice\APPLIC~1\BFGTOOLBAR
[23/09/2007|15:17] C:\DOCUME~1\Malice\APPLIC~1\BitTorrent
[19/08/2007|23:26] C:\DOCUME~1\Malice\APPLIC~1\Creative
[30/12/2004|18:15] C:\DOCUME~1\Malice\APPLIC~1\CyberLink
[10/05/2008|22:45] C:\DOCUME~1\Malice\APPLIC~1\DivX
[07/08/2005|14:15] C:\DOCUME~1\Malice\APPLIC~1\Ecran de veille
[21/03/2007|12:04] C:\DOCUME~1\Malice\APPLIC~1\Google
[17/01/2007|16:08] C:\DOCUME~1\Malice\APPLIC~1\Identities
[22/09/2006|21:23] C:\DOCUME~1\Malice\APPLIC~1\LimeWire
[17/12/2006|18:10] C:\DOCUME~1\Malice\APPLIC~1\Logitech
[06/07/2007|13:32] C:\DOCUME~1\Malice\APPLIC~1\Macromedia
[01/02/2009|21:33] C:\DOCUME~1\Malice\APPLIC~1\Microsoft
[30/10/2007|02:17] C:\DOCUME~1\Malice\APPLIC~1\MSN6
[23/03/2008|20:46] C:\DOCUME~1\Malice\APPLIC~1\PlayFirst
[25/01/2005|23:11] C:\DOCUME~1\Malice\APPLIC~1\Real
[31/07/2007|20:57] C:\DOCUME~1\Malice\APPLIC~1\Screenshot Sender
[02/01/2008|21:12] C:\DOCUME~1\Malice\APPLIC~1\Sonic
[29/04/2006|18:21] C:\DOCUME~1\Malice\APPLIC~1\Sun
[30/07/2005|00:34] C:\DOCUME~1\Malice\APPLIC~1\Symantec
[04/04/2006|12:00] C:\DOCUME~1\Malice\APPLIC~1\Ulead Systems
[22/02/2009|00:43] C:\DOCUME~1\Malice\APPLIC~1\Windows Live Writer
[14/10/2008|23:02] C:\DOCUME~1\Malice\APPLIC~1\Yahoo!
[17/01/2007|16:08] C:\DOCUME~1\Malice\APPLIC~1\Zylom
[11/03/2008|03:41] C:\DOCUME~1\Michel\APPLIC~1\Adobe
[11/10/2006|18:55] C:\DOCUME~1\Michel\APPLIC~1\AdobeUM
[24/07/2007|05:21] C:\DOCUME~1\Michel\APPLIC~1\AOL
[15/02/2009|18:02] C:\DOCUME~1\Michel\APPLIC~1\Apple Computer
[06/01/2005|17:12] C:\DOCUME~1\Michel\APPLIC~1\ArcSoft
[02/06/2007|04:27] C:\DOCUME~1\Michel\APPLIC~1\BFGTOOLBAR
[23/09/2006|13:50] C:\DOCUME~1\Michel\APPLIC~1\CyberLink
[15/10/2006|04:41] C:\DOCUME~1\Michel\APPLIC~1\DivX
[16/09/2007|12:42] C:\DOCUME~1\Michel\APPLIC~1\Google
[05/06/2006|11:04] C:\DOCUME~1\Michel\APPLIC~1\Help
[17/09/2006|12:34] C:\DOCUME~1\Michel\APPLIC~1\Identities
[17/12/2006|18:10] C:\DOCUME~1\Michel\APPLIC~1\Logitech
[16/09/2007|12:44] C:\DOCUME~1\Michel\APPLIC~1\Macromedia
[05/02/2009|13:53] C:\DOCUME~1\Michel\APPLIC~1\Microsoft
[07/03/2009|09:20] C:\DOCUME~1\Michel\APPLIC~1\MSN6
[04/11/2006|04:41] C:\DOCUME~1\Michel\APPLIC~1\Real
[21/08/2006|18:21] C:\DOCUME~1\Michel\APPLIC~1\Sun
[16/10/2005|12:32] C:\DOCUME~1\Michel\APPLIC~1\Symantec
[13/12/2007|04:05] C:\DOCUME~1\Michel\APPLIC~1\Viewpoint
[01/01/2009|19:09] C:\DOCUME~1\Michel\APPLIC~1\Yahoo!
[19/02/2006|19:49] C:\DOCUME~1\Michel\APPLIC~1\You've Got Pictures Screensaver
[17/09/2006|12:34] C:\DOCUME~1\Michel\APPLIC~1\Zylom
[26/12/2004|02:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[16/03/2005|18:33] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec
[30/11/2008|19:55] C:\DOCUME~1\Winnie\APPLIC~1\Adobe
[02/12/2005|21:25] C:\DOCUME~1\Winnie\APPLIC~1\AdobeUM
[08/09/2007|20:57] C:\DOCUME~1\Winnie\APPLIC~1\Ahead
[09/10/2007|12:06] C:\DOCUME~1\Winnie\APPLIC~1\Anuman Interactive
[24/08/2006|16:59] C:\DOCUME~1\Winnie\APPLIC~1\AOL
[06/01/2005|19:43] C:\DOCUME~1\Winnie\APPLIC~1\ArcSoft
[28/07/2008|16:01] C:\DOCUME~1\Winnie\APPLIC~1\Atari
[30/05/2007|22:08] C:\DOCUME~1\Winnie\APPLIC~1\BFGTOOLBAR
[17/03/2008|01:38] C:\DOCUME~1\Winnie\APPLIC~1\Creative
[30/12/2004|16:02] C:\DOCUME~1\Winnie\APPLIC~1\CyberLink
[26/01/2008|16:47] C:\DOCUME~1\Winnie\APPLIC~1\DAEMON Tools
[06/10/2006|20:57] C:\DOCUME~1\Winnie\APPLIC~1\DivX
[09/10/2005|20:00] C:\DOCUME~1\Winnie\APPLIC~1\Ecran de veille
[12/08/2008|15:50] C:\DOCUME~1\Winnie\APPLIC~1\Gaijin Ent
[05/03/2008|02:30] C:\DOCUME~1\Winnie\APPLIC~1\Gamelab
[13/03/2008|23:57] C:\DOCUME~1\Winnie\APPLIC~1\GetRightToGo
[15/01/2007|20:00] C:\DOCUME~1\Winnie\APPLIC~1\Google
[12/04/2005|22:41] C:\DOCUME~1\Winnie\APPLIC~1\Help
[22/01/2008|17:30] C:\DOCUME~1\Winnie\APPLIC~1\Identities
[29/06/2006|19:05] C:\DOCUME~1\Winnie\APPLIC~1\iScreensaver
[01/10/2006|21:26] C:\DOCUME~1\Winnie\APPLIC~1\iWin
[28/12/2004|21:59] C:\DOCUME~1\Winnie\APPLIC~1\Leadertech
[03/03/2008|18:13] C:\DOCUME~1\Winnie\APPLIC~1\LimeWire
[17/12/2006|18:10] C:\DOCUME~1\Winnie\APPLIC~1\Logitech
[04/07/2007|21:35] C:\DOCUME~1\Winnie\APPLIC~1\Macromedia
[05/01/2009|17:13] C:\DOCUME~1\Winnie\APPLIC~1\Microsoft
[16/01/2006|11:39] C:\DOCUME~1\Winnie\APPLIC~1\MSN6
[17/07/2008|14:56] C:\DOCUME~1\Winnie\APPLIC~1\My Stitch
[26/03/2008|22:36] C:\DOCUME~1\Winnie\APPLIC~1\Oberon Games
[10/08/2008|21:37] C:\DOCUME~1\Winnie\APPLIC~1\PlayFirst
[19/01/2005|21:15] C:\DOCUME~1\Winnie\APPLIC~1\Real
[15/10/2006|20:40] C:\DOCUME~1\Winnie\APPLIC~1\Samsung
[26/09/2008|17:14] C:\DOCUME~1\Winnie\APPLIC~1\Sandlot Games
[26/09/2008|17:13] C:\DOCUME~1\Winnie\APPLIC~1\SecuROM
[28/12/2004|21:59] C:\DOCUME~1\Winnie\APPLIC~1\Sonic
[19/02/2006|16:19] C:\DOCUME~1\Winnie\APPLIC~1\Sun
[19/04/2005|17:29] C:\DOCUME~1\Winnie\APPLIC~1\Symantec
[17/01/2006|22:48] C:\DOCUME~1\Winnie\APPLIC~1\Ulead Systems
[12/12/2007|19:07] C:\DOCUME~1\Winnie\APPLIC~1\Viewpoint
[01/07/2007|19:42] C:\DOCUME~1\Winnie\APPLIC~1\Vso
[13/10/2008|18:23] C:\DOCUME~1\Winnie\APPLIC~1\Yahoo!
[15/01/2007|18:58] C:\DOCUME~1\Winnie\APPLIC~1\You've Got Pictures Screensaver
[22/01/2008|17:30] C:\DOCUME~1\Winnie\APPLIC~1\Zylom
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/04/2009 19:47][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[25/01/2008 14:20][--a------] C:\WINDOWS\tasks\At6.job
[25/03/2009 21:00][--a------] C:\WINDOWS\tasks\At5.job
[25/10/2008 14:00][--a------] C:\WINDOWS\tasks\At4.job
[25/01/2008 14:18][--a------] C:\WINDOWS\tasks\At3.job
[25/03/2009 21:00][--a------] C:\WINDOWS\tasks\At2.job
[25/10/2008 14:00][--a------] C:\WINDOWS\tasks\At1.job
[15/04/2009 20:41][--a------] C:\WINDOWS\tasks\Symantec NetDetect.job
[08/01/2005 21:35][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 3.job
[02/01/2005 00:50][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 2.job
[27/12/2004 00:35][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 1.job
[15/04/2009 23:37][--ah-----] C:\WINDOWS\tasks\SA.DAT
[30/08/2002 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[12/08/2008|15:46] C:\Program Files\7788xyx
[19/02/2008|22:23] C:\Program Files\A123 AVI WMV ASF MOV MP4 FLV to MPEG Converter
[12/02/2008|14:06] C:\Program Files\Adobe
[03/01/2005|19:16] C:\Program Files\Agfa
[16/10/2005|18:21] C:\Program Files\Ahead
[12/04/2005|17:06] C:\Program Files\AimOne_AlltoMP3
[01/07/2007|19:38] C:\Program Files\Akimania
[26/03/2008|21:55] C:\Program Files\Alawar
[05/01/2006|17:19] C:\Program Files\Alwil Software
[18/10/2008|11:36] C:\Program Files\Anuman Interactive
[01/01/2009|19:12] C:\Program Files\AOL
[01/01/2009|19:08] C:\Program Files\AOL 9.0b
[01/01/2009|19:08] C:\Program Files\AOL Toolbar
[07/02/2009|19:46] C:\Program Files\Apple Software Update
[01/01/2009|19:15] C:\Program Files\ArcSoft
[14/03/2008|00:10] C:\Program Files\Audacity
[29/10/2007|14:46] C:\Program Files\Audible
[12/04/2005|17:20] C:\Program Files\AudioCDMagic
[01/01/2009|19:10] C:\Program Files\AVS4YOU
[31/05/2007|00:45] C:\Program Files\BFG
[23/09/2007|18:11] C:\Program Files\BitTorrent
[07/02/2009|20:56] C:\Program Files\Bonjour
[05/05/2007|21:43] C:\Program Files\Boonty
[27/09/2008|17:16] C:\Program Files\BoontyGames
[30/03/2008|19:03] C:\Program Files\Burger Shop
[26/01/2009|19:28] C:\Program Files\CCleaner
[15/08/2007|10:48] C:\Program Files\CDBurnerXP Pro 3
[03/08/2008|16:01] C:\Program Files\Common Files
[24/03/2008|15:51] C:\Program Files\Creative
[15/04/2007|14:58] C:\Program Files\Creative Installation Information
[26/12/2004|02:27] C:\Program Files\CyberLink
[05/03/2008|13:10] C:\Program Files\Delicious 2 Deluxe
[02/01/2008|21:36] C:\Program Files\Disc2Phone
[13/10/2008|18:21] C:\Program Files\DivX
[27/04/2005|18:02] C:\Program Files\DVD Shrink
[16/12/2008|20:50] C:\Program Files\EA GAMES
[15/04/2009|23:38] C:\Program Files\eMule
[02/09/2007|18:14] C:\Program Files\eMulee
[03/03/2008|18:57] C:\Program Files\eMuleplus
[22/01/2008|15:42] C:\Program Files\eToro
[22/03/2008|22:41] C:\Program Files\Everest Poker
[26/03/2008|20:39] C:\Program Files\Farm Frenzy
[26/03/2008|21:54] C:\Program Files\Fashion Fits
[07/02/2009|19:45] C:\Program Files\Fichiers communs
[30/07/2008|20:59] C:\Program Files\Fish Tycoon
[12/04/2005|22:41] C:\Program Files\FreeRIP2
[10/03/2007|17:54] C:\Program Files\Gamenext
[31/12/2008|18:08] C:\Program Files\Google
[31/07/2008|21:14] C:\Program Files\Gpotato.eu
[17/12/2006|18:12] C:\Program Files\Hamster Blocks
[11/08/2008|01:11] C:\Program Files\Ice Cream Craze
[12/04/2005|18:16] C:\Program Files\Illustrate
[01/01/2009|19:12] C:\Program Files\Imikimi
[17/03/2005|19:28] C:\Program Files\IncrediMail
[26/12/2004|11:07] C:\Program Files\Infogrames
[21/02/2009|17:36] C:\Program Files\InstallShield Installation Information
[27/03/2009|20:28] C:\Program Files\Internet Explorer
[07/02/2009|19:48] C:\Program Files\iPod
[02/02/2005|12:22] C:\Program Files\ISTsvc
[07/02/2009|19:48] C:\Program Files\iTunes
[10/01/2009|14:21] C:\Program Files\Java
[26/12/2004|14:35] C:\Program Files\Labtec
[25/12/2004|18:32] C:\Program Files\Learn2.com
[09/10/2007|12:04] C:\Program Files\LiveCAD
[19/12/2006|15:10] C:\Program Files\Logitech
[12/08/2008|15:30] C:\Program Files\M6 Jeux
[01/01/2009|19:08] C:\Program Files\Maxis
[05/05/2007|21:31] C:\Program Files\Mes Jeux T‚l‚charg‚s
[19/09/2008|15:25] C:\Program Files\Messenger
[07/02/2009|13:31] C:\Program Files\Messenger Plus! Live
[19/08/2007|00:39] C:\Program Files\MessengerPlus! 3
[22/02/2009|00:42] C:\Program Files\Microsoft
[15/04/2009|23:18] C:\Program Files\Microsoft ActiveSync
[09/05/2007|00:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[26/12/2004|02:27] C:\Program Files\microsoft frontpage
[23/10/2007|16:01] C:\Program Files\Microsoft Games
[30/01/2005|18:27] C:\Program Files\microsoft office
[27/02/2009|07:45] C:\Program Files\Microsoft Silverlight
[14/11/2007|15:22] C:\Program Files\Microsoft SQL Server Compact Edition
[27/12/2008|22:16] C:\Program Files\Microsoft Sync Framework
[26/12/2004|02:27] C:\Program Files\Microsoft Visual Studio
[19/09/2008|15:20] C:\Program Files\Movie Maker
[15/04/2007|15:00] C:\Program Files\Mozilla Firefox
[25/08/2005|12:14] C:\Program Files\MP3 Player Utilities
[06/08/2008|14:04] C:\Program Files\MP3 Player Utilities 3.68
[29/03/2008|14:21] C:\Program Files\MP3 Player Utilities 4.18
[02/08/2007|11:08] C:\Program Files\MSN
[21/05/2008|16:48] C:\Program Files\MSN Games
[26/12/2004|02:27] C:\Program Files\MSN Gaming Zone
[18/08/2007|21:48] C:\Program Files\MSN Messenger
[15/08/2007|14:00] C:\Program Files\MSXML 4.0
[23/10/2006|17:25] C:\Program Files\MUSICMATCH
[12/04/2005|22:38] C:\Program Files\MySearch
[26/03/2008|20:39] C:\Program Files\Nanny Mania
[02/02/2005|12:21] C:\Program Files\NavExcel
[05/01/2006|17:31] C:\Program Files\NavExcel Search Toolbar
[19/09/2008|15:14] C:\Program Files\NetMeeting
[05/07/2007|16:51] C:\Program Files\Neuf
[26/12/2004|02:27] C:\Program Files\Nullsoft
[19/09/2008|15:14] C:\Program Files\Outlook Express
[15/12/2005|17:48] C:\Program Files\PAN vision
[01/01/2009|19:12] C:\Program Files\Photo Story 3 for Windows
[01/01/2009|19:12] C:\Program Files\Photo Viewer
[25/02/2009|20:14] C:\Program Files\PhotoFiltre
[30/11/2005|13:17] C:\Program Files\PIXELA
[26/03/2008|19:19] C:\Program Files\PlayFirst
[23/01/2005|22:46] C:\Program Files\Plus!
[07/02/2009|19:47] C:\Program Files\QuickTime
[26/12/2004|02:27] C:\Program Files\Real
[10/12/2006|22:19] C:\Program Files\ReflexiveArcade
[12/12/2006|21:13] C:\Program Files\Samsung
[26/12/2004|02:29] C:\Program Files\Services en ligne
[12/02/2009|16:47] C:\Program Files\Sierra On-Line
[18/01/2007|22:20] C:\Program Files\SnowyLunchRush_at
[26/12/2004|02:27] C:\Program Files\Sonic
[03/08/2008|16:30] C:\Program Files\Sony
[07/03/2006|16:36] C:\Program Files\Sony Corporation
[17/09/2008|09:57] C:\Program Files\Sun
[05/01/2006|17:06] C:\Program Files\Symantec
[26/10/2007|19:23] C:\Program Files\Ubi Soft
[11/02/2008|23:04] C:\Program Files\Ulead Systems
[26/12/2004|02:27] C:\Program Files\Uninstall Information
[06/11/2008|11:11] C:\Program Files\VGA USB Camera
[26/12/2004|02:27] C:\Program Files\Virtual CD v4 SDK
[26/03/2008|20:39] C:\Program Files\Wedding Dash
[22/02/2009|00:41] C:\Program Files\Windows Live
[01/01/2009|19:13] C:\Program Files\Windows Live SkyDrive
[01/01/2009|19:10] C:\Program Files\Windows Live Toolbar
[25/01/2008|14:19] C:\Program Files\Windows Media Connect 2
[19/09/2008|15:14] C:\Program Files\Windows Media Player
[19/09/2008|15:14] C:\Program Files\Windows NT
[15/04/2007|13:37] C:\Program Files\WinRAR
[18/08/2008|20:42] C:\Program Files\WMA-MP3.com
[28/07/2008|20:59] C:\Program Files\World of Warcraft Trial
[26/12/2004|02:27] C:\Program Files\xerox
[01/01/2009|19:10] C:\Program Files\Yahoo!
[01/01/2009|19:08] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[01/01/2009|19:08] C:\Program Files\Fichiers communs\Adobe
[01/01/2009|19:12] C:\Program Files\Fichiers communs\AOL
[25/12/2004|18:32] C:\Program Files\Fichiers communs\aolback
[07/02/2009|19:48] C:\Program Files\Fichiers communs\Apple
[10/09/2008|17:45] C:\Program Files\Fichiers communs\AVSMedia
[08/07/2008|15:12] C:\Program Files\Fichiers communs\Blizzard Entertainment
[10/03/2007|16:43] C:\Program Files\Fichiers communs\BOONTY Shared
[15/04/2007|15:00] C:\Program Files\Fichiers communs\Creative
[26/12/2004|02:28] C:\Program Files\Fichiers communs\Designer
[16/08/2006|19:15] C:\Program Files\Fichiers communs\Digi338
[11/02/2008|22:30] C:\Program Files\Fichiers communs\FotoNation
[03/04/2007|18:52] C:\Program Files\Fichiers communs\InstallShield
[15/01/2006|18:50] C:\Program Files\Fichiers communs\Java
[26/12/2004|14:35] C:\Program Files\Fichiers communs\Logitech
[22/02/2009|00:37] C:\Program Files\Fichiers communs\Microsoft Shared
[26/12/2004|02:27] C:\Program Files\Fichiers communs\MSSoap
[16/08/2006|19:18] C:\Program Files\Fichiers communs\NewSoft
[25/12/2004|18:32] C:\Program Files\Fichiers communs\Nullsoft
[10/08/2008|21:07] C:\Program Files\Fichiers communs\Oberon Media
[10/10/2007|03:04] C:\Program Files\Fichiers communs\ODBC
[26/12/2004|02:27] C:\Program Files\Fichiers communs\Real
[16/04/2007|13:32] C:\Program Files\Fichiers communs\Scanner
[26/12/2004|02:29] C:\Program Files\Fichiers communs\Services
[03/08/2008|16:02] C:\Program Files\Fichiers communs\Sony Shared
[26/12/2004|02:27] C:\Program Files\Fichiers communs\SpeechEngines
[26/12/2004|02:29] C:\Program Files\Fichiers communs\SureThing Shared
[05/12/2008|21:11] C:\Program Files\Fichiers communs\Symantec Shared
[19/09/2008|15:14] C:\Program Files\Fichiers communs\System
[26/12/2004|02:29] C:\Program Files\Fichiers communs\TVNavigTechnologies Shared
[06/04/2007|16:20] C:\Program Files\Fichiers communs\Ulead Systems
[17/12/2008|21:36] C:\Program Files\Fichiers communs\Windows Live
[14/11/2007|15:14] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[26/12/2004|02:27] C:\Program Files\Fichiers communs\xing shared
--------------------\\ Process
( 53 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-16 00:36:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 37
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Malice\Application Data\Microsoft\Office\Fichiers r‚cents\Hospital Tycoon crack NoCD - patch activation Multilanguage garanted by eMule inside.lnk
[F:214][D:27]-> C:\DOCUME~1\Malice\LOCALS~1\Temp
[F:649][D:0]-> C:\DOCUME~1\Malice\Cookies
[F:1592][D:49]-> C:\DOCUME~1\Malice\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 16/04/2009| 0:28 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 16/04/2009| 0:37 - Option : [2]
--------------------\\ Fin du rapport a 0:37:57
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 3000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Malice ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090108-0] 4.8.1296 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:145 Go (Free:20 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 16/04/2009| 0:35 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\Malice\LOCALS~1\Temp\NSSstub.txt
Supprime! - C:\DOCUME~1\Malice\Cookies\malice@advertstream[2].txt
Supprime! - C:\DOCUME~1\Malice\Cookies\malice@advertising[1].txt
Supprime! - C:\DOCUME~1\Malice\APPLIC~1\BIBDEN~1
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
Supprime! - C:\Program Files\Viewpoint
Supprime! - C:\DOCUME~1\Malice\APPLIC~1\Viewpoint
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[07/02/2009|19:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[15/04/2007|15:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[15/04/2007|15:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe(2)
[08/09/2007|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[26/03/2008|21:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AlawarGameBox
[01/01/2009|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[22/07/2007|23:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
[28/09/2008|16:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
[07/02/2009|19:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[07/02/2009|19:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[10/09/2008|17:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[10/03/2007|16:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[24/03/2008|15:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[21/02/2008|19:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[26/09/2008|17:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Escape From Paradise
[26/03/2008|21:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fugazo
[26/03/2008|22:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Go Go Gourmet
[01/01/2009|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[01/10/2006|21:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin
[05/05/2007|22:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Legacy Interactive
[22/07/2007|23:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[02/09/2007|00:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[22/02/2009|00:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[26/12/2004|15:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[11/07/2006|17:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Newsoft
[05/05/2008|14:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games
[10/08/2008|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[26/12/2004|02:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[26/09/2008|17:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[26/12/2004|02:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[05/01/2006|17:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[12/08/2008|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[05/05/2007|21:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[21/02/2009|17:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[07/07/2006|11:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[17/11/2006|18:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[31/12/2008|18:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[30/11/2007|14:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/03/2008|01:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[26/12/2004|02:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[04/07/2007|12:32] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[26/12/2004|02:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[23/01/2008|14:44] C:\DOCUME~1\Florence\APPLIC~1\Adobe
[23/07/2007|14:36] C:\DOCUME~1\Florence\APPLIC~1\AOL
[20/02/2005|19:41] C:\DOCUME~1\Florence\APPLIC~1\ArcSoft
[28/07/2008|15:46] C:\DOCUME~1\Florence\APPLIC~1\Atari
[18/09/2008|19:59] C:\DOCUME~1\Florence\APPLIC~1\AVS4YOU
[16/05/2007|13:56] C:\DOCUME~1\Florence\APPLIC~1\BFGTOOLBAR
[29/01/2006|16:16] C:\DOCUME~1\Florence\APPLIC~1\CyberLink
[12/01/2008|14:36] C:\DOCUME~1\Florence\APPLIC~1\DivX
[07/07/2007|15:43] C:\DOCUME~1\Florence\APPLIC~1\Google
[20/02/2005|20:11] C:\DOCUME~1\Florence\APPLIC~1\Help
[26/12/2004|02:27] C:\DOCUME~1\Florence\APPLIC~1\Identities
[23/10/2006|21:16] C:\DOCUME~1\Florence\APPLIC~1\Logitech
[03/07/2007|12:47] C:\DOCUME~1\Florence\APPLIC~1\Macromedia
[31/12/2008|18:06] C:\DOCUME~1\Florence\APPLIC~1\Microsoft
[30/01/2005|18:37] C:\DOCUME~1\Florence\APPLIC~1\MSN6
[29/01/2006|16:24] C:\DOCUME~1\Florence\APPLIC~1\Real
[25/05/2008|15:05] C:\DOCUME~1\Florence\APPLIC~1\Sonic
[06/08/2006|18:37] C:\DOCUME~1\Florence\APPLIC~1\Sun
[23/01/2006|17:14] C:\DOCUME~1\Florence\APPLIC~1\Ulead Systems
[12/12/2007|14:39] C:\DOCUME~1\Florence\APPLIC~1\Viewpoint
[19/10/2008|20:38] C:\DOCUME~1\Florence\APPLIC~1\Yahoo!
[25/12/2004|18:32] C:\DOCUME~1\Florence\APPLIC~1\You've Got Pictures Screensaver
[20/06/2007|00:11] C:\DOCUME~1\LOCALS~1\APPLIC~1\Help
[15/04/2009|23:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[13/03/2009|22:23] C:\DOCUME~1\Malice\APPLIC~1\Adobe
[16/06/2006|14:03] C:\DOCUME~1\Malice\APPLIC~1\AdobeUM
[08/09/2007|17:21] C:\DOCUME~1\Malice\APPLIC~1\Ahead
[24/07/2007|20:13] C:\DOCUME~1\Malice\APPLIC~1\AOL
[07/02/2009|19:49] C:\DOCUME~1\Malice\APPLIC~1\Apple Computer
[03/03/2005|14:07] C:\DOCUME~1\Malice\APPLIC~1\ArcSoft
[10/09/2008|17:46] C:\DOCUME~1\Malice\APPLIC~1\AVS4YOU
[08/06/2007|20:46] C:\DOCUME~1\Malice\APPLIC~1\BFGTOOLBAR
[23/09/2007|15:17] C:\DOCUME~1\Malice\APPLIC~1\BitTorrent
[19/08/2007|23:26] C:\DOCUME~1\Malice\APPLIC~1\Creative
[30/12/2004|18:15] C:\DOCUME~1\Malice\APPLIC~1\CyberLink
[10/05/2008|22:45] C:\DOCUME~1\Malice\APPLIC~1\DivX
[07/08/2005|14:15] C:\DOCUME~1\Malice\APPLIC~1\Ecran de veille
[21/03/2007|12:04] C:\DOCUME~1\Malice\APPLIC~1\Google
[17/01/2007|16:08] C:\DOCUME~1\Malice\APPLIC~1\Identities
[22/09/2006|21:23] C:\DOCUME~1\Malice\APPLIC~1\LimeWire
[17/12/2006|18:10] C:\DOCUME~1\Malice\APPLIC~1\Logitech
[06/07/2007|13:32] C:\DOCUME~1\Malice\APPLIC~1\Macromedia
[01/02/2009|21:33] C:\DOCUME~1\Malice\APPLIC~1\Microsoft
[30/10/2007|02:17] C:\DOCUME~1\Malice\APPLIC~1\MSN6
[23/03/2008|20:46] C:\DOCUME~1\Malice\APPLIC~1\PlayFirst
[25/01/2005|23:11] C:\DOCUME~1\Malice\APPLIC~1\Real
[31/07/2007|20:57] C:\DOCUME~1\Malice\APPLIC~1\Screenshot Sender
[02/01/2008|21:12] C:\DOCUME~1\Malice\APPLIC~1\Sonic
[29/04/2006|18:21] C:\DOCUME~1\Malice\APPLIC~1\Sun
[30/07/2005|00:34] C:\DOCUME~1\Malice\APPLIC~1\Symantec
[04/04/2006|12:00] C:\DOCUME~1\Malice\APPLIC~1\Ulead Systems
[22/02/2009|00:43] C:\DOCUME~1\Malice\APPLIC~1\Windows Live Writer
[14/10/2008|23:02] C:\DOCUME~1\Malice\APPLIC~1\Yahoo!
[17/01/2007|16:08] C:\DOCUME~1\Malice\APPLIC~1\Zylom
[11/03/2008|03:41] C:\DOCUME~1\Michel\APPLIC~1\Adobe
[11/10/2006|18:55] C:\DOCUME~1\Michel\APPLIC~1\AdobeUM
[24/07/2007|05:21] C:\DOCUME~1\Michel\APPLIC~1\AOL
[15/02/2009|18:02] C:\DOCUME~1\Michel\APPLIC~1\Apple Computer
[06/01/2005|17:12] C:\DOCUME~1\Michel\APPLIC~1\ArcSoft
[02/06/2007|04:27] C:\DOCUME~1\Michel\APPLIC~1\BFGTOOLBAR
[23/09/2006|13:50] C:\DOCUME~1\Michel\APPLIC~1\CyberLink
[15/10/2006|04:41] C:\DOCUME~1\Michel\APPLIC~1\DivX
[16/09/2007|12:42] C:\DOCUME~1\Michel\APPLIC~1\Google
[05/06/2006|11:04] C:\DOCUME~1\Michel\APPLIC~1\Help
[17/09/2006|12:34] C:\DOCUME~1\Michel\APPLIC~1\Identities
[17/12/2006|18:10] C:\DOCUME~1\Michel\APPLIC~1\Logitech
[16/09/2007|12:44] C:\DOCUME~1\Michel\APPLIC~1\Macromedia
[05/02/2009|13:53] C:\DOCUME~1\Michel\APPLIC~1\Microsoft
[07/03/2009|09:20] C:\DOCUME~1\Michel\APPLIC~1\MSN6
[04/11/2006|04:41] C:\DOCUME~1\Michel\APPLIC~1\Real
[21/08/2006|18:21] C:\DOCUME~1\Michel\APPLIC~1\Sun
[16/10/2005|12:32] C:\DOCUME~1\Michel\APPLIC~1\Symantec
[13/12/2007|04:05] C:\DOCUME~1\Michel\APPLIC~1\Viewpoint
[01/01/2009|19:09] C:\DOCUME~1\Michel\APPLIC~1\Yahoo!
[19/02/2006|19:49] C:\DOCUME~1\Michel\APPLIC~1\You've Got Pictures Screensaver
[17/09/2006|12:34] C:\DOCUME~1\Michel\APPLIC~1\Zylom
[26/12/2004|02:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[16/03/2005|18:33] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec
[30/11/2008|19:55] C:\DOCUME~1\Winnie\APPLIC~1\Adobe
[02/12/2005|21:25] C:\DOCUME~1\Winnie\APPLIC~1\AdobeUM
[08/09/2007|20:57] C:\DOCUME~1\Winnie\APPLIC~1\Ahead
[09/10/2007|12:06] C:\DOCUME~1\Winnie\APPLIC~1\Anuman Interactive
[24/08/2006|16:59] C:\DOCUME~1\Winnie\APPLIC~1\AOL
[06/01/2005|19:43] C:\DOCUME~1\Winnie\APPLIC~1\ArcSoft
[28/07/2008|16:01] C:\DOCUME~1\Winnie\APPLIC~1\Atari
[30/05/2007|22:08] C:\DOCUME~1\Winnie\APPLIC~1\BFGTOOLBAR
[17/03/2008|01:38] C:\DOCUME~1\Winnie\APPLIC~1\Creative
[30/12/2004|16:02] C:\DOCUME~1\Winnie\APPLIC~1\CyberLink
[26/01/2008|16:47] C:\DOCUME~1\Winnie\APPLIC~1\DAEMON Tools
[06/10/2006|20:57] C:\DOCUME~1\Winnie\APPLIC~1\DivX
[09/10/2005|20:00] C:\DOCUME~1\Winnie\APPLIC~1\Ecran de veille
[12/08/2008|15:50] C:\DOCUME~1\Winnie\APPLIC~1\Gaijin Ent
[05/03/2008|02:30] C:\DOCUME~1\Winnie\APPLIC~1\Gamelab
[13/03/2008|23:57] C:\DOCUME~1\Winnie\APPLIC~1\GetRightToGo
[15/01/2007|20:00] C:\DOCUME~1\Winnie\APPLIC~1\Google
[12/04/2005|22:41] C:\DOCUME~1\Winnie\APPLIC~1\Help
[22/01/2008|17:30] C:\DOCUME~1\Winnie\APPLIC~1\Identities
[29/06/2006|19:05] C:\DOCUME~1\Winnie\APPLIC~1\iScreensaver
[01/10/2006|21:26] C:\DOCUME~1\Winnie\APPLIC~1\iWin
[28/12/2004|21:59] C:\DOCUME~1\Winnie\APPLIC~1\Leadertech
[03/03/2008|18:13] C:\DOCUME~1\Winnie\APPLIC~1\LimeWire
[17/12/2006|18:10] C:\DOCUME~1\Winnie\APPLIC~1\Logitech
[04/07/2007|21:35] C:\DOCUME~1\Winnie\APPLIC~1\Macromedia
[05/01/2009|17:13] C:\DOCUME~1\Winnie\APPLIC~1\Microsoft
[16/01/2006|11:39] C:\DOCUME~1\Winnie\APPLIC~1\MSN6
[17/07/2008|14:56] C:\DOCUME~1\Winnie\APPLIC~1\My Stitch
[26/03/2008|22:36] C:\DOCUME~1\Winnie\APPLIC~1\Oberon Games
[10/08/2008|21:37] C:\DOCUME~1\Winnie\APPLIC~1\PlayFirst
[19/01/2005|21:15] C:\DOCUME~1\Winnie\APPLIC~1\Real
[15/10/2006|20:40] C:\DOCUME~1\Winnie\APPLIC~1\Samsung
[26/09/2008|17:14] C:\DOCUME~1\Winnie\APPLIC~1\Sandlot Games
[26/09/2008|17:13] C:\DOCUME~1\Winnie\APPLIC~1\SecuROM
[28/12/2004|21:59] C:\DOCUME~1\Winnie\APPLIC~1\Sonic
[19/02/2006|16:19] C:\DOCUME~1\Winnie\APPLIC~1\Sun
[19/04/2005|17:29] C:\DOCUME~1\Winnie\APPLIC~1\Symantec
[17/01/2006|22:48] C:\DOCUME~1\Winnie\APPLIC~1\Ulead Systems
[12/12/2007|19:07] C:\DOCUME~1\Winnie\APPLIC~1\Viewpoint
[01/07/2007|19:42] C:\DOCUME~1\Winnie\APPLIC~1\Vso
[13/10/2008|18:23] C:\DOCUME~1\Winnie\APPLIC~1\Yahoo!
[15/01/2007|18:58] C:\DOCUME~1\Winnie\APPLIC~1\You've Got Pictures Screensaver
[22/01/2008|17:30] C:\DOCUME~1\Winnie\APPLIC~1\Zylom
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/04/2009 19:47][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[25/01/2008 14:20][--a------] C:\WINDOWS\tasks\At6.job
[25/03/2009 21:00][--a------] C:\WINDOWS\tasks\At5.job
[25/10/2008 14:00][--a------] C:\WINDOWS\tasks\At4.job
[25/01/2008 14:18][--a------] C:\WINDOWS\tasks\At3.job
[25/03/2009 21:00][--a------] C:\WINDOWS\tasks\At2.job
[25/10/2008 14:00][--a------] C:\WINDOWS\tasks\At1.job
[15/04/2009 20:41][--a------] C:\WINDOWS\tasks\Symantec NetDetect.job
[08/01/2005 21:35][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 3.job
[02/01/2005 00:50][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 2.job
[27/12/2004 00:35][--a------] C:\WINDOWS\tasks\Rappel d'enregistrement 1.job
[15/04/2009 23:37][--ah-----] C:\WINDOWS\tasks\SA.DAT
[30/08/2002 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[12/08/2008|15:46] C:\Program Files\7788xyx
[19/02/2008|22:23] C:\Program Files\A123 AVI WMV ASF MOV MP4 FLV to MPEG Converter
[12/02/2008|14:06] C:\Program Files\Adobe
[03/01/2005|19:16] C:\Program Files\Agfa
[16/10/2005|18:21] C:\Program Files\Ahead
[12/04/2005|17:06] C:\Program Files\AimOne_AlltoMP3
[01/07/2007|19:38] C:\Program Files\Akimania
[26/03/2008|21:55] C:\Program Files\Alawar
[05/01/2006|17:19] C:\Program Files\Alwil Software
[18/10/2008|11:36] C:\Program Files\Anuman Interactive
[01/01/2009|19:12] C:\Program Files\AOL
[01/01/2009|19:08] C:\Program Files\AOL 9.0b
[01/01/2009|19:08] C:\Program Files\AOL Toolbar
[07/02/2009|19:46] C:\Program Files\Apple Software Update
[01/01/2009|19:15] C:\Program Files\ArcSoft
[14/03/2008|00:10] C:\Program Files\Audacity
[29/10/2007|14:46] C:\Program Files\Audible
[12/04/2005|17:20] C:\Program Files\AudioCDMagic
[01/01/2009|19:10] C:\Program Files\AVS4YOU
[31/05/2007|00:45] C:\Program Files\BFG
[23/09/2007|18:11] C:\Program Files\BitTorrent
[07/02/2009|20:56] C:\Program Files\Bonjour
[05/05/2007|21:43] C:\Program Files\Boonty
[27/09/2008|17:16] C:\Program Files\BoontyGames
[30/03/2008|19:03] C:\Program Files\Burger Shop
[26/01/2009|19:28] C:\Program Files\CCleaner
[15/08/2007|10:48] C:\Program Files\CDBurnerXP Pro 3
[03/08/2008|16:01] C:\Program Files\Common Files
[24/03/2008|15:51] C:\Program Files\Creative
[15/04/2007|14:58] C:\Program Files\Creative Installation Information
[26/12/2004|02:27] C:\Program Files\CyberLink
[05/03/2008|13:10] C:\Program Files\Delicious 2 Deluxe
[02/01/2008|21:36] C:\Program Files\Disc2Phone
[13/10/2008|18:21] C:\Program Files\DivX
[27/04/2005|18:02] C:\Program Files\DVD Shrink
[16/12/2008|20:50] C:\Program Files\EA GAMES
[15/04/2009|23:38] C:\Program Files\eMule
[02/09/2007|18:14] C:\Program Files\eMulee
[03/03/2008|18:57] C:\Program Files\eMuleplus
[22/01/2008|15:42] C:\Program Files\eToro
[22/03/2008|22:41] C:\Program Files\Everest Poker
[26/03/2008|20:39] C:\Program Files\Farm Frenzy
[26/03/2008|21:54] C:\Program Files\Fashion Fits
[07/02/2009|19:45] C:\Program Files\Fichiers communs
[30/07/2008|20:59] C:\Program Files\Fish Tycoon
[12/04/2005|22:41] C:\Program Files\FreeRIP2
[10/03/2007|17:54] C:\Program Files\Gamenext
[31/12/2008|18:08] C:\Program Files\Google
[31/07/2008|21:14] C:\Program Files\Gpotato.eu
[17/12/2006|18:12] C:\Program Files\Hamster Blocks
[11/08/2008|01:11] C:\Program Files\Ice Cream Craze
[12/04/2005|18:16] C:\Program Files\Illustrate
[01/01/2009|19:12] C:\Program Files\Imikimi
[17/03/2005|19:28] C:\Program Files\IncrediMail
[26/12/2004|11:07] C:\Program Files\Infogrames
[21/02/2009|17:36] C:\Program Files\InstallShield Installation Information
[27/03/2009|20:28] C:\Program Files\Internet Explorer
[07/02/2009|19:48] C:\Program Files\iPod
[02/02/2005|12:22] C:\Program Files\ISTsvc
[07/02/2009|19:48] C:\Program Files\iTunes
[10/01/2009|14:21] C:\Program Files\Java
[26/12/2004|14:35] C:\Program Files\Labtec
[25/12/2004|18:32] C:\Program Files\Learn2.com
[09/10/2007|12:04] C:\Program Files\LiveCAD
[19/12/2006|15:10] C:\Program Files\Logitech
[12/08/2008|15:30] C:\Program Files\M6 Jeux
[01/01/2009|19:08] C:\Program Files\Maxis
[05/05/2007|21:31] C:\Program Files\Mes Jeux T‚l‚charg‚s
[19/09/2008|15:25] C:\Program Files\Messenger
[07/02/2009|13:31] C:\Program Files\Messenger Plus! Live
[19/08/2007|00:39] C:\Program Files\MessengerPlus! 3
[22/02/2009|00:42] C:\Program Files\Microsoft
[15/04/2009|23:18] C:\Program Files\Microsoft ActiveSync
[09/05/2007|00:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[26/12/2004|02:27] C:\Program Files\microsoft frontpage
[23/10/2007|16:01] C:\Program Files\Microsoft Games
[30/01/2005|18:27] C:\Program Files\microsoft office
[27/02/2009|07:45] C:\Program Files\Microsoft Silverlight
[14/11/2007|15:22] C:\Program Files\Microsoft SQL Server Compact Edition
[27/12/2008|22:16] C:\Program Files\Microsoft Sync Framework
[26/12/2004|02:27] C:\Program Files\Microsoft Visual Studio
[19/09/2008|15:20] C:\Program Files\Movie Maker
[15/04/2007|15:00] C:\Program Files\Mozilla Firefox
[25/08/2005|12:14] C:\Program Files\MP3 Player Utilities
[06/08/2008|14:04] C:\Program Files\MP3 Player Utilities 3.68
[29/03/2008|14:21] C:\Program Files\MP3 Player Utilities 4.18
[02/08/2007|11:08] C:\Program Files\MSN
[21/05/2008|16:48] C:\Program Files\MSN Games
[26/12/2004|02:27] C:\Program Files\MSN Gaming Zone
[18/08/2007|21:48] C:\Program Files\MSN Messenger
[15/08/2007|14:00] C:\Program Files\MSXML 4.0
[23/10/2006|17:25] C:\Program Files\MUSICMATCH
[12/04/2005|22:38] C:\Program Files\MySearch
[26/03/2008|20:39] C:\Program Files\Nanny Mania
[02/02/2005|12:21] C:\Program Files\NavExcel
[05/01/2006|17:31] C:\Program Files\NavExcel Search Toolbar
[19/09/2008|15:14] C:\Program Files\NetMeeting
[05/07/2007|16:51] C:\Program Files\Neuf
[26/12/2004|02:27] C:\Program Files\Nullsoft
[19/09/2008|15:14] C:\Program Files\Outlook Express
[15/12/2005|17:48] C:\Program Files\PAN vision
[01/01/2009|19:12] C:\Program Files\Photo Story 3 for Windows
[01/01/2009|19:12] C:\Program Files\Photo Viewer
[25/02/2009|20:14] C:\Program Files\PhotoFiltre
[30/11/2005|13:17] C:\Program Files\PIXELA
[26/03/2008|19:19] C:\Program Files\PlayFirst
[23/01/2005|22:46] C:\Program Files\Plus!
[07/02/2009|19:47] C:\Program Files\QuickTime
[26/12/2004|02:27] C:\Program Files\Real
[10/12/2006|22:19] C:\Program Files\ReflexiveArcade
[12/12/2006|21:13] C:\Program Files\Samsung
[26/12/2004|02:29] C:\Program Files\Services en ligne
[12/02/2009|16:47] C:\Program Files\Sierra On-Line
[18/01/2007|22:20] C:\Program Files\SnowyLunchRush_at
[26/12/2004|02:27] C:\Program Files\Sonic
[03/08/2008|16:30] C:\Program Files\Sony
[07/03/2006|16:36] C:\Program Files\Sony Corporation
[17/09/2008|09:57] C:\Program Files\Sun
[05/01/2006|17:06] C:\Program Files\Symantec
[26/10/2007|19:23] C:\Program Files\Ubi Soft
[11/02/2008|23:04] C:\Program Files\Ulead Systems
[26/12/2004|02:27] C:\Program Files\Uninstall Information
[06/11/2008|11:11] C:\Program Files\VGA USB Camera
[26/12/2004|02:27] C:\Program Files\Virtual CD v4 SDK
[26/03/2008|20:39] C:\Program Files\Wedding Dash
[22/02/2009|00:41] C:\Program Files\Windows Live
[01/01/2009|19:13] C:\Program Files\Windows Live SkyDrive
[01/01/2009|19:10] C:\Program Files\Windows Live Toolbar
[25/01/2008|14:19] C:\Program Files\Windows Media Connect 2
[19/09/2008|15:14] C:\Program Files\Windows Media Player
[19/09/2008|15:14] C:\Program Files\Windows NT
[15/04/2007|13:37] C:\Program Files\WinRAR
[18/08/2008|20:42] C:\Program Files\WMA-MP3.com
[28/07/2008|20:59] C:\Program Files\World of Warcraft Trial
[26/12/2004|02:27] C:\Program Files\xerox
[01/01/2009|19:10] C:\Program Files\Yahoo!
[01/01/2009|19:08] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[01/01/2009|19:08] C:\Program Files\Fichiers communs\Adobe
[01/01/2009|19:12] C:\Program Files\Fichiers communs\AOL
[25/12/2004|18:32] C:\Program Files\Fichiers communs\aolback
[07/02/2009|19:48] C:\Program Files\Fichiers communs\Apple
[10/09/2008|17:45] C:\Program Files\Fichiers communs\AVSMedia
[08/07/2008|15:12] C:\Program Files\Fichiers communs\Blizzard Entertainment
[10/03/2007|16:43] C:\Program Files\Fichiers communs\BOONTY Shared
[15/04/2007|15:00] C:\Program Files\Fichiers communs\Creative
[26/12/2004|02:28] C:\Program Files\Fichiers communs\Designer
[16/08/2006|19:15] C:\Program Files\Fichiers communs\Digi338
[11/02/2008|22:30] C:\Program Files\Fichiers communs\FotoNation
[03/04/2007|18:52] C:\Program Files\Fichiers communs\InstallShield
[15/01/2006|18:50] C:\Program Files\Fichiers communs\Java
[26/12/2004|14:35] C:\Program Files\Fichiers communs\Logitech
[22/02/2009|00:37] C:\Program Files\Fichiers communs\Microsoft Shared
[26/12/2004|02:27] C:\Program Files\Fichiers communs\MSSoap
[16/08/2006|19:18] C:\Program Files\Fichiers communs\NewSoft
[25/12/2004|18:32] C:\Program Files\Fichiers communs\Nullsoft
[10/08/2008|21:07] C:\Program Files\Fichiers communs\Oberon Media
[10/10/2007|03:04] C:\Program Files\Fichiers communs\ODBC
[26/12/2004|02:27] C:\Program Files\Fichiers communs\Real
[16/04/2007|13:32] C:\Program Files\Fichiers communs\Scanner
[26/12/2004|02:29] C:\Program Files\Fichiers communs\Services
[03/08/2008|16:02] C:\Program Files\Fichiers communs\Sony Shared
[26/12/2004|02:27] C:\Program Files\Fichiers communs\SpeechEngines
[26/12/2004|02:29] C:\Program Files\Fichiers communs\SureThing Shared
[05/12/2008|21:11] C:\Program Files\Fichiers communs\Symantec Shared
[19/09/2008|15:14] C:\Program Files\Fichiers communs\System
[26/12/2004|02:29] C:\Program Files\Fichiers communs\TVNavigTechnologies Shared
[06/04/2007|16:20] C:\Program Files\Fichiers communs\Ulead Systems
[17/12/2008|21:36] C:\Program Files\Fichiers communs\Windows Live
[14/11/2007|15:14] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[26/12/2004|02:27] C:\Program Files\Fichiers communs\xing shared
--------------------\\ Process
( 53 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-16 00:36:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 37
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Malice\Application Data\Microsoft\Office\Fichiers r‚cents\Hospital Tycoon crack NoCD - patch activation Multilanguage garanted by eMule inside.lnk
[F:214][D:27]-> C:\DOCUME~1\Malice\LOCALS~1\Temp
[F:649][D:0]-> C:\DOCUME~1\Malice\Cookies
[F:1592][D:49]-> C:\DOCUME~1\Malice\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 16/04/2009| 0:28 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 16/04/2009| 0:37 - Option : [2]
--------------------\\ Fin du rapport a 0:37:57
Logfile of random's system information tool 1.06 (written by random/random)
Run by Malice at 2009-04-16 00:43:22
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 21 GB (14%) free of 149 GB
Total RAM: 511 MB (23% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:43:34, on 16/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\LocalService\Application Data\Microsoft\zylany.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\AOL\1171204510\ee\AOLSoftware.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Malice\Bureau\RSIT.exe
C:\Program Files\trend micro\Malice.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: My Search BHO - {014da6c1-189f-421a-88cd-07cfe51cff10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {35E78239-811E-4c3f-B37D-F339AC16C2C0} - C:\PROGRA~1\Comet\bin\autosearch.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Helper Class - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - C:\Program Files\NavExcel Search Toolbar\NavExcelBar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {fe6bc4ef-5676-484b-88ae-883323913256} - (no file)
O3 - Toolbar: My &Search Bar - {014da6c9-189f-421a-88cd-07cfe51cff10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1171204510\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [couzoosou] C:\WINDOWS\system32\kycoot.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB5; (R1 1.3); MSN Optimized;FR; .NET CLR 1.1.4322; Creative ZENcast v1.02.10; .NET CLR 2.0.50727; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)" -"https://www.justinnozuka.fr/"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [couzoosou] C:\Documents and Settings\LocalService\Application Data\Microsoft\kycoot.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 4.0\resources\fr-FR\local\search.html
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Zip Backup to CD (aofx8oe3wo) - Unknown owner - C:\Documents and Settings\LocalService\Application Data\Microsoft\zylany.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
Run by Malice at 2009-04-16 00:43:22
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 21 GB (14%) free of 149 GB
Total RAM: 511 MB (23% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:43:34, on 16/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\LocalService\Application Data\Microsoft\zylany.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\AOL\1171204510\ee\AOLSoftware.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Malice\Bureau\RSIT.exe
C:\Program Files\trend micro\Malice.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: My Search BHO - {014da6c1-189f-421a-88cd-07cfe51cff10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {35E78239-811E-4c3f-B37D-F339AC16C2C0} - C:\PROGRA~1\Comet\bin\autosearch.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Helper Class - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - C:\Program Files\NavExcel Search Toolbar\NavExcelBar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {fe6bc4ef-5676-484b-88ae-883323913256} - (no file)
O3 - Toolbar: My &Search Bar - {014da6c9-189f-421a-88cd-07cfe51cff10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1171204510\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [couzoosou] C:\WINDOWS\system32\kycoot.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB5; (R1 1.3); MSN Optimized;FR; .NET CLR 1.1.4322; Creative ZENcast v1.02.10; .NET CLR 2.0.50727; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)" -"https://www.justinnozuka.fr/"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [couzoosou] C:\Documents and Settings\LocalService\Application Data\Microsoft\kycoot.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 4.0\resources\fr-FR\local\search.html
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Zip Backup to CD (aofx8oe3wo) - Unknown owner - C:\Documents and Settings\LocalService\Application Data\Microsoft\zylany.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
Re,
==>>Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.<<===
!! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!
▶ Double-cliques sur l'.exe pour lancer l'installe et laisses toi guider ...
▶ Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .
▶ Choisis l'option 1 ( "recherche") et tapes "entrée" .
▶Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité
de son contenu dans ta prochaine réponse ...
( le rapport est en outre sauvegardé ici -> C:\TB.txt )
Tutoriel Toolbard-S&D
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
==>>Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.<<===
!! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!
▶ Double-cliques sur l'.exe pour lancer l'installe et laisses toi guider ...
▶ Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .
▶ Choisis l'option 1 ( "recherche") et tapes "entrée" .
▶Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité
de son contenu dans ta prochaine réponse ...
( le rapport est en outre sauvegardé ici -> C:\TB.txt )
Tutoriel Toolbard-S&D
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 3000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Malice ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090108-0] 4.8.1296 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:145 Go (Free:20 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 16/04/2009| 0:50 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\IstSvc
C:\Program Files\IstSvc\istsvc.exe
C:\Program Files\MySearch
C:\Program Files\MySearch\bar
C:\Program Files\MySearch\bar\1.bin
C:\Program Files\MySearch\bar\Cache
C:\Program Files\MySearch\bar\History
C:\Program Files\MySearch\bar\1.bin\MYSEARCHPLUGINPROXY.CLASS
C:\Program Files\MySearch\bar\1.bin\PARTNER.BMP
C:\Program Files\MySearch\bar\1.bin\PARTNER.DAT
C:\Program Files\MySearch\bar\1.bin\UNINSTALL.INF
C:\Program Files\MySearch\bar\Cache\00087F2B
C:\Program Files\MySearch\bar\Cache\0031B0B4.bmp
C:\Program Files\MySearch\bar\Cache\0031F2FC.bmp
C:\Program Files\MySearch\bar\Cache\009105AB
C:\Program Files\MySearch\bar\Cache\files.ini
C:\Program Files\MySearch\bar\History\search
C:\Program Files\NavExcel
C:\Program Files\NavExcel\NavHelper
C:\Program Files\NavExcel\NavHelper\v2.0.4d
C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.htm
C:\Program Files\NavExcel\NavHelper\v2.0.4d\v2.0.4d.cab
C:\Program Files\NavExcel Search Toolbar
C:\Program Files\NavExcel Search Toolbar\settings.dat
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Malice\Application Data\Microsoft\Office\Fichiers r‚cents\Hospital Tycoon crack NoCD - patch activation Multilanguage garanted by eMule inside.lnk
1 - "C:\ToolBar SD\TB_1.txt" - 16/04/2009| 0:53 - Option : [1]
-----------\\ Fin du rapport a 0:53:10,10
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 3000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Malice ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090108-0] 4.8.1296 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:145 Go (Free:20 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 16/04/2009| 0:50 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\IstSvc
C:\Program Files\IstSvc\istsvc.exe
C:\Program Files\MySearch
C:\Program Files\MySearch\bar
C:\Program Files\MySearch\bar\1.bin
C:\Program Files\MySearch\bar\Cache
C:\Program Files\MySearch\bar\History
C:\Program Files\MySearch\bar\1.bin\MYSEARCHPLUGINPROXY.CLASS
C:\Program Files\MySearch\bar\1.bin\PARTNER.BMP
C:\Program Files\MySearch\bar\1.bin\PARTNER.DAT
C:\Program Files\MySearch\bar\1.bin\UNINSTALL.INF
C:\Program Files\MySearch\bar\Cache\00087F2B
C:\Program Files\MySearch\bar\Cache\0031B0B4.bmp
C:\Program Files\MySearch\bar\Cache\0031F2FC.bmp
C:\Program Files\MySearch\bar\Cache\009105AB
C:\Program Files\MySearch\bar\Cache\files.ini
C:\Program Files\MySearch\bar\History\search
C:\Program Files\NavExcel
C:\Program Files\NavExcel\NavHelper
C:\Program Files\NavExcel\NavHelper\v2.0.4d
C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.htm
C:\Program Files\NavExcel\NavHelper\v2.0.4d\v2.0.4d.cab
C:\Program Files\NavExcel Search Toolbar
C:\Program Files\NavExcel Search Toolbar\settings.dat
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Malice\Application Data\Microsoft\Office\Fichiers r‚cents\Hospital Tycoon crack NoCD - patch activation Multilanguage garanted by eMule inside.lnk
1 - "C:\ToolBar SD\TB_1.txt" - 16/04/2009| 0:53 - Option : [1]
-----------\\ Fin du rapport a 0:53:10,10
Re,
▶ Nettoyage avec ToolBar S&D :
!! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!
▶Relances Toolbar-S&D en double-cliquant sur le raccourci.
▶ Tapes sur l'option 2 ( "nettoyage" ) puis tapes sur "Entrée".
Note : Ne touches à rien lors de la suppression !!
▶ Un rapport sera généré à la fin du processus : postes son contenu dans ta prochaine réponse
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
▶ Nettoyage avec ToolBar S&D :
!! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!
▶Relances Toolbar-S&D en double-cliquant sur le raccourci.
▶ Tapes sur l'option 2 ( "nettoyage" ) puis tapes sur "Entrée".
Note : Ne touches à rien lors de la suppression !!
▶ Un rapport sera généré à la fin du processus : postes son contenu dans ta prochaine réponse
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 3000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Malice ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090108-0] 4.8.1296 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:145 Go (Free:20 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 16/04/2009| 0:55 )
-----------\\ SUPPRESSION
Supprime! - C:\Program Files\IstSvc\istsvc.exe
Supprime! - C:\Program Files\MySearch\bar
Supprime! - C:\Program Files\NavExcel\NavHelper
Supprime! - C:\Program Files\NavExcel Search Toolbar\settings.dat
Supprime! - C:\Program Files\IstSvc
Supprime! - C:\Program Files\MySearch
Supprime! - C:\Program Files\NavExcel
Supprime! - C:\Program Files\NavExcel Search Toolbar
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Malice\Application Data\Microsoft\Office\Fichiers r‚cents\Hospital Tycoon crack NoCD - patch activation Multilanguage garanted by eMule inside.lnk
1 - "C:\ToolBar SD\TB_1.txt" - 16/04/2009| 0:53 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 16/04/2009| 0:57 - Option : [2]
-----------\\ Fin du rapport a 0:57:00,07
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 3000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Malice ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090108-0] 4.8.1296 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:145 Go (Free:20 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 16/04/2009| 0:55 )
-----------\\ SUPPRESSION
Supprime! - C:\Program Files\IstSvc\istsvc.exe
Supprime! - C:\Program Files\MySearch\bar
Supprime! - C:\Program Files\NavExcel\NavHelper
Supprime! - C:\Program Files\NavExcel Search Toolbar\settings.dat
Supprime! - C:\Program Files\IstSvc
Supprime! - C:\Program Files\MySearch
Supprime! - C:\Program Files\NavExcel
Supprime! - C:\Program Files\NavExcel Search Toolbar
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Malice\Application Data\Microsoft\Office\Fichiers r‚cents\Hospital Tycoon crack NoCD - patch activation Multilanguage garanted by eMule inside.lnk
1 - "C:\ToolBar SD\TB_1.txt" - 16/04/2009| 0:53 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 16/04/2009| 0:57 - Option : [2]
-----------\\ Fin du rapport a 0:57:00,07
Re,
Rends toi sur ce site :
https://www.virustotal.com/gui/
Clique sur parcourir et cherche ce fichier : C:\WINDOWS\system32\kycoot.exe
Clique sur Send File.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
Copie le dans ta réponse.
Rends toi sur ce site :
https://www.virustotal.com/gui/
Clique sur parcourir et cherche ce fichier : C:\WINDOWS\system32\kycoot.exe
Clique sur Send File.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
Copie le dans ta réponse.
Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.101 2009.04.15 -
AhnLab-V3 5.0.0.2 2009.04.15 -
AntiVir 7.9.0.143 2009.04.15 TR/Crypt.XPACK.Gen
Antiy-AVL 2.0.3.1 2009.04.15 -
Authentium 5.1.2.4 2009.04.16 -
Avast 4.8.1335.0 2009.04.15 -
AVG 8.5.0.287 2009.04.16 -
BitDefender 7.2 2009.04.16 -
CAT-QuickHeal 10.00 2009.04.15 -
ClamAV 0.94.1 2009.04.15 -
Comodo 1115 2009.04.15 -
DrWeb 4.44.0.09170 2009.04.15 -
eSafe 7.0.17.0 2009.04.13 -
eTrust-Vet 31.6.6455 2009.04.14 -
F-Prot 4.4.4.56 2009.04.15 -
Fortinet 3.117.0.0 2009.04.15 -
GData 19 2009.04.16 -
Ikarus T3.1.1.49.0 2009.04.15 -
K7AntiVirus 7.10.704 2009.04.15 -
Kaspersky 7.0.0.125 2009.04.16 -
McAfee 5585 2009.04.15 -
McAfee+Artemis 5585 2009.04.15 -
McAfee-GW-Edition 6.7.6 2009.04.15 Trojan.Crypt.XPACK.Gen
Microsoft 1.4502 2009.04.15 -
NOD32 4011 2009.04.15 -
Norman 6.00.06 2009.04.15 -
nProtect 2009.1.8.0 2009.04.15 -
Panda 10.0.0.14 2009.04.15 -
PCTools 4.4.2.0 2009.04.15 -
Prevx1 V2 2009.04.16 Low Risk Adware
Rising 21.25.24.00 2009.04.15 -
Sophos 4.40.0 2009.04.15 -
Sunbelt 3.2.1858.2 2009.04.15 -
Symantec 1.4.4.12 2009.04.15 -
TheHacker 6.3.4.0.309 2009.04.15 -
TrendMicro 8.700.0.1004 2009.04.15 -
VBA32 3.12.10.2 2009.04.12 -
ViRobot 2009.4.15.1694 2009.04.15 -
VirusBuster 4.6.5.0 2009.04.15 -
Information additionnelle
File size: 285184 bytes
MD5...: cef89d9e97afa7ac44326de704333300
SHA1..: da31973850f40ff9d67ebf2b6b063baa75f59a44
SHA256: ef7b510a983e1bcdb8bde89c2b9335a96772ca44d69926ca2f83dbb70d022062
SHA512: 07e82717b7647d3044a5fd99d01d84b2a7d6d201541ab3e302172d4650867820
2a53e6e481174c2a9229559c49e7db6e1dcd736da2d5bf23da20afaedb0fd06e
ssdeep: 6144:w3Fnrgr+QAki/nEYUMFfza69QXI7VTiAg/ExUY2bTof0Suv7Xr:w3Fnrgro
NPERM5za69EqBiP/EwvM3uvn
PEiD..: -
TrID..: File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x45ca5
timedatestamp.....: 0x49da9934 (Tue Apr 07 00:07:16 2009)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x45082 0x45200 6.83 e8e839147a848668dcc0e3c960599056
.rdata 0x47000 0x164 0x200 3.57 dac41d8d355d8f97e88ca97b20cf63e6
.data 0x48000 0x446 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0x49000 0x10 0x200 0.00 bf619eac0cdf3f68d496ea9344137e8b
( 2 imports )
> kernel32.dll: CreateThread, GetStartupInfoA, LoadLibraryA, RaiseException, SetEvent, Sleep, lstrcpyA
> user32.dll: MessageBeep, MessageBoxW, RemoveMenu, EnumDisplaySettingsA
( 0 exports )
RDS...: NSRL Reference Data Set
-
Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=2C3CFF03001C797C5AFD04ADF8D076007E26C2E5' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=2C3CFF03001C797C5AFD04ADF8D076007E26C2E5</a>
a-squared 4.0.0.101 2009.04.15 -
AhnLab-V3 5.0.0.2 2009.04.15 -
AntiVir 7.9.0.143 2009.04.15 TR/Crypt.XPACK.Gen
Antiy-AVL 2.0.3.1 2009.04.15 -
Authentium 5.1.2.4 2009.04.16 -
Avast 4.8.1335.0 2009.04.15 -
AVG 8.5.0.287 2009.04.16 -
BitDefender 7.2 2009.04.16 -
CAT-QuickHeal 10.00 2009.04.15 -
ClamAV 0.94.1 2009.04.15 -
Comodo 1115 2009.04.15 -
DrWeb 4.44.0.09170 2009.04.15 -
eSafe 7.0.17.0 2009.04.13 -
eTrust-Vet 31.6.6455 2009.04.14 -
F-Prot 4.4.4.56 2009.04.15 -
Fortinet 3.117.0.0 2009.04.15 -
GData 19 2009.04.16 -
Ikarus T3.1.1.49.0 2009.04.15 -
K7AntiVirus 7.10.704 2009.04.15 -
Kaspersky 7.0.0.125 2009.04.16 -
McAfee 5585 2009.04.15 -
McAfee+Artemis 5585 2009.04.15 -
McAfee-GW-Edition 6.7.6 2009.04.15 Trojan.Crypt.XPACK.Gen
Microsoft 1.4502 2009.04.15 -
NOD32 4011 2009.04.15 -
Norman 6.00.06 2009.04.15 -
nProtect 2009.1.8.0 2009.04.15 -
Panda 10.0.0.14 2009.04.15 -
PCTools 4.4.2.0 2009.04.15 -
Prevx1 V2 2009.04.16 Low Risk Adware
Rising 21.25.24.00 2009.04.15 -
Sophos 4.40.0 2009.04.15 -
Sunbelt 3.2.1858.2 2009.04.15 -
Symantec 1.4.4.12 2009.04.15 -
TheHacker 6.3.4.0.309 2009.04.15 -
TrendMicro 8.700.0.1004 2009.04.15 -
VBA32 3.12.10.2 2009.04.12 -
ViRobot 2009.4.15.1694 2009.04.15 -
VirusBuster 4.6.5.0 2009.04.15 -
Information additionnelle
File size: 285184 bytes
MD5...: cef89d9e97afa7ac44326de704333300
SHA1..: da31973850f40ff9d67ebf2b6b063baa75f59a44
SHA256: ef7b510a983e1bcdb8bde89c2b9335a96772ca44d69926ca2f83dbb70d022062
SHA512: 07e82717b7647d3044a5fd99d01d84b2a7d6d201541ab3e302172d4650867820
2a53e6e481174c2a9229559c49e7db6e1dcd736da2d5bf23da20afaedb0fd06e
ssdeep: 6144:w3Fnrgr+QAki/nEYUMFfza69QXI7VTiAg/ExUY2bTof0Suv7Xr:w3Fnrgro
NPERM5za69EqBiP/EwvM3uvn
PEiD..: -
TrID..: File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x45ca5
timedatestamp.....: 0x49da9934 (Tue Apr 07 00:07:16 2009)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x45082 0x45200 6.83 e8e839147a848668dcc0e3c960599056
.rdata 0x47000 0x164 0x200 3.57 dac41d8d355d8f97e88ca97b20cf63e6
.data 0x48000 0x446 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0x49000 0x10 0x200 0.00 bf619eac0cdf3f68d496ea9344137e8b
( 2 imports )
> kernel32.dll: CreateThread, GetStartupInfoA, LoadLibraryA, RaiseException, SetEvent, Sleep, lstrcpyA
> user32.dll: MessageBeep, MessageBoxW, RemoveMenu, EnumDisplaySettingsA
( 0 exports )
RDS...: NSRL Reference Data Set
-
Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=2C3CFF03001C797C5AFD04ADF8D076007E26C2E5' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=2C3CFF03001C797C5AFD04ADF8D076007E26C2E5</a>
Re,
OKI pou VT.
merci.....
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant en gras ci-dessous :
:processes
explorer.exe
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=-
"VCSPlayer"=-
"CleanEasyImg"=-
"HostManager"=
"iTunesHelper"=-
"couzoosou"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"=-
"BitTorrent"=-
:Files
C:\Windows\At*.job
c:\documents and settings\localservice\application data\microsoft\kycoot.exe
:commands
[emptytemp]
[purity]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
OKI pou VT.
merci.....
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant en gras ci-dessous :
:processes
explorer.exe
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=-
"VCSPlayer"=-
"CleanEasyImg"=-
"HostManager"=
"iTunesHelper"=-
"couzoosou"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"=-
"BitTorrent"=-
:Files
C:\Windows\At*.job
c:\documents and settings\localservice\application data\microsoft\kycoot.exe
:commands
[emptytemp]
[purity]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\VCSPlayer deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CleanEasyImg deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\"HostManager"| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\couzoosou deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Sonic RecordNow! deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\BitTorrent deleted successfully.
========== FILES ==========
File/Folder C:\Windows\At*.job not found.
c:\documents and settings\localservice\application data\microsoft\kycoot.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Malice\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Malice\LOCALS~1\Temp\~DF2112.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\RGIALWGW\affich-12022236-virus-besoin-d-aide-pour-hijackthis[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\10[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\home[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\redirectiframe[1].html scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\6O80MDSC\history_manager[2].html scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\1DZ4W66X\4b588ba3f49a3aa7be9e2778737b12cf[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_61c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04162009_011128
Files moved on Reboot...
C:\DOCUME~1\Malice\LOCALS~1\Temp\WCESLog.log moved successfully.
C:\DOCUME~1\Malice\LOCALS~1\Temp\~DF2112.tmp moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\RGIALWGW\affich-12022236-virus-besoin-d-aide-pour-hijackthis[1].htm moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\10[2].htm moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\home[1].htm moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\redirectiframe[1].html moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\6O80MDSC\history_manager[2].html moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\1DZ4W66X\4b588ba3f49a3aa7be9e2778737b12cf[1].htm moved successfully.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_61c.dat moved successfully.
Process explorer.exe killed successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\VCSPlayer deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CleanEasyImg deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\"HostManager"| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\couzoosou deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Sonic RecordNow! deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\BitTorrent deleted successfully.
========== FILES ==========
File/Folder C:\Windows\At*.job not found.
c:\documents and settings\localservice\application data\microsoft\kycoot.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Malice\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Malice\LOCALS~1\Temp\~DF2112.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\RGIALWGW\affich-12022236-virus-besoin-d-aide-pour-hijackthis[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\10[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\home[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\redirectiframe[1].html scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\6O80MDSC\history_manager[2].html scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\1DZ4W66X\4b588ba3f49a3aa7be9e2778737b12cf[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_61c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04162009_011128
Files moved on Reboot...
C:\DOCUME~1\Malice\LOCALS~1\Temp\WCESLog.log moved successfully.
C:\DOCUME~1\Malice\LOCALS~1\Temp\~DF2112.tmp moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\RGIALWGW\affich-12022236-virus-besoin-d-aide-pour-hijackthis[1].htm moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\10[2].htm moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\home[1].htm moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\9182SGLQ\redirectiframe[1].html moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\6O80MDSC\history_manager[2].html moved successfully.
C:\Documents and Settings\Malice\Local Settings\Temporary Internet Files\Content.IE5\1DZ4W66X\4b588ba3f49a3aa7be9e2778737b12cf[1].htm moved successfully.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_61c.dat moved successfully.