MljDtqol.dll manquant!

Résolu/Fermé
laromande Messages postés 168 Date d'inscription jeudi 23 octobre 2008 Statut Membre Dernière intervention 29 mai 2011 - 28 déc. 2009 à 13:04
laromande Messages postés 168 Date d'inscription jeudi 23 octobre 2008 Statut Membre Dernière intervention 29 mai 2011 - 28 déc. 2009 à 20:01
Bonjour,
quand mon ordi demare il me dit que les fichiers mljDtqol.dll et hgGwWPHy.dll sont manquants. Je suis allé verifier et oui ils étaient maquants. J'ai cherché sur des banques de fichier en ligne mais j'ai pas trouvé. Quelqun peut m'aider??
Merci d'avance

13 réponses

verni29 Messages postés 6699 Date d'inscription dimanche 6 juillet 2008 Statut Contributeur sécurité Dernière intervention 26 décembre 2016 180
28 déc. 2009 à 13:21
Bonjour,

La présence ( ou non ) de ces deux fichiers est un signe d'une infection Vundo.

Pour plus d'infos :

Télécharge Random's System Information Tool (RSIT) de random/random et enregistre le sur ton Bureau.
http://images.malwareremoval.com/random/RSIT.exe

# Double-clique sur " RSIT.exe " pour le lancer .
( Si sous Vista : Click droit sur le fichier et choisir exécuter en tant qu'administrateur )
# dans la fenêtre qui va s’ouvrir choisis 1 month pour l'option "List files/folders created ...".
# clique ensuite sur " Continue " pour lancer l'analyse ...

Si la dernière version de HijackThis n'est pas trouvée sur ton PC, RSIT la téléchargera et te demandera d'accepter la licence.

Attends jusqu’à la fin de l’analyse. deux rapports vont être crées.

# Poste en deux messages le contenu de " log.txt ", et de " info.txt " ( dans la barre des tâches).

Note : Si tu ne les trouves pas,les rapports sont sauvegardés dans le dossier C:\rsit.

A+
2
laromande Messages postés 168 Date d'inscription jeudi 23 octobre 2008 Statut Membre Dernière intervention 29 mai 2011 20
28 déc. 2009 à 13:40
Merci de l'aide, j'ai tout réussit sauf poster dans la barre des taches (je sais pas ce que ça veut dire), tu peux expliquer dufferement s.v.p?
0
verni29 Messages postés 6699 Date d'inscription dimanche 6 juillet 2008 Statut Contributeur sécurité Dernière intervention 26 décembre 2016 180
28 déc. 2009 à 13:45
Re,

Il faut maintenant poster les deux rapports.

Ouvre le poste de travail.
Ils se trouvent en C:\RSIT : log.txt et info.txt

Ouvre les et copie le contenu.
dans ta prochaine réponse, colle le contenu de ces deux rapports ( dans deux messages différents de préférence ).

A+
0
laromande Messages postés 168 Date d'inscription jeudi 23 octobre 2008 Statut Membre Dernière intervention 29 mai 2011 20
28 déc. 2009 à 14:30
info.txt logfile of random's system information tool 1.06 2009-12-28 13:26:01

======Uninstall list======

-->MsiExec /X{7104189A-C592-4A56-AC9E-7C0CA135DA3C}
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1A5BA3E-9ABF-4037-820B-6151022B8ACB}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5BA7C09-E523-478C-9C37-A1D86C76383E}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6366726-BA44-4D6A-8ECE-476E2E616AD1}\setup.exe" -l0x40c
µTorrent-->"C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
182708-->MsiExec.exe /X{312BD3DB-12E4-44EE-90AF-82A21219CC50}
30 jeux de cartes-->C:\Windows\unin040c.exe -f"c:\program files\jeux w98\DeIsL2.isu"
3D Flash Animator 4.9.8.6-->C:\Windows\unvise32.exe C:\Program Files\3D Flash Animator 4.9.8.6\uninstal.log
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A92000000001}
Adobe Shockwave Player 11.5-->"C:\Windows\system32\Adobe\Shockwave 11\uninstaller.exe"
adsl TV-->C:\Program Files\adslTV\Uninstal.exe
Advanced Audio FX Engine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x40c /remove
Advanced Video FX Engine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5BA7C09-E523-478C-9C37-A1D86C76383E}\setup.exe" -l0x40c /remove
AGEIA PhysX v6.10.25-->MsiExec.exe /X{7104189A-C592-4A56-AC9E-7C0CA135DA3C}
ALUpdate-->"C:\Program Files\ESTsoft\ALUpdate\unins000.exe"
ALZip-->"C:\Program Files\ESTsoft\ALZip\unins000.exe"
Any Audio Converter 1.0.2-->"C:\Program Files\Any Audio Converter\unins000.exe"
Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
Autodesk FBX Plug-in 2010.2.1 - 3ds Max 2010 64-bit-->C:\Program Files\Autodesk\FBX\FBXPlugins\2010.2.1\3ds Max 2010 64-bit\Uninstall.exe
BitDefender Internet Security 2008-->MsiExec.exe /I{4FD01CB0-EC34-4199-8037-08DE3E64A0A3}
BlackBerry Connect Desktop pour Sony Ericsson-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{70B45E50-F8F0-47D5-B707-495545A5BD00} /l1036
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Browser Address Error Redirector-->MsiExec.exe /I{62230596-37E5-4618-A329-0D21F529A86F}
CamStudio 2.0 Fr-->"C:\Program Files\CamStudio\unins000.exe"
CamStudio-->C:\Program Files\CamStudio\uninstall.exe
Canon ScanGear Toolbox CS 2.1-->C:\Windows\IsUn040c.exe -f"C:\Program Files\Canon\ScanGear Toolbox CS\Uninst.isu" -c"C:\Program Files\Canon\ScanGear Toolbox CS\uninst.dll"
Cavaj Java Decompiler-->C:\Windows\IsUninst.exe -f"F:\Program Files\Cavaj Java Decompiler\Uninst.isu"
CDDRV_Installer-->MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Conexant HDA D330 MDC V.92 Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F\HXFSETUP.EXE -U -Idel000fz.inf
Cool Nestor-->C:\Windows\unin040c.exe -f"c:\program files\jeux w98\DeIsL1.isu" -c"c:\program files\jeux w98\_ISREG32.DLL"
Cortona VRML Client-->C:\Windows\UNWISE32.EXE C:\PROGRA~1\PARALL~1\CORTON~1\Install.log
Dell Support Center-->MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
Dell Touchpad-->C:\Program Files\DellTPad\Uninstap.exe ADDREMOVE
Dell Webcam Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1A5BA3E-9ABF-4037-820B-6151022B8ACB}\setup.exe" -l0x40c /remove
Dell Webcam Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6366726-BA44-4D6A-8ECE-476E2E616AD1}\setup.exe" -l0x40c /remove
Digital Line Detect-->C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x040c -removeonly
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DR220A-->C:\Windows\unin040c.exe -f"C:\Program Files\DR220\DeIsL1.isu" -c"C:\Program Files\DR220\_ISREG32.DLL"
Driver Detective-->MsiExec.exe /X{4640FDE1-B83A-4376-84ED-86F86BEE2D41}
EZ Vinyl Converter 2.0.0 by MixMeister-->"C:\Program Files\MixMeister EZ Vinyl Converter\unins000.exe"
Facebook for Adobe AIR-->msiexec /qb /x {A45C0FD0-738D-C026-6E41-6BEA9A831376}
Facebook for Adobe AIR-->MsiExec.exe /I{A45C0FD0-738D-C026-6E41-6BEA9A831376}
FMS-->C:\Program Files\FMS\Uninstall.exe
Free Barcode Generator-->C:\Windows\iun6002.exe "C:\Program Files\BarcodeOverprinter\irunin.ini"
Free Video Converter V 2.1-->"C:\Program Files\Free Video Converter\unins000.exe"
Freecorder 2.3 (with Skype Call Recording)-->C:\Windows\iun6002.exe "C:\Program Files\Freecorder\irunin.ini"
Full Tilt Poker-->"C:\Program Files\InstallShield Installation Information\{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}\setup.exe" -runfromtemp -l0x040c -removeonly
Future Pinball-->"C:\Program Files\Future Pinball\unins000.exe"
Gabbasoft Cube Demo-->MsiExec.exe /X{E6B4523B-A47C-4DBA-918C-D9E220B3F4EC}
Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
GLtron version 0.70-->"C:\Program Files\GLtron\unins000.exe"
Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google SketchUp 6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98736A65-3C79-49EC-B7E9-A3C77774B0E6}\setup.exe" -l0x40c -removeonly
Google SketchUp 6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}\setup.exe" -l0x40c -removeonly
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Earth-->MsiExec.exe /X{9074AFC0-CFDA-11DE-B484-005056806466}
GtkRadiant 1.5.0-->MsiExec.exe /I{EC2F741D-308C-42B4-BD04-9A4853F2E402}
Guide de l'utilisateur-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.exe"
Guide de mise en route Dell-->MsiExec.exe /I{9954484F-6EE4-4040-94E3-4B380646F867}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Encoder (KB929182)-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} MSIPATCHREMOVE={5406B219-A1AC-4BC4-8695-72292C8195AC} /qb
IKEA Home Planner-->MsiExec.exe /I{AFA9D219-A7FD-4240-8793-E5C7C9D715F4}
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
Intel(R) PROSet/Wireless Software-->C:\Windows\Installer\iProInst.exe
Intel® Matrix Storage Manager-->C:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
iTunes-->MsiExec.exe /I{D1A74FBB-CA8D-4CCA-9B89-BAAA436DB178}
Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
KhalInstallWrapper-->MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
Labyrinthe 3D 3.15-->"F:\Program Files\CRtLogic\Labyrinthe3D\unins000.exe"
Laptop Integrated Webcam Driver (1.04.01.1011) -->C:\Windows\CtDrvIns.exe -uninstall -script OEM002.uns -plugin OEM02Pin.dll -pluginres OEM02Pin.crl -nodisconprompt -langid 0x040C
Live! Cam Avatar Creator-->C:\Program Files\InstallShield Installation Information\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}\setup.exe -runfromtemp -l0x040c -removeonly /remove
Live! Cam Avatar-->C:\Program Files\InstallShield Installation Information\{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}\setup.exe -runfromtemp -l0x040c -removeonly /remove
Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\SETUP.EXE" -l0x40c UNINSTALL
Logitech SetPoint-->C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe -runfromtemp -l0x040c -removeonly
Logitech Updater-->MsiExec.exe /I{53735ECE-E461-4FD0-B742-23A352436D3A}
MasterMind 3D-->C:\Program Files\MasterMind3D\Uninstal.exe
mCore-->MsiExec.exe /I{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}
MediaDirect-->C:\Program Files\InstallShield Installation Information\{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}\setup.exe -runfromtemp -l0x040c -cluninstall
Messenger Plus! Live & Sponsor (CiD)-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
mHelp-->MsiExec.exe /I{8C6BB412-D3A8-4AAE-A01B-35B681789D68}
Micro Application - Kit d'Impression CD 2000-->C:\Windows\IsUn040c.exe -f"C:\Program Files\Micro Application\Kit d'Impression CD 2000\Uninst.isu"
Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)-->MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Windows Media Video 9 VCM-->RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\wmv9vcm.inf, Uninstall
mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
MobileMe Control Panel-->MsiExec.exe /I{3AC54383-31D1-4907-961B-B12CBB1D0AE8}
Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
Mon Univers Photo Supracolor-->"F:\Program Files\Supra Color\Mon Univers Photo Supracolor\uninstall.exe"
mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
mWMI-->MsiExec.exe /I{63DB9CCD-2B56-4217-9A3D-507AC78320CA}
myphotobook 3.6-->C:\Program Files\myphotobook\uninst.exe
NetWaiting-->C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x040c -removeonly
NewtonPlayGround 1.53-->"C:\Program Files\NewtonPlayGround\unins000.exe"
Nokia Connectivity Cable Driver-->MsiExec.exe /I{52D02A2B-03D2-4E34-A358-DC5D951FD296}
OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
OpenGL Extensions Viewer 3.0-->"C:\Program Files\realtech VR\OpenGL Extensions Viewer 3.0\uninst.exe"
OtsTurntables Free 1.00.027-->"C:\Windows\OTS_UI.EXE" "C:\Program Files\Otstables\OtsTTfre.osi"
Outil de diagnostic de modem-->MsiExec.exe /I{F63A3748-B93D-4360-9AD4-B064481A5C7B}
Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
OutlookAddinSetup-->MsiExec.exe /I{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}
PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
Pinnacle Instant DVD Recorder-->C:\Program Files\InstallShield Installation Information\{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}\Setup.exe -runfromtemp -l0x040cUNINSTALL -removeonly
Pinnacle VideoSpin-->MsiExec.exe /I{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}
Pixillion Image Converter-->C:\Program Files\NCH Software\Pixillion\uninst.exe
Power Video to Audio Converter 1.03-->"C:\Program Files\Sagasoft\Power Video to Audio Converter\unins000.exe"
QuickSet-->MsiExec.exe /I{C4972073-2BFE-475D-8441-564EA97DA161}
QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
Roxio Creator Audio-->MsiExec.exe /I{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}
Roxio Creator Copy-->MsiExec.exe /I{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}
Roxio Creator Data-->MsiExec.exe /I{08E81ABD-79F7-49C2-881F-FD6CB0975693}
Roxio Creator DE-->C:\ProgramData\Uninstall\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}\setup.exe /x {09760D42-E223-42AD-8C3E-55B47D0DDAC3}
Roxio Creator DE-->MsiExec.exe /I{ED439A64-F018-4DD4-8BA5-328D85AB09AB}
Roxio Creator Tools-->MsiExec.exe /I{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}
Roxio Express Labeler 3-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Roxio Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
'Science Ain't Fair'-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34966B25-A82F-11D5-9E0F-0050FC0220CE}\Setup.exe"
ScoreFitter Volume 1-->MsiExec.exe /I{9DCBDF08-F1C0-4935-A958-9501384FC528}
ScoreFitter Volume 2-->MsiExec.exe /I{74E5BA31-CB34-4388-BC7F-91DC8830AABC}
Search Settings 1.2-->MsiExec.exe /X{D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
Security Update for Windows Media Encoder (KB954156)-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} MSIPATCHREMOVE={E836F1B7-43FB-46B0-A0D9-E4D2A5951659} /qb
Seven Remix 1.0-->C:\Program Files\NiwradSoft\NiwradSoft Shell Pack\uninst.exe
Sony Ericsson Device Data-->MsiExec.exe /I{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}
Sony Ericsson Drivers-->MsiExec.exe /I{C60BA916-9E44-4DA4-B11A-9E27B7624EF5}
Sony Ericsson PC Suite-->C:\Windows\Installer\{D6BF6477-8369-489F-8DE6-3731F4B88560}\Setup.exe /uninstall
Sony Ericsson PC Suite-->MsiExec.exe /I{25BEC3AB-5CD4-481D-9143-215C1BBB189E}
Sony Ericsson Themes Creator 4.08-->C:\Program Files\Sony Ericsson\Themes Creator\Uninstall.exe
Studio 11 Bonus DVD-->C:\Program Files\InstallShield Installation Information\{45A1BF92-700A-4408-B95E-79F462E3D67D}\setup.exe -runfromtemp -l0x040c UNINSTALL -removeonly
Studio 11-->C:\Program Files\InstallShield Installation Information\{110B1ADF-2EAE-4E8F-B501-D2A1E6D8ED9D}\Setup2.exe -runfromtemp -l0x040c UNINSTALL -removeonly
Tetris-->"C:\Program Files\Tetris\unins000.exe"
THE HOUSE OF THE DEAD 2-->MsiExec.exe /X{2C8B0579-46E6-4088-8E57-44833265798F}
TmNationsForever-->"C:\Program Files\TmNationsForever\unins000.exe"
TuxGuitar-->C:\Program Files\tuxguitar-1.1\uninstall.exe
UNO© Freeware-->C:\Windows\GPInstall.exe "/UNINST=C:\Program Files\UNO Freeware\UnInst.log" "/APPNAME=UNO© Freeware"
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Usenet.nl-->"C:\Program Files\Usenet.nl\unins000.exe"
UseNeXT-->"C:\Program Files\UseNeXT\unins000.exe"
Utilitaire de configuration iPhone-->MsiExec.exe /I{FA54AFB1-5745-4389-B8C1-9F7509672ED1}
VideoLAN VLC media player 0.8.6i-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Viewpoint Media Player (Remove Only)-->C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe -u
voute-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\Jeux W98\ST6UNST.LOG"
WIDCOMM Bluetooth Software 6.0.1.4900-->MsiExec.exe /X{03D1988F-469F-4843-8E6E-E5FE9D17889D}
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
Windows Live Movie Maker Bêta-->MsiExec.exe /X{F874DF52-A31F-44C1-A606-EF40F1549261}
Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
Windows Media Tools 4.0-->C:\Program Files\Windows Media Components\Tools\_insttoo.exe /U
Windows Movie Maker 2.6-->MsiExec.exe /X{B3DAF54F-DB25-4586-9EF1-96D24BB14088}
Xvid 1.2.2 final uninstall-->"C:\Program Files\Xvid\unins001.exe"
XviD MPEG4 Video Codec (remove only)-->"C:\Windows\system32\xvid-uninstall.exe"
Yahoo! Desktop Login-->MsiExec.exe /I{F9AEEC34-CF00-4CBD-9E36-DF9DC4002685}
ZyGoVideo 2.0-->C:\Windows\unvise32.exe C:\Program Files\uninstal.log

======Hosts File======

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

======Security center information======

AV: AVG Anti-Virus Free
AV: Bitdefender Antivirus
FW: Bitdefender Firewall
AS: BitDefender AntiSpam
AS: AVG Anti-Virus Free (disabled)
AS: Windows Defender (disabled)

=====Application event log=====

Computer Name: PC-de-Lucas
Event Code: 1530
Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

DÉTAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-3484608450-3105273323-3831902016-1000:
Process 676 (\Device\HarddiskVolume3\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3484608450-3105273323-3831902016-1000

Record Number: 507
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20080506124808.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Lucas
Event Code: 1030
Message: Produit : Microsoft Office 2000 CD-ROM 2. L’application a tenté d’installer une version supérieure du fichier Windows protégé C:\Program Files\Common Files\System\OLE DB\MSDAURL.DLL. Vous devrez peut-être mettre à jour votre système d’exploitation pour que cette application fonctionne correctement. (Version de package : 8.102.1403.0, version protégée du système d’exploitation : 6.0.6000.16386).
Record Number: 466
Source Name: MsiInstaller
Time Written: 20080506120610.000000-000
Event Type: Avertissement
User: PC-DE-LUCAS\Lucas

Computer Name: PC-de-Lucas
Event Code: 1030
Message: Produit : Microsoft Office 2000 Small Business. L’application a tenté d’installer une version supérieure du fichier Windows protégé C:\Windows\system32\MAPISTUB.DLL. Vous devrez peut-être mettre à jour votre système d’exploitation pour que cette application fonctionne correctement. (Version de package : 1.0.2536.0, version protégée du système d’exploitation : 1.0.2536.0).
Record Number: 457
Source Name: MsiInstaller
Time Written: 20080506114641.000000-000
Event Type: Avertissement
User: PC-DE-LUCAS\Lucas

Computer Name: PC-de-Lucas
Event Code: 1030
Message: Produit : Microsoft Office 2000 Small Business. L’application a tenté d’installer une version supérieure du fichier Windows protégé C:\Program Files\Common Files\System\OLE DB\MSDAURL.DLL. Vous devrez peut-être mettre à jour votre système d’exploitation pour que cette application fonctionne correctement. (Version de package : 8.102.1403.0, version protégée du système d’exploitation : 6.0.6000.16386).
Record Number: 456
Source Name: MsiInstaller
Time Written: 20080506114607.000000-000
Event Type: Avertissement
User: PC-DE-LUCAS\Lucas

Computer Name: PC-de-Lucas
Event Code: 1530
Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

DÉTAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-3484608450-3105273323-3831902016-1000:
Process 672 (\Device\HarddiskVolume3\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3484608450-3105273323-3831902016-1000

Record Number: 419
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20080506111858.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

=====Security event log=====

Computer Name: PC-de-Lucas
Event Code: 4624
Message: L’ouverture de session d’un compte s’est correctement déroulée.

Sujet :
ID de sécurité : S-1-0-0
Nom du compte : -
Domaine du compte : -
ID d’ouverture de session : 0x0

Type d’ouverture de session : 3

Nouvelle ouverture de session :
ID de sécurité : S-1-5-7
Nom du compte : ANONYMOUS LOGON
Domaine du compte : AUTORITE NT
ID d’ouverture de session : 0x9c3efe
GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

Informations sur le processus :
ID du processus : 0x0
Nom du processus : -

Informations sur le réseau :
Nom de la station de travail : PRINCIPAL
Adresse du réseau source : 192.168.1.48
Port source : 4366

Informations détaillées sur l’authentification :
Processus d’ouverture de session : NtLmSsp
Package d’authentification : NTLM
Services en transit : -
Nom du package (NTLM uniquement) : NTLM V1
Longueur de la clé : 0

Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
- Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
- Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
- Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
- La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
Record Number: 50301
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090817170904.553000-000
Event Type: Succès de l'audit
User:

Computer Name: PC-de-Lucas
Event Code: 4634
Message: Fermeture de session d’un compte.

Sujet :
ID de sécurité : S-1-5-7
Nom du compte : ANONYMOUS LOGON
Domaine du compte : AUTORITE NT
ID du compte : 0x9bd015

Type d’ouverture de session : 3

Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.
Record Number: 50300
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090817170801.885000-000
Event Type: Succès de l'audit
User:

Computer Name: PC-de-Lucas
Event Code: 4624
Message: L’ouverture de session d’un compte s’est correctement déroulée.

Sujet :
ID de sécurité : S-1-0-0
Nom du compte : -
Domaine du compte : -
ID d’ouverture de session : 0x0

Type d’ouverture de session : 3

Nouvelle ouverture de session :
ID de sécurité : S-1-5-7
Nom du compte : ANONYMOUS LOGON
Domaine du compte : AUTORITE NT
ID d’ouverture de session : 0x9bd015
GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

Informations sur le processus :
ID du processus : 0x0
Nom du processus : -

Informations sur le réseau :
Nom de la station de travail : PC-DE-CHANTAL
Adresse du réseau source : 192.168.1.43
Port source : 49471

Informations détaillées sur l’authentification :
Processus d’ouverture de session : NtLmSsp
Package d’authentification : NTLM
Services en transit : -
Nom du package (NTLM uniquement) : NTLM V1
Longueur de la clé : 128

Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
- Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
- Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
- Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
- La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
Record Number: 50299
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090817170751.501000-000
Event Type: Succès de l'audit
User:

Computer Name: PC-de-Lucas
Event Code: 4634
Message: Fermeture de session d’un compte.

Sujet :
ID de sécurité : S-1-5-21-3484608450-3105273323-3831902016-1000
Nom du compte : Lucas
Domaine du compte : PC-DE-LUCAS
ID du compte : 0x9406df

Type d’ouverture de session : 7

Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.
Record Number: 50298
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090817165508.248000-000
Event Type: Succès de l'audit
User:

Computer Name: PC-de-Lucas
Event Code: 4634
Message: Fermeture de session d’un compte.

Sujet :
ID de sécurité : S-1-5-21-3484608450-3105273323-3831902016-1000
Nom du compte : Lucas
Domaine du compte : PC-DE-LUCAS
ID du compte : 0x940744

Type d’ouverture de session : 7

Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.
Record Number: 50297
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090817165508.247000-000
Event Type: Succès de l'audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"NUMBER_OF_PROCESSORS"=2
"OS"=Windows_NT
"Path"=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\Common Files\Roxio Shared\10.0\DLLShared;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Microsoft SQL Server\80\Tools\Binn;C:\Program Files\ESTsoft\ALZip;C:\Program Files\Pinnacle\Shared Files\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\ESTsoft\ALZip;C:\Program Files\Pinnacle\Shared Files;C:\Program Files\Pinnacle\Shared Files\Filter;C:\Program Files\Common Files\Teleca Shared
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_LEVEL"=6
"PROCESSOR_REVISION"=0f0d
"RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\10.0\Roxio Central36\
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

-----------------EOF-----------------
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
laromande Messages postés 168 Date d'inscription jeudi 23 octobre 2008 Statut Membre Dernière intervention 29 mai 2011 20
28 déc. 2009 à 14:32
Logfile of random's system information tool 1.06 (written by random/random)
Run by Lucas at 2009-12-28 13:25:25
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 85 GB (64%) free of 134 GB
Total RAM: 2037 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:25:53, on 28.12.2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\mobsync.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\msb.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Windows\system32\conime.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Users\Lucas\AppData\Local\Temp\c.exe
C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Lucas\Desktop\RSIT.exe
C:\Program Files\trend micro\Lucas.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ch.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ch/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (file missing)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8841B1-F10B-460C-86FC-4B71187C765E} - C:\Windows\system32\hgGwWPHY.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (file missing)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\hgGwWPHY.dll,#1
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Chin Five] "C:\ProgramData\Store nurb nurb.ps8bbv"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [PCLEUSBTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\Windows\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\Lucas\AppData\Local\Temp\mlJDtqoL.dll,#1
O4 - HKCU\..\Run: [Google Update] "C:\Users\Lucas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Chin Five] "C:\ProgramData\Store nurb nurb.inwizx"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [vegas] rundll32.exe C:\Windows\system32\sshnas.dll,DllWork
O4 - HKCU\..\Run: [ZagrebLand] C:\Users\Lucas\AppData\Local\Temp\c.exe
O4 - HKCU\..\Run: [Videocan] C:\Windows\msb.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate1c9a4bfe48a36af) (gupdate1c9a4bfe48a36af) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
0
verni29 Messages postés 6699 Date d'inscription dimanche 6 juillet 2008 Statut Contributeur sécurité Dernière intervention 26 décembre 2016 180
28 déc. 2009 à 14:44
Le PC est bien infecté.

Commence par ceci :

Télécharge LopS&D.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

Installe le logiciel. Un raccourci va apparaitre sur le bureau.

* Lance le logiciel en tant qu’administrateur. ( click droit sur le raccouci et choisis Exécuter en tant qu’administrateur )
* Tu choisis la langue et l'option 1 pour effectuer la recherche.

A la fin de la recherche, un rapport LopR.txt apparait. Il se trouve également en C:\LopR.txt.
Tu posteras ce rapport dans le prochain message.

A+
0
laromande Messages postés 168 Date d'inscription jeudi 23 octobre 2008 Statut Membre Dernière intervention 29 mai 2011 20
28 déc. 2009 à 14:57
--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A11
USER : Lucas ( Not Administrator ! )
BOOT : Normal boot
Antivirus : Bitdefender Antivirus 8.0 (Activated)
Firewall : Bitdefender Firewall 8.0 (Activated)
C:\ (Local Disk) - NTFS - Total:130 Go (Free:83 Go)
D:\ (Local Disk) - NTFS - Total:9 Go (Free:5 Go)
E:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 28.12.2009|14:52 )

[ UAC => 1 ]

--------------------\\ Listing des dossiers dans Local

[14.12.2009|16:58] C:\Users\Lucas\AppData\Local\{31E384F6-C403-42FF-A27A-32C054E52A94}
[28.11.2009|10:08] C:\Users\Lucas\AppData\Local\Adobe
[08.05.2008|16:45] C:\Users\Lucas\AppData\Local\Apple
[19.09.2009|07:20] C:\Users\Lucas\AppData\Local\Apple Computer
[06.05.2008|11:32] C:\Users\Lucas\AppData\Local\Application Data
[29.11.2008|18:47] C:\Users\Lucas\AppData\Local\Apps
[15.12.2009|17:58] C:\Users\Lucas\AppData\Local\d3d9caps.dat
[25.12.2009|09:44] C:\Users\Lucas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[06.04.2009|09:00] C:\Users\Lucas\AppData\Local\Deployment
[13.12.2009|07:32] C:\Users\Lucas\AppData\Local\DNA
[05.07.2009|07:03] C:\Users\Lucas\AppData\Local\Downloaded Installations
[05.05.2009|18:03] C:\Users\Lucas\AppData\Local\eMule
[03.10.2009|06:28] C:\Users\Lucas\AppData\Local\FullTiltPoker
[06.12.2009|08:08] C:\Users\Lucas\AppData\Local\GDIPFONTCACHEV1.DAT
[15.07.2009|09:49] C:\Users\Lucas\AppData\Local\Google
[06.05.2008|11:32] C:\Users\Lucas\AppData\Local\Historique
[28.12.2009|13:48] C:\Users\Lucas\AppData\Local\IconCache.db
[19.08.2009|13:38] C:\Users\Lucas\AppData\Local\keyfile3.drm
[06.08.2009|10:09] C:\Users\Lucas\AppData\Local\MediaDirect
[19.08.2009|13:38] C:\Users\Lucas\AppData\Local\Microsoft
[28.03.2009|19:27] C:\Users\Lucas\AppData\Local\Microsoft Games
[30.05.2009|08:37] C:\Users\Lucas\AppData\Local\Microsoft Help
[10.05.2008|06:30] C:\Users\Lucas\AppData\Local\MicroVision Applications
[23.04.2009|17:26] C:\Users\Lucas\AppData\Local\Mozilla
[15.11.2009|17:51] C:\Users\Lucas\AppData\Local\MusE
[27.10.2009|15:42] C:\Users\Lucas\AppData\Local\PC_Drivers_Headquarters
[28.06.2009|07:53] C:\Users\Lucas\AppData\Local\Pinnacle
[20.02.2009|17:56] C:\Users\Lucas\AppData\Local\Powercinema
[07.12.2009|10:01] C:\Users\Lucas\AppData\Local\realtech_VR
[12.12.2009|18:29] C:\Users\Lucas\AppData\Local\Sony Ericsson
[06.05.2008|13:32] C:\Users\Lucas\AppData\Local\SupportSoft
[28.12.2009|14:51] C:\Users\Lucas\AppData\Local\Temp
[28.12.2009|14:17] C:\Users\Lucas\AppData\Local\Temp(57)
[06.05.2008|11:32] C:\Users\Lucas\AppData\Local\Temporary Internet Files
[01.12.2008|18:44] C:\Users\Lucas\AppData\Local\VirtualStore
[11.05.2008|08:14] C:\Users\Lucas\AppData\Local\Windows Collaboration
[22.06.2009|18:43] C:\Users\Lucas\AppData\Local\WMTools Downloaded Files

--------------------\\ Tâches planifiées dans C:\Windows\tasks

[28.12.2009 14:47][--ah-----] C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[28.12.2009 14:41][--ah-----] C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
[28.12.2009 14:28][--a------] C:\Windows\tasks\Google Software Updater.job
[28.12.2009 14:42][--a------] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3484608450-3105273323-3831902016-1000UA.job
[28.12.2009 10:33][--a------] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3484608450-3105273323-3831902016-1000Core.job
[28.12.2009 14:39][--a------] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[28.12.2009 14:40][--a------] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[28.12.2009 14:50][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{536DBF20-63E9-48FF-89F6-29E99AAA92BF}.job
[28.12.2009 14:25][--ah-----] C:\Windows\tasks\SA.DAT
[22.12.2009 15:08][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing des dossiers dans C:\ProgramData

[25.12.2009|19:24] C:\ProgramData\__FileUploader.log
[19.03.2009|18:21] C:\ProgramData\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[16.09.2009|17:31] C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[02.05.2009|10:42] C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[10.07.2008|10:51] C:\ProgramData\692498.dat
[28.11.2009|10:09] C:\ProgramData\Adobe
[08.05.2008|16:44] C:\ProgramData\Apple
[20.02.2009|16:52] C:\ProgramData\Apple Computer
[06.05.2008|11:31] C:\ProgramData\Application Data
[21.11.2009|10:57] C:\ProgramData\avg8
[22.09.2008|15:48] C:\ProgramData\AVS4YOU
[07.07.2009|11:47] C:\ProgramData\BitDefender
[06.09.2008|20:03] C:\ProgramData\BM63c59ab4.txt
[22.09.2008|15:47] C:\ProgramData\BM63c59ab4.xml
[06.05.2008|11:31] C:\ProgramData\Bureau
[22.06.2009|11:36] C:\ProgramData\cdrom sign
[27.06.2008|20:49] C:\ProgramData\CyberLink
[01.05.2008|12:13] C:\ProgramData\Dell
[06.05.2008|11:31] C:\ProgramData\Documents
[06.05.2008|11:31] C:\ProgramData\Favoris
[15.07.2009|09:50] C:\ProgramData\Google
[28.12.2009|14:28] C:\ProgramData\Google Updater
[17.07.2008|09:14] C:\ProgramData\Hewlett-Packard
[26.12.2009|14:30] C:\ProgramData\hps
[01.05.2008|12:14] C:\ProgramData\InstallShield
[01.05.2008|11:59] C:\ProgramData\Intel
[22.10.2008|14:03] C:\ProgramData\LogiShrd
[22.10.2008|14:03] C:\ProgramData\Logitech
[16.07.2008|17:57] C:\ProgramData\McAfee
[06.05.2008|11:31] C:\ProgramData\Menu D‚marrer
[23.05.2008|08:51] C:\ProgramData\Messenger Plus!
[17.06.2009|10:46] C:\ProgramData\Microsoft
[17.06.2009|11:08] C:\ProgramData\Microsoft Help
[06.05.2008|11:31] C:\ProgramData\ModŠles
[27.05.2009|19:14] C:\ProgramData\ntuser.pol
[05.10.2009|16:07] C:\ProgramData\Office Genuine Advantage
[27.10.2009|15:42] C:\ProgramData\PC Drivers HeadQuarters
[04.07.2009|19:24] C:\ProgramData\Pinnacle
[04.07.2009|19:24] C:\ProgramData\Pinnacle Studio
[30.06.2009|16:00] C:\ProgramData\Pinnacle VideoSpin
[09.05.2009|17:14] C:\ProgramData\Propellerhead Software
[22.09.2008|15:47] C:\ProgramData\pskt.ini
[07.12.2009|09:55] C:\ProgramData\realtech VR
[21.02.2009|12:31] C:\ProgramData\River Past G5
[26.12.2009|11:59] C:\ProgramData\Roxio
[01.05.2008|12:15] C:\ProgramData\Sonic
[12.12.2009|18:28] C:\ProgramData\Sony Ericsson
[05.10.2008|11:56] C:\ProgramData\Spybot - Search & Destroy
[01.03.2009|13:00] C:\ProgramData\Store nurb nurb.0ngyl
[01.03.2009|03:09] C:\ProgramData\Store nurb nurb.0t9zsj
[14.02.2009|10:56] C:\ProgramData\Store nurb nurb.0x93w7
[01.03.2009|09:42] C:\ProgramData\Store nurb nurb.1155s1
[16.03.2009|03:13] C:\ProgramData\Store nurb nurb.15r2ui
[22.02.2009|19:40] C:\ProgramData\Store nurb nurb.1ce103w
[11.03.2009|22:50] C:\ProgramData\Store nurb nurb.1jrasmq
[28.02.2009|19:52] C:\ProgramData\Store nurb nurb.1r627
[28.02.2009|16:58] C:\ProgramData\Store nurb nurb.1s62i
[13.03.2009|02:20] C:\ProgramData\Store nurb nurb.1tla2
[16.03.2009|18:21] C:\ProgramData\Store nurb nurb.20bv8
[13.03.2009|09:15] C:\ProgramData\Store nurb nurb.28ut6
[16.03.2009|06:51] C:\ProgramData\Store nurb nurb.2cd1n
[28.02.2009|16:14] C:\ProgramData\Store nurb nurb.2ixbjz
[01.03.2009|00:36] C:\ProgramData\Store nurb nurb.2j6a3
[11.03.2009|18:50] C:\ProgramData\Store nurb nurb.2nz2vm
[12.03.2009|19:47] C:\ProgramData\Store nurb nurb.2qd251
[16.03.2009|01:02] C:\ProgramData\Store nurb nurb.2qj40
[17.03.2009|02:44] C:\ProgramData\Store nurb nurb.33xmcyh
[13.03.2009|09:37] C:\ProgramData\Store nurb nurb.3adtql
[01.03.2009|12:37] C:\ProgramData\Store nurb nurb.3c6h7
[15.03.2009|10:07] C:\ProgramData\Store nurb nurb.3ddcm
[23.02.2009|01:30] C:\ProgramData\Store nurb nurb.3ghdc
[22.02.2009|18:13] C:\ProgramData\Store nurb nurb.3gk5j76
[23.02.2009|00:03] C:\ProgramData\Store nurb nurb.3inux
[22.02.2009|15:40] C:\ProgramData\Store nurb nurb.3m18xv
[15.03.2009|20:40] C:\ProgramData\Store nurb nurb.3mbimt
[17.03.2009|05:16] C:\ProgramData\Store nurb nurb.3mjndr8
[12.03.2009|00:18] C:\ProgramData\Store nurb nurb.3p1vkz
[28.02.2009|22:47] C:\ProgramData\Store nurb nurb.3rhn8r
[23.02.2009|02:57] C:\ProgramData\Store nurb nurb.3z74wz
[22.02.2009|21:08] C:\ProgramData\Store nurb nurb.40tff
[17.03.2009|04:11] C:\ProgramData\Store nurb nurb.45bxah0
[17.03.2009|20:29] C:\ProgramData\Store nurb nurb.4b4m3y
[12.03.2009|20:52] C:\ProgramData\Store nurb nurb.4bwkht
[16.03.2009|17:37] C:\ProgramData\Store nurb nurb.4cbaaft
[11.03.2009|23:56] C:\ProgramData\Store nurb nurb.4f82x
[17.03.2009|00:54] C:\ProgramData\Store nurb nurb.4qq5giq
[17.03.2009|01:38] C:\ProgramData\Store nurb nurb.4r9k7
[13.03.2009|11:26] C:\ProgramData\Store nurb nurb.4tzrbon
[28.02.2009|20:36] C:\ProgramData\Store nurb nurb.4xrvqhz
[15.03.2009|11:35] C:\ProgramData\Store nurb nurb.4zkoh
[13.03.2009|07:04] C:\ProgramData\Store nurb nurb.53mg9ji
[01.03.2009|10:48] C:\ProgramData\Store nurb nurb.575bzdo
[22.02.2009|14:57] C:\ProgramData\Store nurb nurb.5960ph
[23.02.2009|02:35] C:\ProgramData\Store nurb nurb.5gsqe8
[16.03.2009|17:59] C:\ProgramData\Store nurb nurb.5tr3ed2
[15.03.2009|17:39] C:\ProgramData\Store nurb nurb.5z1scis
[22.02.2009|19:19] C:\ProgramData\Store nurb nurb.5zule6r
[01.03.2009|08:37] C:\ProgramData\Store nurb nurb.62pyw
[17.03.2009|06:00] C:\ProgramData\Store nurb nurb.6iak5v
[17.06.2009|08:46] C:\ProgramData\Store nurb nurb.6lkhyt
[13.03.2009|05:36] C:\ProgramData\Store nurb nurb.6m64vs
[16.03.2009|14:20] C:\ProgramData\Store nurb nurb.6ntribf
[01.03.2009|07:31] C:\ProgramData\Store nurb nurb.6p8dpfb
[17.03.2009|20:07] C:\ProgramData\Store nurb nurb.6sdf7fj
[16.03.2009|05:24] C:\ProgramData\Store nurb nurb.6wjzdq
[15.03.2009|08:39] C:\ProgramData\Store nurb nurb.6y9e65
[01.03.2009|14:27] C:\ProgramData\Store nurb nurb.73g0b8
[12.03.2009|02:50] C:\ProgramData\Store nurb nurb.7aamm9v
[28.02.2009|18:25] C:\ProgramData\Store nurb nurb.7brz4ii
[11.03.2009|21:01] C:\ProgramData\Store nurb nurb.7fd1yet
[13.03.2009|05:58] C:\ProgramData\Store nurb nurb.7ipam8
[23.02.2009|00:24] C:\ProgramData\Store nurb nurb.7ldybi
[11.03.2009|18:06] C:\ProgramData\Store nurb nurb.7mhcr
[12.03.2009|18:19] C:\ProgramData\Store nurb nurb.7rdg5q
[11.03.2009|19:34] C:\ProgramData\Store nurb nurb.7smiflq
[01.03.2009|00:58] C:\ProgramData\Store nurb nurb.7svyp
[17.06.2009|07:40] C:\ProgramData\Store nurb nurb.7u4wo
[16.03.2009|15:04] C:\ProgramData\Store nurb nurb.80py4q
[13.03.2009|01:14] C:\ProgramData\Store nurb nurb.8dmo95b
[22.02.2009|21:30] C:\ProgramData\Store nurb nurb.8iktr
[16.03.2009|18:43] C:\ProgramData\Store nurb nurb.8se6b
[13.03.2009|16:10] C:\ProgramData\Store nurb nurb.8vr9p
[16.03.2009|13:37] C:\ProgramData\Store nurb nurb.8x5o3w0
[13.03.2009|19:02] C:\ProgramData\Store nurb nurb.978a7fc
[13.03.2009|04:31] C:\ProgramData\Store nurb nurb.9dma69g
[17.03.2009|03:49] C:\ProgramData\Store nurb nurb.9gbsl
[28.02.2009|16:36] C:\ProgramData\Store nurb nurb.9leqwu0
[13.03.2009|17:38] C:\ProgramData\Store nurb nurb.9nqb5
[22.02.2009|20:46] C:\ProgramData\Store nurb nurb.9txhuc3
[16.03.2009|19:49] C:\ProgramData\Store nurb nurb.9uu9v0i
[15.03.2009|23:34] C:\ProgramData\Store nurb nurb.9wkny
[12.03.2009|21:36] C:\ProgramData\Store nurb nurb.9x1x32
[13.03.2009|16:32] C:\ProgramData\Store nurb nurb.a3n4lu
[17.06.2009|08:24] C:\ProgramData\Store nurb nurb.a892npm
[13.03.2009|08:31] C:\ProgramData\Store nurb nurb.aihd736
[22.02.2009|23:19] C:\ProgramData\Store nurb nurb.aiwdwa0
[12.03.2009|17:14] C:\ProgramData\Store nurb nurb.alic6s
[01.03.2009|14:49] C:\ProgramData\Store nurb nurb.atckpu
[12.03.2009|02:29] C:\ProgramData\Store nurb nurb.auamq4
[01.03.2009|02:47] C:\ProgramData\Store nurb nurb.avj2em7
[17.03.2009|17:55] C:\ProgramData\Store nurb nurb.ay3h917
[14.03.2009|22:13] C:\ProgramData\Store nurb nurb.bbvj1
[15.03.2009|23:13] C:\ProgramData\Store nurb nurb.bklszzs
[28.02.2009|22:25] C:\ProgramData\Store nurb nurb.bp2rlp0
[17.03.2009|02:00] C:\ProgramData\Store nurb nurb.bs5pl
[11.03.2009|20:39] C:\ProgramData\Store nurb nurb.btnizxi
[28.02.2009|20:58] C:\ProgramData\Store nurb nurb.byq4l9h
[11.03.2009|23:34] C:\ProgramData\Store nurb nurb.c6x8sr
[12.03.2009|21:14] C:\ProgramData\Store nurb nurb.c7nlul
[01.03.2009|05:20] C:\ProgramData\Store nurb nurb.ca1te
[16.03.2009|23:27] C:\ProgramData\Store nurb nurb.ccf9c
[11.03.2009|19:55] C:\ProgramData\Store nurb nurb.ccq177
[17.03.2009|18:17] C:\ProgramData\Store nurb nurb.cdkxpw
[13.03.2009|13:15] C:\ProgramData\Store nurb nurb.cfpjv
[17.03.2009|19:01] C:\ProgramData\Store nurb nurb.cgsldh9
[01.03.2009|15:33] C:\ProgramData\Store nurb nurb.cjtb7rp
[23.02.2009|01:52] C:\ProgramData\Store nurb nurb.cjvc6f
[11.03.2009|22:07] C:\ProgramData\Store nurb nurb.cl9hb
[15.03.2009|12:19] C:\ProgramData\Store nurb nurb.cwos1i
[16.03.2009|21:16] C:\ProgramData\Store nurb nurb.d0kv4m
[13.03.2009|14:43] C:\ProgramData\Store nurb nurb.d17dte
[11.03.2009|22:28] C:\ProgramData\Store nurb nurb.d2hrr
[28.02.2009|19:09] C:\ProgramData\Store nurb nurb.d5c6yh
[01.03.2009|10:26] C:\ProgramData\Store nurb nurb.d5iqm7
[16.03.2009|15:48] C:\ProgramData\Store nurb nurb.dc7orz
[01.03.2009|06:04] C:\ProgramData\Store nurb nurb.dcn97ai
[22.02.2009|20:02] C:\ProgramData\Store nurb nurb.dnhh3
[01.03.2009|10:04] C:\ProgramData\Store nurb nurb.dqt4unt
[13.03.2009|05:15] C:\ProgramData\Store nurb nurb.ec007a6
[15.03.2009|11:13] C:\ProgramData\Store nurb nurb.eog3hf
[16.03.2009|04:18] C:\ProgramData\Store nurb nurb.erpnq
[16.03.2009|21:38] C:\ProgramData\Store nurb nurb.ew05l
[14.03.2009|21:51] C:\ProgramData\Store nurb nurb.eyupl6
[17.03.2009|16:57] C:\ProgramData\Store nurb nurb.f4udzs
[13.03.2009|08:09] C:\ProgramData\Store nurb nurb.fbjqm2
[17.03.2009|16:35] C:\ProgramData\Store nurb nurb.fc464z
[12.03.2009|20:09] C:\ProgramData\Store nurb nurb.ffhi1zj
[15.03.2009|10:29] C:\ProgramData\Store nurb nurb.flpahe
[28.02.2009|23:09] C:\ProgramData\Store nurb nurb.frk5ci
[17.03.2009|03:05] C:\ProgramData\Store nurb nurb.ft0m5
[01.03.2009|06:26] C:\ProgramData\Store nurb nurb.fxhm6l0
[16.03.2009|02:29] C:\ProgramData\Store nurb nurb.fxkh0
[12.03.2009|21:58] C:\ProgramData\Store nurb nurb.fxq1z8g
[15.03.2009|15:06] C:\ProgramData\Store nurb nurb.fzvi3v
[01.03.2009|04:58] C:\ProgramData\Store nurb nurb.g24xve
[07.06.2009|11:44] C:\ProgramData\Store nurb nurb.g2ti2h
[16.03.2009|22:21] C:\ProgramData\Store nurb nurb.g58w6
[11.03.2009|18:28] C:\ProgramData\Store nurb nurb.g84r8
[13.03.2009|03:04] C:\ProgramData\Store nurb nurb.g9y81wd
[22.02.2009|22:57] C:\ProgramData\Store nurb nurb.ginxg5
[12.03.2009|17:36] C:\ProgramData\Store nurb nurb.gj5cv
[13.03.2009|00:52] C:\ProgramData\Store nurb nurb.gjyu4c
[15.03.2009|16:11] C:\ProgramData\Store nurb nurb.glp1oc
[17.03.2009|04:55] C:\ProgramData\Store nurb nurb.gpeyf
[11.03.2009|23:12] C:\ProgramData\Store nurb nurb.gqkyf
[11.03.2009|21:23] C:\ProgramData\Store nurb nurb.grxj69
[15.03.2009|13:03] C:\ProgramData\Store nurb nurb.gw282
[15.03.2009|09:45] C:\ProgramData\Store nurb nurb.gx0ilpl
[12.03.2009|01:45] C:\ProgramData\Store nurb nurb.gx4vurk
[13.03.2009|15:48] C:\ProgramData\Store nurb nurb.gx7t5d
[16.03.2009|02:07] C:\ProgramData\Store nurb nurb.h0rz7k
[01.03.2009|07:53] C:\ProgramData\Store nurb nurb.h2m3s
[15.03.2009|16:55] C:\ProgramData\Store nurb nurb.h3a26p9
[15.03.2009|09:23] C:\ProgramData\Store nurb nurb.h6053l
[11.03.2009|21:45] C:\ProgramData\Store nurb nurb.ha3f8
[13.03.2009|03:25] C:\ProgramData\Store nurb nurb.hcfrl8
[12.03.2009|18:41] C:\ProgramData\Store nurb nurb.hfk0l7d
[12.03.2009|19:03] C:\ProgramData\Store nurb nurb.hgm4p
[12.03.2009|23:03] C:\ProgramData\Store nurb nurb.hiraav
[01.03.2009|05:42] C:\ProgramData\Store nurb nurb.hjy6z
[13.03.2009|01:36] C:\ProgramData\Store nurb nurb.hom2pw8
[01.03.2009|15:54] C:\ProgramData\Store nurb nurb.hrawc
[22.02.2009|16:46] C:\ProgramData\Store nurb nurb.hsi9n
[01.03.2009|11:53] C:\ProgramData\Store nurb nurb.hu6ka
[22.02.2009|21:52] C:\ProgramData\Store nurb nurb.hyz2t
[13.03.2009|02:42] C:\ProgramData\Store nurb nurb.i0wyps5
[16.03.2009|20:54] C:\ProgramData\Store nurb nurb.i10qn
[14.03.2009|16:26] C:\ProgramData\Store nurb nurb.i6vwz
[17.03.2009|07:06] C:\ProgramData\Store nurb nurb.iex35tw
[15.03.2009|19:56] C:\ProgramData\Store nurb nurb.ile41
[16.03.2009|19:05] C:\ProgramData\Store nurb nurb.ilhhsx
[16.03.2009|01:45] C:\ProgramData\Store nurb nurb.ilj16
[16.03.2009|05:46] C:\ProgramData\Store nurb nurb.im7aio
[17.06.2009|09:08] C:\ProgramData\Store nurb nurb.inwizx
[13.03.2009|04:53] C:\ProgramData\Store nurb nurb.iqqojc
[13.03.2009|10:42] C:\ProgramData\Store nurb nurb.ir6g0z
[22.02.2009|20:24] C:\ProgramData\Store nurb nurb.ir8ej
[28.02.2009|22:03] C:\ProgramData\Store nurb nurb.isnwi9
[13.03.2009|06:20] C:\ProgramData\Store nurb nurb.iumnjs
[01.03.2009|14:05] C:\ProgramData\Store nurb nurb.ixany7
[22.02.2009|14:13] C:\ProgramData\Store nurb nurb.ixq7xa4
[16.03.2009|20:32] C:\ProgramData\Store nurb nurb.izgp6
[01.03.2009|07:09] C:\ProgramData\Store nurb nurb.j29pisq
[11.03.2009|20:17] C:\ProgramData\Store nurb nurb.j60p1p4
[28.02.2009|17:20] C:\ProgramData\Store nurb nurb.j66kpwu
[14.03.2009|21:07] C:\ProgramData\Store nurb nurb.j7ysz6
[15.03.2009|14:07] C:\ProgramData\Store nurb nurb.j8qgxm
[15.03.2009|12:41] C:\ProgramData\Store nurb nurb.j9o4otm
[17.03.2009|19:45] C:\ProgramData\Store nurb nurb.ji9cl
[16.03.2009|00:18] C:\ProgramData\Store nurb nurb.jqzau
[13.03.2009|12:10] C:\ProgramData\Store nurb nurb.jsdpt
[17.03.2009|00:11] C:\ProgramData\Store nurb nurb.k1dk5
[12.03.2009|01:01] C:\ProgramData\Store nurb nurb.k98tul
[16.03.2009|16:10] C:\ProgramData\Store nurb nurb.kdcd8s
[16.03.2009|23:49] C:\ProgramData\Store nurb nurb.kn21swf
[15.03.2009|18:50] C:\ProgramData\Store nurb nurb.kp16oi
[13.03.2009|16:54] C:\ProgramData\Store nurb nurb.kub7m
[17.03.2009|06:44] C:\ProgramData\Store nurb nurb.kypd1
[12.03.2009|19:25] C:\ProgramData\Store nurb nurb.l1swgby
[12.03.2009|02:07] C:\ProgramData\Store nurb nurb.l4l8vr
[15.03.2009|22:07] C:\ProgramData\Store nurb nurb.la8vfr
[15.03.2009|22:51] C:\ProgramData\Store nurb nurb.lb1kkvg
[01.03.2009|13:43] C:\ProgramData\Store nurb nurb.lfj8ve3
[11.03.2009|19:12] C:\ProgramData\Store nurb nurb.ll7vemx
[22.02.2009|17:51] C:\ProgramData\Store nurb nurb.lrpiql
[16.03.2009|06:08] C:\ProgramData\Store nurb nurb.lrqos04
[15.03.2009|19:12] C:\ProgramData\Store nurb nurb.lxl67
[13.03.2009|15:05] C:\ProgramData\Store nurb nurb.lyvp9
[16.03.2009|04:40] C:\ProgramData\Store nurb nurb.mangmjf
[12.03.2009|01:23] C:\ProgramData\Store nurb nurb.mbcz7
[22.02.2009|17:08] C:\ProgramData\Store nurb nurb.mcz0ot6
[16.03.2009|03:35] C:\ProgramData\Store nurb nurb.melyh6p
[01.03.2009|00:15] C:\ProgramData\Store nurb nurb.mmirxo
[28.02.2009|18:47] C:\ProgramData\Store nurb nurb.mpqnyb
[14.03.2009|18:32] C:\ProgramData\Store nurb nurb.muwicq
[17.06.2009|08:02] C:\ProgramData\Store nurb nurb.mvlnx
[16.03.2009|13:15] C:\ProgramData\Store nurb nurb.mvuoeq
[14.03.2009|17:04] C:\ProgramData\Store nurb nurb.mwyq75v
[22.02.2009|15:18] C:\ProgramData\Store nurb nurb.n1f1l
[13.03.2009|09:59] C:\ProgramData\Store nurb nurb.n4kkm
[17.03.2009|02:22] C:\ProgramData\Store nurb nurb.n4pv7i
[14.03.2009|20:02] C:\ProgramData\Store nurb nurb.namrwnh
[16.03.2009|22:43] C:\ProgramData\Store nurb nurb.nh8cjbw
[01.03.2009|03:53] C:\ProgramData\Store nurb nurb.nl4js
[15.03.2009|19:34] C:\ProgramData\Store nurb nurb.nq7e4ah
[12.03.2009|00:39] C:\ProgramData\Store nurb nurb.ntbkg
[01.03.2009|13:21] C:\ProgramData\Store nurb nurb.nvdw7e6
[01.03.2009|04:37] C:\ProgramData\Store nurb nurb.nvryux
[14.03.2009|17:26] C:\ProgramData\Store nurb nurb.nx2vyb
[15.03.2009|08:17] C:\ProgramData\Store nurb nurb.o0kc8
[15.03.2009|22:29] C:\ProgramData\Store nurb nurb.o0rvwa8
[15.03.2009|21:45] C:\ProgramData\Store nurb nurb.o193g61
[15.03.2009|20:18] C:\ProgramData\Store nurb nurb.oa5zi
[13.03.2009|10:20] C:\ProgramData\Store nurb nurb.oelv4
[22.02.2009|16:02] C:\ProgramData\Store nurb nurb.ogmhv
[28.02.2009|19:31] C:\ProgramData\Store nurb nurb.oluti
[01.03.2009|11:32] C:\ProgramData\Store nurb nurb.orp55
[14.03.2009|18:10] C:\ProgramData\Store nurb nurb.oti6mi
[16.03.2009|20:10] C:\ProgramData\Store nurb nurb.otyd41p
[01.03.2009|08:15] C:\ProgramData\Store nurb nurb.oucdve8
[15.03.2009|21:01] C:\ProgramData\Store nurb nurb.p06k1c
[13.03.2009|18:22] C:\ProgramData\Store nurb nurb.p9kyuo6
[13.03.2009|01:58] C:\ProgramData\Store nurb nurb.pcmyn
[13.03.2009|08:53] C:\ProgramData\Store nurb nurb.pez5qq
[14.03.2009|21:29] C:\ProgramData\Store nurb nurb.pezej
[13.03.2009|15:26] C:\ProgramData\Store nurb nurb.pkqgzy
[22.02.2009|22:35] C:\ProgramData\Store nurb nurb.pkwzt
[01.03.2009|01:42] C:\ProgramData\Store nurb nurb.ppvdi
[17.03.2009|20:51] C:\ProgramData\Store nurb nurb.ps8bbv
[13.03.2009|03:47] C:\ProgramData\Store nurb nurb.pxcy1
[23.02.2009|00:46] C:\ProgramData\Store nurb nurb.pzbnxb
[15.03.2009|11:57] C:\ProgramData\Store nurb nurb.q3t1iz
[17.03.2009|17:19] C:\ProgramData\Store nurb nurb.q7omz
[23.02.2009|02:14] C:\ProgramData\Store nurb nurb.q899i
[01.03.2009|11:10] C:\ProgramData\Store nurb nurb.qagv8zc
[15.03.2009|09:01] C:\ProgramData\Store nurb nurb.qc6wp
[13.03.2009|13:37] C:\ProgramData\Store nurb nurb.qibk4rk
[13.03.2009|07:26] C:\ProgramData\Store nurb nurb.qm59vaa
[14.02.2009|10:56] C:\ProgramData\Store nurb nurb.qrsn65
[14.03.2009|19:40] C:\ProgramData\Store nurb nurb.r3xi62l
[16.03.2009|15:26] C:\ProgramData\Store nurb nurb.rd46fin
[16.03.2009|12:53] C:\ProgramData\Store nurb nurb.rjrezb
[16.03.2009|16:31] C:\ProgramData\Store nurb nurb.rn9vaf6
[16.03.2009|03:57] C:\ProgramData\Store nurb nurb.ro4h6ca
[16.03.2009|14:42] C:\ProgramData\Store nurb nurb.rs3hsdt
[13.03.2009|12:32] C:\ProgramData\Store nurb nurb.ru3moh
[15.03.2009|15:28] C:\ProgramData\Store nurb nurb.s08if
[13.03.2009|13:59] C:\ProgramData\Store nurb nurb.s1zttq
[28.02.2009|17:41] C:\ProgramData\Store nurb nurb.s55zq
[13.03.2009|04:09] C:\ProgramData\Store nurb nurb.s8yhdc6
[22.02.2009|17:29] C:\ProgramData\Store nurb nurb.scrk1zw
[01.03.2009|16:16] C:\ProgramData\Store nurb nurb.sh1a7
[28.02.2009|15:30] C:\ProgramData\Store nurb nurb.skm6cpq
[16.03.2009|05:02] C:\ProgramData\Store nurb nurb.t0oqlhf
[15.03.2009|13:45] C:\ProgramData\Store nurb nurb.tb6i87y
[15.03.2009|16:33] C:\ProgramData\Store nurb nurb.ty5t2t
[22.02.2009|23:41] C:\ProgramData\Store nurb nurb.u0hjs
[13.03.2009|11:48] C:\ProgramData\Store nurb nurb.u1sjj3
[12.03.2009|22:41] C:\ProgramData\Store nurb nurb.uaf5cx
[17.03.2009|03:27] C:\ProgramData\Store nurb nurb.ugkesq8
[28.02.2009|15:52] C:\ProgramData\Store nurb nurb.ulr64i2
[16.03.2009|23:05] C:\ProgramData\Store nurb nurb.ulvcq
[14.03.2009|19:18] C:\ProgramData\Store nurb nurb.un2tq28
[22.02.2009|18:57] C:\ProgramData\Store nurb nurb.uscn77m
[01.03.2009|01:20] C:\ProgramData\Store nurb nurb.usm9h
[15.03.2009|10:51] C:\ProgramData\Store nurb nurb.utvk5y
[12.03.2009|23:25] C:\ProgramData\Store nurb nurb.uvaq2cq
[16.03.2009|02:51] C:\ProgramData\Store nurb nurb.uvgas
[16.03.2009|16:53] C:\ProgramData\Store nurb nurb.uw3f3e
[13.03.2009|00:09] C:\ProgramData\Store nurb nurb.v1bjmo
[28.02.2009|23:53] C:\ProgramData\Store nurb nurb.v1v16
[17.03.2009|06:22] C:\ProgramData\Store nurb nurb.v37kwo
[16.03.2009|00:40] C:\ProgramData\Store nurb nurb.v4fvrr
[28.02.2009|21:20] C:\ProgramData\Store nurb nurb.v4g01
[13.03.2009|11:04] C:\ProgramData\Store nurb nurb.v4xbqj6
[01.03.2009|09:21] C:\ProgramData\Store nurb nurb.v72vf2
[17.03.2009|01:16] C:\ProgramData\Store nurb nurb.v8p1w2
[13.03.2009|12:53] C:\ProgramData\Store nurb nurb.v9jaglu
[01.03.2009|02:26] C:\ProgramData\Store nurb nurb.vduep5
[01.03.2009|03:31] C:\ProgramData\Store nurb nurb.vhh25
[13.03.2009|14:21] C:\ProgramData\Store nurb nurb.vlc68wc
[16.03.2009|13:58] C:\ProgramData\Store nurb nurb.vlivxa2
[01.03.2009|16:38] C:\ProgramData\Store nurb nurb.vn8vepz
[13.03.2009|06:42] C:\ProgramData\Store nurb nurb.vq8ayn
[28.02.2009|15:08] C:\ProgramData\Store nurb nurb.vxv73lx
[17.03.2009|18:39] C:\ProgramData\Store nurb nurb.w37zi
[13.03.2009|00:31] C:\ProgramData\Store nurb nurb.w9ozlsd
[22.02.2009|16:24] C:\ProgramData\Store nurb nurb.wc6ql
[28.02.2009|23:31] C:\ProgramData\Store nurb nurb.wh1wh
[16.03.2009|01:24] C:\ProgramData\Store nurb nurb.wj319
[28.02.2009|21:42] C:\ProgramData\Store nurb nurb.wldhkv7
[14.03.2009|18:56] C:\ProgramData\Store nurb nurb.wnfbo1
[12.03.2009|22:20] C:\ProgramData\Store nurb nurb.wslo50b
[17.03.2009|00:32] C:\ProgramData\Store nurb nurb.ww47yx3
[28.02.2009|18:03] C:\ProgramData\Store nurb nurb.wyyyvf
[19.04.2009|11:30] C:\ProgramData\Store nurb nurb.x21dh1
[14.03.2009|20:24] C:\ProgramData\Store nurb nurb.x598m
[01.03.2009|04:15] C:\ProgramData\Store nurb nurb.x5ulg
[01.03.2009|08:59] C:\ProgramData\Store nurb nurb.x7lvbs5
[23.02.2009|01:08] C:\ProgramData\Store nurb nurb.xex3udt
[16.03.2009|22:00] C:\ProgramData\Store nurb nurb.xh5j1
[17.03.2009|04:33] C:\ProgramData\Store nurb nurb.xjwo8
[17.03.2009|19:22] C:\ProgramData\Store nurb nurb.xkh7n
[22.02.2009|14:35] C:\ProgramData\Store nurb nurb.xl28rk
[22.02.2009|18:35] C:\ProgramData\Store nurb nurb.xs3wmph
[15.03.2009|23:56] C:\ProgramData\Store nurb nurb.xschv
[16.03.2009|07:13] C:\ProgramData\Store nurb nurb.xsg0gvf
[15.03.2009|17:17] C:\ProgramData\Store nurb nurb.xspbxnx
[16.03.2009|06:29] C:\ProgramData\Store nurb nurb.xtd1w
[12.03.2009|20:30] C:\ProgramData\Store nurb nurb.xvvjx4
[14.03.2009|17:48] C:\ProgramData\Store nurb nurb.y11d38f
[16.03.2009|19:27] C:\ProgramData\Store nurb nurb.y22wi
[12.03.2009|17:58] C:\ProgramData\Store nurb nurb.y2t7t
[12.03.2009|16:52] C:\ProgramData\Store nurb nurb.y9fs7b
[12.03.2009|23:47] C:\ProgramData\Store nurb nurb.ycxg90j
[13.03.2009|18:00] C:\ProgramData\Store nurb nurb.yepdek
[13.03.2009|07:47] C:\ProgramData\Store nurb nurb.yl5i0
[01.03.2009|12:15] C:\ProgramData\Store nurb nurb.yro65qh
[01.03.2009|06:48] C:\ProgramData\Store nurb nurb.yysgepm
[28.02.2009|20:14] C:\ProgramData\Store nurb nurb.z7yn8zq
[15.03.2009|21:23] C:\ProgramData\Store nurb nurb.zd69zhh
[01.03.2009|15:11] C:\ProgramData\Store nurb nurb.zea3w8t
[22.02.2009|22:13] C:\ProgramData\Store nurb nurb.zjcwlm
[14.03.2009|20:46] C:\ProgramData\Store nurb nurb.zjp0s
[13.03.2009|17:16] C:\ProgramData\Store nurb nurb.zqntk
[17.03.2009|05:38] C:\ProgramData\Store nurb nurb.zrn7f4v
[01.03.2009|02:04] C:\ProgramData\Store nurb nurb.ztzyxe
[07.06.2009|11:44] C:\ProgramData\Store nurb nurb.zw7gqc2
[16.03.2009|17:15] C:\ProgramData\Store nurb nurb.zwtr8r2
[01.05.2008|12:10] C:\ProgramData\SupportSoft
[12.12.2009|18:28] C:\ProgramData\Teleca
[20.09.2009|12:34] C:\ProgramData\TrackMania
[27.10.2009|15:42] C:\ProgramData\UAB
[01.05.2008|12:16] C:\ProgramData\Uninstall
[07.06.2009|11:44] C:\ProgramData\way rdr ford mpeg
[03.11.2008|16:45] C:\ProgramData\WindowsSearch
[06.05.2008|15:36] C:\ProgramData\WLInstaller

--------------------\\ Listing des dossiers dans C:\Program Files

[28.11.2009|10:07] C:\Program Files\Adobe
[04.07.2009|20:32] C:\Program Files\AdorageI-GfxDatas
[04.07.2009|20:30] C:\Program Files\AdorageI-SAL
[17.05.2009|07:11] C:\Program Files\adslTV
[13.07.2009|11:15] C:\Program Files\AdVantage
[15.08.2009|10:14] C:\Program Files\Any Audio Converter
[09.08.2008|08:06] C:\Program Files\Apple Software Update
[06.05.2008|11:55] C:\Program Files\AVG
[07.07.2009|11:43] C:\Program Files\BitDefender
[28.12.2009|14:22] C:\Program Files\Bonjour
[28.12.2009|14:02] C:\Program Files\Common Files
[01.05.2008|11:48] C:\Program Files\CONEXANT
[15.08.2009|09:44] C:\Program Files\Creative
[15.08.2009|09:45] C:\Program Files\Creative Live! Cam
[01.05.2008|12:12] C:\Program Files\CyberLink
[15.08.2009|09:44] C:\Program Files\Dell
[01.05.2008|12:10] C:\Program Files\Dell Support Center
[28.12.2009|14:22] C:\Program Files\DellTPad
[01.05.2008|11:59] C:\Program Files\Digital Line Detect
[08.11.2008|07:59] C:\Program Files\DivX
[02.11.2008|13:38] C:\Program Files\ESTsoft
[06.05.2008|11:31] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[29.09.2008|16:30] C:\Program Files\FileSubmit
[16.12.2009|20:46] C:\Program Files\GabbaSoft
[15.07.2009|09:50] C:\Program Files\Google
[23.08.2009|10:22] C:\Program Files\IKEA HomePlanner
[17.03.2009|18:27] C:\Program Files\Incomplete
[22.12.2009|15:03] C:\Program Files\InstallShield Installation Information
[01.05.2008|12:07] C:\Program Files\Intel
[01.05.2008|12:00] C:\Program Files\Intel, Inc
[01.06.2009|10:59] C:\Program Files\InterActual
[10.12.2009|19:13] C:\Program Files\Internet Explorer
[01.11.2009|11:09] C:\Program Files\iPod
[28.12.2009|14:22] C:\Program Files\iTunes
[17.11.2009|18:21] C:\Program Files\Java
[06.05.2008|16:38] C:\Program Files\Logitech
[02.11.2008|13:22] C:\Program Files\Micro Application
[19.03.2009|16:57] C:\Program Files\Microsoft
[11.12.2009|17:25] C:\Program Files\Microsoft Games
[17.06.2009|11:07] C:\Program Files\Microsoft Office
[27.09.2009|08:33] C:\Program Files\Microsoft Silverlight
[10.10.2008|14:39] C:\Program Files\Microsoft SQL Server
[19.03.2009|17:00] C:\Program Files\Microsoft SQL Server Compact Edition
[14.05.2009|19:03] C:\Program Files\Microsoft Sync Framework
[30.05.2009|08:42] C:\Program Files\Microsoft.NET
[06.09.2008|13:57] C:\Program Files\MixMeister EZ Vinyl Converter
[01.05.2008|11:58] C:\Program Files\Modem Diagnostic Tool
[15.10.2009|18:08] C:\Program Files\Movie Maker
[02.11.2006|13:37] C:\Program Files\MSBuild
[28.09.2008|08:03] C:\Program Files\MSXML 4.0
[12.09.2009|14:29] C:\Program Files\NCH Software
[01.05.2008|11:59] C:\Program Files\NetWaiting
[14.12.2009|20:39] C:\Program Files\NiwradSoft
[10.10.2008|14:43] C:\Program Files\Outsim
[28.03.2009|07:56] C:\Program Files\ParallelGraphics
[27.10.2009|15:41] C:\Program Files\PC Drivers HeadQuarters
[04.07.2009|19:21] C:\Program Files\Pinnacle
[28.12.2009|14:22] C:\Program Files\QuickTime
[07.12.2009|09:55] C:\Program Files\realtech VR
[02.11.2006|13:37] C:\Program Files\Reference Assemblies
[01.05.2008|12:16] C:\Program Files\Roxio
[28.12.2009|14:22] C:\Program Files\Search Settings
[01.05.2008|11:48] C:\Program Files\Sigmatel
[21.02.2009|12:22] C:\Program Files\Sony
[12.12.2009|18:29] C:\Program Files\Sony Ericsson
[17.06.2008|16:44] C:\Program Files\TEMP
[28.12.2009|14:17] C:\Program Files\trend micro
[10.10.2008|14:41] C:\Program Files\Uninstall Information
[16.09.2009|17:33] C:\Program Files\Utilitaire de configuration iPhone
[31.08.2008|12:23] C:\Program Files\VideoLAN
[28.06.2009|07:00] C:\Program Files\WIDCOMM
[15.10.2009|18:08] C:\Program Files\Windows Calendar
[15.10.2009|18:08] C:\Program Files\Windows Collaboration
[28.12.2009|14:22] C:\Program Files\Windows Defender
[15.10.2009|18:08] C:\Program Files\Windows Journal
[14.11.2009|13:09] C:\Program Files\Windows Live
[10.05.2009|11:46] C:\Program Files\Windows Live Safety Center
[19.03.2009|16:57] C:\Program Files\Windows Live SkyDrive
[10.12.2009|19:13] C:\Program Files\Windows Mail
[28.06.2009|08:48] C:\Program Files\Windows Media Components
[28.12.2009|14:22] C:\Program Files\Windows Media Player
[06.05.2008|11:31] C:\Program Files\Windows NT
[15.10.2009|18:08] C:\Program Files\Windows Photo Gallery
[18.11.2009|03:25] C:\Program Files\Windows Portable Devices
[14.12.2009|20:44] C:\Program Files\Windows Sidebar
[04.11.2008|17:33] C:\Program Files\WMV9_VCM
[08.12.2009|13:13] C:\Program Files\Xvid
[21.02.2009|16:25] C:\Program Files\Yahoo!

--------------------\\ Listing des dossiers dans C:\Program Files\Common Files

[28.11.2009|10:07] C:\Program Files\Common Files\Adobe
[16.12.2009|19:51] C:\Program Files\Common Files\Adobe AIR
[01.11.2009|11:09] C:\Program Files\Common Files\Apple
[22.02.2009|13:57] C:\Program Files\Common Files\AVSMedia
[07.07.2009|11:44] C:\Program Files\Common Files\BitDefender
[17.06.2009|11:25] C:\Program Files\Common Files\DESIGNER
[14.12.2009|16:58] C:\Program Files\Common Files\InstallShield
[01.05.2008|11:58] C:\Program Files\Common Files\Java
[21.10.2008|11:36] C:\Program Files\Common Files\Logishrd
[20.02.2009|16:37] C:\Program Files\Common Files\Logitech
[17.06.2009|11:25] C:\Program Files\Common Files\microsoft shared
[28.03.2009|07:56] C:\Program Files\Common Files\ParallelGraphics
[01.05.2008|12:15] C:\Program Files\Common Files\PX Storage Engine
[01.05.2008|12:01] C:\Program Files\Common Files\Reallusion
[04.11.2008|17:33] C:\Program Files\Common Files\River Past
[01.05.2008|12:15] C:\Program Files\Common Files\Roxio Shared
[02.11.2006|12:18] C:\Program Files\Common Files\Services
[01.05.2008|12:15] C:\Program Files\Common Files\Sonic Shared
[12.12.2009|18:28] C:\Program Files\Common Files\Sony Ericsson Shared
[02.11.2006|12:18] C:\Program Files\Common Files\SpeechEngines
[01.05.2008|12:10] C:\Program Files\Common Files\supportsoft
[28.12.2009|14:22] C:\Program Files\Common Files\SureThing Shared
[29.03.2009|13:01] C:\Program Files\Common Files\SWF Studio
[15.10.2009|18:08] C:\Program Files\Common Files\System
[12.12.2009|18:28] C:\Program Files\Common Files\Teleca Shared
[19.03.2009|16:51] C:\Program Files\Common Files\Windows Live
[06.05.2008|15:42] C:\Program Files\Common Files\WindowsLiveInstaller
[20.09.2009|08:32] C:\Program Files\Common Files\Wise Installation Wizard
[29.06.2009|18:43] C:\Program Files\Common Files\Yahoo!

--------------------\\ Process

( 85 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

C:\ProgramData\Store nurb nurb.0ngyl
C:\ProgramData\Store nurb nurb.1r627
C:\ProgramData\Store nurb nurb.1s62i
C:\ProgramData\Store nurb nurb.1tla2
C:\ProgramData\Store nurb nurb.20bv8
C:\ProgramData\Store nurb nurb.28ut6
C:\ProgramData\Store nurb nurb.2cd1n
C:\ProgramData\Store nurb nurb.2j6a3
C:\ProgramData\Store nurb nurb.2qj40
C:\ProgramData\Store nurb nurb.3c6h7
C:\ProgramData\Store nurb nurb.3ddcm
C:\ProgramData\Store nurb nurb.3ghdc
C:\ProgramData\Store nurb nurb.3inux
C:\ProgramData\Store nurb nurb.40tff
C:\ProgramData\Store nurb nurb.4f82x
C:\ProgramData\Store nurb nurb.4r9k7
C:\ProgramData\Store nurb nurb.4zkoh
C:\ProgramData\Store nurb nurb.62pyw
C:\ProgramData\Store nurb nurb.7mhcr
C:\ProgramData\Store nurb nurb.7svyp
C:\ProgramData\Store nurb nurb.7u4wo
C:\ProgramData\Store nurb nurb.8iktr
C:\ProgramData\Store nurb nurb.8se6b
C:\ProgramData\Store nurb nurb.8vr9p
C:\ProgramData\Store nurb nurb.9gbsl
C:\ProgramData\Store nurb nurb.9nqb5
C:\ProgramData\Store nurb nurb.9wkny
C:\ProgramData\Store nurb nurb.bbvj1
C:\ProgramData\Store nurb nurb.bs5pl
C:\ProgramData\Store nurb nurb.ca1te
C:\ProgramData\Store nurb nurb.ccf9c
C:\ProgramData\Store nurb nurb.cfpjv
C:\ProgramData\Store nurb nurb.cl9hb
C:\ProgramData\Store nurb nurb.d2hrr
C:\ProgramData\Store nurb nurb.dnhh3
C:\ProgramData\Store nurb nurb.erpnq
C:\ProgramData\Store nurb nurb.ew05l
C:\ProgramData\Store nurb nurb.ft0m5
C:\ProgramData\Store nurb nurb.fxkh0
C:\ProgramData\Store nurb nurb.g58w6
C:\ProgramData\Store nurb nurb.g84r8
C:\ProgramData\Store nurb nurb.gj5cv
C:\ProgramData\Store nurb nurb.gpeyf
C:\ProgramData\Store nurb nurb.gqkyf
C:\ProgramData\Store nurb nurb.gw282
C:\ProgramData\Store nurb nurb.h2m3s
C:\ProgramData\Store nurb nurb.ha3f8
C:\ProgramData\Store nurb nurb.hgm4p
C:\ProgramData\Store nurb nurb.hjy6z
C:\ProgramData\Store nurb nurb.hrawc
C:\ProgramData\Store nurb nurb.hsi9n
C:\ProgramData\Store nurb nurb.hu6ka
C:\ProgramData\Store nurb nurb.hyz2t
C:\ProgramData\Store nurb nurb.i10qn
C:\ProgramData\Store nurb nurb.i6vwz
C:\ProgramData\Store nurb nurb.ile41
C:\ProgramData\Store nurb nurb.ilj16
C:\ProgramData\Store nurb nurb.ir8ej
C:\ProgramData\Store nurb nurb.izgp6
C:\ProgramData\Store nurb nurb.ji9cl
C:\ProgramData\Store nurb nurb.jqzau
C:\ProgramData\Store nurb nurb.jsdpt
C:\ProgramData\Store nurb nurb.k1dk5
C:\ProgramData\Store nurb nurb.kub7m
C:\ProgramData\Store nurb nurb.kypd1
C:\ProgramData\Store nurb nurb.lxl67
C:\ProgramData\Store nurb nurb.lyvp9
C:\ProgramData\Store nurb nurb.mbcz7
C:\ProgramData\Store nurb nurb.mvlnx
C:\ProgramData\Store nurb nurb.n1f1l
C:\ProgramData\Store nurb nurb.n4kkm
C:\ProgramData\Store nurb nurb.nl4js
C:\ProgramData\Store nurb nurb.ntbkg
C:\ProgramData\Store nurb nurb.o0kc8
C:\ProgramData\Store nurb nurb.oa5zi
C:\ProgramData\Store nurb nurb.oelv4
C:\ProgramData\Store nurb nurb.ogmhv
C:\ProgramData\Store nurb nurb.oluti
C:\ProgramData\Store nurb nurb.orp55
C:\ProgramData\Store nurb nurb.pcmyn
C:\ProgramData\Store nurb nurb.pezej
C:\ProgramData\Store nurb nurb.pkwzt
C:\ProgramData\Store nurb nurb.ppvdi
C:\ProgramData\Store nurb nurb.pxcy1
C:\ProgramData\Store nurb nurb.q7omz
C:\ProgramData\Store nurb nurb.q899i
C:\ProgramData\Store nurb nurb.qc6wp
C:\ProgramData\Store nurb nurb.s08if
C:\ProgramData\Store nurb nurb.s55zq
C:\ProgramData\Store nurb nurb.sh1a7
C:\ProgramData\Store nurb nurb.u0hjs
C:\ProgramData\Store nurb nurb.ulvcq
C:\ProgramData\Store nurb nurb.usm9h
C:\ProgramData\Store nurb nurb.uvgas
C:\ProgramData\Store nurb nurb.v1v16
C:\ProgramData\Store nurb nurb.v4g01
C:\ProgramData\Store nurb nurb.vhh25
C:\ProgramData\Store nurb nurb.w37zi
C:\ProgramData\Store nurb nurb.wc6ql
C:\ProgramData\Store nurb nurb.wh1wh
C:\ProgramData\Store nurb nurb.wj319
C:\ProgramData\Store nurb nurb.x598m
C:\ProgramData\Store nurb nurb.x5ulg
C:\ProgramData\Store nurb nurb.xh5j1
C:\ProgramData\Store nurb nurb.xjwo8
C:\ProgramData\Store nurb nurb.xkh7n
C:\ProgramData\Store nurb nurb.xschv
C:\ProgramData\Store nurb nurb.xtd1w
C:\ProgramData\Store nurb nurb.y22wi
C:\ProgramData\Store nurb nurb.y2t7t
C:\ProgramData\Store nurb nurb.yl5i0
C:\ProgramData\Store nurb nurb.zjp0s
C:\ProgramData\Store nurb nurb.zqntk
C:\ProgramData\Store nurb nurb.0t9zsj
C:\ProgramData\Store nurb nurb.0x93w7
C:\ProgramData\Store nurb nurb.1155s1
C:\ProgramData\Store nurb nurb.15r2ui
C:\ProgramData\Store nurb nurb.2ixbjz
C:\ProgramData\Store nurb nurb.2nz2vm
C:\ProgramData\Store nurb nurb.2qd251
C:\ProgramData\Store nurb nurb.3adtql
C:\ProgramData\Store nurb nurb.3m18xv
C:\ProgramData\Store nurb nurb.3mbimt
C:\ProgramData\Store nurb nurb.3p1vkz
C:\ProgramData\Store nurb nurb.3rhn8r
C:\ProgramData\Store nurb nurb.3z74wz
C:\ProgramData\Store nurb nurb.4b4m3y
C:\ProgramData\Store nurb nurb.4bwkht
C:\ProgramData\Store nurb nurb.5960ph
C:\ProgramData\Store nurb nurb.5gsqe8
C:\ProgramData\Store nurb nurb.6iak5v
C:\ProgramData\Store nurb nurb.6lkhyt
C:\ProgramData\Store nurb nurb.6m64vs
C:\ProgramData\Store nurb nurb.6wjzdq
C:\ProgramData\Store nurb nurb.6y9e65
C:\ProgramData\Store nurb nurb.73g0b8
C:\ProgramData\Store nurb nurb.7ipam8
C:\ProgramData\Store nurb nurb.7ldybi
C:\ProgramData\Store nurb nurb.7rdg5q
C:\ProgramData\Store nurb nurb.80py4q
C:\ProgramData\Store nurb nurb.9x1x32
C:\ProgramData\Store nurb nurb.a3n4lu
C:\ProgramData\Store nurb nurb.alic6s
C:\ProgramData\Store nurb nurb.atckpu
C:\ProgramData\Store nurb nurb.auamq4
C:\ProgramData\Store nurb nurb.c6x8sr
C:\ProgramData\Store nurb nurb.c7nlul
C:\ProgramData\Store nurb nurb.ccq177
C:\ProgramData\Store nurb nurb.cdkxpw
C:\ProgramData\Store nurb nurb.cjvc6f
C:\ProgramData\Store nurb nurb.cwos1i
C:\ProgramData\Store nurb nurb.d0kv4m
C:\ProgramData\Store nurb nurb.d17dte
C:\ProgramData\Store nurb nurb.d5c6yh
C:\ProgramData\Store nurb nurb.d5iqm7
C:\ProgramData\Store nurb nurb.dc7orz
C:\ProgramData\Store nurb nurb.eog3hf
C:\ProgramData\Store nurb nurb.eyupl6
C:\ProgramData\Store nurb nurb.f4udzs
C:\ProgramData\Store nurb nurb.fbjqm2
C:\ProgramData\Store nurb nurb.fc464z
C:\ProgramData\Store nurb nurb.flpahe
C:\ProgramData\Store nurb nurb.frk5ci
C:\ProgramData\Store nurb nurb.fzvi3v
C:\ProgramData\Store nurb nurb.g24xve
C:\ProgramData\Store nurb nurb.g2ti2h
C:\ProgramData\Store nurb nurb.ginxg5
C:\ProgramData\Store nurb nurb.gjyu4c
C:\ProgramData\Store nurb nurb.glp1oc
C:\ProgramData\Store nurb nurb.grxj69
C:\ProgramData\Store nurb nurb.gx7t5d
C:\ProgramData\Store nurb nurb.h0rz7k
C:\ProgramData\Store nurb nurb.h6053l
C:\ProgramData\Store nurb nurb.hcfrl8
C:\ProgramData\Store nurb nurb.hiraav
C:\ProgramData\Store nurb nurb.ilhhsx
C:\ProgramData\Store nurb nurb.im7aio
C:\ProgramData\Store nurb nurb.inwizx
C:\ProgramData\Store nurb nurb.iqqojc
C:\ProgramData\Store nurb nurb.ir6g0z
C:\ProgramData\Store nurb nurb.isnwi9
C:\ProgramData\Store nurb nurb.iumnjs
C:\ProgramData\Store nurb nurb.ixany7
C:\ProgramData\Store nurb nurb.j7ysz6
C:\ProgramData\Store nurb nurb.j8qgxm
C:\ProgramData\Store nurb nurb.k98tul
C:\ProgramData\Store nurb nurb.kdcd8s
C:\ProgramData\Store nurb nurb.kp16oi
C:\ProgramData\Store nurb nurb.l4l8vr
C:\ProgramData\Store nurb nurb.la8vfr
C:\ProgramData\Store nurb nurb.lrpiql
C:\ProgramData\Store nurb nurb.mmirxo
C:\ProgramData\Store nurb nurb.mpqnyb
C:\ProgramData\Store nurb nurb.muwicq
C:\ProgramData\Store nurb nurb.mvuoeq
C:\ProgramData\Store nurb nurb.n4pv7i
C:\ProgramData\Store nurb nurb.nvryux
C:\ProgramData\Store nurb nurb.nx2vyb
C:\ProgramData\Store nurb nurb.oti6mi
C:\ProgramData\Store nurb nurb.p06k1c
C:\ProgramData\Store nurb nurb.pez5qq
C:\ProgramData\Store nurb nurb.pkqgzy
C:\ProgramData\Store nurb nurb.ps8bbv
C:\ProgramData\Store nurb nurb.pzbnxb
C:\ProgramData\Store nurb nurb.q3t1iz
C:\ProgramData\Store nurb nurb.qrsn65
C:\ProgramData\Store nurb nurb.rjrezb
C:\ProgramData\Store nurb nurb.ru3moh
C:\ProgramData\Store nurb nurb.s1zttq
C:\ProgramData\Store nurb nurb.ty5t2t
C:\ProgramData\Store nurb nurb.u1sjj3
C:\ProgramData\Store nurb nurb.uaf5cx
C:\ProgramData\Store nurb nurb.utvk5y
C:\ProgramData\Store nurb nurb.uw3f3e
C:\ProgramData\Store nurb nurb.v1bjmo
C:\ProgramData\Store nurb nurb.v37kwo
C:\ProgramData\Store nurb nurb.v4fvrr
C:\ProgramData\Store nurb nurb.v72vf2
C:\ProgramData\Store nurb nurb.v8p1w2
C:\ProgramData\Store nurb nurb.vduep5
C:\ProgramData\Store nurb nurb.vq8ayn
C:\ProgramData\Store nurb nurb.wnfbo1
C:\ProgramData\Store nurb nurb.wyyyvf
C:\ProgramData\Store nurb nurb.x21dh1
C:\ProgramData\Store nurb nurb.xl28rk
C:\ProgramData\Store nurb nurb.xvvjx4
C:\ProgramData\Store nurb nurb.y9fs7b
C:\ProgramData\Store nurb nurb.yepdek
C:\ProgramData\Store nurb nurb.zjcwlm
C:\ProgramData\Store nurb nurb.ztzyxe
C:\ProgramData\Store nurb nurb.1ce103w
C:\ProgramData\Store nurb nurb.1jrasmq
C:\ProgramData\Store nurb nurb.33xmcyh
C:\ProgramData\Store nurb nurb.3gk5j76
C:\ProgramData\Store nurb nurb.3mjndr8
C:\ProgramData\Store nurb nurb.45bxah0
C:\ProgramData\Store nurb nurb.4cbaaft
C:\ProgramData\Store nurb nurb.4qq5giq
C:\ProgramData\Store nurb nurb.4tzrbon
C:\ProgramData\Store nurb nurb.4xrvqhz
C:\ProgramData\Store nurb nurb.53mg9ji
C:\ProgramData\Store nurb nurb.575bzdo
C:\ProgramData\Store nurb nurb.5tr3ed2
C:\ProgramData\Store nurb nurb.5z1scis
C:\ProgramData\Store nurb nurb.5zule6r
C:\ProgramData\Store nurb nurb.6ntribf
C:\ProgramData\Store nurb nurb.6p8dpfb
C:\ProgramData\Store nurb nurb.6sdf7fj
C:\ProgramData\Store nurb nurb.7aamm9v
C:\ProgramData\Store nurb nurb.7brz4ii
C:\ProgramData\Store nurb nurb.7fd1yet
C:\ProgramData\Store nurb nurb.7smiflq
C:\ProgramData\Store nurb nurb.8dmo95b
C:\ProgramData\Store nurb nurb.8x5o3w0
C:\ProgramData\Store nurb nurb.978a7fc
C:\ProgramData\Store nurb nurb.9dma69g
C:\ProgramData\Store nurb nurb.9leqwu0
C:\ProgramData\Store nurb nurb.9txhuc3
C:\ProgramData\Store nurb nurb.9uu9v0i
C:\ProgramData\Store nurb nurb.a892npm
C:\ProgramData\Store nurb nurb.aihd736
C:\ProgramData\Store nurb nurb.aiwdwa0
C:\ProgramData\Store nurb nurb.avj2em7
C:\ProgramData\Store nurb nurb.ay3h917
C:\ProgramData\Store nurb nurb.bklszzs
C:\ProgramData\Store nurb nurb.bp2rlp0
C:\ProgramData\Store nurb nurb.btnizxi
C:\ProgramData\Store nurb nurb.byq4l9h
C:\ProgramData\Store nurb nurb.cgsldh9
C:\ProgramData\Store nurb nurb.cjtb7rp
C:\ProgramData\Store nurb nurb.dcn97ai
C:\ProgramData\Store nurb nurb.dqt4unt
C:\ProgramData\Store nurb nurb.ec007a6
C:\ProgramData\Store nurb nurb.ffhi1zj
C:\ProgramData\Store nurb nurb.fxhm6l0
C:\ProgramData\Store nurb nurb.fxq1z8g
C:\ProgramData\Store nurb nurb.g9y81wd
C:\ProgramData\Store nurb nurb.gx0ilpl
C:\ProgramData\Store nurb nurb.gx4vurk
C:\ProgramData\Store nurb nurb.h3a26p9
C:\ProgramData\Store nurb nurb.hfk0l7d
C:\ProgramData\Store nurb nurb.hom2pw8
C:\ProgramData\Store nurb nurb.i0wyps5
C:\ProgramData\Store nurb nurb.iex35tw
C:\ProgramData\Store nurb nurb.ixq7xa4
C:\ProgramData\Store nurb nurb.j29pisq
C:\ProgramData\Store nurb nurb.j60p1p4
C:\ProgramData\Store nurb nurb.j66kpwu
C:\ProgramData\Store nurb nurb.j9o4otm
C:\ProgramData\Store nurb nurb.kn21swf
C:\ProgramData\Store nurb nurb.l1swgby
C:\ProgramData\Store nurb nurb.lb1kkvg
C:\ProgramData\Store nurb nurb.lfj8ve3
C:\ProgramData\Store nurb nurb.ll7vemx
C:\ProgramData\Store nurb nurb.lrqos04
C:\ProgramData\Store nurb nurb.mangmjf
C:\ProgramData\Store nurb nurb.mcz0ot6
C:\ProgramData\Store nurb nurb.melyh6p
C:\ProgramData\Store nurb nurb.mwyq75v
C:\ProgramData\Store nurb nurb.namrwnh
C:\ProgramData\Store nurb nurb.nh8cjbw
C:\ProgramData\Store nurb nurb.nq7e4ah
C:\ProgramData\Store nurb nurb.nvdw7e6
C:\ProgramData\Store nurb nurb.o0rvwa8
C:\ProgramData\Store nurb nurb.o193g61
C:\ProgramData\Store nurb nurb.otyd41p
C:\ProgramData\Store nurb nurb.oucdve8
C:\ProgramData\Store nurb nurb.p9kyuo6
C:\ProgramData\Store nurb nurb.qagv8zc
C:\ProgramData\Store nurb nurb.qibk4rk
C:\ProgramData\Store nurb nurb.qm59vaa
C:\ProgramData\Store nurb nurb.r3xi62l
C:\ProgramData\Store nurb nurb.rd46fin
C:\ProgramData\Store nurb nurb.rn9vaf6
C:\ProgramData\Store nurb nurb.ro4h6ca
C:\ProgramData\Store nurb nurb.rs3hsdt
C:\ProgramData\Store nurb nurb.s8yhdc6
C:\ProgramData\Store nurb nurb.scrk1zw
C:\ProgramData\Store nurb nurb.skm6cpq
C:\ProgramData\Store nurb nurb.t0oqlhf
C:\ProgramData\Store nurb nurb.tb6i87y
C:\ProgramData\Store nurb nurb.ugkesq8
C:\ProgramData\Store nurb nurb.ulr64i2
C:\ProgramData\Store nurb nurb.un2tq28
C:\ProgramData\Store nurb nurb.uscn77m
C:\ProgramData\Store nurb nurb.uvaq2cq
C:\ProgramData\Store nurb nurb.v4xbqj6
C:\ProgramData\Store nurb nurb.v9jaglu
C:\ProgramData\Store nurb nurb.vlc68wc
C:\ProgramData\Store nurb nurb.vlivxa2
C:\ProgramData\Store nurb nurb.vn8vepz
C:\ProgramData\Store nurb nurb.vxv73lx
C:\ProgramData\Store nurb nurb.w9ozlsd
C:\ProgramData\Store nurb nurb.wldhkv7
C:\ProgramData\Store nurb nurb.wslo50b
C:\ProgramData\Store nurb nurb.ww47yx3
C:\ProgramData\Store nurb nurb.x7lvbs5
C:\ProgramData\Store nurb nurb.xex3udt
C:\ProgramData\Store nurb nurb.xs3wmph
C:\ProgramData\Store nurb nurb.xsg0gvf
C:\ProgramData\Store nurb nurb.xspbxnx
C:\ProgramData\Store nurb nurb.y11d38f
C:\ProgramData\Store nurb nurb.ycxg90j
C:\ProgramData\Store nurb nurb.yro65qh
C:\ProgramData\Store nurb nurb.yysgepm
C:\ProgramData\Store nurb nurb.z7yn8zq
C:\ProgramData\Store nurb nurb.zd69zhh
C:\ProgramData\Store nurb nurb.zea3w8t
C:\ProgramData\Store nurb nurb.zrn7f4v
C:\ProgramData\Store nurb nurb.zw7gqc2
C:\ProgramData\Store nurb nurb.zwtr8r2

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\ProgramData\way rdr ford mpeg
C:\Users\Lucas\AppData\Local\Temp\nsrDB80.tmp
C:\Users\Lucas\AppData\Roaming\MICROS~1\Windows\Cookies\lucas@ero-advertising[2].txt

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Chin Five"="\"C:\\ProgramData\\Store nurb nurb.inwizx\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Chin Five"="\"C:\\ProgramData\\Store nurb nurb.ps8bbv\""

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-28 14:53:52
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
C:\Users\Lucas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I6I3EHG7\st[3] 4517 bytes
scan completed successfully
hidden processes: 0
hidden files: 36

--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !

[F:155][D:50]-> C:\Users\Lucas\AppData\Local\Temp
[F:335][D:1]-> C:\Users\Lucas\AppData\Roaming\MICROS~1\Windows\Cookies
[F:202][D:9]-> C:\Users\Lucas\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:84][D:2]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 28.12.2009|14:57 - Option : [1]

--------------------\\ Fin du rapport a 14:57:02
[ UAC => 1 ]
0
verni29 Messages postés 6699 Date d'inscription dimanche 6 juillet 2008 Statut Contributeur sécurité Dernière intervention 26 décembre 2016 180
28 déc. 2009 à 15:14
Re,

On attrape cette infection via des bannières de publicités sur des pages Webs ou en installant certains logiciels comme :
* BitDownload
* BitGrabber
* BitRoll
* MessengerPlus! 3 sous le nom de sponsors
* Messenger Plus! Live sous le nom de sponsors
* NetPumper
* TorrentQ
* Torrent101


--------------------------------------------------------------------------------------------

* Relance le logiciel LopS&D en tant qu’administrateur. ( click droit sur le raccouci et choisis Exécuter en tant qu’administrateur )
* Choisis l'option 3 pour supprimer l'infection.
* Après redémarrage, choisis ton compte et laisse le logiciel travailler.

A la fin du nettoyage, un rapport LopR.txt apparait. Il se trouve en C:\LopR.txt.

A+
0
laromande Messages postés 168 Date d'inscription jeudi 23 octobre 2008 Statut Membre Dernière intervention 29 mai 2011 20
28 déc. 2009 à 15:43
--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A11
USER : Lucas ( Not Administrator ! )
BOOT : Normal boot
Antivirus : Bitdefender Antivirus 8.0 (Activated)
Firewall : Bitdefender Firewall 8.0 (Activated)
C:\ (Local Disk) - NTFS - Total:130 Go (Free:83 Go)
D:\ (Local Disk) - NTFS - Total:9 Go (Free:5 Go)
E:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [3] ( 28.12.2009|15:28 )

[ UAC => 1 ]


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\Users\Lucas\AppData\Local\Temp\nsrDB80.tmp
Supprime! - C:\Users\Lucas\AppData\Roaming\MICROS~1\Windows\Cookies\lucas@ero-advertising[2].txt
Supprime! - C:\ProgramData\Store nurb nurb.0ngyl
Supprime! - C:\ProgramData\Store nurb nurb.1r627
Supprime! - C:\ProgramData\Store nurb nurb.1s62i
Supprime! - C:\ProgramData\Store nurb nurb.1tla2
Supprime! - C:\ProgramData\Store nurb nurb.20bv8
Supprime! - C:\ProgramData\Store nurb nurb.28ut6
Supprime! - C:\ProgramData\Store nurb nurb.2cd1n
Supprime! - C:\ProgramData\Store nurb nurb.2j6a3
Supprime! - C:\ProgramData\Store nurb nurb.2qj40
Supprime! - C:\ProgramData\Store nurb nurb.3c6h7
Supprime! - C:\ProgramData\Store nurb nurb.3ddcm
Supprime! - C:\ProgramData\Store nurb nurb.3ghdc
Supprime! - C:\ProgramData\Store nurb nurb.3inux
Supprime! - C:\ProgramData\Store nurb nurb.40tff
Supprime! - C:\ProgramData\Store nurb nurb.4f82x
Supprime! - C:\ProgramData\Store nurb nurb.4r9k7
Supprime! - C:\ProgramData\Store nurb nurb.4zkoh
Supprime! - C:\ProgramData\Store nurb nurb.62pyw
Supprime! - C:\ProgramData\Store nurb nurb.7mhcr
Supprime! - C:\ProgramData\Store nurb nurb.7svyp
Supprime! - C:\ProgramData\Store nurb nurb.7u4wo
Supprime! - C:\ProgramData\Store nurb nurb.8iktr
Supprime! - C:\ProgramData\Store nurb nurb.8se6b
Supprime! - C:\ProgramData\Store nurb nurb.8vr9p
Supprime! - C:\ProgramData\Store nurb nurb.9gbsl
Supprime! - C:\ProgramData\Store nurb nurb.9nqb5
Supprime! - C:\ProgramData\Store nurb nurb.9wkny
Supprime! - C:\ProgramData\Store nurb nurb.bbvj1
Supprime! - C:\ProgramData\Store nurb nurb.bs5pl
Supprime! - C:\ProgramData\Store nurb nurb.ca1te
Supprime! - C:\ProgramData\Store nurb nurb.ccf9c
Supprime! - C:\ProgramData\Store nurb nurb.cfpjv
Supprime! - C:\ProgramData\Store nurb nurb.cl9hb
Supprime! - C:\ProgramData\Store nurb nurb.d2hrr
Supprime! - C:\ProgramData\Store nurb nurb.dnhh3
Supprime! - C:\ProgramData\Store nurb nurb.erpnq
Supprime! - C:\ProgramData\Store nurb nurb.ew05l
Supprime! - C:\ProgramData\Store nurb nurb.ft0m5
Supprime! - C:\ProgramData\Store nurb nurb.fxkh0
Supprime! - C:\ProgramData\Store nurb nurb.g58w6
Supprime! - C:\ProgramData\Store nurb nurb.g84r8
Supprime! - C:\ProgramData\Store nurb nurb.gj5cv
Supprime! - C:\ProgramData\Store nurb nurb.gpeyf
Supprime! - C:\ProgramData\Store nurb nurb.gqkyf
Supprime! - C:\ProgramData\Store nurb nurb.gw282
Supprime! - C:\ProgramData\Store nurb nurb.h2m3s
Supprime! - C:\ProgramData\Store nurb nurb.ha3f8
Supprime! - C:\ProgramData\Store nurb nurb.hgm4p
Supprime! - C:\ProgramData\Store nurb nurb.hjy6z
Supprime! - C:\ProgramData\Store nurb nurb.hrawc
Supprime! - C:\ProgramData\Store nurb nurb.hsi9n
Supprime! - C:\ProgramData\Store nurb nurb.hu6ka
Supprime! - C:\ProgramData\Store nurb nurb.hyz2t
Supprime! - C:\ProgramData\Store nurb nurb.i10qn
Supprime! - C:\ProgramData\Store nurb nurb.i6vwz
Supprime! - C:\ProgramData\Store nurb nurb.ile41
Supprime! - C:\ProgramData\Store nurb nurb.ilj16
Supprime! - C:\ProgramData\Store nurb nurb.ir8ej
Supprime! - C:\ProgramData\Store nurb nurb.izgp6
Supprime! - C:\ProgramData\Store nurb nurb.ji9cl
Supprime! - C:\ProgramData\Store nurb nurb.jqzau
Supprime! - C:\ProgramData\Store nurb nurb.jsdpt
Supprime! - C:\ProgramData\Store nurb nurb.k1dk5
Supprime! - C:\ProgramData\Store nurb nurb.kub7m
Supprime! - C:\ProgramData\Store nurb nurb.kypd1
Supprime! - C:\ProgramData\Store nurb nurb.lxl67
Supprime! - C:\ProgramData\Store nurb nurb.lyvp9
Supprime! - C:\ProgramData\Store nurb nurb.mbcz7
Supprime! - C:\ProgramData\Store nurb nurb.mvlnx
Supprime! - C:\ProgramData\Store nurb nurb.n1f1l
Supprime! - C:\ProgramData\Store nurb nurb.n4kkm
Supprime! - C:\ProgramData\Store nurb nurb.nl4js
Supprime! - C:\ProgramData\Store nurb nurb.ntbkg
Supprime! - C:\ProgramData\Store nurb nurb.o0kc8
Supprime! - C:\ProgramData\Store nurb nurb.oa5zi
Supprime! - C:\ProgramData\Store nurb nurb.oelv4
Supprime! - C:\ProgramData\Store nurb nurb.ogmhv
Supprime! - C:\ProgramData\Store nurb nurb.oluti
Supprime! - C:\ProgramData\Store nurb nurb.orp55
Supprime! - C:\ProgramData\Store nurb nurb.pcmyn
Supprime! - C:\ProgramData\Store nurb nurb.pezej
Supprime! - C:\ProgramData\Store nurb nurb.pkwzt
Supprime! - C:\ProgramData\Store nurb nurb.ppvdi
Supprime! - C:\ProgramData\Store nurb nurb.pxcy1
Supprime! - C:\ProgramData\Store nurb nurb.q7omz
Supprime! - C:\ProgramData\Store nurb nurb.q899i
Supprime! - C:\ProgramData\Store nurb nurb.qc6wp
Supprime! - C:\ProgramData\Store nurb nurb.s08if
Supprime! - C:\ProgramData\Store nurb nurb.s55zq
Supprime! - C:\ProgramData\Store nurb nurb.sh1a7
Supprime! - C:\ProgramData\Store nurb nurb.u0hjs
Supprime! - C:\ProgramData\Store nurb nurb.ulvcq
Supprime! - C:\ProgramData\Store nurb nurb.usm9h
Supprime! - C:\ProgramData\Store nurb nurb.uvgas
Supprime! - C:\ProgramData\Store nurb nurb.v1v16
Supprime! - C:\ProgramData\Store nurb nurb.v4g01
Supprime! - C:\ProgramData\Store nurb nurb.vhh25
Supprime! - C:\ProgramData\Store nurb nurb.w37zi
Supprime! - C:\ProgramData\Store nurb nurb.wc6ql
Supprime! - C:\ProgramData\Store nurb nurb.wh1wh
Supprime! - C:\ProgramData\Store nurb nurb.wj319
Supprime! - C:\ProgramData\Store nurb nurb.x598m
Supprime! - C:\ProgramData\Store nurb nurb.x5ulg
Supprime! - C:\ProgramData\Store nurb nurb.xh5j1
Supprime! - C:\ProgramData\Store nurb nurb.xjwo8
Supprime! - C:\ProgramData\Store nurb nurb.xkh7n
Supprime! - C:\ProgramData\Store nurb nurb.xschv
Supprime! - C:\ProgramData\Store nurb nurb.xtd1w
Supprime! - C:\ProgramData\Store nurb nurb.y22wi
Supprime! - C:\ProgramData\Store nurb nurb.y2t7t
Supprime! - C:\ProgramData\Store nurb nurb.yl5i0
Supprime! - C:\ProgramData\Store nurb nurb.zjp0s
Supprime! - C:\ProgramData\Store nurb nurb.zqntk
Supprime! - C:\ProgramData\Store nurb nurb.0t9zsj
Supprime! - C:\ProgramData\Store nurb nurb.0x93w7
Supprime! - C:\ProgramData\Store nurb nurb.1155s1
Supprime! - C:\ProgramData\Store nurb nurb.15r2ui
Supprime! - C:\ProgramData\Store nurb nurb.2ixbjz
Supprime! - C:\ProgramData\Store nurb nurb.2nz2vm
Supprime! - C:\ProgramData\Store nurb nurb.2qd251
Supprime! - C:\ProgramData\Store nurb nurb.3adtql
Supprime! - C:\ProgramData\Store nurb nurb.3m18xv
Supprime! - C:\ProgramData\Store nurb nurb.3mbimt
Supprime! - C:\ProgramData\Store nurb nurb.3p1vkz
Supprime! - C:\ProgramData\Store nurb nurb.3rhn8r
Supprime! - C:\ProgramData\Store nurb nurb.3z74wz
Supprime! - C:\ProgramData\Store nurb nurb.4b4m3y
Supprime! - C:\ProgramData\Store nurb nurb.4bwkht
Supprime! - C:\ProgramData\Store nurb nurb.5960ph
Supprime! - C:\ProgramData\Store nurb nurb.5gsqe8
Supprime! - C:\ProgramData\Store nurb nurb.6iak5v
Supprime! - C:\ProgramData\Store nurb nurb.6lkhyt
Supprime! - C:\ProgramData\Store nurb nurb.6m64vs
Supprime! - C:\ProgramData\Store nurb nurb.6wjzdq
Supprime! - C:\ProgramData\Store nurb nurb.6y9e65
Supprime! - C:\ProgramData\Store nurb nurb.73g0b8
Supprime! - C:\ProgramData\Store nurb nurb.7ipam8
Supprime! - C:\ProgramData\Store nurb nurb.7ldybi
Supprime! - C:\ProgramData\Store nurb nurb.7rdg5q
Supprime! - C:\ProgramData\Store nurb nurb.80py4q
Supprime! - C:\ProgramData\Store nurb nurb.9x1x32
Supprime! - C:\ProgramData\Store nurb nurb.a3n4lu
Supprime! - C:\ProgramData\Store nurb nurb.alic6s
Supprime! - C:\ProgramData\Store nurb nurb.atckpu
Supprime! - C:\ProgramData\Store nurb nurb.auamq4
Supprime! - C:\ProgramData\Store nurb nurb.c6x8sr
Supprime! - C:\ProgramData\Store nurb nurb.c7nlul
Supprime! - C:\ProgramData\Store nurb nurb.ccq177
Supprime! - C:\ProgramData\Store nurb nurb.cdkxpw
Supprime! - C:\ProgramData\Store nurb nurb.cjvc6f
Supprime! - C:\ProgramData\Store nurb nurb.cwos1i
Supprime! - C:\ProgramData\Store nurb nurb.d0kv4m
Supprime! - C:\ProgramData\Store nurb nurb.d17dte
Supprime! - C:\ProgramData\Store nurb nurb.d5c6yh
Supprime! - C:\ProgramData\Store nurb nurb.d5iqm7
Supprime! - C:\ProgramData\Store nurb nurb.dc7orz
Supprime! - C:\ProgramData\Store nurb nurb.eog3hf
Supprime! - C:\ProgramData\Store nurb nurb.eyupl6
Supprime! - C:\ProgramData\Store nurb nurb.f4udzs
Supprime! - C:\ProgramData\Store nurb nurb.fbjqm2
Supprime! - C:\ProgramData\Store nurb nurb.fc464z
Supprime! - C:\ProgramData\Store nurb nurb.flpahe
Supprime! - C:\ProgramData\Store nurb nurb.frk5ci
Supprime! - C:\ProgramData\Store nurb nurb.fzvi3v
Supprime! - C:\ProgramData\Store nurb nurb.g24xve
Supprime! - C:\ProgramData\Store nurb nurb.g2ti2h
Supprime! - C:\ProgramData\Store nurb nurb.ginxg5
Supprime! - C:\ProgramData\Store nurb nurb.gjyu4c
Supprime! - C:\ProgramData\Store nurb nurb.glp1oc
Supprime! - C:\ProgramData\Store nurb nurb.grxj69
Supprime! - C:\ProgramData\Store nurb nurb.gx7t5d
Supprime! - C:\ProgramData\Store nurb nurb.h0rz7k
Supprime! - C:\ProgramData\Store nurb nurb.h6053l
Supprime! - C:\ProgramData\Store nurb nurb.hcfrl8
Supprime! - C:\ProgramData\Store nurb nurb.hiraav
Supprime! - C:\ProgramData\Store nurb nurb.ilhhsx
Supprime! - C:\ProgramData\Store nurb nurb.im7aio
Supprime! - C:\ProgramData\Store nurb nurb.inwizx
Supprime! - C:\ProgramData\Store nurb nurb.iqqojc
Supprime! - C:\ProgramData\Store nurb nurb.ir6g0z
Supprime! - C:\ProgramData\Store nurb nurb.isnwi9
Supprime! - C:\ProgramData\Store nurb nurb.iumnjs
Supprime! - C:\ProgramData\Store nurb nurb.ixany7
Supprime! - C:\ProgramData\Store nurb nurb.j7ysz6
Supprime! - C:\ProgramData\Store nurb nurb.j8qgxm
Supprime! - C:\ProgramData\Store nurb nurb.k98tul
Supprime! - C:\ProgramData\Store nurb nurb.kdcd8s
Supprime! - C:\ProgramData\Store nurb nurb.kp16oi
Supprime! - C:\ProgramData\Store nurb nurb.l4l8vr
Supprime! - C:\ProgramData\Store nurb nurb.la8vfr
Supprime! - C:\ProgramData\Store nurb nurb.lrpiql
Supprime! - C:\ProgramData\Store nurb nurb.mmirxo
Supprime! - C:\ProgramData\Store nurb nurb.mpqnyb
Supprime! - C:\ProgramData\Store nurb nurb.muwicq
Supprime! - C:\ProgramData\Store nurb nurb.mvuoeq
Supprime! - C:\ProgramData\Store nurb nurb.n4pv7i
Supprime! - C:\ProgramData\Store nurb nurb.nvryux
Supprime! - C:\ProgramData\Store nurb nurb.nx2vyb
Supprime! - C:\ProgramData\Store nurb nurb.oti6mi
Supprime! - C:\ProgramData\Store nurb nurb.p06k1c
Supprime! - C:\ProgramData\Store nurb nurb.pez5qq
Supprime! - C:\ProgramData\Store nurb nurb.pkqgzy
Supprime! - C:\ProgramData\Store nurb nurb.ps8bbv
Supprime! - C:\ProgramData\Store nurb nurb.pzbnxb
Supprime! - C:\ProgramData\Store nurb nurb.q3t1iz
Supprime! - C:\ProgramData\Store nurb nurb.qrsn65
Supprime! - C:\ProgramData\Store nurb nurb.rjrezb
Supprime! - C:\ProgramData\Store nurb nurb.ru3moh
Supprime! - C:\ProgramData\Store nurb nurb.s1zttq
Supprime! - C:\ProgramData\Store nurb nurb.ty5t2t
Supprime! - C:\ProgramData\Store nurb nurb.u1sjj3
Supprime! - C:\ProgramData\Store nurb nurb.uaf5cx
Supprime! - C:\ProgramData\Store nurb nurb.utvk5y
Supprime! - C:\ProgramData\Store nurb nurb.uw3f3e
Supprime! - C:\ProgramData\Store nurb nurb.v1bjmo
Supprime! - C:\ProgramData\Store nurb nurb.v37kwo
Supprime! - C:\ProgramData\Store nurb nurb.v4fvrr
Supprime! - C:\ProgramData\Store nurb nurb.v72vf2
Supprime! - C:\ProgramData\Store nurb nurb.v8p1w2
Supprime! - C:\ProgramData\Store nurb nurb.vduep5
Supprime! - C:\ProgramData\Store nurb nurb.vq8ayn
Supprime! - C:\ProgramData\Store nurb nurb.wnfbo1
Supprime! - C:\ProgramData\Store nurb nurb.wyyyvf
Supprime! - C:\ProgramData\Store nurb nurb.x21dh1
Supprime! - C:\ProgramData\Store nurb nurb.xl28rk
Supprime! - C:\ProgramData\Store nurb nurb.xvvjx4
Supprime! - C:\ProgramData\Store nurb nurb.y9fs7b
Supprime! - C:\ProgramData\Store nurb nurb.yepdek
Supprime! - C:\ProgramData\Store nurb nurb.zjcwlm
Supprime! - C:\ProgramData\Store nurb nurb.ztzyxe
Supprime! - C:\ProgramData\Store nurb nurb.1ce103w
Supprime! - C:\ProgramData\Store nurb nurb.1jrasmq
Supprime! - C:\ProgramData\Store nurb nurb.33xmcyh
Supprime! - C:\ProgramData\Store nurb nurb.3gk5j76
Supprime! - C:\ProgramData\Store nurb nurb.3mjndr8
Supprime! - C:\ProgramData\Store nurb nurb.45bxah0
Supprime! - C:\ProgramData\Store nurb nurb.4cbaaft
Supprime! - C:\ProgramData\Store nurb nurb.4qq5giq
Supprime! - C:\ProgramData\Store nurb nurb.4tzrbon
Supprime! - C:\ProgramData\Store nurb nurb.4xrvqhz
Supprime! - C:\ProgramData\Store nurb nurb.53mg9ji
Supprime! - C:\ProgramData\Store nurb nurb.575bzdo
Supprime! - C:\ProgramData\Store nurb nurb.5tr3ed2
Supprime! - C:\ProgramData\Store nurb nurb.5z1scis
Supprime! - C:\ProgramData\Store nurb nurb.5zule6r
Supprime! - C:\ProgramData\Store nurb nurb.6ntribf
Supprime! - C:\ProgramData\Store nurb nurb.6p8dpfb
Supprime! - C:\ProgramData\Store nurb nurb.6sdf7fj
Supprime! - C:\ProgramData\Store nurb nurb.7aamm9v
Supprime! - C:\ProgramData\Store nurb nurb.7brz4ii
Supprime! - C:\ProgramData\Store nurb nurb.7fd1yet
Supprime! - C:\ProgramData\Store nurb nurb.7smiflq
Supprime! - C:\ProgramData\Store nurb nurb.8dmo95b
Supprime! - C:\ProgramData\Store nurb nurb.8x5o3w0
Supprime! - C:\ProgramData\Store nurb nurb.978a7fc
Supprime! - C:\ProgramData\Store nurb nurb.9dma69g
Supprime! - C:\ProgramData\Store nurb nurb.9leqwu0
Supprime! - C:\ProgramData\Store nurb nurb.9txhuc3
Supprime! - C:\ProgramData\Store nurb nurb.9uu9v0i
Supprime! - C:\ProgramData\Store nurb nurb.a892npm
Supprime! - C:\ProgramData\Store nurb nurb.aihd736
Supprime! - C:\ProgramData\Store nurb nurb.aiwdwa0
Supprime! - C:\ProgramData\Store nurb nurb.avj2em7
Supprime! - C:\ProgramData\Store nurb nurb.ay3h917
Supprime! - C:\ProgramData\Store nurb nurb.bklszzs
Supprime! - C:\ProgramData\Store nurb nurb.bp2rlp0
Supprime! - C:\ProgramData\Store nurb nurb.btnizxi
Supprime! - C:\ProgramData\Store nurb nurb.byq4l9h
Supprime! - C:\ProgramData\Store nurb nurb.cgsldh9
Supprime! - C:\ProgramData\Store nurb nurb.cjtb7rp
Supprime! - C:\ProgramData\Store nurb nurb.dcn97ai
Supprime! - C:\ProgramData\Store nurb nurb.dqt4unt
Supprime! - C:\ProgramData\Store nurb nurb.ec007a6
Supprime! - C:\ProgramData\Store nurb nurb.ffhi1zj
Supprime! - C:\ProgramData\Store nurb nurb.fxhm6l0
Supprime! - C:\ProgramData\Store nurb nurb.fxq1z8g
Supprime! - C:\ProgramData\Store nurb nurb.g9y81wd
Supprime! - C:\ProgramData\Store nurb nurb.gx0ilpl
Supprime! - C:\ProgramData\Store nurb nurb.gx4vurk
Supprime! - C:\ProgramData\Store nurb nurb.h3a26p9
Supprime! - C:\ProgramData\Store nurb nurb.hfk0l7d
Supprime! - C:\ProgramData\Store nurb nurb.hom2pw8
Supprime! - C:\ProgramData\Store nurb nurb.i0wyps5
Supprime! - C:\ProgramData\Store nurb nurb.iex35tw
Supprime! - C:\ProgramData\Store nurb nurb.ixq7xa4
Supprime! - C:\ProgramData\Store nurb nurb.j29pisq
Supprime! - C:\ProgramData\Store nurb nurb.j60p1p4
Supprime! - C:\ProgramData\Store nurb nurb.j66kpwu
Supprime! - C:\ProgramData\Store nurb nurb.j9o4otm
Supprime! - C:\ProgramData\Store nurb nurb.kn21swf
Supprime! - C:\ProgramData\Store nurb nurb.l1swgby
Supprime! - C:\ProgramData\Store nurb nurb.lb1kkvg
Supprime! - C:\ProgramData\Store nurb nurb.lfj8ve3
Supprime! - C:\ProgramData\Store nurb nurb.ll7vemx
Supprime! - C:\ProgramData\Store nurb nurb.lrqos04
Supprime! - C:\ProgramData\Store nurb nurb.mangmjf
Supprime! - C:\ProgramData\Store nurb nurb.mcz0ot6
Supprime! - C:\ProgramData\Store nurb nurb.melyh6p
Supprime! - C:\ProgramData\Store nurb nurb.mwyq75v
Supprime! - C:\ProgramData\Store nurb nurb.namrwnh
Supprime! - C:\ProgramData\Store nurb nurb.nh8cjbw
Supprime! - C:\ProgramData\Store nurb nurb.nq7e4ah
Supprime! - C:\ProgramData\Store nurb nurb.nvdw7e6
Supprime! - C:\ProgramData\Store nurb nurb.o0rvwa8
Supprime! - C:\ProgramData\Store nurb nurb.o193g61
Supprime! - C:\ProgramData\Store nurb nurb.otyd41p
Supprime! - C:\ProgramData\Store nurb nurb.oucdve8
Supprime! - C:\ProgramData\Store nurb nurb.p9kyuo6
Supprime! - C:\ProgramData\Store nurb nurb.qagv8zc
Supprime! - C:\ProgramData\Store nurb nurb.qibk4rk
Supprime! - C:\ProgramData\Store nurb nurb.qm59vaa
Supprime! - C:\ProgramData\Store nurb nurb.r3xi62l
Supprime! - C:\ProgramData\Store nurb nurb.rd46fin
Supprime! - C:\ProgramData\Store nurb nurb.rn9vaf6
Supprime! - C:\ProgramData\Store nurb nurb.ro4h6ca
Supprime! - C:\ProgramData\Store nurb nurb.rs3hsdt
Supprime! - C:\ProgramData\Store nurb nurb.s8yhdc6
Supprime! - C:\ProgramData\Store nurb nurb.scrk1zw
Supprime! - C:\ProgramData\Store nurb nurb.skm6cpq
Supprime! - C:\ProgramData\Store nurb nurb.t0oqlhf
Supprime! - C:\ProgramData\Store nurb nurb.tb6i87y
Supprime! - C:\ProgramData\Store nurb nurb.ugkesq8
Supprime! - C:\ProgramData\Store nurb nurb.ulr64i2
Supprime! - C:\ProgramData\Store nurb nurb.un2tq28
Supprime! - C:\ProgramData\Store nurb nurb.uscn77m
Supprime! - C:\ProgramData\Store nurb nurb.uvaq2cq
Supprime! - C:\ProgramData\Store nurb nurb.v4xbqj6
Supprime! - C:\ProgramData\Store nurb nurb.v9jaglu
Supprime! - C:\ProgramData\Store nurb nurb.vlc68wc
Supprime! - C:\ProgramData\Store nurb nurb.vlivxa2
Supprime! - C:\ProgramData\Store nurb nurb.vn8vepz
Supprime! - C:\ProgramData\Store nurb nurb.vxv73lx
Supprime! - C:\ProgramData\Store nurb nurb.w9ozlsd
Supprime! - C:\ProgramData\Store nurb nurb.wldhkv7
Supprime! - C:\ProgramData\Store nurb nurb.wslo50b
Supprime! - C:\ProgramData\Store nurb nurb.ww47yx3
Supprime! - C:\ProgramData\Store nurb nurb.x7lvbs5
Supprime! - C:\ProgramData\Store nurb nurb.xex3udt
Supprime! - C:\ProgramData\Store nurb nurb.xs3wmph
Supprime! - C:\ProgramData\Store nurb nurb.xsg0gvf
Supprime! - C:\ProgramData\Store nurb nurb.xspbxnx
Supprime! - C:\ProgramData\Store nurb nurb.y11d38f
Supprime! - C:\ProgramData\Store nurb nurb.ycxg90j
Supprime! - C:\ProgramData\Store nurb nurb.yro65qh
Supprime! - C:\ProgramData\Store nurb nurb.yysgepm
Supprime! - C:\ProgramData\Store nurb nurb.z7yn8zq
Supprime! - C:\ProgramData\Store nurb nurb.zd69zhh
Supprime! - C:\ProgramData\Store nurb nurb.zea3w8t
Supprime! - C:\ProgramData\Store nurb nurb.zrn7f4v
Supprime! - C:\ProgramData\Store nurb nurb.zw7gqc2
Supprime! - C:\ProgramData\Store nurb nurb.zwtr8r2
Supprime! - C:\ProgramData\way rdr ford mpeg

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans Local

[14.12.2009|16:58] C:\Users\Lucas\AppData\Local\{31E384F6-C403-42FF-A27A-32C054E52A94}
[28.11.2009|10:08] C:\Users\Lucas\AppData\Local\Adobe
[08.05.2008|16:45] C:\Users\Lucas\AppData\Local\Apple
[19.09.2009|07:20] C:\Users\Lucas\AppData\Local\Apple Computer
[06.05.2008|11:32] C:\Users\Lucas\AppData\Local\Application Data
[29.11.2008|18:47] C:\Users\Lucas\AppData\Local\Apps
[15.12.2009|17:58] C:\Users\Lucas\AppData\Local\d3d9caps.dat
[25.12.2009|09:44] C:\Users\Lucas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[06.04.2009|09:00] C:\Users\Lucas\AppData\Local\Deployment
[13.12.2009|07:32] C:\Users\Lucas\AppData\Local\DNA
[05.07.2009|07:03] C:\Users\Lucas\AppData\Local\Downloaded Installations
[05.05.2009|18:03] C:\Users\Lucas\AppData\Local\eMule
[03.10.2009|06:28] C:\Users\Lucas\AppData\Local\FullTiltPoker
[06.12.2009|08:08] C:\Users\Lucas\AppData\Local\GDIPFONTCACHEV1.DAT
[15.07.2009|09:49] C:\Users\Lucas\AppData\Local\Google
[06.05.2008|11:32] C:\Users\Lucas\AppData\Local\Historique
[28.12.2009|13:48] C:\Users\Lucas\AppData\Local\IconCache.db
[19.08.2009|13:38] C:\Users\Lucas\AppData\Local\keyfile3.drm
[06.08.2009|10:09] C:\Users\Lucas\AppData\Local\MediaDirect
[19.08.2009|13:38] C:\Users\Lucas\AppData\Local\Microsoft
[28.03.2009|19:27] C:\Users\Lucas\AppData\Local\Microsoft Games
[30.05.2009|08:37] C:\Users\Lucas\AppData\Local\Microsoft Help
[10.05.2008|06:30] C:\Users\Lucas\AppData\Local\MicroVision Applications
[23.04.2009|17:26] C:\Users\Lucas\AppData\Local\Mozilla
[15.11.2009|17:51] C:\Users\Lucas\AppData\Local\MusE
[27.10.2009|15:42] C:\Users\Lucas\AppData\Local\PC_Drivers_Headquarters
[28.06.2009|07:53] C:\Users\Lucas\AppData\Local\Pinnacle
[20.02.2009|17:56] C:\Users\Lucas\AppData\Local\Powercinema
[07.12.2009|10:01] C:\Users\Lucas\AppData\Local\realtech_VR
[12.12.2009|18:29] C:\Users\Lucas\AppData\Local\Sony Ericsson
[06.05.2008|13:32] C:\Users\Lucas\AppData\Local\SupportSoft
[28.12.2009|15:29] C:\Users\Lucas\AppData\Local\Temp
[28.12.2009|14:17] C:\Users\Lucas\AppData\Local\Temp(57)
[06.05.2008|11:32] C:\Users\Lucas\AppData\Local\Temporary Internet Files
[01.12.2008|18:44] C:\Users\Lucas\AppData\Local\VirtualStore
[11.05.2008|08:14] C:\Users\Lucas\AppData\Local\Windows Collaboration
[22.06.2009|18:43] C:\Users\Lucas\AppData\Local\WMTools Downloaded Files

--------------------\\ Tâches planifiées dans C:\Windows\tasks

[28.12.2009 15:27][--ah-----] C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[28.12.2009 14:58][--ah-----] C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
[28.12.2009 14:28][--a------] C:\Windows\tasks\Google Software Updater.job
[28.12.2009 14:42][--a------] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3484608450-3105273323-3831902016-1000UA.job
[28.12.2009 10:33][--a------] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3484608450-3105273323-3831902016-1000Core.job
[28.12.2009 14:39][--a------] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[28.12.2009 14:40][--a------] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[28.12.2009 15:30][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{536DBF20-63E9-48FF-89F6-29E99AAA92BF}.job
[28.12.2009 14:25][--ah-----] C:\Windows\tasks\SA.DAT
[22.12.2009 15:08][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing des dossiers dans C:\ProgramData

[25.12.2009|19:24] C:\ProgramData\__FileUploader.log
[19.03.2009|18:21] C:\ProgramData\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[16.09.2009|17:31] C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[02.05.2009|10:42] C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[10.07.2008|10:51] C:\ProgramData\692498.dat
[28.11.2009|10:09] C:\ProgramData\Adobe
[08.05.2008|16:44] C:\ProgramData\Apple
[20.02.2009|16:52] C:\ProgramData\Apple Computer
[06.05.2008|11:31] C:\ProgramData\Application Data
[21.11.2009|10:57] C:\ProgramData\avg8
[22.09.2008|15:48] C:\ProgramData\AVS4YOU
[07.07.2009|11:47] C:\ProgramData\BitDefender
[06.09.2008|20:03] C:\ProgramData\BM63c59ab4.txt
[22.09.2008|15:47] C:\ProgramData\BM63c59ab4.xml
[06.05.2008|11:31] C:\ProgramData\Bureau
[22.06.2009|11:36] C:\ProgramData\cdrom sign
[27.06.2008|20:49] C:\ProgramData\CyberLink
[01.05.2008|12:13] C:\ProgramData\Dell
[06.05.2008|11:31] C:\ProgramData\Documents
[06.05.2008|11:31] C:\ProgramData\Favoris
[15.07.2009|09:50] C:\ProgramData\Google
[28.12.2009|14:28] C:\ProgramData\Google Updater
[17.07.2008|09:14] C:\ProgramData\Hewlett-Packard
[26.12.2009|14:30] C:\ProgramData\hps
[01.05.2008|12:14] C:\ProgramData\InstallShield
[01.05.2008|11:59] C:\ProgramData\Intel
[22.10.2008|14:03] C:\ProgramData\LogiShrd
[22.10.2008|14:03] C:\ProgramData\Logitech
[16.07.2008|17:57] C:\ProgramData\McAfee
[06.05.2008|11:31] C:\ProgramData\Menu D‚marrer
[23.05.2008|08:51] C:\ProgramData\Messenger Plus!
[17.06.2009|10:46] C:\ProgramData\Microsoft
[17.06.2009|11:08] C:\ProgramData\Microsoft Help
[06.05.2008|11:31] C:\ProgramData\ModŠles
[27.05.2009|19:14] C:\ProgramData\ntuser.pol
[05.10.2009|16:07] C:\ProgramData\Office Genuine Advantage
[27.10.2009|15:42] C:\ProgramData\PC Drivers HeadQuarters
[04.07.2009|19:24] C:\ProgramData\Pinnacle
[04.07.2009|19:24] C:\ProgramData\Pinnacle Studio
[30.06.2009|16:00] C:\ProgramData\Pinnacle VideoSpin
[09.05.2009|17:14] C:\ProgramData\Propellerhead Software
[22.09.2008|15:47] C:\ProgramData\pskt.ini
[07.12.2009|09:55] C:\ProgramData\realtech VR
[21.02.2009|12:31] C:\ProgramData\River Past G5
[26.12.2009|11:59] C:\ProgramData\Roxio
[01.05.2008|12:15] C:\ProgramData\Sonic
[12.12.2009|18:28] C:\ProgramData\Sony Ericsson
[05.10.2008|11:56] C:\ProgramData\Spybot - Search & Destroy
[01.05.2008|12:10] C:\ProgramData\SupportSoft
[12.12.2009|18:28] C:\ProgramData\Teleca
[20.09.2009|12:34] C:\ProgramData\TrackMania
[27.10.2009|15:42] C:\ProgramData\UAB
[01.05.2008|12:16] C:\ProgramData\Uninstall
[03.11.2008|16:45] C:\ProgramData\WindowsSearch
[06.05.2008|15:36] C:\ProgramData\WLInstaller

--------------------\\ Listing des dossiers dans C:\Program Files

[28.11.2009|10:07] C:\Program Files\Adobe
[04.07.2009|20:32] C:\Program Files\AdorageI-GfxDatas
[04.07.2009|20:30] C:\Program Files\AdorageI-SAL
[17.05.2009|07:11] C:\Program Files\adslTV
[13.07.2009|11:15] C:\Program Files\AdVantage
[15.08.2009|10:14] C:\Program Files\Any Audio Converter
[09.08.2008|08:06] C:\Program Files\Apple Software Update
[06.05.2008|11:55] C:\Program Files\AVG
[07.07.2009|11:43] C:\Program Files\BitDefender
[28.12.2009|14:22] C:\Program Files\Bonjour
[28.12.2009|14:02] C:\Program Files\Common Files
[01.05.2008|11:48] C:\Program Files\CONEXANT
[15.08.2009|09:44] C:\Program Files\Creative
[15.08.2009|09:45] C:\Program Files\Creative Live! Cam
[01.05.2008|12:12] C:\Program Files\CyberLink
[15.08.2009|09:44] C:\Program Files\Dell
[01.05.2008|12:10] C:\Program Files\Dell Support Center
[28.12.2009|14:22] C:\Program Files\DellTPad
[01.05.2008|11:59] C:\Program Files\Digital Line Detect
[08.11.2008|07:59] C:\Program Files\DivX
[02.11.2008|13:38] C:\Program Files\ESTsoft
[06.05.2008|11:31] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[29.09.2008|16:30] C:\Program Files\FileSubmit
[16.12.2009|20:46] C:\Program Files\GabbaSoft
[15.07.2009|09:50] C:\Program Files\Google
[23.08.2009|10:22] C:\Program Files\IKEA HomePlanner
[17.03.2009|18:27] C:\Program Files\Incomplete
[22.12.2009|15:03] C:\Program Files\InstallShield Installation Information
[01.05.2008|12:07] C:\Program Files\Intel
[01.05.2008|12:00] C:\Program Files\Intel, Inc
[01.06.2009|10:59] C:\Program Files\InterActual
[10.12.2009|19:13] C:\Program Files\Internet Explorer
[01.11.2009|11:09] C:\Program Files\iPod
[28.12.2009|14:22] C:\Program Files\iTunes
[17.11.2009|18:21] C:\Program Files\Java
[06.05.2008|16:38] C:\Program Files\Logitech
[02.11.2008|13:22] C:\Program Files\Micro Application
[19.03.2009|16:57] C:\Program Files\Microsoft
[11.12.2009|17:25] C:\Program Files\Microsoft Games
[17.06.2009|11:07] C:\Program Files\Microsoft Office
[27.09.2009|08:33] C:\Program Files\Microsoft Silverlight
[10.10.2008|14:39] C:\Program Files\Microsoft SQL Server
[19.03.2009|17:00] C:\Program Files\Microsoft SQL Server Compact Edition
[14.05.2009|19:03] C:\Program Files\Microsoft Sync Framework
[30.05.2009|08:42] C:\Program Files\Microsoft.NET
[06.09.2008|13:57] C:\Program Files\MixMeister EZ Vinyl Converter
[01.05.2008|11:58] C:\Program Files\Modem Diagnostic Tool
[15.10.2009|18:08] C:\Program Files\Movie Maker
[02.11.2006|13:37] C:\Program Files\MSBuild
[28.09.2008|08:03] C:\Program Files\MSXML 4.0
[12.09.2009|14:29] C:\Program Files\NCH Software
[01.05.2008|11:59] C:\Program Files\NetWaiting
[14.12.2009|20:39] C:\Program Files\NiwradSoft
[10.10.2008|14:43] C:\Program Files\Outsim
[28.03.2009|07:56] C:\Program Files\ParallelGraphics
[27.10.2009|15:41] C:\Program Files\PC Drivers HeadQuarters
[04.07.2009|19:21] C:\Program Files\Pinnacle
[28.12.2009|14:22] C:\Program Files\QuickTime
[07.12.2009|09:55] C:\Program Files\realtech VR
[02.11.2006|13:37] C:\Program Files\Reference Assemblies
[01.05.2008|12:16] C:\Program Files\Roxio
[28.12.2009|14:22] C:\Program Files\Search Settings
[01.05.2008|11:48] C:\Program Files\Sigmatel
[21.02.2009|12:22] C:\Program Files\Sony
[12.12.2009|18:29] C:\Program Files\Sony Ericsson
[17.06.2008|16:44] C:\Program Files\TEMP
[28.12.2009|14:17] C:\Program Files\trend micro
[10.10.2008|14:41] C:\Program Files\Uninstall Information
[16.09.2009|17:33] C:\Program Files\Utilitaire de configuration iPhone
[31.08.2008|12:23] C:\Program Files\VideoLAN
[28.06.2009|07:00] C:\Program Files\WIDCOMM
[15.10.2009|18:08] C:\Program Files\Windows Calendar
[15.10.2009|18:08] C:\Program Files\Windows Collaboration
[28.12.2009|14:22] C:\Program Files\Windows Defender
[15.10.2009|18:08] C:\Program Files\Windows Journal
[14.11.2009|13:09] C:\Program Files\Windows Live
[10.05.2009|11:46] C:\Program Files\Windows Live Safety Center
[19.03.2009|16:57] C:\Program Files\Windows Live SkyDrive
[10.12.2009|19:13] C:\Program Files\Windows Mail
[28.06.2009|08:48] C:\Program Files\Windows Media Components
[28.12.2009|14:22] C:\Program Files\Windows Media Player
[06.05.2008|11:31] C:\Program Files\Windows NT
[15.10.2009|18:08] C:\Program Files\Windows Photo Gallery
[18.11.2009|03:25] C:\Program Files\Windows Portable Devices
[14.12.2009|20:44] C:\Program Files\Windows Sidebar
[04.11.2008|17:33] C:\Program Files\WMV9_VCM
[08.12.2009|13:13] C:\Program Files\Xvid
[21.02.2009|16:25] C:\Program Files\Yahoo!

--------------------\\ Listing des dossiers dans C:\Program Files\Common Files

[28.11.2009|10:07] C:\Program Files\Common Files\Adobe
[16.12.2009|19:51] C:\Program Files\Common Files\Adobe AIR
[01.11.2009|11:09] C:\Program Files\Common Files\Apple
[22.02.2009|13:57] C:\Program Files\Common Files\AVSMedia
[07.07.2009|11:44] C:\Program Files\Common Files\BitDefender
[17.06.2009|11:25] C:\Program Files\Common Files\DESIGNER
[14.12.2009|16:58] C:\Program Files\Common Files\InstallShield
[01.05.2008|11:58] C:\Program Files\Common Files\Java
[21.10.2008|11:36] C:\Program Files\Common Files\Logishrd
[20.02.2009|16:37] C:\Program Files\Common Files\Logitech
[17.06.2009|11:25] C:\Program Files\Common Files\microsoft shared
[28.03.2009|07:56] C:\Program Files\Common Files\ParallelGraphics
[01.05.2008|12:15] C:\Program Files\Common Files\PX Storage Engine
[01.05.2008|12:01] C:\Program Files\Common Files\Reallusion
[04.11.2008|17:33] C:\Program Files\Common Files\River Past
[01.05.2008|12:15] C:\Program Files\Common Files\Roxio Shared
[02.11.2006|12:18] C:\Program Files\Common Files\Services
[01.05.2008|12:15] C:\Program Files\Common Files\Sonic Shared
[12.12.2009|18:28] C:\Program Files\Common Files\Sony Ericsson Shared
[02.11.2006|12:18] C:\Program Files\Common Files\SpeechEngines
[01.05.2008|12:10] C:\Program Files\Common Files\supportsoft
[28.12.2009|14:22] C:\Program Files\Common Files\SureThing Shared
[29.03.2009|13:01] C:\Program Files\Common Files\SWF Studio
[15.10.2009|18:08] C:\Program Files\Common Files\System
[12.12.2009|18:28] C:\Program Files\Common Files\Teleca Shared
[19.03.2009|16:51] C:\Program Files\Common Files\Windows Live
[06.05.2008|15:42] C:\Program Files\Common Files\WindowsLiveInstaller
[20.09.2009|08:32] C:\Program Files\Common Files\Wise Installation Wizard
[29.06.2009|18:43] C:\Program Files\Common Files\Yahoo!

--------------------\\ Process

( 79 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-28 15:33:05
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 35

--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !

[F:150][D:50]-> C:\Users\Lucas\AppData\Local\Temp
[F:334][D:1]-> C:\Users\Lucas\AppData\Roaming\MICROS~1\Windows\Cookies
[F:217][D:9]-> C:\Users\Lucas\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:84][D:2]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 28.12.2009|14:57 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 28.12.2009|15:35 - Option : [3]

--------------------\\ Fin du rapport a 15:35:17
[ UAC => 1 ]
0
verni29 Messages postés 6699 Date d'inscription dimanche 6 juillet 2008 Statut Contributeur sécurité Dernière intervention 26 décembre 2016 180
28 déc. 2009 à 15:52
Re,

1/ Il y pas mal de fichiers à supprimer.

Télécharge OTM (de Old_Timer).
http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/
Enregistre-le sur ton Bureau.

* Double-clique sur OTM pour le lancer.
note : Si tu es sous Vista, click droit sur l'icone d'OTMoveIt3 --> exécuter en tant qu'administrateur pour le lancer
* Vérifie que l'option Unregister Dll's and Ocx's est cochée.
* Copie la liste qui se trouve dans la zone code ci-dessous et colle-la dans le cadre de gauche de OTMoveIt sous Paste instructions for Items to be Moved.


:files
C:\ProgramData\Store nurb nurb.*
C:\ProgramData\BM63c59ab4.xml
C:\ProgramData\BM63c59ab4.txt
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
C:\Program Files\AdVantage\
C:\Windows\system32\sshnas.dll
C:\Windows\msa.exe
C:\Windows\msb.exe
C:\Windows\system32\hgGwWPHY.dll
C:\Users\Lucas\AppData\Local\Temp\c.exe
C:\Users\Lucas\AppData\Local\Temp\mlJDtqoL.dll

:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AE55C7EC-82F8-46CB-8DC2-57BF42F025FF}"=-
"{1E8841B1-F10B-460C-86FC-4B71187C765E}"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Videocan"=-
"ZagrebLand"=-
"vegas"=-
"MSServer"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSServer"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E8841B1-F10B-460C-86FC-4B71187C765E}]

* Clique sur MoveIt! pour lancer la suppression. Le résultat apparaitra dans le cadre "Results".
* Le PC va redémarrer pour supprimer les fichiers.
* après le redémarrage, un rapport va s'ouvrir.
* Copie/Colle le contenu du rapport dans ton prochain message.

Si tu ne trouves plus le rapport,c'est un fichier .log qui se trouve en C:\_OTM\MovedFiles.

2/ il y a une analyse à faire sur un fichier.

Tu vas sur le site de VirusTotal et tu vas pouvoir analyser le fichier
https://www.virustotal.com/gui/

* Copier le chemin indiqué ci-dessous et le coller dans la zone à analyser

Chemin : C:\ProgramData\692498.dat

* Tu cliques ensuite sur envoyer le fichier.
* Après analyse, clique sur formaté .
* dans la fenêtre ouverte, sélectionne tout le texte ( CTRL+A ) puis copie-lr ( CTRL+C )

Tu postes ensuite le rapport de l'analyse dans ton prochain message.

Tuto : https://forum.pcastuces.com/scan_chez_virus_total-f31s15.htm

A+
0
laromande Messages postés 168 Date d'inscription jeudi 23 octobre 2008 Statut Membre Dernière intervention 29 mai 2011 20
28 déc. 2009 à 16:04
Fichier 692498.dat reçu le 2009.12.28 15:01:56 (UTC)
Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.43 2009.12.28 -
AhnLab-V3 5.0.0.2 2009.12.28 -
AntiVir 7.9.1.122 2009.12.28 -
Antiy-AVL 2.0.3.7 2009.12.28 -
Authentium 5.2.0.5 2009.12.28 -
Avast 4.8.1351.0 2009.12.27 -
AVG 8.5.0.430 2009.12.28 -
BitDefender 7.2 2009.12.28 -
CAT-QuickHeal 10.00 2009.12.28 -
ClamAV 0.94.1 2009.12.28 -
Comodo 3394 2009.12.28 -
DrWeb 5.0.1.12222 2009.12.28 -
eSafe 7.0.17.0 2009.12.28 -
eTrust-Vet 35.1.7201 2009.12.28 -
F-Prot 4.5.1.85 2009.12.27 -
F-Secure 9.0.15370.0 2009.12.28 -
Fortinet 4.0.14.0 2009.12.28 -
GData 19 2009.12.28 -
Ikarus T3.1.1.79.0 2009.12.28 -
Jiangmin 13.0.900 2009.12.28 -
K7AntiVirus 7.10.932 2009.12.28 -
Kaspersky 7.0.0.125 2009.12.28 -
McAfee 5844 2009.12.27 -
McAfee+Artemis 5844 2009.12.27 -
McAfee-GW-Edition 6.8.5 2009.12.28 -
Microsoft 1.5302 2009.12.26 -
NOD32 4722 2009.12.28 -
Norman 6.04.03 2009.12.28 -
nProtect 2009.1.8.0 2009.12.28 -
Panda 10.0.2.2 2009.12.15 -
PCTools 7.0.3.5 2009.12.28 -
Prevx 3.0 2009.12.28 -
Rising 22.28.00.04 2009.12.28 -
Sophos 4.49.0 2009.12.28 -
Sunbelt 3.2.1858.2 2009.12.27 -
Symantec 1.4.4.12 2009.12.28 -
TheHacker 6.5.0.3.115 2009.12.28 -
TrendMicro 9.120.0.1004 2009.12.28 -
VBA32 3.12.12.0 2009.12.26 -
ViRobot 2009.12.28.2111 2009.12.28 -
VirusBuster 5.0.21.0 2009.12.27 -
Information additionnelle
File size: 1891 bytes
MD5...: 9c969508108fed44b7725ea96cdccb6c
SHA1..: 33ece29926d50f97fbc3f936413211bcc5d14522
SHA256: 8c765aa9340c73a4aa3cadd2b8c336713257e99cf648e2a8416bcfecc9292733
ssdeep: 48:hSVpZ0YUl8cx/pAcgwBzggmx6D8E0xo0ioaC+WF1:hSVcPl8cx/pA5KUgmEQR<br>xo0idC+WF1<br>
PEiD..: -
PEInfo: -
RDS...: NSRL Reference Data Set<br>-
pdfid.: -
trid..: Unknown!
sigcheck:<br>publisher....: n/a<br>copyright....: n/a<br>product......: n/a<br>description..: n/a<br>original name: n/a<br>internal name: n/a<br>file version.: n/a<br>comments.....: n/a<br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>
0
verni29 Messages postés 6699 Date d'inscription dimanche 6 juillet 2008 Statut Contributeur sécurité Dernière intervention 26 décembre 2016 180
28 déc. 2009 à 16:43
laromande,

As-tu passé OTM ?

A+
0
laromande Messages postés 168 Date d'inscription jeudi 23 octobre 2008 Statut Membre Dernière intervention 29 mai 2011 20
28 déc. 2009 à 20:01
Oui, ça a marché j'ai redemarré mon ordi et il n'y avait plus les messages et les fichiers etaient a nouveau la. Ensuite pour un autre problème j'ai réinstallé mon système et ça marche. Merci beaucoup, j'aurais pas reussi sans ton aide!
0