Scan Malwarebytes, Fichiers infectés

Bonjour,

J'ai éffectué un scan avec malwarebytes-anti-malware, et il m'a détecté des infections. Pourriez vous m'aider a interpreter ce scan et me dire les bonnes démarches. Je n'ai pas supprimé ce qu'il a trouvé par peur d'effacer des choses importantes.
Voici les resultats du scan:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5363

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

15/04/2011 00:28:12
mbam-log-2011-04-15 (00-27-59).txt

Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 229514
Temps écoulé: 47 minute(s), 21 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 4
Valeur(s) du Registre infectée(s): 3
Elément(s) de données du Registre infecté(s): 8
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 3

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> No action taken.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\FICHIERS COMMUNS\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> No action taken.

Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.SearchPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Page_URL (Hijack.StartPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page_bak (Hijack.StartPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.SearchPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.SearchPage) -> Bad: (http://ww12.cherche.us Good: (http://www.google.com) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL\SearchAssistant (Hijack.SearchPage) -> Bad: (http://www.cherche.us) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\program files\pdfforge toolbar\IE\4.3\pdfforgetoolbarie.dll (Adware.WidgiToolbar) -> No action taken.
c:\program files\fichiers communs\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> No action taken.
c:\program files\pdfforge toolbar\widgihelper.exe (Adware.WidgiToolbar) -> No action taken.

Help me please !

60 réponses

Résumé de la discussion

Un balayage Malwarebytes a détecté des éléments nuisibles, principalement des clés et des valeurs de registre liées à Adware.WidgiToolbar et un redirect de page, indiquant une compromission du navigateur. Parmi les résultats, 3 fichiers et plusieurs clés de registre signalés infectés, dont des DLL et des entrées de démarrage, et un hijack de page d’accueil a été noté. Les échanges suggèrent un nettoyage via Ad-Remover, qui a supprimé des clés et fichiers indésirables et réinitialisé les entrées liées à WidgiToolbar, suivi d’instructions pour un scan supplémentaire avec OTL. En cas de persistance des symptômes après nettoyage, la discussion évoque une réparation du démarrage avec CD Windows (boot.ini et MBR) et des commandes en invite pour rétablir le système.

Bobot (l’IA à votre service)
  1. salut mbam n'est pas à jour peu importe

    ▶ Télécharge ici : Ad-remover sur ton bureau :

    ▶ Déconnecte toi et ferme toutes applications en cours !

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    ▶ sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

    ▶ clique le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

    ▶ Au menu principal choisis "option Nettoyer" et tape sur [entrée] .

    ▶ Laisse travailler l'outil et ne touche à rien ...

    ▶ Poste le rapport qui apparait à la fin , sur le forum ...

    ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

    1. Voici ce que cela donne :

      ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

      Mis à jour par TeamXscript le 12/04/11
      Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
      Site web: http://www.teamxscript.org

      C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 01:02:32 le 15/04/2011, Mode normal

      Microsoft Windows XP Professionnel Service Pack 3 (X86)
      utilisateur@PC01 ( )

      ============== ACTION(S) ==============

      Service: "Application Updater" Stoppé et supprimé

      Fichier supprimé: C:\Program Files\Mozilla FireFox\extensions\pdfforge@mybrowserbar.com
      Fichier supprimé: C:\Documents and Settings\utilisateur\Application Data\Mozilla\FireFox\Profiles\q2cg1aoh.default\searchplugins\cherche.xml
      Fichier supprimé: C:\Documents and Settings\utilisateur\scriptjava.html
      Fichier supprimé: C:\Documents and Settings\utilisateur\tmp1.7
      Dossier supprimé: C:\Program Files\Application Updater
      Dossier supprimé: C:\Documents and Settings\utilisateur\Application Data\pdfforge
      Dossier supprimé: C:\Program Files\pdfforge Toolbar
      Dossier supprimé: C:\Documents and Settings\utilisateur\Application Data\Search Settings
      Dossier supprimé: C:\Program Files\Fichiers communs\Spigot

      (!) -- Fichiers temporaires supprimés.

      -- Fichier ouvert: C:\Documents and Settings\utilisateur\Application Data\Mozilla\FireFox\Profiles\q2cg1aoh.default\Prefs.js --
      Ligne supprimée: user_pref("keyword.URL", "hxxp://www.cherche.us/Result.php?cx=partner-pub-0420647136319153%3A5n6ugpj...
      -- Fichier Fermé --

      Clé supprimée: HKLM\Software\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
      Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
      Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402}
      Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
      Clé supprimée: HKLM\Software\Classes\CLSID\{E49F0B41-3322-11D4-AEFE-00C04F61025C}
      Clé supprimée: HKLM\Software\Application Updater
      Clé supprimée: HKLM\Software\pdfforge
      Clé supprimée: HKLM\Software\Search Settings
      Clé supprimée: HKCU\Software\pdfforge
      Clé supprimée: HKCU\Software\Search Settings
      Clé supprimée: HKCU\Software\AppDataLow\Software\pdfforge
      Clé supprimée: HKCU\Software\AppDataLow\Software\Search Settings
      Clé supprimée: HKLM\Software\Classes\Installer\Products\7A931B0A5D8E8E947AFB2124E1562280
      Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\7A931B0A5D8E8E947AFB2124E1562280
      Clé supprimée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{557C21FE-7274-410D-853E-9ED4471BF193}
      Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}

      Valeur supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|binternet
      Valeur supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SearchSettings
      Valeur supprimée: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{B922D405-6D13-4A2B-AE89-08A030DA4402}

      ============== SCAN ADDITIONNEL ==============

      **** Mozilla Firefox Version [4.0 (fr)] ****

      Searchplugins\bing.xml ( hxxp://www.bing.com/search)
      Components\browsercomps.dll (Mozilla Foundation)
      Extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} (Skype extension )

      -- C:\Documents and Settings\utilisateur\Application Data\Mozilla\FireFox\Profiles\q2cg1aoh.default --
      Extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4} (TV-Fox)
      Extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}(2) (MR Tech Toolkit)
      Prefs.js - browser.download.lastDir, C:\\Documents and Settings\\utilisateur\\Mes documents\\ECE\\Administration\\Uniformation\\Cat...
      Prefs.js - browser.startup.homepage, hxxp://www.apbif.org/
      Prefs.js - browser.startup.homepage_override.buildID, 20110318052756
      Prefs.js - browser.startup.homepage_override.mstone, rv:2.0

      ========================================

      **** Internet Explorer Version [8.0.6001.18702] ****

      HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
      HKCU_Main|Start Page - hxxp://fr.msn.com/
      HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
      HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
      HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKLM_Main|Start Page - hxxp://fr.msn.com/
      HKCU_URLSearchHooks|{B922D405-6D13-4A2B-AE89-08A030DA4402} (x)
      HKLM_Extensions\{4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - "PalTalk" (C:\Program Files\Paltalk Messenger\Paltalk.exe,476)
      HKLM_Extensions\{85d1f590-48f4-11d9-9669-0800200c9a66} - "?" (?)
      HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)
      BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)

      ========================================

      C:\Program Files\Ad-Remover\Quarantine: 74 Fichier(s)
      C:\Program Files\Ad-Remover\Backup: 14 Fichier(s)

      C:\Ad-Report-CLEAN[1].txt - 15/04/2011 01:02:38 (1515 Octet(s))

      Fin à: 01:03:45, 15/04/2011

      ============== E.O.F ==============
      1. Télécharge ici :OTL

        ▶ enregistre le sur ton Bureau.

        si tu as XP => double clique
        si tu as Vista ou windows 7 => clic droit "executer en tant que...."


        sur OTL.exe pour le lancer.

        ▶ => Configuration

        ▶Clic sur Analyse.

        A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

        Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

        ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

        Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

        ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

        ▶ Clique sur Ouvrir.

        ▶ Clique sur "Cliquez ici pour déposer le fichier".

        juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

        http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

        ▶ Copie ce lien dans ta réponse.

        ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
        1. Voici le premier lien :

          http://www.cijoint.fr/cjlink.php?file=cj201104/cijty0DWLc.txt

          Voici le second :

          http://www.cijoint.fr/cjlink.php?file=cj201104/cijHAMzXLM.txt

          J'aimerai bien savoir faire tout cela !

          Merci pour tout
          1. DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!! (car l'outil est detecté a tort comme infection contenant un module qui sert à arrêter des processus , et un autre servant à prendre des droits dans le registre pour effectuer des suppressions)

            ▶ Télécharge ici :List_Kill'em

            et enregistre le sur ton bureau et lance l'installation

            Laisse coché :

            ♦ Executer List_Kill'em

            une fois terminée , clic sur "terminer"

            choisis l'option Search

            ▶ laisse travailler l'outil

            Attention : il se peut que l'outil bloque anormalement longtemps arrivé à 95%, relance-le avec le raccourci sur le bureau sans l'arreter , puis clique sur le tout petit "X" en bas de la fenetre d'accueil du programme, ca le debloquera pour finir son scan

            ▶ Poste les rapports qui apparaitront sur ton bureau : List'em.txt et More.txt

            ▶▶▶ NE LES POSTE PAS SUR LE FORUM

            Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

            ▶ Clique sur Parcourir et selectionne , un par un , les fichiers concernés apparus sur ton bureau

            ▶ Clique sur Ouvrir.

            ▶ Clique sur "Cliquez ici pour déposer le fichier".

            Un lien de cette forme :

            http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt

            est ajouté dans la page.

            ▶ Copie ces liens dans ta réponse.
            1. List'em :

              http://www.cijoint.fr/cjlink.php?file=cj201104/cijSEowiY0.txt

              More :

              http://www.cijoint.fr/cjlink.php?file=cj201104/cijiHWx728.txt
              1. toujours protections desactivées :

                ATTENTION !! ce script est réservé uniquement à cette machine , ne pas reproduire !!!!!

                ▶ Relance List&Kill'em,avec le raccourci sur ton bureau.

                mais cette fois-ci :

                ▶ choisis l'option Tools puis Script

                une fenêtre noire va s'ouvrir brievement , et List_Kill'em va se fermer

                un nouveau document texte s'ouvre , copie/colle ce en gras si dessous :


                REM:"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Adobe Reader Speed Launcher"
                REM:"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "NPSStartup"
                REM:"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v ""
                ADD:"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v "ProxyOverride" /t REG_DWORD /d *.local
                REM:HKCU\Software\BB692CD5ACA2C93120313F03D91D3E77

                ▶ enregistre le document texte avec l'onglet fichier (enregistrer) de ce dernier , puis ferme-le

                laisse travailler l'outil

                ▶ poste le resultat

                ▶ Ferme List_Kill'em

                Note : le rapport est sur ton bureau : Script_(4 chiffres).txt
                1. Voici le résultat :

                  http://www.cijoint.fr/cjlink.php?file=cj201104/cijGTg91Y8.txt
                  1. ▶ Relance List_Kill'em,avec le raccourci sur ton bureau.

                    mais cette fois-ci :

                    ▶ choisis l'Option Suppression

                    ▶▶▶ Ne clique qu'une seule fois sur le bouton !!

                    laisse travailler l'outil.

                    en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                    ▶ colle le contenu dans ta reponse
                    1. Voici le contenu :

                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.3.9 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                      Mis à jour le 14/04/2011 | 23.30 par g3n-h@ckm@n
                      Utilisateur : utilisateur (Administrateurs)
                      Ordinateur : PC01

                      Système d'exploitation : Microsoft Windows XP (32 bits)

                      c:\ -> [Fixed] | [] | Total : 76230 Mo | Free : 46630 Mo -> NTFS
                      d:\ -> [CDROM] | [] | Total : 0 Mo | Free : 0 Mo ->

                      Scan : 02:02:50 | 15/04/2011

                      ¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤

                      127.0.0.1 localhost

                      ¤¤¤¤¤¤¤¤¤¤ Supression Fichiers | Dossiers ¤¤¤¤¤¤¤¤¤¤

                      Mise en quarantaine : C:\Documents and Settings\All Users\Application Data\Temp\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}
                      Mise en quarantaine : C:\Documents and Settings\All Users\Application Data\Temp
                      Erreur de suppression : C:\Documents and Settings\All Users\Application Data\Temp
                      Mise en quarantaine : C:\Documents and Settings\utilisateur\Menu Démarrer\Programmes\Démarrage\binternet.lnk
                      Mise en quarantaine : C:\WINDOWS\Temp\PR65.tmp
                      Mise en quarantaine : C:\WINDOWS\Temp\~GLF3248.TMP
                      Mise en quarantaine : C:\WINDOWS\Temp\~GLG3248.TMP
                      Mise en quarantaine : C:\WINDOWS\Temp\setup.exe
                      Mise en quarantaine : C:\WINDOWS\Temp\~GL_302C.EXE

                      ¤¤¤¤¤¤¤¤¤¤ Suppression Clés ¤¤¤¤¤¤¤¤¤¤

                      ¤¤¤¤¤¤¤¤¤¤¤ Services néfastes ¤¤¤¤¤¤¤¤¤¤

                      ¤¤¤¤¤¤¤¤¤¤ Suppression Valeurs ¤¤¤¤¤¤¤¤¤¤

                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                      [HKLM\..\..\Security Center] | FirstRunDisabled = 1
                      [HKLM\..\..\Security Center] | AntiVirusDisableNotify = 0
                      [HKLM\..\..\Security Center] | UpdatesDisableNotify = 0
                      [HKLM\..\..\Security Center] | AntiVirusOverride = 0
                      [HKLM\..\..\Security Center] | FirewallOverride = 0
                      [HKLM\..\..\Security Center] | FirewallDisableNotify = 1

                      Fin : 02:09:13

                      ¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤

                      Est-ce normal qu'à la fin le nettoyage de disque s'active ?
                      1. oui justement je me demandais s'il etait bien fonctionnel sur tous les pc :)

                        merci de la confirmation :)

                        mets malwarebytes à jour et scan complet puis poste le rapport :)
                        1. Puis-je brancher aussi mon disque dur externe pour vérification ou non ?

                          Je crois qu'il y en a pour un bout de temps, pourrais-je te le poster demain matin le rapport si tu es OK ?
                          1. alors avant malwarebytes :

                            ▶ Télécharge ici : USBFIX sur ton bureau

                            branche tous tes periphériques sans les ouvrir

                            /!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

                            si tu as XP => double clique
                            si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                            sur l'icône Usbfix située sur ton Bureau.
                            Sur la page, clique sur le bouton :

                            ▶ choisi l option Suppression

                            ▶ UsbFix scannera ton pc , laisse travailler l outil.

                            ▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

                            ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                            ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                            1. ############################## | UsbFix 7.043 | [Suppression]

                              Utilisateur: utilisateur (Administrateur) # PC01 [ ]
                              Mis à jour le 12/04/2011 par TeamXscript
                              Lancé à 02:37:50 | 15/04/2011
                              Site Web: http://www.teamxscript.org
                              Submit your sample: http://www.teamxscript.org/Upload.php
                              Contact: TeamXscript.ElDesaparecido@gmail.com

                              CPU: Intel(R) Pentium(R) D CPU 2.80GHz
                              CPU 2: Intel(R) Pentium(R) D CPU 2.80GHz
                              Microsoft Windows XP Professionnel (5.1.2600 32-Bit) # Service Pack 3
                              Internet Explorer 8.0.6001.18702

                              Antivirus: AntiVir Desktop 10.0.1.52 [(!) Disabled | (!) Outdated]
                              RAM -> 2038 Mo
                              C:\ (%systemdrive%) -> Disque fixe # 74 Go (46 Go libre(s) - 61%) [] # NTFS
                              D:\ -> CD-ROM
                              F:\ -> Disque fixe # 466 Go (234 Go libre(s) - 50%) [My Book] # FAT32

                              ################## | Éléments infectieux |

                              Supprimé! C:\Recycler\S-1-5-21-1482476501-1604221776-1417001333-1003
                              Supprimé! C:\Recycler\S-1-5-21-321696159-428212251-2569933376-1003
                              Supprimé! C:\Recycler\S-1-5-21-5024690470-6111750144-909111224-1992
                              Supprimé! C:\Recycler\S-1-5-21-8441444613-2845449365-996543396-7742
                              Supprimé! C:\Recycler\S-1-5-21-8746733103-3098886034-343742420-4521
                              Supprimé! C:\msvcr71.dll
                              Supprimé! F:\autorun.inf

                              ################## | Registre |

                              Supprimé! HKLM\software\microsoft\windows nt\currentversion\winlogon|Taskman

                              ################## | Mountpoints2 |

                              Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{083bfd26-fdbb-11dd-be4a-806d6172696f}

                              ################## | Listing |

                              [15/04/2011 - 01:03:46 | N | 5367] C:\Ad-Report-CLEAN[1].txt
                              [11/06/2008 - 12:44:04 | N | 6480] C:\ANYCALLMUSIC.adf
                              [07/04/2009 - 10:23:44 | N | 53248] C:\Anycall_Land.dll
                              [24/10/2010 - 17:16:24 | D ] C:\Audacity
                              [18/02/2009 - 14:13:39 | N | 0] C:\AUTOEXEC.BAT
                              [07/04/2009 - 10:45:04 | N | 77824] C:\BackupRestoreWM.dll
                              [07/04/2009 - 10:45:04 | N | 33280] C:\BackupSYM.dll
                              [14/09/2009 - 19:28:56 | N | 212] C:\boot.ini
                              [14/04/2008 - 14:00:00 | N | 4952] C:\Bootfont.bin
                              [04/08/2008 - 01:48:44 | N | 22824] C:\ceutil.dll
                              [16/04/2009 - 10:38:48 | N | 32256] C:\Common.dll
                              [18/02/2009 - 14:13:39 | N | 0] C:\CONFIG.SYS
                              [07/04/2009 - 10:40:44 | N | 248239] C:\connect_ani.dat
                              [07/04/2009 - 10:40:44 | N | 252890] C:\Connect_ATT.dat
                              [07/04/2009 - 10:43:10 | N | 36864] C:\ConvLunar.dll
                              [18/02/2009 - 15:04:28 | D ] C:\DELL
                              [07/04/2009 - 10:44:22 | N | 16384] C:\dmstpb.dll
                              [18/02/2009 - 14:21:29 | D ] C:\Documents and Settings
                              [31/07/2008 - 12:14:14 | N | 54346] C:\DRM Adaptor.ndf
                              [07/04/2009 - 10:23:44 | N | 237568] C:\drmcm.dll
                              [16/04/2009 - 10:38:12 | N | 12288] C:\Dump.dll
                              [16/04/2009 - 10:39:48 | N | 233472] C:\EmailAdaptor.dll
                              [07/04/2009 - 10:23:40 | N | 3810128] C:\energetic&soothing.classifier
                              [01/07/2009 - 22:08:07 | D ] C:\Exifer
                              [01/07/2009 - 21:56:50 | N | 30] C:\Exiferupdate.ini
                              [07/04/2009 - 10:23:40 | N | 476160] C:\EzNpsSharedLib.dll
                              [07/04/2009 - 10:23:40 | N | 3821846] C:\fast&slow.classifier
                              [07/04/2009 - 10:54:42 | N | 90112] C:\flashdll.dll
                              [07/04/2009 - 10:39:44 | N | 319808] C:\FsAdmin64.exe
                              [07/04/2009 - 10:39:44 | N | 204800] C:\FsDeviceLib64.dll
                              [07/04/2009 - 10:39:44 | N | 24064] C:\FsExService64.exe
                              [07/04/2009 - 10:39:44 | N | 226832] C:\FsUsbExAdmin.exe
                              [07/04/2009 - 10:39:44 | N | 110592] C:\FsUsbExDevice.Dll
                              [07/04/2009 - 10:39:44 | N | 147456] C:\FsUsbExDeviceLib.dll
                              [07/04/2009 - 10:39:44 | N | 36608] C:\FsUsbExDisk.sys
                              [07/04/2009 - 10:39:44 | N | 233472] C:\FsUsbExService.exe
                              [10/04/2009 - 15:03:16 | N | 7045120] C:\FunCodecFilter.ax
                              [07/04/2009 - 10:23:40 | N | 249856] C:\fun_id3tag.dll
                              [07/04/2009 - 10:55:02 | N | 102400] C:\FUSCrypt.dll
                              [18/03/2009 - 03:06:40 | N | 114688] C:\FUSCryptForLimo.dll
                              [05/08/2004 - 22:00:00 | N | 1712128] C:\GdiPlus.dll
                              [31/12/2009 - 23:41:27 | D ] C:\Help
                              [07/04/2009 - 11:10:42 | N | 176128] C:\HSPIO.dll
                              [31/12/2009 - 23:41:27 | D ] C:\Image
                              [07/04/2009 - 10:45:06 | N | 27648] C:\InstallSYM.dll
                              [07/04/2009 - 10:45:06 | N | 86016] C:\InstAppWM.dll
                              [18/02/2009 - 14:13:39 | N | 0] C:\IO.SYS
                              [11/12/2009 - 16:32:06 | D ] C:\Joomla
                              [07/04/2009 - 10:44:22 | N | 482816] C:\JSRHandler.dll
                              [18/02/2009 - 15:13:49 | D ] C:\KAV
                              [15/04/2011 - 01:35:48 | D ] C:\Kill'em
                              [25/08/2008 - 19:21:22 | N | 162816] C:\KMPWebModule.dll
                              [07/04/2009 - 10:23:40 | N | 221281] C:\KRCaptionDll.dll
                              [07/04/2009 - 10:23:46 | N | 540672] C:\KTFDRM20.dll
                              [07/04/2009 - 10:23:46 | N | 659456] C:\KTFDRM_UCC.dll
                              [07/04/2009 - 10:23:40 | N | 22368] C:\Lfani15u.dll
                              [07/04/2009 - 10:23:40 | N | 30048] C:\Lfbmp15u.dll
                              [07/04/2009 - 10:23:40 | N | 390496] C:\Lfcmp15u.dll
                              [07/04/2009 - 10:23:42 | N | 423264] C:\Lfcmw15u.dll
                              [07/04/2009 - 10:23:40 | N | 54624] C:\Lfdrw15u.dll
                              [07/04/2009 - 10:23:42 | N | 99680] C:\Lffax15u.dll
                              [07/04/2009 - 10:23:42 | N | 18272] C:\Lffit15u.dll
                              [07/04/2009 - 10:23:42 | N | 34656] C:\Lfgif15u.dll
                              [07/04/2009 - 10:23:42 | N | 17248] C:\Lfimg15u.dll
                              [07/04/2009 - 10:23:42 | N | 17248] C:\Lfitg15u.dll
                              [07/04/2009 - 10:23:42 | N | 67936] C:\Lfjbg15u.dll
                              [07/04/2009 - 10:23:42 | N | 128352] C:\Lfpng15u.dll
                              [07/04/2009 - 10:23:42 | N | 14176] C:\Lfraw15u.dll
                              [07/04/2009 - 10:23:42 | N | 20320] C:\Lftga15u.dll
                              [07/04/2009 - 10:23:42 | N | 152928] C:\Lftif15u.dll
                              [07/04/2009 - 10:23:42 | N | 15712] C:\Lfwmp15u.dll
                              [07/04/2009 - 10:54:32 | N | 503808] C:\libpin3_dll.dll
                              [07/04/2009 - 10:23:42 | N | 267616] C:\Ltdis15u.dll
                              [07/04/2009 - 10:23:42 | N | 259424] C:\Ltefx15u.dll
                              [07/04/2009 - 10:23:42 | N | 185696] C:\Ltfil15u.dll
                              [07/04/2009 - 10:23:42 | N | 214368] C:\Ltimgclr15u.dll
                              [07/04/2009 - 10:23:42 | N | 353632] C:\Ltimgcor15u.dll
                              [07/04/2009 - 10:23:42 | N | 214368] C:\Ltimgefx15u.dll
                              [07/04/2009 - 10:23:42 | N | 447840] C:\Ltimgsfx15u.dll
                              [07/04/2009 - 10:23:42 | N | 128352] C:\Ltimgutl15u.dll
                              [07/04/2009 - 10:23:42 | N | 488800] C:\Ltkrn15u.dll
                              [07/04/2009 - 10:23:42 | N | 107872] C:\Ltpnt15u.dll
                              [07/04/2009 - 10:23:42 | N | 2241888] C:\Ltwvc15u.dll
                              [07/04/2009 - 10:23:42 | N | 1097728] C:\M5_EmuHw.dll
                              [07/04/2009 - 10:23:42 | N | 507904] C:\M5_EmuMapi30.dll
                              [07/04/2009 - 10:23:42 | N | 1998848] C:\M5_EmuSmw5.dll
                              [18/03/2009 - 03:07:50 | N | 1560720] C:\MacOSX.msstyles
                              [07/04/2009 - 10:23:46 | N | 315392] C:\MACSSDK.dll
                              [07/04/2009 - 10:23:44 | N | 40960] C:\MAMACExtract.dll
                              [07/04/2009 - 10:23:46 | N | 1241088] C:\MediaInfo.dll
                              [09/04/2009 - 11:07:30 | N | 167936] C:\MedicDll.dll
                              [14/04/2008 - 12:26:46 | N | 1028096] C:\mfc42.dll
                              [03/04/2007 - 13:14:48 | N | 981760] C:\mfc42u.dll
                              [07/04/2009 - 10:23:42 | N | 159744] C:\Mirage.dll
                              [07/04/2009 - 10:55:04 | N | 23384] C:\MMSProfile.ppz
                              [07/04/2009 - 10:23:42 | N | 294912] C:\MMTCM3EncoderDLL.dll
                              [16/04/2009 - 10:39:10 | N | 327680] C:\MObexDll.dll
                              [31/12/2009 - 23:41:52 | D ] C:\ModelExtension
                              [07/04/2009 - 11:10:24 | N | 184320] C:\Modem.dll
                              [18/02/2009 - 14:13:39 | N | 0] C:\MSDOS.SYS
                              [18/02/2009 - 15:10:12 | RHD ] C:\MSOCache
                              [07/04/2009 - 11:10:18 | N | 499712] C:\msvcp71.dll
                              [14/04/2008 - 12:26:50 | N | 343040] C:\msvcrt.dll
                              [07/04/2009 - 10:23:46 | N | 28672] C:\MTDES.dll
                              [07/04/2009 - 10:23:44 | N | 692224] C:\NeoCertDll.dll
                              [16/04/2009 - 17:09:28 | N | 1863680] C:\NewPCStudio.exe
                              [16/04/2009 - 10:43:28 | N | 925696] C:\NLANG_Scheduler.dll
                              [07/04/2009 - 10:40:26 | N | 4960256] C:\NPS.dat
                              [08/07/2008 - 15:20:56 | N | 569344] C:\npsadec.dll
                              [08/07/2008 - 15:22:22 | N | 139264] C:\npsaef.dll
                              [16/04/2009 - 10:41:18 | N | 102400] C:\NPSAgent.exe
                              [16/04/2009 - 17:01:18 | N | 94208] C:\NPSAlarm.exe
                              [07/04/2009 - 10:55:04 | N | 287232] C:\NPSAndroidDownloader.dll
                              [16/04/2009 - 10:44:02 | N | 2801664] C:\NPSApp.exe
                              [01/08/2008 - 15:23:36 | N | 471040] C:\npsappactl.dll
                              [16/04/2009 - 10:38:14 | N | 77824] C:\NPSArbiter.dll
                              [08/07/2008 - 15:29:34 | N | 139264] C:\npsasrc.dll
                              [09/09/2008 - 17:30:46 | N | 204800] C:\npsasvr.exe
                              [08/07/2008 - 15:23:38 | N | 192512] C:\npsawms.dll
                              [16/04/2009 - 17:00:34 | N | 192512] C:\NPSBackupAndRestore.exe
                              [16/04/2009 - 10:39:08 | N | 53248] C:\NPSBinaryInfo_DU.dll
                              [16/04/2009 - 10:38:30 | N | 86016] C:\NPSBinaryInfo_Limo.dll
                              [16/04/2009 - 10:38:46 | N | 94208] C:\NPSBinaryInfo_Qualcomm.dll
                              [16/04/2009 - 10:38:48 | N | 94208] C:\NPSBinaryInfo_Symbian.dll
                              [16/04/2009 - 10:39:06 | N | 30208] C:\NPSBinaryInfo_WM.dll
                              [16/04/2009 - 17:00:20 | N | 1404928] C:\NPSBinaryUpgrade.exe
                              [25/11/2008 - 17:51:44 | N | 86016] C:\NPSBSCKoreaUMS.dll
                              [25/11/2008 - 17:52:12 | N | 16384] C:\NPSBVCKoreaUMS.dll
                              [08/02/2011 - 10:17:22 | N | 0] C:\NPSC.log
                              [16/04/2009 - 10:38:18 | N | 155648] C:\NPSCBT.dll
                              [16/04/2009 - 17:07:22 | N | 684032] C:\NPSCDBurner.exe
                              [16/04/2009 - 17:06:54 | N | 831488] C:\NPSCDRipper.exe
                              [16/04/2009 - 10:39:00 | N | 147456] C:\NPSCM.exe
                              [16/04/2009 - 16:59:14 | N | 430080] C:\NPSCommon5.dll
                              [16/04/2009 - 10:44:12 | N | 1163264] C:\NPSComnCtrl.dll
                              [16/04/2009 - 10:39:16 | N | 73728] C:\NPSConnection.exe
                              [16/04/2009 - 16:59:48 | N | 315392] C:\NPSConverter.dll
                              [16/04/2009 - 17:02:20 | N | 1474560] C:\NPSConvey.dll
                              [16/04/2009 - 10:38:12 | N | 57344] C:\NPSCore.dll
                              [16/04/2009 - 17:01:30 | N | 790528] C:\NPSCustomCtrl.dll
                              [16/04/2009 - 10:45:06 | N | 405504] C:\NPSCW.exe
                              [07/04/2009 - 10:40:24 | N | 617472] C:\NPSDataHouse.exe
                              [16/04/2009 - 10:38:18 | N | 90112] C:\NPSDBProxy.dll
                              [16/04/2009 - 10:41:42 | N | 425984] C:\NPSDCAATCDMA.dll
                              [16/04/2009 - 10:42:56 | N | 765952] C:\NPSDCAATOBEX.dll
                              [16/04/2009 - 10:40:38 | N | 507904] C:\NPSDCACHINA2HSP.dll
                              [16/04/2009 - 17:12:50 | N | 585728] C:\NPSDCACHINAHSP.dll
                              [16/04/2009 - 10:40:46 | N | 626688] C:\NPSDCADU.dll
                              [16/04/2009 - 10:41:02 | N | 528384] C:\NPSDCAGM.dll
                              [16/04/2009 - 10:42:54 | N | 823296] C:\NPSDCAGMOBEX.dll
                              [16/04/2009 - 10:43:52 | N | 344064] C:\NPSDCAHSP.dll
                              [16/04/2009 - 10:41:16 | N | 503808] C:\NPSDCAKOREAHSP.dll
                              [16/04/2009 - 10:53:28 | N | 839680] C:\NPSDCAMITSOBEX.dll
                              [16/04/2009 - 10:43:56 | N | 913408] C:\NPSDCAOBEX.dll
                              [16/04/2009 - 10:44:32 | N | 622592] C:\NPSDCASW.dll
                              [16/04/2009 - 10:41:50 | N | 409600] C:\NPSDCASYM.dll
                              [16/04/2009 - 16:59:48 | N | 630784] C:\NPSDCAWM.dll
                              [16/04/2009 - 10:39:18 | N | 61440] C:\NPSDCM.dll
                              [16/04/2009 - 17:05:56 | N | 221184] C:\NPSDDay.exe
                              [16/04/2009 - 10:41:44 | N | 180224] C:\NPSDENG.exe
                              [16/04/2009 - 10:39:12 | N | 765952] C:\NPSDeviceDRM3rd.dll
                              [16/04/2009 - 17:04:42 | N | 663552] C:\NPSDeviceList.dll
                              [16/04/2009 - 18:34:48 | N | 2191360] C:\NPSDexplorer.exe
                              [16/04/2009 - 10:39:42 | N | 352256] C:\NPSDM.exe
                              [16/04/2009 - 17:01:42 | N | 901120] C:\NPSDMPPlayer.exe
                              [16/04/2009 - 10:39:30 | N | 1085440] C:\NPSDump.exe
                              [07/04/2009 - 10:23:44 | N | 73728] C:\NPSEffectFilter.dll
                              [16/04/2009 - 17:02:56 | N | 159744] C:\NPSEmailSync.exe
                              [16/04/2009 - 10:44:42 | N | 1810432] C:\NPSFull.exe
                              [16/04/2009 - 16:59:34 | N | 159744] C:\NPSFunction5.dll
                              [25/11/2008 - 18:08:26 | N | 909312] C:\NPSFUSClientDU.exe
                              [07/04/2009 - 10:54:40 | N | 2584394] C:\NPSGuide.dat
                              [16/04/2009 - 10:43:12 | N | 61440] C:\NPSGuide.exe
                              [16/04/2009 - 10:38:16 | N | 114688] C:\NPSHSPAgent.dll
                              [16/04/2009 - 17:09:12 | N | 1335296] C:\NPSIFXBinaryUpgrade.exe
                              [16/04/2009 - 17:07:40 | N | 299008] C:\NPSImageViewer.exe
                              [07/04/2009 - 10:23:44 | N | 61440] C:\NPSImgFilter.ax
                              [16/04/2009 - 17:04:12 | N | 135168] C:\NPSInstApp.exe
                              [16/04/2009 - 17:06:12 | N | 241664] C:\NPSInternetConnector.exe
                              [16/04/2009 - 17:04:58 | N | 2949120] C:\NPSLang.dll
                              [16/04/2009 - 10:42:22 | N | 712704] C:\NPSLang_BackupAndRestore.dll
                              [16/04/2009 - 10:38:40 | N | 532480] C:\NPSLang_DDay.dll
                              [16/04/2009 - 10:38:46 | N | 622592] C:\NPSLang_EmailSync.dll
                              [16/04/2009 - 10:41:54 | N | 253952] C:\NPSLang_InstApp.dll
                              [16/04/2009 - 10:43:26 | N | 692224] C:\NPSLang_InternetConnector.dll
                              [16/04/2009 - 10:39:00 | N | 475136] C:\NPSLang_Memo.dll
                              [16/04/2009 - 10:41:56 | N | 626688] C:\NPSLang_MessageManager.dll
                              [16/04/2009 - 10:52:40 | N | 1204224] C:\NPSLang_MyDiary.dll
                              [16/04/2009 - 10:43:02 | N | 806912] C:\NPSLang_MyExplorer.dll
                              [16/04/2009 - 10:39:00 | N | 1536000] C:\NPSLang_Phonebook.dll
                              [16/04/2009 - 10:41:52 | N | 327680] C:\NPSLang_SMSSender.dll
                              [16/04/2009 - 10:40:00 | N | 507904] C:\NPSLang_TimeTable.dll
                              [16/04/2009 - 16:58:44 | N | 573440] C:\NPSLang_ToDo.dll
                              [16/04/2009 - 10:40:02 | N | 331776] C:\NPSLang_VoiceMemo.dll
                              [07/04/2009 - 10:55:04 | N | 285184] C:\NPSLinuxMitsDownloader.dll
                              [10/04/2009 - 16:08:20 | N | 270848] C:\NPSLinuxMitsNpDownloader.dll
                              [16/04/2009 - 10:46:32 | N | 1503232] C:\NPSMainChecker.exe
                              [17/04/2009 - 10:22:20 | N | 7274496] C:\NPSMediaManager.exe
                              [16/04/2009 - 17:08:24 | N | 180224] C:\NPSMemo.exe
                              [16/04/2009 - 17:05:06 | N | 593920] C:\NPSMessageManager.exe
                              [16/04/2009 - 17:00:34 | N | 1110016] C:\NPSMitsBinaryUpgrade.exe
                              [16/04/2009 - 17:00:24 | N | 249856] C:\NPSMMSPlay.dll
                              [16/04/2009 - 17:08:40 | N | 917504] C:\NPSMMSSender.exe
                              [16/04/2009 - 10:38:16 | N | 61440] C:\NPSModelDB.dll
                              [08/07/2008 - 15:24:20 | N | 131072] C:\npsmpgs.dll
                              [16/04/2009 - 18:34:48 | N | 466944] C:\NPSMTPExplorer.exe
                              [30/12/2008 - 02:41:12 | N | 94208] C:\NPSMusicManager.dll
                              [16/04/2009 - 17:08:18 | N | 1114112] C:\NPSMusicPlayer.exe
                              [16/04/2009 - 16:59:36 | N | 45568] C:\NPSMyComputer.dll
                              [16/04/2009 - 17:09:36 | N | 434176] C:\NPSMyDiary.exe
                              [16/04/2009 - 17:03:14 | N | 557056] C:\NPSMyExplorer.exe
                              [16/04/2009 - 19:05:22 | N | 557056] C:\NPSNetworkProviderDB.dat
                              [16/04/2009 - 17:06:34 | N | 1970176] C:\NPSNotifyClient.exe
                              [16/04/2009 - 17:09:40 | N | 884736] C:\NPSPhonebook.exe
                              [16/04/2009 - 10:33:36 | N | 480234] C:\NPSPhoneProfile.ppz
                              [16/04/2009 - 10:43:56 | N | 73728] C:\NPSPwRecovery.exe
                              [16/04/2009 - 17:00:34 | N | 1613824] C:\NPSQualcommBinaryUpgrade.exe
                              [07/04/2009 - 10:44:22 | N | 153984] C:\NPSRapiServer.dll
                              [16/04/2009 - 10:24:32 | N | 161152] C:\NPSRapiServer_k.dll
                              [07/04/2009 - 10:44:22 | N | 138624] C:\NPSRapiServer_m.dll
                              [16/04/2009 - 18:27:06 | N | 987136] C:\npssamsungmodeldb.dat
                              [16/04/2009 - 17:07:30 | N | 675840] C:\NPSScheduler.exe
                              [07/04/2009 - 10:44:22 | N | 34176] C:\NPSSendMessage.exe
                              [16/04/2009 - 17:05:34 | N | 356352] C:\NPSSIMEditor.exe
                              [16/04/2009 - 17:04:32 | N | 221184] C:\NPSSMSSender.exe
                              [16/04/2009 - 17:03:14 | N | 712704] C:\NPSStageSync.exe
                              [07/04/2009 - 10:23:44 | N | 65536] C:\NPSSubPicture.dll
                              [16/04/2009 - 17:03:14 | N | 1363968] C:\NPSSymbianBinaryUpgrade.exe
                              [16/04/2009 - 10:42:58 | N | 573440] C:\NPSSync.dll
                              [16/04/2009 - 17:04:36 | N | 307200] C:\NPSTimeTable.exe
                              [16/04/2009 - 17:07:54 | N | 270336] C:\NPSToDo.exe
                              [16/04/2009 - 10:43:56 | N | 622592] C:\NPSToolboxAdd.exe
                              [16/04/2009 - 17:06:06 | N | 880640] C:\NPSToWeb2.exe
                              [16/04/2009 - 10:44:36 | N | 40960] C:\NPSToWebBtn.dll
                              [16/04/2009 - 10:43:24 | N | 50176] C:\NPSUserWebFeedback.exe
                              [08/07/2008 - 18:23:12 | N | 139264] C:\npsvae.dll
                              [01/08/2008 - 13:25:02 | N | 839680] C:\npsvctl.dll
                              [16/04/2009 - 17:01:52 | N | 741376] C:\NPSVideoConverter.exe
                              [16/04/2009 - 17:07:20 | N | 655360] C:\NPSVideoPlayer.exe
                              [16/04/2009 - 17:02:54 | N | 229376] C:\NPSVoiceMemo.exe
                              [08/07/2008 - 19:15:30 | N | 143360] C:\npsvsrc.dll
                              [09/09/2008 - 17:33:18 | N | 204800] C:\npsvsvr.exe
                              [08/07/2008 - 18:19:26 | N | 167936] C:\npsvve.dll
                              [08/07/2008 - 18:26:08 | N | 200704] C:\npsvwms.dll
                              [16/04/2009 - 17:05:04 | N | 102400] C:\NPSWidgetContainer.exe
                              [16/04/2009 - 17:04:36 | N | 675840] C:\NPSWizard.exe
                              [16/04/2009 - 10:38:52 | N | 217088] C:\NPSWMBinaryEngine.dll
                              [16/04/2009 - 17:00:28 | N | 2265088] C:\NPSWMBinaryUpgrade.exe
                              [07/04/2009 - 10:23:44 | N | 667648] C:\NPS_MEDIA_USER_DB.dat
                              [10/04/2007 - 11:40:46 | N | 74240] C:\nsldap32v11.dll
                              [14/04/2008 - 14:00:00 | N | 47564] C:\NTDETECT.COM
                              [14/04/2008 - 14:00:00 | N | 252240] C:\ntldr
                              [16/04/2009 - 10:38:50 | N | 27136] C:\ObexInterface.dll
                              [09/04/2009 - 19:58:38 | N | 274432] C:\Octans_HomeDL.dll
                              [19/02/2009 - 10:34:24 | N | 266240] C:\Omnia_HomeDL_VISTA.dll
                              [19/02/2009 - 10:34:24 | N | 266240] C:\Omnia_HomeDL_XP.dll
                              [15/04/2011 - 01:04:38 | ASH | 2145386496] C:\pagefile.sys
                              [07/04/2009 - 11:10:24 | N | 90112] C:\PC_Download_DLL_AP.dll
                              [13/09/2009 - 16:46:12 | D ] C:\PDFCreator
                              [06/10/2009 - 16:55:22 | D ] C:\PhotoFiltre
                              [07/04/2009 - 10:23:44 | N | 94208] C:\proghelp.dll
                              [15/04/2011 - 01:35:42 | D ] C:\Program Files
                              [07/06/2010 - 15:19:10 | N | 9157] C:\qr.dat
                              [04/08/2008 - 01:48:44 | N | 138024] C:\rapi.dll
                              [15/04/2011 - 02:39:42 | SHD ] C:\RECYCLER
                              [31/12/2009 - 23:41:53 | D ] C:\resources
                              [07/04/2009 - 10:23:44 | N | 352256] C:\SamsungMediaServer.dll
                              [07/04/2009 - 10:23:46 | N | 384512] C:\SAPEncoder.dll
                              [07/04/2009 - 10:44:22 | N | 13880] C:\SetupNPSRapiServer.exe
                              [07/04/2009 - 10:44:22 | N | 13880] C:\SetupNPSRapiServer_SGH-i900.exe
                              [07/04/2009 - 10:23:44 | N | 2367488] C:\SMAFMMS5EMU.dll
                              [16/04/2009 - 10:38:36 | N | 122880] C:\Smllib.dll
                              [07/04/2009 - 10:23:46 | N | 383488] C:\SMPDecoder.dll
                              [07/04/2009 - 10:23:46 | N | 434176] C:\SMPEncoder.dll
                              [20/06/2010 - 02:49:15 | D ] C:\SolidWorks Data
                              [07/04/2009 - 10:40:24 | N | 904332] C:\splash.dat
                              [07/04/2009 - 10:23:44 | N | 624640] C:\StarBurn.dll
                              [07/04/2009 - 10:23:44 | N | 131072] C:\Sub3.dll
                              [16/04/2009 - 16:50:16 | N | 208896] C:\Symbian_Downloader_DLL.dll
                              [16/04/2009 - 10:39:02 | N | 94208] C:\SyncEngine.dll
                              [14/04/2011 - 22:26:59 | SHD ] C:\System Volume Information
                              [07/04/2009 - 10:44:22 | N | 35840] C:\TCLAppointment.dll
                              [07/04/2009 - 10:23:44 | N | 40960] C:\TCM2Decoder12.dll
                              [07/04/2009 - 10:23:44 | N | 40960] C:\TCM2Decoder16.dll
                              [07/04/2009 - 10:23:44 | N | 36864] C:\TCM2Decoder2.dll
                              [07/04/2009 - 10:23:44 | N | 36864] C:\TCM2Decoder24.dll
                              [07/04/2009 - 10:23:44 | N | 40960] C:\TCM2Decoder8.dll
                              [07/04/2009 - 10:23:44 | N | 98304] C:\TCM2Encoder.dll
                              [07/04/2009 - 10:23:44 | N | 229376] C:\TCMSEncoder.dll
                              [07/04/2009 - 10:39:44 | N | 16392] C:\TFsExDisk.sys
                              [10/03/2008 - 00:59:42 | ASH | 4096] C:\Thumbs.db
                              [07/04/2009 - 10:23:44 | N | 36864] C:\tn30CSTK.dll
                              [05/06/2008 - 01:08:56 | N | 5734400] C:\ToolkitPro1112vc80U.dll
                              [16/04/2009 - 10:38:18 | N | 114688] C:\Type.dll
                              [28/08/2005 - 21:51:42 | N | 766] C:\Uninstall.ico
                              [31/12/2009 - 23:41:53 | D ] C:\USB Drivers
                              [15/04/2011 - 02:41:56 | D ] C:\UsbFix
                              [15/04/2011 - 02:42:08 | A | 1339] C:\UsbFix.txt
                              [16/04/2009 - 10:38:32 | N | 102400] C:\vObject.dll
                              [14/04/2011 - 23:35:58 | D ] C:\WINDOWS
                              [07/04/2009 - 11:10:30 | N | 16384] C:\winusb.dll
                              [01/03/2001 - 09:27:00 | N | 278800] C:\wmv8ds32.ax
                              [28/04/2000 - 11:01:00 | N | 262416] C:\wmvds32.ax
                              [07/04/2009 - 10:23:44 | N | 126976] C:\WnASPI32.dll
                              [23/01/2010 - 00:59:08 | D ] C:\XPortail
                              [07/04/2009 - 10:23:46 | N | 151552] C:\XSYNCClt.dll
                              [28/07/2008 - 12:31:06 | D ] F:\wd_windows_tools
                              [28/07/2008 - 12:32:14 | D ] F:\wd_mac_tools
                              [28/07/2008 - 12:32:22 | D ] F:\autorun
                              [31/03/2008 - 12:57:12 | N | 87] F:\Install.ini
                              [01/04/2008 - 15:05:20 | N | 319488] F:\setup.exe
                              [28/08/2008 - 18:28:46 | SHD ] F:\System Volume Information
                              [28/08/2008 - 18:38:58 | D ] F:\Films
                              [29/08/2008 - 21:10:30 | D ] F:\Campings
                              [14/09/2008 - 21:37:36 | D ] F:\Technologie
                              [17/09/2008 - 21:29:10 | D ] F:\Photos
                              [18/09/2008 - 12:00:24 | SHD ] F:\Recycled
                              [05/12/2008 - 23:57:52 | D ] F:\Soft
                              [17/02/2009 - 18:54:58 | D ] F:\Da^wah 'ila l-Lah
                              [22/10/2009 - 18:52:14 | D ] F:\Sauvegarde PC
                              [16/04/2010 - 08:54:20 | D ] F:\1-TECHNOLOGIE
                              [21/03/2010 - 15:50:06 | D ] F:\cours chaykh
                              [15/08/2010 - 21:09:52 | D ] F:\0a161b8819e54857cd13f1
                              [04/09/2010 - 16:07:06 | D ] F:\Disque ECE 04 09 2010
                              [27/03/2011 - 15:08:36 | D ] F:\Disque ECE 27 03 2011

                              ################## | Vaccin |

                              C:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
                              F:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)

                              ################## | Upload |

                              Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC01.zip
                              http://www.teamxscript.org/Upload.php
                              Merci de votre contribution.

                              ################## | E.O.F |
                              1. J'étais en train de me dire la même chose. Je crois que c'est le logiciel livré avec mon téléphone portable qui a foutu le bazarre (Samsung New PC Studio). J'en ai pas besoin. Il faudrait que je le désinstalle si tu es ok.
                                1. C'est bon, c'est beaucoup plus beaucoup maintenant après avoir désinstaller tous les petits modules et avec un redémarrage :)

                                  Quelle est l'étape suivante ?
                                  1. Au secours ! Il s'est passé une catastrophe. Après t'avoir posté mon message précédent j'ai vu qu'il restait 2 applications samsung non désinstallés dans le panneau de config. Je les ai désinstallé puis redémarrer et là :
                                    Le PC affiche un écran tout noir avec écris en haut : NTDLR manque appuyer sur CTRL+ALT+SUPPR. Mais quand je le fais j'obtiens la même chose.

                                    J'ai du aller chercher un autre PC pour t'écrire. L'autre ne répond plus. Je suis un paniqué je t'avoue.
                                    • 1
                                    • 2
                                    • 3