Analyse Malwarebytes' Anti-Malware (MBAM)
Fermé
miosotis
-
26 juin 2009 à 09:52
kevin05 Messages postés 3636 Date d'inscription samedi 29 novembre 2008 Statut Contributeur sécurité Dernière intervention 13 mai 2010 - 2 juil. 2009 à 23:14
kevin05 Messages postés 3636 Date d'inscription samedi 29 novembre 2008 Statut Contributeur sécurité Dernière intervention 13 mai 2010 - 2 juil. 2009 à 23:14
A voir également:
- Analyse Malwarebytes' Anti-Malware (MBAM)
- Malwarebytes anti malware - Télécharger - Antivirus & Antimalwares
- Analyse disque dur - Télécharger - Informations & Diagnostic
- Analyse performance pc - Guide
- Roguekiller anti-malware - Télécharger - Antivirus & Antimalwares
- Malwarebytes adwcleaner - Télécharger - Antivirus & Antimalwares
43 réponses
kevin05
Messages postés
3636
Date d'inscription
samedi 29 novembre 2008
Statut
Contributeur sécurité
Dernière intervention
13 mai 2010
147
26 juin 2009 à 11:10
26 juin 2009 à 11:10
Salut
Moi je propose ceci :
? Télécharge Toolbar-S&D ( Merci à Eric_71, Angel Dark, Sham_Rock et XmichouX ) sur ton Bureau
? Lance l'installation du programme en exécutant le fichier téléchargé.
? Double-clique maintenant sur le raccourci de Toolbar-S&D.
? Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
? Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
? Poste le rapport généré. (C:\TB.txt)
Tuto
Moi je propose ceci :
? Télécharge Toolbar-S&D ( Merci à Eric_71, Angel Dark, Sham_Rock et XmichouX ) sur ton Bureau
? Lance l'installation du programme en exécutant le fichier téléchargé.
? Double-clique maintenant sur le raccourci de Toolbar-S&D.
? Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
? Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
? Poste le rapport généré. (C:\TB.txt)
Tuto
kevin05
Messages postés
3636
Date d'inscription
samedi 29 novembre 2008
Statut
Contributeur sécurité
Dernière intervention
13 mai 2010
147
26 juin 2009 à 11:55
26 juin 2009 à 11:55
Lance Toolbars S&D
Cette infection n'est pas du ressort de l'AV
Cette infection n'est pas du ressort de l'AV
boogieman83
Messages postés
395
Date d'inscription
jeudi 14 mai 2009
Statut
Membre
Dernière intervention
10 mai 2012
94
26 juin 2009 à 11:00
26 juin 2009 à 11:00
salut
c'est pas possible d'avoir autant de fichiers infectés
as tu un antivirus ? et lequel
je te propose une analyse en ligne avec bitdefender
il va nettoyer ton pc ensuite tu refais un scan avec malwaerebytes et tu postes le rapport
http://www.bitdefender.fr/scan_fr/scan8/ie.html
c'est pas possible d'avoir autant de fichiers infectés
as tu un antivirus ? et lequel
je te propose une analyse en ligne avec bitdefender
il va nettoyer ton pc ensuite tu refais un scan avec malwaerebytes et tu postes le rapport
http://www.bitdefender.fr/scan_fr/scan8/ie.html
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Merci à vous deux, j'ai Avira antivir Personnal comme antivirus; il est gratuit, mais on m'avait dit qu'il est efficace. Moi je veux bien télécharger Bitdefender, mais je crois qu'il ne faut pas avoir plusieurs antivirus et de plus je ne veux mon disque dur est déjà plein au 3/4. Pensez vous que je dois désintaller l'actuel pour Bitdefender?
J'attends votre réponse avant d'opter pour ta solution Kévin; pour le moment j'ai lancé avira... on verra le résultat dans quelques heures je pense.
Encore merci
J'attends votre réponse avant d'opter pour ta solution Kévin; pour le moment j'ai lancé avira... on verra le résultat dans quelques heures je pense.
Encore merci
Voici le rapport:
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.00GHz )
BIOS : Version 1.00
USER : KS ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:55 Go (Free:17 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 26/06/2009|12:13 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\KaZaA
C:\Program Files\KaZaA\BGP2P
C:\Program Files\KaZaA\Db
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA\BGP2P\bdupd.dll
C:\Program Files\KaZaA\BGP2P\plugins
C:\Program Files\KaZaA\BGP2P\plugins.htm
C:\Program Files\KaZaA\BGP2P\versions.dat
C:\Program Files\KaZaA\BGP2P\plugins\ace.xmd
C:\Program Files\KaZaA\BGP2P\plugins\adsntfs.xmd
C:\Program Files\KaZaA\BGP2P\plugins\alz.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arj.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bach.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bzip2.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cab.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.rvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_dll.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_emu.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_vfs.cvd
C:\Program Files\KaZaA\BGP2P\plugins\chm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cpio.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cran.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cran.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cran.xmd
C:\Program Files\KaZaA\BGP2P\plugins\dbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\docfile.xmd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.cvd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.ivd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.xmd
C:\Program Files\KaZaA\BGP2P\plugins\epoc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\e_spyw.ivd
C:\Program Files\KaZaA\BGP2P\plugins\gzip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hlp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.cvd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hqx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\html.xmd
C:\Program Files\KaZaA\BGP2P\plugins\imp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\inno.xmd
C:\Program Files\KaZaA\BGP2P\plugins\instyler.xmd
C:\Program Files\KaZaA\BGP2P\plugins\iso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\java.cvd
C:\Program Files\KaZaA\BGP2P\plugins\java.xmd
C:\Program Files\KaZaA\BGP2P\plugins\jpeg.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lnk.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbox.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.ivd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_w95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_x95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_xf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mime.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\na.cvd
C:\Program Files\KaZaA\BGP2P\plugins\na.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nsis.xmd
C:\Program Files\KaZaA\BGP2P\plugins\objd.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pdf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pst.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\regscan.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rpm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rtf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rup.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rup.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.cvd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.ivd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sfx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\swf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\td0.xmd
C:\Program Files\KaZaA\BGP2P\plugins\thebat.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tnef.xmd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.cvd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.ivd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.xmd
C:\Program Files\KaZaA\BGP2P\plugins\update.txt
C:\Program Files\KaZaA\BGP2P\plugins\uudecode.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ve.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ve.ivd
C:\Program Files\KaZaA\BGP2P\plugins\ve.xmd
C:\Program Files\KaZaA\BGP2P\plugins\vedata.cvd
C:\Program Files\KaZaA\BGP2P\plugins\viza.xmd
C:\Program Files\KaZaA\BGP2P\plugins\wise.xmd
C:\Program Files\KaZaA\BGP2P\plugins\xishield.xmd
C:\Program Files\KaZaA\BGP2P\plugins\z.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zoo.xmd
C:\Program Files\KaZaA\Db\ctx4-060124.cab
C:\Program Files\KaZaA\Db\data1024.dbb
C:\Program Files\KaZaA\Db\data256.dbb
C:\Program Files\KaZaA\Db\k7tqkgkk_tssv125.dat
C:\Program Files\KaZaA\Db\np.tmp
C:\Program Files\KaZaA\Db\ova4-060412.cab
C:\Program Files\KaZaA\Db\tsi4-060404a.cab
C:\Program Files\KaZaA\Db\tsi4-060404b.cab
C:\Program Files\KaZaA\Db\tss4.cab
C:\Program Files\Need2Find
C:\Program Files\Need2Find\bar
C:\Program Files\Need2Find\bar\1.bin
C:\Program Files\Need2Find\bar\Cache
C:\Program Files\Need2Find\bar\History
C:\Program Files\Need2Find\bar\Settings
C:\Program Files\Need2Find\bar\1.bin\N2FFXTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\N2NTSTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\PARTNER.DAT
C:\Program Files\Need2Find\bar\Cache\0252BDD8
C:\Program Files\Need2Find\bar\Cache\0254C735
C:\Program Files\Need2Find\bar\Cache\files.ini
C:\Program Files\Need2Find\bar\History\search
C:\Program Files\Need2Find\bar\Settings\prevcfg.htm
C:\DOCUME~1\AS\APPLIC~1\ShopperReports
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232420.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232481.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156233430.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234704.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234765.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234826.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234891.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234952.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235013.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235093.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235154.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156237582.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156341467.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156216961.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156217024.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156267763.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318114.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318178.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318239.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318300.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318361.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156319047.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Application Data
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748521.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748790.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748852.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748914.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748975.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155751143.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\Program Files\ShopperReports
C:\Program Files\ShopperReports\Bin
C:\Program Files\ShopperReports\cs
C:\Program Files\ShopperReports\Bin\2.0.0
C:\Program Files\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\MENUDM~1\PROGRA~1\WhenUSearch
C:\WINDOWS\Fonts\acrsec.fon
-----------\\ Extensions
(AS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(KS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page"="http://www.plusnetwork.com"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Page_URL"="http://home.neuf.fr"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
[b]==> EGDACCESS <==/b
C:\WINDOWS\system32\22389_up.exe
C:\WINDOWS\system32\27806_up.exe
[b]==> SASSER <==/b
--------------------\\ ROGUES ..
C:\PROGRA~1\SpamBlockerUtility_Icons
1 - "C:\ToolBar SD\TB_1.txt" - 26/06/2009|12:22 - Option : [1]
-----------\\ Fin du rapport a 12:22:31,42
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.00GHz )
BIOS : Version 1.00
USER : KS ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:55 Go (Free:17 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 26/06/2009|12:13 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\KaZaA
C:\Program Files\KaZaA\BGP2P
C:\Program Files\KaZaA\Db
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA\BGP2P\bdupd.dll
C:\Program Files\KaZaA\BGP2P\plugins
C:\Program Files\KaZaA\BGP2P\plugins.htm
C:\Program Files\KaZaA\BGP2P\versions.dat
C:\Program Files\KaZaA\BGP2P\plugins\ace.xmd
C:\Program Files\KaZaA\BGP2P\plugins\adsntfs.xmd
C:\Program Files\KaZaA\BGP2P\plugins\alz.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arj.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bach.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bzip2.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cab.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.rvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_dll.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_emu.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_vfs.cvd
C:\Program Files\KaZaA\BGP2P\plugins\chm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cpio.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cran.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cran.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cran.xmd
C:\Program Files\KaZaA\BGP2P\plugins\dbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\docfile.xmd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.cvd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.ivd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.xmd
C:\Program Files\KaZaA\BGP2P\plugins\epoc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\e_spyw.ivd
C:\Program Files\KaZaA\BGP2P\plugins\gzip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hlp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.cvd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hqx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\html.xmd
C:\Program Files\KaZaA\BGP2P\plugins\imp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\inno.xmd
C:\Program Files\KaZaA\BGP2P\plugins\instyler.xmd
C:\Program Files\KaZaA\BGP2P\plugins\iso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\java.cvd
C:\Program Files\KaZaA\BGP2P\plugins\java.xmd
C:\Program Files\KaZaA\BGP2P\plugins\jpeg.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lnk.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbox.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.ivd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_w95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_x95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_xf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mime.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\na.cvd
C:\Program Files\KaZaA\BGP2P\plugins\na.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nsis.xmd
C:\Program Files\KaZaA\BGP2P\plugins\objd.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pdf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pst.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\regscan.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rpm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rtf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rup.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rup.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.cvd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.ivd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sfx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\swf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\td0.xmd
C:\Program Files\KaZaA\BGP2P\plugins\thebat.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tnef.xmd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.cvd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.ivd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.xmd
C:\Program Files\KaZaA\BGP2P\plugins\update.txt
C:\Program Files\KaZaA\BGP2P\plugins\uudecode.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ve.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ve.ivd
C:\Program Files\KaZaA\BGP2P\plugins\ve.xmd
C:\Program Files\KaZaA\BGP2P\plugins\vedata.cvd
C:\Program Files\KaZaA\BGP2P\plugins\viza.xmd
C:\Program Files\KaZaA\BGP2P\plugins\wise.xmd
C:\Program Files\KaZaA\BGP2P\plugins\xishield.xmd
C:\Program Files\KaZaA\BGP2P\plugins\z.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zoo.xmd
C:\Program Files\KaZaA\Db\ctx4-060124.cab
C:\Program Files\KaZaA\Db\data1024.dbb
C:\Program Files\KaZaA\Db\data256.dbb
C:\Program Files\KaZaA\Db\k7tqkgkk_tssv125.dat
C:\Program Files\KaZaA\Db\np.tmp
C:\Program Files\KaZaA\Db\ova4-060412.cab
C:\Program Files\KaZaA\Db\tsi4-060404a.cab
C:\Program Files\KaZaA\Db\tsi4-060404b.cab
C:\Program Files\KaZaA\Db\tss4.cab
C:\Program Files\Need2Find
C:\Program Files\Need2Find\bar
C:\Program Files\Need2Find\bar\1.bin
C:\Program Files\Need2Find\bar\Cache
C:\Program Files\Need2Find\bar\History
C:\Program Files\Need2Find\bar\Settings
C:\Program Files\Need2Find\bar\1.bin\N2FFXTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\N2NTSTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\PARTNER.DAT
C:\Program Files\Need2Find\bar\Cache\0252BDD8
C:\Program Files\Need2Find\bar\Cache\0254C735
C:\Program Files\Need2Find\bar\Cache\files.ini
C:\Program Files\Need2Find\bar\History\search
C:\Program Files\Need2Find\bar\Settings\prevcfg.htm
C:\DOCUME~1\AS\APPLIC~1\ShopperReports
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232420.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232481.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156233430.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234704.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234765.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234826.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234891.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234952.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235013.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235093.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235154.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156237582.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156341467.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156216961.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156217024.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156267763.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318114.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318178.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318239.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318300.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318361.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156319047.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Application Data
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748521.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748790.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748852.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748914.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748975.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155751143.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\Program Files\ShopperReports
C:\Program Files\ShopperReports\Bin
C:\Program Files\ShopperReports\cs
C:\Program Files\ShopperReports\Bin\2.0.0
C:\Program Files\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\MENUDM~1\PROGRA~1\WhenUSearch
C:\WINDOWS\Fonts\acrsec.fon
-----------\\ Extensions
(AS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(KS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page"="http://www.plusnetwork.com"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Page_URL"="http://home.neuf.fr"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
[b]==> EGDACCESS <==/b
C:\WINDOWS\system32\22389_up.exe
C:\WINDOWS\system32\27806_up.exe
[b]==> SASSER <==/b
--------------------\\ ROGUES ..
C:\PROGRA~1\SpamBlockerUtility_Icons
1 - "C:\ToolBar SD\TB_1.txt" - 26/06/2009|12:22 - Option : [1]
-----------\\ Fin du rapport a 12:22:31,42
lol, je me suis trompée, voilà le rapport:
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.00GHz )
BIOS : Version 1.00
USER : KS ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:55 Go (Free:17 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 26/06/2009|12:13 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\KaZaA
C:\Program Files\KaZaA\BGP2P
C:\Program Files\KaZaA\Db
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA\BGP2P\bdupd.dll
C:\Program Files\KaZaA\BGP2P\plugins
C:\Program Files\KaZaA\BGP2P\plugins.htm
C:\Program Files\KaZaA\BGP2P\versions.dat
C:\Program Files\KaZaA\BGP2P\plugins\ace.xmd
C:\Program Files\KaZaA\BGP2P\plugins\adsntfs.xmd
C:\Program Files\KaZaA\BGP2P\plugins\alz.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arj.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bach.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bzip2.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cab.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.rvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_dll.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_emu.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_vfs.cvd
C:\Program Files\KaZaA\BGP2P\plugins\chm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cpio.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cran.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cran.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cran.xmd
C:\Program Files\KaZaA\BGP2P\plugins\dbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\docfile.xmd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.cvd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.ivd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.xmd
C:\Program Files\KaZaA\BGP2P\plugins\epoc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\e_spyw.ivd
C:\Program Files\KaZaA\BGP2P\plugins\gzip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hlp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.cvd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hqx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\html.xmd
C:\Program Files\KaZaA\BGP2P\plugins\imp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\inno.xmd
C:\Program Files\KaZaA\BGP2P\plugins\instyler.xmd
C:\Program Files\KaZaA\BGP2P\plugins\iso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\java.cvd
C:\Program Files\KaZaA\BGP2P\plugins\java.xmd
C:\Program Files\KaZaA\BGP2P\plugins\jpeg.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lnk.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbox.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.ivd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_w95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_x95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_xf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mime.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\na.cvd
C:\Program Files\KaZaA\BGP2P\plugins\na.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nsis.xmd
C:\Program Files\KaZaA\BGP2P\plugins\objd.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pdf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pst.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\regscan.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rpm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rtf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rup.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rup.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.cvd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.ivd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sfx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\swf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\td0.xmd
C:\Program Files\KaZaA\BGP2P\plugins\thebat.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tnef.xmd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.cvd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.ivd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.xmd
C:\Program Files\KaZaA\BGP2P\plugins\update.txt
C:\Program Files\KaZaA\BGP2P\plugins\uudecode.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ve.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ve.ivd
C:\Program Files\KaZaA\BGP2P\plugins\ve.xmd
C:\Program Files\KaZaA\BGP2P\plugins\vedata.cvd
C:\Program Files\KaZaA\BGP2P\plugins\viza.xmd
C:\Program Files\KaZaA\BGP2P\plugins\wise.xmd
C:\Program Files\KaZaA\BGP2P\plugins\xishield.xmd
C:\Program Files\KaZaA\BGP2P\plugins\z.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zoo.xmd
C:\Program Files\KaZaA\Db\ctx4-060124.cab
C:\Program Files\KaZaA\Db\data1024.dbb
C:\Program Files\KaZaA\Db\data256.dbb
C:\Program Files\KaZaA\Db\k7tqkgkk_tssv125.dat
C:\Program Files\KaZaA\Db\np.tmp
C:\Program Files\KaZaA\Db\ova4-060412.cab
C:\Program Files\KaZaA\Db\tsi4-060404a.cab
C:\Program Files\KaZaA\Db\tsi4-060404b.cab
C:\Program Files\KaZaA\Db\tss4.cab
C:\Program Files\Need2Find
C:\Program Files\Need2Find\bar
C:\Program Files\Need2Find\bar\1.bin
C:\Program Files\Need2Find\bar\Cache
C:\Program Files\Need2Find\bar\History
C:\Program Files\Need2Find\bar\Settings
C:\Program Files\Need2Find\bar\1.bin\N2FFXTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\N2NTSTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\PARTNER.DAT
C:\Program Files\Need2Find\bar\Cache\0252BDD8
C:\Program Files\Need2Find\bar\Cache\0254C735
C:\Program Files\Need2Find\bar\Cache\files.ini
C:\Program Files\Need2Find\bar\History\search
C:\Program Files\Need2Find\bar\Settings\prevcfg.htm
C:\DOCUME~1\AS\APPLIC~1\ShopperReports
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232420.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232481.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156233430.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234704.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234765.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234826.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234891.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234952.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235013.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235093.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235154.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156237582.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156341467.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156216961.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156217024.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156267763.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318114.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318178.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318239.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318300.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318361.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156319047.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Application Data
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748521.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748790.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748852.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748914.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748975.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155751143.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\Program Files\ShopperReports
C:\Program Files\ShopperReports\Bin
C:\Program Files\ShopperReports\cs
C:\Program Files\ShopperReports\Bin\2.0.0
C:\Program Files\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\MENUDM~1\PROGRA~1\WhenUSearch
C:\WINDOWS\Fonts\acrsec.fon
-----------\\ Extensions
(AS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(KS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page"="http://www.plusnetwork.com"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Page_URL"="http://home.neuf.fr"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
[b]==> EGDACCESS <==/b
C:\WINDOWS\system32\22389_up.exe
C:\WINDOWS\system32\27806_up.exe
[b]==> SASSER <==/b
--------------------\\ ROGUES ..
C:\PROGRA~1\SpamBlockerUtility_Icons
1 - "C:\ToolBar SD\TB_1.txt" - 26/06/2009|12:22 - Option : [1]
-----------\\ Fin du rapport a 12:22:31,42
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.00GHz )
BIOS : Version 1.00
USER : KS ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:55 Go (Free:17 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 26/06/2009|12:13 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\KaZaA
C:\Program Files\KaZaA\BGP2P
C:\Program Files\KaZaA\Db
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA\BGP2P\bdupd.dll
C:\Program Files\KaZaA\BGP2P\plugins
C:\Program Files\KaZaA\BGP2P\plugins.htm
C:\Program Files\KaZaA\BGP2P\versions.dat
C:\Program Files\KaZaA\BGP2P\plugins\ace.xmd
C:\Program Files\KaZaA\BGP2P\plugins\adsntfs.xmd
C:\Program Files\KaZaA\BGP2P\plugins\alz.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arj.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bach.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bzip2.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cab.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.rvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_dll.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_emu.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_vfs.cvd
C:\Program Files\KaZaA\BGP2P\plugins\chm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cpio.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cran.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cran.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cran.xmd
C:\Program Files\KaZaA\BGP2P\plugins\dbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\docfile.xmd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.cvd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.ivd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.xmd
C:\Program Files\KaZaA\BGP2P\plugins\epoc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\e_spyw.ivd
C:\Program Files\KaZaA\BGP2P\plugins\gzip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hlp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.cvd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hqx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\html.xmd
C:\Program Files\KaZaA\BGP2P\plugins\imp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\inno.xmd
C:\Program Files\KaZaA\BGP2P\plugins\instyler.xmd
C:\Program Files\KaZaA\BGP2P\plugins\iso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\java.cvd
C:\Program Files\KaZaA\BGP2P\plugins\java.xmd
C:\Program Files\KaZaA\BGP2P\plugins\jpeg.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lnk.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbox.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.ivd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_w95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_x95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_xf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mime.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\na.cvd
C:\Program Files\KaZaA\BGP2P\plugins\na.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nsis.xmd
C:\Program Files\KaZaA\BGP2P\plugins\objd.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pdf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pst.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\regscan.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rpm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rtf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rup.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rup.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.cvd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.ivd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sfx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\swf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\td0.xmd
C:\Program Files\KaZaA\BGP2P\plugins\thebat.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tnef.xmd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.cvd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.ivd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.xmd
C:\Program Files\KaZaA\BGP2P\plugins\update.txt
C:\Program Files\KaZaA\BGP2P\plugins\uudecode.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ve.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ve.ivd
C:\Program Files\KaZaA\BGP2P\plugins\ve.xmd
C:\Program Files\KaZaA\BGP2P\plugins\vedata.cvd
C:\Program Files\KaZaA\BGP2P\plugins\viza.xmd
C:\Program Files\KaZaA\BGP2P\plugins\wise.xmd
C:\Program Files\KaZaA\BGP2P\plugins\xishield.xmd
C:\Program Files\KaZaA\BGP2P\plugins\z.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zoo.xmd
C:\Program Files\KaZaA\Db\ctx4-060124.cab
C:\Program Files\KaZaA\Db\data1024.dbb
C:\Program Files\KaZaA\Db\data256.dbb
C:\Program Files\KaZaA\Db\k7tqkgkk_tssv125.dat
C:\Program Files\KaZaA\Db\np.tmp
C:\Program Files\KaZaA\Db\ova4-060412.cab
C:\Program Files\KaZaA\Db\tsi4-060404a.cab
C:\Program Files\KaZaA\Db\tsi4-060404b.cab
C:\Program Files\KaZaA\Db\tss4.cab
C:\Program Files\Need2Find
C:\Program Files\Need2Find\bar
C:\Program Files\Need2Find\bar\1.bin
C:\Program Files\Need2Find\bar\Cache
C:\Program Files\Need2Find\bar\History
C:\Program Files\Need2Find\bar\Settings
C:\Program Files\Need2Find\bar\1.bin\N2FFXTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\N2NTSTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\PARTNER.DAT
C:\Program Files\Need2Find\bar\Cache\0252BDD8
C:\Program Files\Need2Find\bar\Cache\0254C735
C:\Program Files\Need2Find\bar\Cache\files.ini
C:\Program Files\Need2Find\bar\History\search
C:\Program Files\Need2Find\bar\Settings\prevcfg.htm
C:\DOCUME~1\AS\APPLIC~1\ShopperReports
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232420.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232481.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156233430.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234704.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234765.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234826.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234891.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234952.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235013.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235093.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235154.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156237582.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156341467.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156216961.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156217024.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156267763.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318114.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318178.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318239.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318300.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318361.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156319047.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Application Data
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748521.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748790.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748852.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748914.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748975.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155751143.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\Program Files\ShopperReports
C:\Program Files\ShopperReports\Bin
C:\Program Files\ShopperReports\cs
C:\Program Files\ShopperReports\Bin\2.0.0
C:\Program Files\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\MENUDM~1\PROGRA~1\WhenUSearch
C:\WINDOWS\Fonts\acrsec.fon
-----------\\ Extensions
(AS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(KS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page"="http://www.plusnetwork.com"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Page_URL"="http://home.neuf.fr"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
[b]==> EGDACCESS <==/b
C:\WINDOWS\system32\22389_up.exe
C:\WINDOWS\system32\27806_up.exe
[b]==> SASSER <==/b
--------------------\\ ROGUES ..
C:\PROGRA~1\SpamBlockerUtility_Icons
1 - "C:\ToolBar SD\TB_1.txt" - 26/06/2009|12:22 - Option : [1]
-----------\\ Fin du rapport a 12:22:31,42
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.00GHz )
BIOS : Version 1.00
USER : KS ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:55 Go (Free:17 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 26/06/2009|12:13 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\KaZaA
C:\Program Files\KaZaA\BGP2P
C:\Program Files\KaZaA\Db
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA\BGP2P\bdupd.dll
C:\Program Files\KaZaA\BGP2P\plugins
C:\Program Files\KaZaA\BGP2P\plugins.htm
C:\Program Files\KaZaA\BGP2P\versions.dat
C:\Program Files\KaZaA\BGP2P\plugins\ace.xmd
C:\Program Files\KaZaA\BGP2P\plugins\adsntfs.xmd
C:\Program Files\KaZaA\BGP2P\plugins\alz.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arj.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bach.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bzip2.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cab.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.rvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_dll.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_emu.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_vfs.cvd
C:\Program Files\KaZaA\BGP2P\plugins\chm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cpio.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cran.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cran.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cran.xmd
C:\Program Files\KaZaA\BGP2P\plugins\dbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\docfile.xmd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.cvd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.ivd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.xmd
C:\Program Files\KaZaA\BGP2P\plugins\epoc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\e_spyw.ivd
C:\Program Files\KaZaA\BGP2P\plugins\gzip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hlp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.cvd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hqx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\html.xmd
C:\Program Files\KaZaA\BGP2P\plugins\imp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\inno.xmd
C:\Program Files\KaZaA\BGP2P\plugins\instyler.xmd
C:\Program Files\KaZaA\BGP2P\plugins\iso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\java.cvd
C:\Program Files\KaZaA\BGP2P\plugins\java.xmd
C:\Program Files\KaZaA\BGP2P\plugins\jpeg.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lnk.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbox.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.ivd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_w95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_x95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_xf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mime.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\na.cvd
C:\Program Files\KaZaA\BGP2P\plugins\na.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nsis.xmd
C:\Program Files\KaZaA\BGP2P\plugins\objd.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pdf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pst.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\regscan.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rpm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rtf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rup.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rup.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.cvd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.ivd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sfx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\swf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\td0.xmd
C:\Program Files\KaZaA\BGP2P\plugins\thebat.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tnef.xmd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.cvd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.ivd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.xmd
C:\Program Files\KaZaA\BGP2P\plugins\update.txt
C:\Program Files\KaZaA\BGP2P\plugins\uudecode.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ve.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ve.ivd
C:\Program Files\KaZaA\BGP2P\plugins\ve.xmd
C:\Program Files\KaZaA\BGP2P\plugins\vedata.cvd
C:\Program Files\KaZaA\BGP2P\plugins\viza.xmd
C:\Program Files\KaZaA\BGP2P\plugins\wise.xmd
C:\Program Files\KaZaA\BGP2P\plugins\xishield.xmd
C:\Program Files\KaZaA\BGP2P\plugins\z.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zoo.xmd
C:\Program Files\KaZaA\Db\ctx4-060124.cab
C:\Program Files\KaZaA\Db\data1024.dbb
C:\Program Files\KaZaA\Db\data256.dbb
C:\Program Files\KaZaA\Db\k7tqkgkk_tssv125.dat
C:\Program Files\KaZaA\Db\np.tmp
C:\Program Files\KaZaA\Db\ova4-060412.cab
C:\Program Files\KaZaA\Db\tsi4-060404a.cab
C:\Program Files\KaZaA\Db\tsi4-060404b.cab
C:\Program Files\KaZaA\Db\tss4.cab
C:\Program Files\Need2Find
C:\Program Files\Need2Find\bar
C:\Program Files\Need2Find\bar\1.bin
C:\Program Files\Need2Find\bar\Cache
C:\Program Files\Need2Find\bar\History
C:\Program Files\Need2Find\bar\Settings
C:\Program Files\Need2Find\bar\1.bin\N2FFXTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\N2NTSTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\PARTNER.DAT
C:\Program Files\Need2Find\bar\Cache\0252BDD8
C:\Program Files\Need2Find\bar\Cache\0254C735
C:\Program Files\Need2Find\bar\Cache\files.ini
C:\Program Files\Need2Find\bar\History\search
C:\Program Files\Need2Find\bar\Settings\prevcfg.htm
C:\DOCUME~1\AS\APPLIC~1\ShopperReports
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232420.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232481.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156233430.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234704.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234765.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234826.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234891.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234952.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235013.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235093.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235154.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156237582.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156341467.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156216961.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156217024.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156267763.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318114.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318178.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318239.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318300.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318361.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156319047.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Application Data
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748521.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748790.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748852.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748914.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748975.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155751143.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\Program Files\ShopperReports
C:\Program Files\ShopperReports\Bin
C:\Program Files\ShopperReports\cs
C:\Program Files\ShopperReports\Bin\2.0.0
C:\Program Files\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\MENUDM~1\PROGRA~1\WhenUSearch
C:\WINDOWS\Fonts\acrsec.fon
-----------\\ Extensions
(AS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(KS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page"="http://www.plusnetwork.com"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Page_URL"="http://home.neuf.fr"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
[b]==> EGDACCESS <==/b
C:\WINDOWS\system32\22389_up.exe
C:\WINDOWS\system32\27806_up.exe
[b]==> SASSER <==/b
--------------------\\ ROGUES ..
C:\PROGRA~1\SpamBlockerUtility_Icons
1 - "C:\ToolBar SD\TB_1.txt" - 26/06/2009|12:22 - Option : [1]
-----------\\ Fin du rapport a 12:22:31,42
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.00GHz )
BIOS : Version 1.00
USER : KS ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:55 Go (Free:17 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 26/06/2009|12:13 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\KaZaA
C:\Program Files\KaZaA\BGP2P
C:\Program Files\KaZaA\Db
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA\BGP2P\bdupd.dll
C:\Program Files\KaZaA\BGP2P\plugins
C:\Program Files\KaZaA\BGP2P\plugins.htm
C:\Program Files\KaZaA\BGP2P\versions.dat
C:\Program Files\KaZaA\BGP2P\plugins\ace.xmd
C:\Program Files\KaZaA\BGP2P\plugins\adsntfs.xmd
C:\Program Files\KaZaA\BGP2P\plugins\alz.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arj.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bach.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bzip2.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cab.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.rvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_dll.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_emu.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_vfs.cvd
C:\Program Files\KaZaA\BGP2P\plugins\chm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cpio.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cran.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cran.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cran.xmd
C:\Program Files\KaZaA\BGP2P\plugins\dbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\docfile.xmd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.cvd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.ivd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.xmd
C:\Program Files\KaZaA\BGP2P\plugins\epoc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\e_spyw.ivd
C:\Program Files\KaZaA\BGP2P\plugins\gzip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hlp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.cvd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hqx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\html.xmd
C:\Program Files\KaZaA\BGP2P\plugins\imp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\inno.xmd
C:\Program Files\KaZaA\BGP2P\plugins\instyler.xmd
C:\Program Files\KaZaA\BGP2P\plugins\iso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\java.cvd
C:\Program Files\KaZaA\BGP2P\plugins\java.xmd
C:\Program Files\KaZaA\BGP2P\plugins\jpeg.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lnk.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbox.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.ivd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_w95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_x95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_xf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mime.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\na.cvd
C:\Program Files\KaZaA\BGP2P\plugins\na.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nsis.xmd
C:\Program Files\KaZaA\BGP2P\plugins\objd.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pdf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pst.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\regscan.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rpm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rtf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rup.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rup.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.cvd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.ivd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sfx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\swf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\td0.xmd
C:\Program Files\KaZaA\BGP2P\plugins\thebat.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tnef.xmd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.cvd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.ivd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.xmd
C:\Program Files\KaZaA\BGP2P\plugins\update.txt
C:\Program Files\KaZaA\BGP2P\plugins\uudecode.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ve.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ve.ivd
C:\Program Files\KaZaA\BGP2P\plugins\ve.xmd
C:\Program Files\KaZaA\BGP2P\plugins\vedata.cvd
C:\Program Files\KaZaA\BGP2P\plugins\viza.xmd
C:\Program Files\KaZaA\BGP2P\plugins\wise.xmd
C:\Program Files\KaZaA\BGP2P\plugins\xishield.xmd
C:\Program Files\KaZaA\BGP2P\plugins\z.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zoo.xmd
C:\Program Files\KaZaA\Db\ctx4-060124.cab
C:\Program Files\KaZaA\Db\data1024.dbb
C:\Program Files\KaZaA\Db\data256.dbb
C:\Program Files\KaZaA\Db\k7tqkgkk_tssv125.dat
C:\Program Files\KaZaA\Db\np.tmp
C:\Program Files\KaZaA\Db\ova4-060412.cab
C:\Program Files\KaZaA\Db\tsi4-060404a.cab
C:\Program Files\KaZaA\Db\tsi4-060404b.cab
C:\Program Files\KaZaA\Db\tss4.cab
C:\Program Files\Need2Find
C:\Program Files\Need2Find\bar
C:\Program Files\Need2Find\bar\1.bin
C:\Program Files\Need2Find\bar\Cache
C:\Program Files\Need2Find\bar\History
C:\Program Files\Need2Find\bar\Settings
C:\Program Files\Need2Find\bar\1.bin\N2FFXTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\N2NTSTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\PARTNER.DAT
C:\Program Files\Need2Find\bar\Cache\0252BDD8
C:\Program Files\Need2Find\bar\Cache\0254C735
C:\Program Files\Need2Find\bar\Cache\files.ini
C:\Program Files\Need2Find\bar\History\search
C:\Program Files\Need2Find\bar\Settings\prevcfg.htm
C:\DOCUME~1\AS\APPLIC~1\ShopperReports
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232420.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232481.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156233430.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234704.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234765.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234826.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234891.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234952.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235013.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235093.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235154.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156237582.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156341467.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156216961.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156217024.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156267763.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318114.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318178.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318239.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318300.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318361.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156319047.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Application Data
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748521.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748790.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748852.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748914.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748975.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155751143.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\Program Files\ShopperReports
C:\Program Files\ShopperReports\Bin
C:\Program Files\ShopperReports\cs
C:\Program Files\ShopperReports\Bin\2.0.0
C:\Program Files\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\MENUDM~1\PROGRA~1\WhenUSearch
C:\WINDOWS\Fonts\acrsec.fon
-----------\\ Extensions
(AS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(KS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page"="http://www.plusnetwork.com"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Page_URL"="http://home.neuf.fr"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
[b]==> EGDACCESS <==/b
C:\WINDOWS\system32\22389_up.exe
C:\WINDOWS\system32\27806_up.exe
[b]==> SASSER <==/b
--------------------\\ ROGUES ..
C:\PROGRA~1\SpamBlockerUtility_Icons
1 - "C:\ToolBar SD\TB_1.txt" - 26/06/2009|12:22 - Option : [1]
-----------\\ Fin du rapport a 12:22:31,42
eh bien je vais creer un nouveau post pour afficher le rapport de l'analyse, merci de continuer à m'aider
kevin05
Messages postés
3636
Date d'inscription
samedi 29 novembre 2008
Statut
Contributeur sécurité
Dernière intervention
13 mai 2010
147
26 juin 2009 à 14:18
26 juin 2009 à 14:18
Vire Kazaa c'est lui même un virus !
? Relance Toolbar-S&D en double-cliquant sur le raccourci.
? Tape sur "2" puis valide en appuyant sur "Entrée".
/!\ Ne ferme pas la fenêtre lors de la suppression !
? Un rapport sera généré, poste son contenu ici.
NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
Et tu as d'autre infectionS :
- Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
- Double-clique sur RSIT.exe afin de lancer le programme.
- A l'écran Disclaimer Choisis "1 months" dans le menu déroulant puis clique sur <continue>.
- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt
Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
? Relance Toolbar-S&D en double-cliquant sur le raccourci.
? Tape sur "2" puis valide en appuyant sur "Entrée".
/!\ Ne ferme pas la fenêtre lors de la suppression !
? Un rapport sera généré, poste son contenu ici.
NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
Et tu as d'autre infectionS :
- Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
- Double-clique sur RSIT.exe afin de lancer le programme.
- A l'écran Disclaimer Choisis "1 months" dans le menu déroulant puis clique sur <continue>.
- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt
Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
Voila le rapport demandé, je continue par le 2ème point que tu m'as dit;
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.00GHz )
BIOS : Version 1.00
USER : KS ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:55 Go (Free:17 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 26/06/2009|17:53 )
-----------\\ SUPPRESSION
Supprime! - C:\Program Files\KaZaA\BGP2P
Supprime! - C:\Program Files\KaZaA\Db
Supprime! - C:\Program Files\KaZaA\My Shared Folder
Supprime! - C:\Program Files\Need2Find\bar
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232420.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232481.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156233430.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234704.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234765.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234826.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234891.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234952.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235013.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235093.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235154.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156237582.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156341467.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156216961.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156217024.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156267763.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318114.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318178.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318239.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318300.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318361.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156319047.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748521.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748790.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748852.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748914.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748975.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155751143.log
Supprime! - C:\Program Files\ShopperReports\Bin
Supprime! - C:\Program Files\ShopperReports\cs
Supprime! - C:\DOCUME~1\KS\MENUDM~1\PROGRA~1\WhenUSearch
Supprime! - C:\WINDOWS\Fonts\acrsec.fon
Supprime! - C:\Program Files\KaZaA
Supprime! - C:\Program Files\Need2Find
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports
Supprime! - C:\Program Files\ShopperReports
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(AS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(KS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page"="http://www.plusnetwork.com"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Page_URL"="http://home.neuf.fr"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
[b]==> EGDACCESS <==/b
C:\WINDOWS\system32\22389_up.exe
C:\WINDOWS\system32\27806_up.exe
[b]==> SASSER <==/b
--------------------\\ ROGUES ..
C:\PROGRA~1\SpamBlockerUtility_Icons
1 - "C:\ToolBar SD\TB_1.txt" - 26/06/2009|12:22 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 26/06/2009|18:06 - Option : [2]
-----------\\ Fin du rapport a 18:06:19,45
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.00GHz )
BIOS : Version 1.00
USER : KS ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:55 Go (Free:17 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 26/06/2009|17:53 )
-----------\\ SUPPRESSION
Supprime! - C:\Program Files\KaZaA\BGP2P
Supprime! - C:\Program Files\KaZaA\Db
Supprime! - C:\Program Files\KaZaA\My Shared Folder
Supprime! - C:\Program Files\Need2Find\bar
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232420.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232481.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156233430.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234704.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234765.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234826.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234891.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234952.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235013.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235093.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235154.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156237582.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156341467.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156216961.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156217024.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156267763.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318114.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318178.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318239.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318300.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318361.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156319047.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748521.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748790.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748852.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748914.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748975.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155751143.log
Supprime! - C:\Program Files\ShopperReports\Bin
Supprime! - C:\Program Files\ShopperReports\cs
Supprime! - C:\DOCUME~1\KS\MENUDM~1\PROGRA~1\WhenUSearch
Supprime! - C:\WINDOWS\Fonts\acrsec.fon
Supprime! - C:\Program Files\KaZaA
Supprime! - C:\Program Files\Need2Find
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports
Supprime! - C:\Program Files\ShopperReports
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(AS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(KS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page"="http://www.plusnetwork.com"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Page_URL"="http://home.neuf.fr"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
[b]==> EGDACCESS <==/b
C:\WINDOWS\system32\22389_up.exe
C:\WINDOWS\system32\27806_up.exe
[b]==> SASSER <==/b
--------------------\\ ROGUES ..
C:\PROGRA~1\SpamBlockerUtility_Icons
1 - "C:\ToolBar SD\TB_1.txt" - 26/06/2009|12:22 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 26/06/2009|18:06 - Option : [2]
-----------\\ Fin du rapport a 18:06:19,45
Supprime! - C:\Program Files\Need2Find\bar
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232420.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232481.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156233430.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234704.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234765.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234826.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234891.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234952.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235013.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235093.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235154.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156237582.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156341467.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156216961.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156217024.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156267763.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318114.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318178.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318239.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318300.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318361.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156319047.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748521.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748790.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748852.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748914.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748975.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155751143.log
Supprime! - C:\Program Files\ShopperReports\Bin
Supprime! - C:\Program Files\ShopperReports\cs
Supprime! - C:\DOCUME~1\KS\MENUDM~1\PROGRA~1\WhenUSearch
Supprime! - C:\WINDOWS\Fonts\acrsec.fon
Supprime! - C:\Program Files\KaZaA
Supprime! - C:\Program Files\Need2Find
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232420.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232481.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156233430.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234704.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234765.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234826.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234891.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234952.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235013.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235093.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235154.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156237582.log
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156341467.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156216961.log
Supprime! - C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156217024.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156267763.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318114.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318178.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318239.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318300.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318361.log
Supprime! - C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156319047.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748521.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748790.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748852.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748914.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748975.log
Supprime! - C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155751143.log
Supprime! - C:\Program Files\ShopperReports\Bin
Supprime! - C:\Program Files\ShopperReports\cs
Supprime! - C:\DOCUME~1\KS\MENUDM~1\PROGRA~1\WhenUSearch
Supprime! - C:\WINDOWS\Fonts\acrsec.fon
Supprime! - C:\Program Files\KaZaA
Supprime! - C:\Program Files\Need2Find
Supprime! - C:\DOCUME~1\AS\APPLIC~1\ShopperReports
Bon voilà j'ai fait l'analyse avec RSIT et je me trouve avec 2 blocs note que je vais sauvegarder; s'il faut te les montrer, dis moi comment je peux faire, ils sont vraiment longs
kevin05
Messages postés
3636
Date d'inscription
samedi 29 novembre 2008
Statut
Contributeur sécurité
Dernière intervention
13 mai 2010
147
26 juin 2009 à 19:07
26 juin 2009 à 19:07
Poste moi juste le LOG.txt
Pas besion de linfo.txt ;)
Pas besion de linfo.txt ;)
Maintenant mon pC va beaucoup mieux pour travailler... Mais il lui faut toujours 1/4 heure pour démarrer, que faire s'il vous plait;
j'ai fait msconfig, tout décoché sauf l'antivirus, et au redémarrage un message me dit que revenir à une configuration normale, tout en étant toujours aussi lonf.
D'autre part, j'ai observé en face de cases que j'ai décochées, des lignes de signes, chinois ...je dirais, ça m'a l'air plutôt louche, qu'en dites vous?
j'ai fait msconfig, tout décoché sauf l'antivirus, et au redémarrage un message me dit que revenir à une configuration normale, tout en étant toujours aussi lonf.
D'autre part, j'ai observé en face de cases que j'ai décochées, des lignes de signes, chinois ...je dirais, ça m'a l'air plutôt louche, qu'en dites vous?
kevin05
Messages postés
3636
Date d'inscription
samedi 29 novembre 2008
Statut
Contributeur sécurité
Dernière intervention
13 mai 2010
147
28 juin 2009 à 19:15
28 juin 2009 à 19:15
Ok refait un analyse MBAM et poste le rapport stp