[Virus] Infecté par Magic control agent
Résolu/Fermé
A voir également:
- Slends magic
- Honor magic 5 pro vs s23 ultra - Guide
- File magic - Télécharger - Traitement de texte
- Magic iso - Télécharger - Gravure
- Magic karaoke maker - Télécharger - DJ & Karaoké
- Magic utilities - Télécharger - Optimisation
43 réponses
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
7 sept. 2006 à 16:02
7 sept. 2006 à 16:02
Salut
oui, en effet : il est plutôt très coriace celui-ci
Télécharge Blacklight (de F-Secure) :
https://www.f-secure.com/en
et sauvegarde le sur ton Bureau.
Double-clique blbeta.exe et accepte la licence ;clique Scan puis Next
Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).
Copie et colle le contenu de ce rapport dans ta prochaine réponse
@+
oui, en effet : il est plutôt très coriace celui-ci
Télécharge Blacklight (de F-Secure) :
https://www.f-secure.com/en
et sauvegarde le sur ton Bureau.
Double-clique blbeta.exe et accepte la licence ;clique Scan puis Next
Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).
Copie et colle le contenu de ce rapport dans ta prochaine réponse
@+
Voici le resultat
09/07/06 16:29:15 [Info]: BlackLight Engine 1.0.46 initialized
09/07/06 16:29:15 [Info]: OS: 5.1 build 2600 (Service Pack 2)
09/07/06 16:29:15 [Note]: 7019 4
09/07/06 16:29:15 [Note]: 7005 0
09/07/06 16:29:17 [Note]: 7006 0
09/07/06 16:29:17 [Note]: 7011 1736
09/07/06 16:29:17 [Note]: 7026 0
09/07/06 16:29:17 [Note]: 7026 0
09/07/06 16:29:17 [Note]: 7024 3
09/07/06 16:29:17 [Info]: Hidden process: C:\windows\system32\bvcxkxlymh.exe
09/07/06 16:29:18 [Note]: FSRAW library version 1.7.1019
09/07/06 16:30:05 [Note]: 4020 21816 131072
09/07/06 16:30:05 [Note]: 4020 21816 131072
09/07/06 16:30:05 [Note]: 4018 21816 131072
09/07/06 16:34:22 [Info]: Hidden file: c:\WINDOWS\Prefetch\BVCXKXLYMH.EXE-228148B5.pf
09/07/06 16:34:22 [Note]: 10002 1
09/07/06 16:34:39 [Info]: Hidden file: c:\WINDOWS\system32\bvcxkxlymh_nav.dat
09/07/06 16:34:39 [Note]: 10002 1
09/07/06 16:34:40 [Info]: Hidden file: c:\WINDOWS\system32\bvcxkxlymh.dat
09/07/06 16:34:40 [Note]: 10002 1
09/07/06 16:34:41 [Info]: Hidden file: C:\windows\system32\bvcxkxlymh.exe
09/07/06 16:34:41 [Note]: 10002 1
09/07/06 16:34:41 [Info]: Hidden file: c:\WINDOWS\system32\bvcxkxlymh_navps.dat
09/07/06 16:34:41 [Note]: 10002 1
09/07/06 16:35:15 [Note]: 7007 0
09/07/06 16:29:15 [Info]: BlackLight Engine 1.0.46 initialized
09/07/06 16:29:15 [Info]: OS: 5.1 build 2600 (Service Pack 2)
09/07/06 16:29:15 [Note]: 7019 4
09/07/06 16:29:15 [Note]: 7005 0
09/07/06 16:29:17 [Note]: 7006 0
09/07/06 16:29:17 [Note]: 7011 1736
09/07/06 16:29:17 [Note]: 7026 0
09/07/06 16:29:17 [Note]: 7026 0
09/07/06 16:29:17 [Note]: 7024 3
09/07/06 16:29:17 [Info]: Hidden process: C:\windows\system32\bvcxkxlymh.exe
09/07/06 16:29:18 [Note]: FSRAW library version 1.7.1019
09/07/06 16:30:05 [Note]: 4020 21816 131072
09/07/06 16:30:05 [Note]: 4020 21816 131072
09/07/06 16:30:05 [Note]: 4018 21816 131072
09/07/06 16:34:22 [Info]: Hidden file: c:\WINDOWS\Prefetch\BVCXKXLYMH.EXE-228148B5.pf
09/07/06 16:34:22 [Note]: 10002 1
09/07/06 16:34:39 [Info]: Hidden file: c:\WINDOWS\system32\bvcxkxlymh_nav.dat
09/07/06 16:34:39 [Note]: 10002 1
09/07/06 16:34:40 [Info]: Hidden file: c:\WINDOWS\system32\bvcxkxlymh.dat
09/07/06 16:34:40 [Note]: 10002 1
09/07/06 16:34:41 [Info]: Hidden file: C:\windows\system32\bvcxkxlymh.exe
09/07/06 16:34:41 [Note]: 10002 1
09/07/06 16:34:41 [Info]: Hidden file: c:\WINDOWS\system32\bvcxkxlymh_navps.dat
09/07/06 16:34:41 [Note]: 10002 1
09/07/06 16:35:15 [Note]: 7007 0
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
7 sept. 2006 à 17:15
7 sept. 2006 à 17:15
re
repasse spybot et vois s'il le detete toujours, ensuite reposte un nouveau hijackthis stp
++
repasse spybot et vois s'il le detete toujours, ensuite reposte un nouveau hijackthis stp
++
Il le trouve toujours et il arive pas a le delete:
raport Hitjackthis
raport Hitjackthis
Logfile of HijackThis v1.99.1 Scan saved at 18:42:12, on 07/09/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\PESTPA~1\PPControl.exe C:\PROGRA~1\PESTPA~1\CookiePatrol.exe C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Apache Group\Apache\Apache.exe C:\Program Files\CA\eTrust Antivirus\InoRpc.exe C:\Program Files\Apache Group\Apache\Apache.exe C:\Program Files\CA\eTrust Antivirus\InoRT.exe C:\Program Files\CA\eTrust Antivirus\InoTask.exe C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\explorer.exe C:\Program Files\Winamp\Winamp.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe C:\Documents and Settings\shinta\Bureau\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 83.206.128.73:80 R3 - Default URLSearchHook is missing O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe O4 - HKCU\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe O4 - Startup: Adobe Gamma Loader.exe O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Fichiers communs\justDo\IECatcher.DLL O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Fichiers communs\justDo\IECatcher.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU) O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU) O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_s... O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" --ntservice (file missing) O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Unknown owner - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: rpcapd - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) O23 - Service: SAVScan - Unknown owner - C:\Program Files\Norton AntiVirus\SAVScan.exe (file missing) O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: SSL Explorer - Unknown owner - C:\Program Files\sslexplorer\platforms\windows\wrapper.exe" -s "C:\Program Files\sslexplorer\conf\wrapper.conf (file missing) O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
7 sept. 2006 à 18:56
7 sept. 2006 à 18:56
re
as tu un antivirus, un parfeu ???
ok, evite de mettre ton rapport en bleu stp c'est pas très lisible ...
Relance HijackThis : choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked" :
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKCU\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - Startup: Adobe Gamma Loader.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_s...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
ensuite, télécharge ceci :
# Ccleaner : Telecharge et installe ceci, dans la colonne de gauche clique sur "erreurs" coche toute les cases, puis clique en bas sur "chercher des erreurs" une fois finit, clique sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs .
*Relance Ccleaner ,vas dans l'onglet "nettoyeur" present sur la gauche, decoche la derniere case (Avancé si elle
est cochée) puis clique sur "lancer le nettoyage"
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
tuto: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
et enfin :
scan en ligne : colle rapport entier ( s’il y a quelque chose) :
http://www.bitdefender.fr/bd/site/search.php#
++
**tout ce que je sais, c'est que je ne sais rien ! et c'est déjà pas mal ...**
as tu un antivirus, un parfeu ???
ok, evite de mettre ton rapport en bleu stp c'est pas très lisible ...
Relance HijackThis : choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked" :
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKCU\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - Startup: Adobe Gamma Loader.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_s...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
ensuite, télécharge ceci :
# Ccleaner : Telecharge et installe ceci, dans la colonne de gauche clique sur "erreurs" coche toute les cases, puis clique en bas sur "chercher des erreurs" une fois finit, clique sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs .
*Relance Ccleaner ,vas dans l'onglet "nettoyeur" present sur la gauche, decoche la derniere case (Avancé si elle
est cochée) puis clique sur "lancer le nettoyage"
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
tuto: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
et enfin :
scan en ligne : colle rapport entier ( s’il y a quelque chose) :
http://www.bitdefender.fr/bd/site/search.php#
++
**tout ce que je sais, c'est que je ne sais rien ! et c'est déjà pas mal ...**
bon voila c fait jai fait tout ske tu ma dit , cclean ne pouvait opas suprimer une erreur.
et apres lanalyse bitdefender, jai eu mon raport:
le voila:
http://shintasadamoto.free.fr/d.html
et apres lanalyse bitdefender, jai eu mon raport:
le voila:
http://shintasadamoto.free.fr/d.html
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
9 sept. 2006 à 18:51
9 sept. 2006 à 18:51
Salut
où en sont tes soucis ???
++
où en sont tes soucis ???
++
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
12 sept. 2006 à 10:39
12 sept. 2006 à 10:39
Salut
relance Blacklight et fais l'option 2
voir tuto en image ici :
http://perso.orange.fr/entraide-hijackthis/Mailskinner/Blacklight.htm
tiens nous au courant, @+
relance Blacklight et fais l'option 2
voir tuto en image ici :
http://perso.orange.fr/entraide-hijackthis/Mailskinner/Blacklight.htm
tiens nous au courant, @+
toujours pareil. auncun changement mais alors ia vraiment aucun changement pourtant il voit 5probleme , les rename chaqun mais sa change absolument rien.
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
12 sept. 2006 à 23:00
12 sept. 2006 à 23:00
ok,
# Affiche les dossiers système et fichiers cachés :
Ouvrir le poste de travail :
- Outils --> Options des dossiers
- Affichage --> zone Paramètres avancés
- Cocher : Afficher le contenu des dossiers système
- Cocher : Afficher les fichiers et dossiers cachés
- Décocher : Masquer les extensions des fichiers dont le type est connu
- Décocher : Masquer les fichiers protégés du système d'exploitation (recommandé)
répondre Oui au message
Clique sur "Appliquer à tous les dossiers"
Clique sur OK
# supprime manuellement les fichiers en gras suivants :
c:\WINDOWS\Prefetch <== seulemenet son contenu !
C:\windows\system32\bvcxkxlymh.exe
c:\WINDOWS\system32\bvcxkxlymh_nav.dat
C:\windows\system32\bvcxkxlymh.exe
c:\WINDOWS\system32\bvcxkxlymh_navps.dat
ensuite repasse spybot, et dis nous ce qu'il en est !
++
# Affiche les dossiers système et fichiers cachés :
Ouvrir le poste de travail :
- Outils --> Options des dossiers
- Affichage --> zone Paramètres avancés
- Cocher : Afficher le contenu des dossiers système
- Cocher : Afficher les fichiers et dossiers cachés
- Décocher : Masquer les extensions des fichiers dont le type est connu
- Décocher : Masquer les fichiers protégés du système d'exploitation (recommandé)
répondre Oui au message
Clique sur "Appliquer à tous les dossiers"
Clique sur OK
# supprime manuellement les fichiers en gras suivants :
c:\WINDOWS\Prefetch <== seulemenet son contenu !
C:\windows\system32\bvcxkxlymh.exe
c:\WINDOWS\system32\bvcxkxlymh_nav.dat
C:\windows\system32\bvcxkxlymh.exe
c:\WINDOWS\system32\bvcxkxlymh_navps.dat
ensuite repasse spybot, et dis nous ce qu'il en est !
++
Salut! J'ai suivi les conseils que tu as donnés à Shinta, concernant les moyens de se débarasser de magic agent, à partir de l'étape blacklight (je n'ai pas trouver scan hitjackthis), après avoir fait une recherche spyboat... apparement, il se serait débarassé de 8 problèmes (ce n'est pas la première fois) y compris de magic! Bref, voici le rapport fsbl
http://www.communicanis.com/ideesrecues.html09/30/06 23:22:35 [Info]: BlackLight Engine 1.0.47 initialized
09/30/06 23:22:35 [Info]: OS: 5.1 build 2600 (Service Pack 2)
09/30/06 23:22:35 [Note]: 7019 4
09/30/06 23:22:35 [Note]: 7005 0
09/30/06 23:22:37 [Note]: 7006 0
09/30/06 23:22:37 [Note]: 7011 672
09/30/06 23:22:38 [Note]: 7026 0
09/30/06 23:22:38 [Note]: 7026 0
09/30/06 23:22:38 [Note]: 7024 3
09/30/06 23:22:38 [Info]: Hidden process: C:\windows\system32\sqcbfcpmbv.exe
09/30/06 23:22:38 [Note]: FSRAW library version 1.7.1020
09/30/06 23:23:36 [Info]: Hidden file: c:\WINDOWS\Prefetch\SQCBFCPMBV.EXE-00F29985.pf
09/30/06 23:23:36 [Note]: 10002 1
09/30/06 23:23:45 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv.dat
09/30/06 23:23:45 [Note]: 10002 1
09/30/06 23:23:45 [Info]: Hidden file: C:\windows\system32\sqcbfcpmbv.exe
09/30/06 23:23:45 [Note]: 10002 1
09/30/06 23:23:46 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv_nav.dat
09/30/06 23:23:46 [Note]: 10002 1
09/30/06 23:23:46 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv_navps.dat
09/30/06 23:23:46 [Note]: 10002 1
09/30/06 23:36:11 [Note]: 7007 0
J'ai ensuite suivi l'étape dossiers systèmes et fichiers cachés, mais je n'ai pas trouvé les fichiers à effacer... Je débute...
Merci pour ton aide!
http://www.communicanis.com/ideesrecues.html09/30/06 23:22:35 [Info]: BlackLight Engine 1.0.47 initialized
09/30/06 23:22:35 [Info]: OS: 5.1 build 2600 (Service Pack 2)
09/30/06 23:22:35 [Note]: 7019 4
09/30/06 23:22:35 [Note]: 7005 0
09/30/06 23:22:37 [Note]: 7006 0
09/30/06 23:22:37 [Note]: 7011 672
09/30/06 23:22:38 [Note]: 7026 0
09/30/06 23:22:38 [Note]: 7026 0
09/30/06 23:22:38 [Note]: 7024 3
09/30/06 23:22:38 [Info]: Hidden process: C:\windows\system32\sqcbfcpmbv.exe
09/30/06 23:22:38 [Note]: FSRAW library version 1.7.1020
09/30/06 23:23:36 [Info]: Hidden file: c:\WINDOWS\Prefetch\SQCBFCPMBV.EXE-00F29985.pf
09/30/06 23:23:36 [Note]: 10002 1
09/30/06 23:23:45 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv.dat
09/30/06 23:23:45 [Note]: 10002 1
09/30/06 23:23:45 [Info]: Hidden file: C:\windows\system32\sqcbfcpmbv.exe
09/30/06 23:23:45 [Note]: 10002 1
09/30/06 23:23:46 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv_nav.dat
09/30/06 23:23:46 [Note]: 10002 1
09/30/06 23:23:46 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv_navps.dat
09/30/06 23:23:46 [Note]: 10002 1
09/30/06 23:36:11 [Note]: 7007 0
J'ai ensuite suivi l'étape dossiers systèmes et fichiers cachés, mais je n'ai pas trouvé les fichiers à effacer... Je débute...
Merci pour ton aide!
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
1 oct. 2006 à 01:27
1 oct. 2006 à 01:27
Salut
Télécharge ceci :
Lien : hijackthis
Démo : http://pageperso.aol.fr/balltrap34/demohijack.htm
Choisir l'option "do a scan and a logfile", et faire un copier/coller du rapport ainsi générer sur le forum.
@+
Télécharge ceci :
Lien : hijackthis
Démo : http://pageperso.aol.fr/balltrap34/demohijack.htm
Choisir l'option "do a scan and a logfile", et faire un copier/coller du rapport ainsi générer sur le forum.
@+
J'ai téléchargé hijack: forcément j'avais mal noté le nom! Merci!
Qu'est ce que je dois faire maintenant?
Encore merci
Logfile of HijackThis v1.99.1
Scan saved at 00:43:20, on 01/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Documents and Settings\Julien\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [HbTools] C:\Program Files\HbTools\Bin\4.8.0.0\HbtOEAddOn.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MailSkinner] c:\program files\mailskinner\mailskinner.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
Qu'est ce que je dois faire maintenant?
Encore merci
Logfile of HijackThis v1.99.1
Scan saved at 00:43:20, on 01/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Documents and Settings\Julien\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [HbTools] C:\Program Files\HbTools\Bin\4.8.0.0\HbtOEAddOn.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MailSkinner] c:\program files\mailskinner\mailskinner.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
J'ai téléchargé hijack: forcément j'avais mal noté le nom! Merci!
Qu'est ce que je dois faire maintenant?
Encore merci
Logfile of HijackThis v1.99.1
Scan saved at 00:43:20, on 01/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Documents and Settings\Julien\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [HbTools] C:\Program Files\HbTools\Bin\4.8.0.0\HbtOEAddOn.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MailSkinner] c:\program files\mailskinner\mailskinner.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
Qu'est ce que je dois faire maintenant?
Encore merci
Logfile of HijackThis v1.99.1
Scan saved at 00:43:20, on 01/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Documents and Settings\Julien\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [HbTools] C:\Program Files\HbTools\Bin\4.8.0.0\HbtOEAddOn.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MailSkinner] c:\program files\mailskinner\mailskinner.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
1 oct. 2006 à 14:23
1 oct. 2006 à 14:23
Salut
combien d'antivirus actifs as tu ???
va dans ajout/ supprimer un programme : et vire ceci MailSkinner
ensuite :
télécharge ceci :
# Ewido (gratuit) :
ewido
tuto : (merci à Moe) http://perso.wanadoo.fr/entraide-hijackthis/Ewido/
poste le rapport ici stp
#CleanUp40 (qui élimine les fichiers temporaires + cookies : gratuit )
http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
tuto : (merci à Balltrap) http://pageperso.aol.fr/balltrap34/democleanup.htm
@+
combien d'antivirus actifs as tu ???
va dans ajout/ supprimer un programme : et vire ceci MailSkinner
ensuite :
télécharge ceci :
# Ewido (gratuit) :
ewido
tuto : (merci à Moe) http://perso.wanadoo.fr/entraide-hijackthis/Ewido/
poste le rapport ici stp
#CleanUp40 (qui élimine les fichiers temporaires + cookies : gratuit )
http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
tuto : (merci à Balltrap) http://pageperso.aol.fr/balltrap34/democleanup.htm
@+
Voilà le rapport:
---------------------------------------------------------
+ Created at: 14:22:15 01/10/2006
+ Scan result:
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc24.exe -> Adware.HotBar : No action taken.
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc26.dll -> Adware.HotBar : No action taken.
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc28.exe -> Adware.HotBar : No action taken.
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc29.dll -> Adware.HotBar : No action taken.
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc30.dll -> Adware.HotBar : No action taken.
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc31.dll -> Adware.HotBar : No action taken.
C:\WINDOWS\system32\tpqjozfb.exe -> Adware.HotBar : No action taken.
C:\Program Files\Masta\pipi.exe -> Dialer.Masta.c : No action taken.
:mozilla.14:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.15:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.16:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@msnlivefavorites.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.34:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.35:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
:mozilla.23:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.24:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.25:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.38:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.62:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.63:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.64:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : No action taken.
:mozilla.42:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@estat[1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@as1.falkag[2].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@ads.pointroll[2].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.30:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.31:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.32:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@smartadserver[2].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.26:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.28:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.59:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@weborama[1].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@zedo[2].txt -> TrackingCookie.Zedo : No action taken.
::Report end
---------------------------------------------------------
+ Created at: 14:22:15 01/10/2006
+ Scan result:
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc24.exe -> Adware.HotBar : No action taken.
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc26.dll -> Adware.HotBar : No action taken.
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc28.exe -> Adware.HotBar : No action taken.
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc29.dll -> Adware.HotBar : No action taken.
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc30.dll -> Adware.HotBar : No action taken.
C:\RECYCLER\S-1-5-21-1645522239-1767777339-682003330-1003\Dc31.dll -> Adware.HotBar : No action taken.
C:\WINDOWS\system32\tpqjozfb.exe -> Adware.HotBar : No action taken.
C:\Program Files\Masta\pipi.exe -> Dialer.Masta.c : No action taken.
:mozilla.14:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.15:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.16:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@msnlivefavorites.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.34:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.35:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
:mozilla.23:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.24:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.25:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.38:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.62:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.63:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.64:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : No action taken.
:mozilla.42:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@estat[1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@as1.falkag[2].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@ads.pointroll[2].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.30:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.31:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.32:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@smartadserver[2].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.26:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.28:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.59:C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\cookies.txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@weborama[1].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\Julien\Cookies\julien@zedo[2].txt -> TrackingCookie.Zedo : No action taken.
::Report end
Salut!
Je ne sais pas si ils sont actifs, mais comme anti virus, j'ai avast, et hier soir j'ai téléchargé antivir... J'ai voulu télécharger la nouvelle version d'avast, mais il me dit qu'il y a un problème lors de l'installation... Du coup je ne sais pas!
Je viens de lancer ewido: je t'envoies le rapport dès que c'est ok!
Je dois attendre pour lancer cleanup?
Je ne sais pas si ils sont actifs, mais comme anti virus, j'ai avast, et hier soir j'ai téléchargé antivir... J'ai voulu télécharger la nouvelle version d'avast, mais il me dit qu'il y a un problème lors de l'installation... Du coup je ne sais pas!
Je viens de lancer ewido: je t'envoies le rapport dès que c'est ok!
Je dois attendre pour lancer cleanup?
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
1 oct. 2006 à 15:18
1 oct. 2006 à 15:18
oui, fais cleanup après ewido !
déinstalle antivir, et garde avast ( car il faut obligatoirement avoir qu'un seul antivirus ! )
++
déinstalle antivir, et garde avast ( car il faut obligatoirement avoir qu'un seul antivirus ! )
++
Je t'envoies quand même le rapport clean up!
CleanUp! started on 10/01/06 14:25:46.
...
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_info.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_logout.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_none.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_options.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_pause.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_reboot.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_remove.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_rename.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_resume.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_search.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_server.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_shared.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_showcat.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_shutdown.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_sources_0.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_sources_10.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_sources_25.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_sources_5.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_sources_50.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_static.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_stop.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_timer.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_timer_off.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_uparrow.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_updoublearrow.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_users.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_version.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\main_bg.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\main_menubg.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\main_topbar.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\main_topbardarker.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\main_topbarseperator.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\m_category.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\m_catprio.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\m_clearcompleted.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\paused.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_black.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue1.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue2.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue3.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue4.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue5.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue6.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_green.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_greenpercent.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_red.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_yellow.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\qs_con.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\qs_down.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\qs_up.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\qs_user.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\red.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stalled.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_0.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_1.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_10.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_11.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_12.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_13.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_14.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_15.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_16.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_17.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_2.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_3.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_4.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_5.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_6.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_7.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_8.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_9.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_back.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_con.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_down.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_hidden.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_space.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_up.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_visible.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stopped.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\transparent.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_complete.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_completing.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_connecting.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_downloading.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_error.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_hashing.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_next.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_paused.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_stalled.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_stopped.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_uploading.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_waiting.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_waitinghash.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\waiting.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\waitinghash.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\yellow.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\VBE\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\WMC0000.tmp\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\wz86f\eMule0.47a-Installer.exe - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\wz86f\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_avast4_\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\15d15e7.DLL - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\Corecomp.ini - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\Ctl3d32.dll - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\IsUninst.exe - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\allez salut.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\balcon .jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\balcon 2.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\côté droit par balcon.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\côté gauche par balcon.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrèe salont droite.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée chambre par balcon.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée chambre par couloir.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée cuisine par balcon.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée cuisine.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée gauche .jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée maison.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée salle de bain.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée salon 1.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée salon 2.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée salon par balcon.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée salont gauche.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\IMAGE_065.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\IMAGE_160.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\IMAGE_164.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\IMAGE_165.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\maison d'Hécate.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\maison Nova.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\pipi.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\plantule 2.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\plantule 3.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\plantules 1.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\poissons maison.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\salon et entrée cuisine.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\sortie cuisine.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\sortie salle de bain.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\voilà.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\~nsu.tmp\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Perflib_Perfdata_290.dat currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\Julien\LOCALS~1\Temp\~DF387A.tmp currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\Julien\LOCALS~1\Temp\~DF398B.tmp currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\Julien\LOCALS~1\Temp\~DF5B17.tmp currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\Julien\LOCALS~1\Temp\~DF5B1C.tmp currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\SET3.tmp - deleted
C:\WINDOWS\SET4.tmp - deleted
C:\WINDOWS\SET8.tmp - deleted
C:\WINDOWS\IE4 Error Log.txt - deleted
C:\WINDOWS\temp\ASPNETSetup_00000.log - deleted
C:\WINDOWS\temp\DSP33.tmp - deleted
C:\WINDOWS\temp\DSP34.tmp - deleted
C:\WINDOWS\temp\DSP35.tmp - deleted
C:\WINDOWS\temp\DSP36.tmp - deleted
C:\WINDOWS\temp\install_msk.exe - deleted
C:\WINDOWS\temp\msksetup.log - deleted
C:\WINDOWS\temp\nsu43.tmp - deleted
C:\WINDOWS\temp\nsy42.tmp - deleted
C:\WINDOWS\temp\Perflib_Perfdata_104.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_150.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_198.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_210.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_25c.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_278.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_27c.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_348.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_508.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_678.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_6c8.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_734.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_73c.dat - deleted
C:\WINDOWS\temp\RegModule.exe - deleted
C:\WINDOWS\temp\RegModule.ini - deleted
C:\WINDOWS\temp\T30DebugLogFile.txt - deleted
C:\WINDOWS\temp\WGAErrLog.txt - deleted
C:\WINDOWS\temp\WGANotify.settings - deleted
C:\WINDOWS\temp\_avast4_\ - deleted
C:\Documents and Settings\NetworkService\Cookies\index.dat - deleted
C:\Documents and Settings\NetworkService\locals~1\tempor~1\Content.IE5\index.dat - deleted
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat - deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\ - deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\Historique\History.IE5\index.dat - deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat - deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\Perflib_Perfdata_290.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF387A.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF398B.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B17.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B1C.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Administrateur\Cookies\index.dat - deleted
C:\Documents and Settings\Administrateur\locals~1\tempor~1\Content.IE5\index.dat - deleted
C:\Documents and Settings\Administrateur\Local Settings\Temp\dat27.tmp - deleted
C:\Documents and Settings\Administrateur\Local Settings\Historique\History.IE5\index.dat - deleted
C:\Documents and Settings\All Users\DRM\DRMv1.bak - deleted
C:\Documents and Settings\Julien\Application Data\Microsoft\Address Book\Julien.wab~ - deleted
C:\Documents and Settings\Julien\Application Data\Microsoft\Office\Récent\index.dat - deleted
C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\bookmarks.bak - deleted
C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\bookmarks.html.sbsd.bak - deleted
C:\Documents and Settings\Julien\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\koboldef@free.fr\SharingMetadata\volume.xml~ - deleted
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\koboldef@free.fr\SharingMetadata\Working\database_F208_DC37_8DB_F915\fsr.chk - deleted
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\koboldes@free.fr\SharingMetadata\volume.xml~ - deleted
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\koboldes@free.fr\SharingMetadata\Working\database_F208_DC37_8DB_F915\fsr.chk - deleted
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\raleuse20@hotmail.com\SharingMetadata\volume.xml~ - deleted
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\raleuse20@hotmail.com\SharingMetadata\Working\database_F208_DC37_8DB_F915\fsr.chk - deleted
C:\Documents and Settings\Julien\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Historique\History.IE5\MSHist012006100120061002\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF387A.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF398B.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B17.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B1C.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF387A.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF398B.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B17.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B1C.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\UserData\index.dat - deleted
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat - deleted
C:\Program Files\eMule\downloads.bak - deleted
C:\Program Files\eMule\config\clients.met.bak - deleted
C:\Program Files\eMule\config\eMule Light.tmpl - deleted
C:\Program Files\eMule\config\eMule.tmpl - deleted
C:\Program Files\eMule\Temp\001.part.met.bak - deleted
C:\Program Files\eMule\Temp\003.part.met.bak - deleted
C:\Program Files\eMule\Temp\004.part.met.bak - deleted
C:\Program Files\eMule\Temp\006.part.met.bak - deleted
C:\Program Files\eMule\Temp\007.part.met.bak - deleted
C:\Program Files\eMule\Temp\008.part.met.bak - deleted
C:\Program Files\eMule\Temp\009.part.met.bak - deleted
C:\Program Files\eMule\Temp\010.part.met.bak - deleted
C:\Program Files\eMule\Temp\011.part.met.bak - deleted
C:\Program Files\eMule\Temp\012.part.met.bak - deleted
C:\Program Files\eMule\Temp\013.part.met.bak - deleted
C:\Program Files\eMule\Temp\014.part.met.bak - deleted
C:\Program Files\eMule\Temp\015.part.met.bak - deleted
C:\Program Files\eMule\Temp\016.part.met.bak - deleted
C:\Program Files\eMule\Temp\017.part.met.bak - deleted
C:\Program Files\eMule\Temp\018.part.met.bak - deleted
C:\Program Files\eMule\Temp\021.part.met.bak - deleted
C:\Program Files\eMule\Temp\026.part.met.bak - deleted
C:\Program Files\eMule\Temp\031.part.met.bak - deleted
C:\Program Files\eMule\Temp\033.part.met.bak - deleted
C:\Program Files\eMule\Temp\034.part.met.bak - deleted
C:\Program Files\eMule\Temp\041.part.met.bak - deleted
C:\Program Files\eMule\Temp\042.part.met.bak - deleted
C:\Program Files\eMule\Temp\069.part.met.bak - deleted
C:\Program Files\eMule\Temp\094.part.met.bak - deleted
C:\Program Files\eMule\Temp\095.part.met.bak - deleted
C:\Program Files\eMule\Temp\102.part.met.bak - deleted
C:\Program Files\eMule\Temp\103.part.met.bak - deleted
C:\Program Files\Mozilla Firefox\softokn3.chk - deleted
C:\Program Files\Soft4Ever\looknstop\JeuDeReglesStandard.bak - deleted
C:\Program Files\Spybot - Search & Destroy\advcheck.dll.bak - deleted
C:\WINDOWS\imsins.BAK - deleted
C:\WINDOWS\Installer\MSIE6.tmp - deleted
C:\WINDOWS\pchealth\helpctr\Config\Cache\Professional_32_1036.dat.bak - deleted
C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat - deleted
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk - deleted
C:\WINDOWS\system32\CONFIG.TMP - deleted
C:\WINDOWS\system32\CatRoot2\edb.chk - deleted
C:\WINDOWS\system32\NtmsData\NTMSDATA.BAK - deleted
E:\Mes documents\EP STEF\~$P STEF.doc - deleted
E:\Mes documents\Mel\OMC\~$OMC.doc - deleted
E:\Mes documents\Sauvegarde de la licence\drmv1key.bak - deleted
E:\Mes documents\Sauvegarde de la licence\drmv1lic.bak - deleted
E:\Mes documents\Sauvegarde de la licence\drmv2key.bak - deleted
E:\Mes documents\Sauvegarde de la licence\drmv2lic.bak - deleted
Emptied Recycle Bin on drive C:
Emptied Recycle Bin on drive E:
'Run MRU' list - removed from the registry.
Paint Recent File List - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
WinZip File MRU list - removed from the registry.
CleanUp! 4.0 recovered 111.0 MB of disk space from 2324 files.
CleanUp! finished on 10/01/06 14:27:28.
CleanUp! started on 10/01/06 14:25:46.
...
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_info.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_logout.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_none.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_options.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_pause.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_reboot.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_remove.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_rename.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_resume.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_search.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_server.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_shared.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_showcat.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_shutdown.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_sources_0.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_sources_10.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_sources_25.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_sources_5.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_sources_50.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_static.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_stop.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_timer.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_timer_off.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_uparrow.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_updoublearrow.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_users.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\l_version.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\main_bg.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\main_menubg.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\main_topbar.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\main_topbardarker.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\main_topbarseperator.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\m_category.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\m_catprio.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\m_clearcompleted.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\paused.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_black.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue1.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue2.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue3.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue4.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue5.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_blue6.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_green.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_greenpercent.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_red.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\p_yellow.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\qs_con.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\qs_down.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\qs_up.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\qs_user.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\red.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stalled.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_0.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_1.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_10.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_11.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_12.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_13.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_14.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_15.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_16.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_17.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_2.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_3.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_4.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_5.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_6.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_7.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_8.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_9.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_back.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_con.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_down.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_hidden.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_space.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_up.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stats_visible.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\stopped.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\transparent.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_complete.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_completing.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_connecting.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_downloading.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_error.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_hashing.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_next.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_paused.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_stalled.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_stopped.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_uploading.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_waiting.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\t_waitinghash.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\waiting.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\waitinghash.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\yellow.gif - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\webserver\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\emule\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Répertoire temporaire 1 pour eMulev0.47a.-MorphXTv8.13-bin.zip\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\VBE\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\WMC0000.tmp\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\wz86f\eMule0.47a-Installer.exe - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\wz86f\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_avast4_\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\15d15e7.DLL - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\Corecomp.ini - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\Ctl3d32.dll - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\IsUninst.exe - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_ISTMP1.DIR\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\allez salut.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\balcon .jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\balcon 2.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\côté droit par balcon.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\côté gauche par balcon.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrèe salont droite.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée chambre par balcon.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée chambre par couloir.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée cuisine par balcon.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée cuisine.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée gauche .jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée maison.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée salle de bain.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée salon 1.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée salon 2.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée salon par balcon.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\entrée salont gauche.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\IMAGE_065.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\IMAGE_160.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\IMAGE_164.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\IMAGE_165.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\maison d'Hécate.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\maison Nova.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\pipi.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\plantule 2.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\plantule 3.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\plantules 1.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\poissons maison.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\salon et entrée cuisine.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\sortie cuisine.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\sortie salle de bain.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\voilà.jpg - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\_PegEx~1\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\~nsu.tmp\ - deleted
C:\DOCUME~1\Julien\LOCALS~1\Temp\Perflib_Perfdata_290.dat currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\Julien\LOCALS~1\Temp\~DF387A.tmp currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\Julien\LOCALS~1\Temp\~DF398B.tmp currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\Julien\LOCALS~1\Temp\~DF5B17.tmp currently in use. Will be deleted when Windows is restarted.
C:\DOCUME~1\Julien\LOCALS~1\Temp\~DF5B1C.tmp currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\SET3.tmp - deleted
C:\WINDOWS\SET4.tmp - deleted
C:\WINDOWS\SET8.tmp - deleted
C:\WINDOWS\IE4 Error Log.txt - deleted
C:\WINDOWS\temp\ASPNETSetup_00000.log - deleted
C:\WINDOWS\temp\DSP33.tmp - deleted
C:\WINDOWS\temp\DSP34.tmp - deleted
C:\WINDOWS\temp\DSP35.tmp - deleted
C:\WINDOWS\temp\DSP36.tmp - deleted
C:\WINDOWS\temp\install_msk.exe - deleted
C:\WINDOWS\temp\msksetup.log - deleted
C:\WINDOWS\temp\nsu43.tmp - deleted
C:\WINDOWS\temp\nsy42.tmp - deleted
C:\WINDOWS\temp\Perflib_Perfdata_104.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_150.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_198.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_210.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_25c.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_278.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_27c.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_348.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_508.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_678.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_6c8.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_734.dat - deleted
C:\WINDOWS\temp\Perflib_Perfdata_73c.dat - deleted
C:\WINDOWS\temp\RegModule.exe - deleted
C:\WINDOWS\temp\RegModule.ini - deleted
C:\WINDOWS\temp\T30DebugLogFile.txt - deleted
C:\WINDOWS\temp\WGAErrLog.txt - deleted
C:\WINDOWS\temp\WGANotify.settings - deleted
C:\WINDOWS\temp\_avast4_\ - deleted
C:\Documents and Settings\NetworkService\Cookies\index.dat - deleted
C:\Documents and Settings\NetworkService\locals~1\tempor~1\Content.IE5\index.dat - deleted
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat - deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\ - deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\Historique\History.IE5\index.dat - deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat - deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\Perflib_Perfdata_290.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF387A.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF398B.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B17.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B1C.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Administrateur\Cookies\index.dat - deleted
C:\Documents and Settings\Administrateur\locals~1\tempor~1\Content.IE5\index.dat - deleted
C:\Documents and Settings\Administrateur\Local Settings\Temp\dat27.tmp - deleted
C:\Documents and Settings\Administrateur\Local Settings\Historique\History.IE5\index.dat - deleted
C:\Documents and Settings\All Users\DRM\DRMv1.bak - deleted
C:\Documents and Settings\Julien\Application Data\Microsoft\Address Book\Julien.wab~ - deleted
C:\Documents and Settings\Julien\Application Data\Microsoft\Office\Récent\index.dat - deleted
C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\bookmarks.bak - deleted
C:\Documents and Settings\Julien\Application Data\Mozilla\Firefox\Profiles\3074pnyj.default\bookmarks.html.sbsd.bak - deleted
C:\Documents and Settings\Julien\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\koboldef@free.fr\SharingMetadata\volume.xml~ - deleted
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\koboldef@free.fr\SharingMetadata\Working\database_F208_DC37_8DB_F915\fsr.chk - deleted
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\koboldes@free.fr\SharingMetadata\volume.xml~ - deleted
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\koboldes@free.fr\SharingMetadata\Working\database_F208_DC37_8DB_F915\fsr.chk - deleted
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\raleuse20@hotmail.com\SharingMetadata\volume.xml~ - deleted
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Messenger\raleuse20@hotmail.com\SharingMetadata\Working\database_F208_DC37_8DB_F915\fsr.chk - deleted
C:\Documents and Settings\Julien\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Historique\History.IE5\MSHist012006100120061002\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF387A.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF398B.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B17.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B1C.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF387A.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF398B.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B17.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temp\~DF5B1C.tmp currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Julien\UserData\index.dat - deleted
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat - deleted
C:\Program Files\eMule\downloads.bak - deleted
C:\Program Files\eMule\config\clients.met.bak - deleted
C:\Program Files\eMule\config\eMule Light.tmpl - deleted
C:\Program Files\eMule\config\eMule.tmpl - deleted
C:\Program Files\eMule\Temp\001.part.met.bak - deleted
C:\Program Files\eMule\Temp\003.part.met.bak - deleted
C:\Program Files\eMule\Temp\004.part.met.bak - deleted
C:\Program Files\eMule\Temp\006.part.met.bak - deleted
C:\Program Files\eMule\Temp\007.part.met.bak - deleted
C:\Program Files\eMule\Temp\008.part.met.bak - deleted
C:\Program Files\eMule\Temp\009.part.met.bak - deleted
C:\Program Files\eMule\Temp\010.part.met.bak - deleted
C:\Program Files\eMule\Temp\011.part.met.bak - deleted
C:\Program Files\eMule\Temp\012.part.met.bak - deleted
C:\Program Files\eMule\Temp\013.part.met.bak - deleted
C:\Program Files\eMule\Temp\014.part.met.bak - deleted
C:\Program Files\eMule\Temp\015.part.met.bak - deleted
C:\Program Files\eMule\Temp\016.part.met.bak - deleted
C:\Program Files\eMule\Temp\017.part.met.bak - deleted
C:\Program Files\eMule\Temp\018.part.met.bak - deleted
C:\Program Files\eMule\Temp\021.part.met.bak - deleted
C:\Program Files\eMule\Temp\026.part.met.bak - deleted
C:\Program Files\eMule\Temp\031.part.met.bak - deleted
C:\Program Files\eMule\Temp\033.part.met.bak - deleted
C:\Program Files\eMule\Temp\034.part.met.bak - deleted
C:\Program Files\eMule\Temp\041.part.met.bak - deleted
C:\Program Files\eMule\Temp\042.part.met.bak - deleted
C:\Program Files\eMule\Temp\069.part.met.bak - deleted
C:\Program Files\eMule\Temp\094.part.met.bak - deleted
C:\Program Files\eMule\Temp\095.part.met.bak - deleted
C:\Program Files\eMule\Temp\102.part.met.bak - deleted
C:\Program Files\eMule\Temp\103.part.met.bak - deleted
C:\Program Files\Mozilla Firefox\softokn3.chk - deleted
C:\Program Files\Soft4Ever\looknstop\JeuDeReglesStandard.bak - deleted
C:\Program Files\Spybot - Search & Destroy\advcheck.dll.bak - deleted
C:\WINDOWS\imsins.BAK - deleted
C:\WINDOWS\Installer\MSIE6.tmp - deleted
C:\WINDOWS\pchealth\helpctr\Config\Cache\Professional_32_1036.dat.bak - deleted
C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat - deleted
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk - deleted
C:\WINDOWS\system32\CONFIG.TMP - deleted
C:\WINDOWS\system32\CatRoot2\edb.chk - deleted
C:\WINDOWS\system32\NtmsData\NTMSDATA.BAK - deleted
E:\Mes documents\EP STEF\~$P STEF.doc - deleted
E:\Mes documents\Mel\OMC\~$OMC.doc - deleted
E:\Mes documents\Sauvegarde de la licence\drmv1key.bak - deleted
E:\Mes documents\Sauvegarde de la licence\drmv1lic.bak - deleted
E:\Mes documents\Sauvegarde de la licence\drmv2key.bak - deleted
E:\Mes documents\Sauvegarde de la licence\drmv2lic.bak - deleted
Emptied Recycle Bin on drive C:
Emptied Recycle Bin on drive E:
'Run MRU' list - removed from the registry.
Paint Recent File List - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
WinZip File MRU list - removed from the registry.
CleanUp! 4.0 recovered 111.0 MB of disk space from 2324 files.
CleanUp! finished on 10/01/06 14:27:28.
ça y est je crois que j'ai tout fait... je lancce spyboat? Au fait en supprimant antivir, j'ai vu que j'ai aussi ad aware: c'est un antivirus?
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
1 oct. 2006 à 16:40
1 oct. 2006 à 16:40
No action taken.
refais ewido et regle le sur "deleted" pour qu'il te vire tout ce qu'il te trouve
ad-aware, c'est pas un antivirus,c'est un anti-spywares, complement de spybot !
lance le aussi !
++
refais ewido et regle le sur "deleted" pour qu'il te vire tout ce qu'il te trouve
ad-aware, c'est pas un antivirus,c'est un anti-spywares, complement de spybot !
lance le aussi !
++
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
2 oct. 2006 à 16:45
2 oct. 2006 à 16:45
Salut
je me doute bien qu'il est encore là : il faut supprimer les fichiers trouvés precedement ( en gras ) :
C:\windows\system32\sqcbfcpmbv.exe
c:\WINDOWS\system32\sqcbfcpmbv.dat
C:\windows\system32\sqcbfcpmbv.exe
c:\WINDOWS\system32\sqcbfcpmbv_nav.dat
c:\WINDOWS\system32\sqcbfcpmbv_navps.dat
pour les supprimer, il faut suivre "le chemin" :
poste de travail < clic sur disque local C:\ < dossier Windows < dossier systeme32 < nom du fichier à supprimer
c:\WINDOWS\Prefetch ==> supprimer tout son contenu !
pour le faire : un raccourci : demarrer < executer et tape " Prefetch"
( Ctrl + A = pour tout selectionner, puis Maj suppr pour tout supprimer )
ensuite poste un nouveau hijackthis stp
@+
**tout ce que je sais, c'est que je ne sais rien ! et c'est déjà pas mal ...**
je me doute bien qu'il est encore là : il faut supprimer les fichiers trouvés precedement ( en gras ) :
C:\windows\system32\sqcbfcpmbv.exe
c:\WINDOWS\system32\sqcbfcpmbv.dat
C:\windows\system32\sqcbfcpmbv.exe
c:\WINDOWS\system32\sqcbfcpmbv_nav.dat
c:\WINDOWS\system32\sqcbfcpmbv_navps.dat
pour les supprimer, il faut suivre "le chemin" :
poste de travail < clic sur disque local C:\ < dossier Windows < dossier systeme32 < nom du fichier à supprimer
c:\WINDOWS\Prefetch ==> supprimer tout son contenu !
pour le faire : un raccourci : demarrer < executer et tape " Prefetch"
( Ctrl + A = pour tout selectionner, puis Maj suppr pour tout supprimer )
ensuite poste un nouveau hijackthis stp
@+
**tout ce que je sais, c'est que je ne sais rien ! et c'est déjà pas mal ...**
green day
Messages postés
26371
Date d'inscription
vendredi 30 septembre 2005
Statut
Modérateur, Contributeur sécurité
Dernière intervention
27 décembre 2019
2 162
2 oct. 2006 à 21:17
2 oct. 2006 à 21:17
re
effectivement !
fais ceci stp :
# scan en ligne : colle rapport entier ( s’il y a quelque chose) :
http://www.bitdefender.fr/bd/site/search.php#
# refais la manip avec BlackLight , et poste le rapport
# et poste un nouveau hijackthis stp
precise tes soucis !
@+
effectivement !
fais ceci stp :
# scan en ligne : colle rapport entier ( s’il y a quelque chose) :
http://www.bitdefender.fr/bd/site/search.php#
# refais la manip avec BlackLight , et poste le rapport
# et poste un nouveau hijackthis stp
precise tes soucis !
@+
Je ne sais pas quoi télécharger comme logiciel bitdefender: j'en ai téléchargé une version (pro8) mais j'ai galéré à le lancer, du coup je l'ai viré! estce que tu peux me dire quelle version je dois prendre?
(pardon: jsuis pas très douée!)
Voilà le rapport blacklight
10/02/06 23:23:07 [Info]: BlackLight Engine 1.0.47 initialized
10/02/06 23:23:07 [Info]: OS: 5.1 build 2600 (Service Pack 2)
10/02/06 23:23:07 [Note]: 7019 4
10/02/06 23:23:07 [Note]: 7005 0
10/02/06 23:23:09 [Note]: 7006 0
10/02/06 23:23:09 [Note]: 7011 672
10/02/06 23:23:09 [Note]: 7026 0
10/02/06 23:23:09 [Note]: 7026 0
10/02/06 23:23:13 [Note]: FSRAW library version 1.7.1020
10/02/06 23:26:45 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv.dat
10/02/06 23:26:45 [Note]: 10002 1
10/02/06 23:26:45 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv.exe
10/02/06 23:26:45 [Note]: 10002 1
10/02/06 23:26:46 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv_nav.dat
10/02/06 23:26:46 [Note]: 10002 1
10/02/06 23:26:46 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv_navps.dat
10/02/06 23:26:46 [Note]: 10002 1
10/02/06 23:28:30 [Note]: 7007 0
et le rapport hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 23:21:17, on 02/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Softwin\BitDefender8\bdnagent.exe
C:\Program Files\Softwin\BitDefender8\bdswitch.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Julien\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [sqcbfcpmbv] c:\windows\system32\sqcbfcpmbv.exe sqcbfcpmbv
O4 - HKLM\..\Run: [HbTools] C:\Program Files\HbTools\Bin\4.8.0.0\HbtOEAddOn.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MailSkinner] c:\program files\mailskinner\mailskinner.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
(pardon: jsuis pas très douée!)
Voilà le rapport blacklight
10/02/06 23:23:07 [Info]: BlackLight Engine 1.0.47 initialized
10/02/06 23:23:07 [Info]: OS: 5.1 build 2600 (Service Pack 2)
10/02/06 23:23:07 [Note]: 7019 4
10/02/06 23:23:07 [Note]: 7005 0
10/02/06 23:23:09 [Note]: 7006 0
10/02/06 23:23:09 [Note]: 7011 672
10/02/06 23:23:09 [Note]: 7026 0
10/02/06 23:23:09 [Note]: 7026 0
10/02/06 23:23:13 [Note]: FSRAW library version 1.7.1020
10/02/06 23:26:45 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv.dat
10/02/06 23:26:45 [Note]: 10002 1
10/02/06 23:26:45 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv.exe
10/02/06 23:26:45 [Note]: 10002 1
10/02/06 23:26:46 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv_nav.dat
10/02/06 23:26:46 [Note]: 10002 1
10/02/06 23:26:46 [Info]: Hidden file: c:\WINDOWS\system32\sqcbfcpmbv_navps.dat
10/02/06 23:26:46 [Note]: 10002 1
10/02/06 23:28:30 [Note]: 7007 0
et le rapport hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 23:21:17, on 02/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Softwin\BitDefender8\bdnagent.exe
C:\Program Files\Softwin\BitDefender8\bdswitch.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Julien\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [sqcbfcpmbv] c:\windows\system32\sqcbfcpmbv.exe sqcbfcpmbv
O4 - HKLM\..\Run: [HbTools] C:\Program Files\HbTools\Bin\4.8.0.0\HbtOEAddOn.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MailSkinner] c:\program files\mailskinner\mailskinner.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe