Fenetres intempestive hijackthis ci-joint
deuf78
-
jessydu54870 Messages postés 176 Statut Membre -
jessydu54870 Messages postés 176 Statut Membre -
Bonjour,
ci-jont mon rapport hijack et si possible j'aimeraique qelq'un m'explique la marche a suivre pour la suite
merci
www.commentcamarche.net/forumLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:48:21, on 24/05/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\System32\ACEngSvr.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\ATK Hotkey\KBFiltr.exe
C:\Program Files\ATK Hotkey\WDC.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\P4P\P4P.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\HiJackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [TrayServer] C:\Program Files\MAGIX\Video_deluxe_2008_e-version\TrayServer.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Users\deuf\AppData\Local\Temp\E_S32C7.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\deuf\AppData\Local\Temp\efcYRjJB.dll,#1
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\deuf\AppData\Local\Temp\opnnmJbX.dll,c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [f0b4d9fd] rundll32.exe "C:\Users\deuf\AppData\Local\Temp\vnbrdewk.dll",b
O4 - HKCU\..\Run: [BMf387ea61] Rundll32.exe "C:\Users\deuf\AppData\Local\Temp\mhseqsbs.dll",s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
ci-jont mon rapport hijack et si possible j'aimeraique qelq'un m'explique la marche a suivre pour la suite
merci
www.commentcamarche.net/forumLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:48:21, on 24/05/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\System32\ACEngSvr.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\ATK Hotkey\KBFiltr.exe
C:\Program Files\ATK Hotkey\WDC.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\P4P\P4P.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\HiJackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [TrayServer] C:\Program Files\MAGIX\Video_deluxe_2008_e-version\TrayServer.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Users\deuf\AppData\Local\Temp\E_S32C7.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\deuf\AppData\Local\Temp\efcYRjJB.dll,#1
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\deuf\AppData\Local\Temp\opnnmJbX.dll,c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [f0b4d9fd] rundll32.exe "C:\Users\deuf\AppData\Local\Temp\vnbrdewk.dll",b
O4 - HKCU\..\Run: [BMf387ea61] Rundll32.exe "C:\Users\deuf\AppData\Local\Temp\mhseqsbs.dll",s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
A voir également:
- Fenetres intempestive hijackthis ci-joint
- Hijackthis - Télécharger - Antivirus & Antimalwares
- Module ci+ pirate ✓ - Forum TNT / Satellite / Réception
- Pas de module ci - Forum Téléviseurs
- Astra - Carte TNT sat et module CI?? - Forum TNT / Satellite / Réception
- Problème lecture module Cam Sat HD 441651 sur TV LG - Forum TNT / Satellite / Réception
3 réponses
salut
fais ca :
télécharge Lop S&D.exe sur ton Bureau.https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
* Double-clique dessus pour lancer l'installation
* Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
* Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)
---
fais ca :
télécharge Lop S&D.exe sur ton Bureau.https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
* Double-clique dessus pour lancer l'installation
* Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
* Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)
---
ok fais ca pour les 2 rapport :
pour virer ce qui est trouvé:
* Choisis cette fois ci l'Option 2 (Suppression)
* Ne ferme pas la fenêtre lors de la suppression !
* Poste le rapport généré (C:\lopR.txt)
et tu me reposte un log hijackthis
pour virer ce qui est trouvé:
* Choisis cette fois ci l'Option 2 (Suppression)
* Ne ferme pas la fenêtre lors de la suppression !
* Poste le rapport généré (C:\lopR.txt)
et tu me reposte un log hijackthis
j'ai peut être mal formuler ma question en faite je voulais juste savoir quel était la différence entre les deux prog hijackthis et lop S&D, sinon voila les choses que tu m'a demandé.
1) PC DE PORTABLE rapport généré (C:\lopR.txt) ET log hijackthis
-----------------------[ Lop S&D 4.2.0-9 XP/Vista ]---------------------
[ Windows 'Longhorn' (NT 6.0) Workstation Build 6000 ]
[ USER : deuf ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 25/05/2008 | 3:31:40,57 ] [ PC : PC-DE-DEUF ]
[ MAJ : 16-05-2008 | 23:35 ]
[ UAC => 0 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
Restauré! - Fichier Hosts
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans Application Data ]------------
[12/05/2008|18:47] C:\Users\deuf\AppData\Roaming\Adobe\AUM
[12/05/2008|18:47] C:\Users\deuf\AppData\Roaming\Adobe\Online Services
[12/05/2008|16:03] C:\Users\deuf\AppData\Roaming\Adobe\Photoshop Album
[08/05/2008|12:16] C:\Users\deuf\AppData\Roaming\Adobe\Linguistics
[05/05/2008|17:27] C:\Users\deuf\AppData\Roaming\Adobe\Flash Player
[05/05/2008|16:53] C:\Users\deuf\AppData\Roaming\Adobe\Acrobat
[17/05/2008|14:09] C:\Users\deuf\AppData\Roaming\Ahead\Nero Burning ROM
[05/05/2008|16:54] C:\Users\deuf\AppData\Roaming\ATI\ACE
[22/05/2008|00:27] C:\Users\deuf\AppData\Roaming\AVSMedia\AVS Video Editor
[24/05/2008|20:56] C:\Users\deuf\AppData\Roaming\Azureus\active
[24/05/2008|20:56] C:\Users\deuf\AppData\Roaming\Azureus\dht
[24/05/2008|20:56] C:\Users\deuf\AppData\Roaming\Azureus\net
[24/05/2008|20:50] C:\Users\deuf\AppData\Roaming\Azureus\tmp
[24/05/2008|20:47] C:\Users\deuf\AppData\Roaming\Azureus\torrents
[22/05/2008|15:45] C:\Users\deuf\AppData\Roaming\Azureus\logs
[05/05/2008|21:48] C:\Users\deuf\AppData\Roaming\Azureus\media
[05/05/2008|20:01] C:\Users\deuf\AppData\Roaming\Azureus\shares
[05/05/2008|20:01] C:\Users\deuf\AppData\Roaming\Azureus\plugins
[07/05/2008|03:20] C:\Users\deuf\AppData\Roaming\DivX\DivX Codec
[21/05/2008|23:52] C:\Users\deuf\AppData\Roaming\eMule\config
[24/05/2008|17:24] C:\Users\deuf\AppData\Roaming\EPSON\Creativity Suite
[24/05/2008|16:50] C:\Users\deuf\AppData\Roaming\EPSON\ESCNDV
[16/05/2008|20:58] C:\Users\deuf\AppData\Roaming\Google\Local Search History
[05/05/2008|16:53] C:\Users\deuf\AppData\Roaming\Identities\{93891547-46FC-4EB3-A045-FD4FCB73E0A3}
[12/05/2008|23:43] C:\Users\deuf\AppData\Roaming\InstallShield\ISEngine12.0
[17/05/2008|13:54] C:\Users\deuf\AppData\Roaming\LimeWire\.AppSpecialShare
[06/05/2008|00:54] C:\Users\deuf\AppData\Roaming\LimeWire\xml
[06/05/2008|00:53] C:\Users\deuf\AppData\Roaming\LimeWire\themes
[05/05/2008|17:27] C:\Users\deuf\AppData\Roaming\Macromedia\Flash Player
[22/05/2008|00:06] C:\Users\deuf\AppData\Roaming\MAGIX\Video_deluxe_2008_e-version
[23/05/2008|15:39] C:\Users\deuf\AppData\Roaming\Microsoft\ModŠles
[21/05/2008|16:32] C:\Users\deuf\AppData\Roaming\Microsoft\Windows Photo Gallery
[18/05/2008|20:17] C:\Users\deuf\AppData\Roaming\Microsoft\preuve
[16/05/2008|00:25] C:\Users\deuf\AppData\Roaming\Microsoft\HTML Help
[15/05/2008|17:12] C:\Users\deuf\AppData\Roaming\Microsoft\Word
[14/05/2008|14:06] C:\Users\deuf\AppData\Roaming\Microsoft\Network
[12/05/2008|19:01] C:\Users\deuf\AppData\Roaming\Microsoft\Office
[12/05/2008|19:01] C:\Users\deuf\AppData\Roaming\Microsoft\OIS
[08/05/2008|01:26] C:\Users\deuf\AppData\Roaming\Microsoft\Macros compl‚mentaires
[07/05/2008|17:00] C:\Users\deuf\AppData\Roaming\Microsoft\Installer
[06/05/2008|01:09] C:\Users\deuf\AppData\Roaming\Microsoft\Crypto
[05/05/2008|20:23] C:\Users\deuf\AppData\Roaming\Microsoft\MSN Messenger
[05/05/2008|19:03] C:\Users\deuf\AppData\Roaming\Microsoft\eHome
[05/05/2008|18:54] C:\Users\deuf\AppData\Roaming\Microsoft\Internet Explorer
[05/05/2008|18:46] C:\Users\deuf\AppData\Roaming\Microsoft\IdentityCRL
[05/05/2008|18:39] C:\Users\deuf\AppData\Roaming\Microsoft\MMC
[05/05/2008|17:32] C:\Users\deuf\AppData\Roaming\Microsoft\Windows
[05/05/2008|16:54] C:\Users\deuf\AppData\Roaming\Microsoft\SystemCertificates
[05/05/2008|16:52] C:\Users\deuf\AppData\Roaming\Microsoft\Protect
[05/05/2008|16:49] C:\Users\deuf\AppData\Roaming\Microsoft\Credentials
[05/05/2008|17:55] C:\Users\deuf\AppData\Roaming\Mozilla\Firefox
[12/05/2008|16:44] C:\Users\deuf\AppData\Roaming\Nokia\Nseries Update Manager
[12/05/2008|16:02] C:\Users\deuf\AppData\Roaming\Nokia\NSLauncher
[12/05/2008|16:03] C:\Users\deuf\AppData\Roaming\PC Suite\Settings
[23/05/2008|17:15] C:\Users\deuf\AppData\Roaming\PC Tools\Spyware Doctor
[22/05/2008|02:17] C:\Users\deuf\AppData\Roaming\Sony\Vegas Movie Studio Platinum
[21/05/2008|23:49] C:\Users\deuf\AppData\Roaming\Sony Corporation\Sony Picture Utility
[05/05/2008|17:55] C:\Users\deuf\AppData\Roaming\Talkback\MozillaOrg
[07/05/2008|00:44] C:\Users\deuf\AppData\Roaming\Yahoo!\Companion
----------------[ Tâches planifiées dans C:\Windows\tasks ]---------------
[24/05/2008 16:02][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{EFDFF894-FCB5-4EFE-AAFD-8FA72E20235E}.job
[19/05/2008 20:31][--a------] C:\Windows\tasks\Norton Internet Security - Run Full System Scan - deuf.job
[25/05/2008 03:27][--ah-----] C:\Windows\tasks\SA.DAT
[25/05/2008 03:26][--a------] C:\Windows\tasks\SCHEDLGU.TXT
------[ Listing des dossiers dans C:\ProgramData ]------
[12/05/2008|16:03] C:\ProgramData\Adobe
[02/11/2006|15:02] C:\ProgramData\Application Data
[05/05/2008|16:08] C:\ProgramData\ASUS
[05/05/2008|20:01] C:\ProgramData\Azureus
[23/05/2008|00:53] C:\ProgramData\BMf387ea61.txt
[25/05/2008|01:49] C:\ProgramData\BMf387ea61.xml
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[21/05/2008|23:53] C:\ProgramData\eMule
[15/05/2008|13:06] C:\ProgramData\EPSON
[02/11/2006|15:02] C:\ProgramData\Favorites
[05/05/2008|20:20] C:\ProgramData\Google
[17/05/2008|12:59] C:\ProgramData\LightScribe
[21/05/2008|23:58] C:\ProgramData\MAGIX
[05/05/2008|20:29] C:\ProgramData\Messenger Plus!
[07/05/2008|17:12] C:\ProgramData\Microsoft
[17/05/2008|12:46] C:\ProgramData\Nero
[05/05/2008|16:15] C:\ProgramData\P4G
[12/05/2008|16:03] C:\ProgramData\PC Suite
[22/05/2008|02:42] C:\ProgramData\Pinnacle
[22/05/2008|02:55] C:\ProgramData\Pinnacle VideoSpin
[25/05/2008|03:30] C:\ProgramData\pskt.ini
[22/05/2008|00:49] C:\ProgramData\Sony
[19/05/2008|18:54] C:\ProgramData\Sony Corporation
[25/05/2008|03:18] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[24/05/2008|18:58] C:\ProgramData\Symantec
[25/05/2008|03:31] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[15/05/2008|13:12] C:\ProgramData\UDL
[22/05/2008|02:48] C:\ProgramData\VideoSpin
[05/05/2008|18:33] C:\ProgramData\WLInstaller
[07/05/2008|00:45] C:\ProgramData\Yahoo!
[07/05/2008|02:00] C:\ProgramData\Yahoo! Companion
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[12/05/2008|16:03] C:\Program Files\Adobe
[07/05/2008|17:01] C:\Program Files\ASUS
[05/05/2008|15:39] C:\Program Files\ATI
[05/05/2008|15:41] C:\Program Files\ATI Technologies
[05/05/2008|15:52] C:\Program Files\ATK Hotkey
[05/05/2008|15:52] C:\Program Files\ATKGFNEX
[05/05/2008|15:53] C:\Program Files\ATKOSD2
[22/05/2008|00:53] C:\Program Files\AVSVideo
[05/05/2008|19:53] C:\Program Files\Azureus
[22/05/2008|02:48] C:\Program Files\Common Files
[06/05/2008|04:20] C:\Program Files\desktop.ini
[07/05/2008|02:54] C:\Program Files\DivX
[21/05/2008|23:51] C:\Program Files\eMule
[15/05/2008|13:10] C:\Program Files\epson
[07/05/2008|14:06] C:\Program Files\Google
[19/05/2008|18:59] C:\Program Files\InstallShield Installation Information
[05/05/2008|15:35] C:\Program Files\Intel
[06/05/2008|04:15] C:\Program Files\Internet Explorer
[05/05/2008|20:15] C:\Program Files\Java
[05/05/2008|20:12] C:\Program Files\LimeWire
[21/05/2008|23:57] C:\Program Files\MAGIX
[05/05/2008|20:22] C:\Program Files\Messenger Plus! Live
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[07/05/2008|17:13] C:\Program Files\Microsoft Office
[08/05/2008|20:39] C:\Program Files\Microsoft Silverlight
[07/05/2008|17:12] C:\Program Files\Microsoft.NET
[05/05/2008|15:31] C:\Program Files\Motorola
[18/04/2007|11:24] C:\Program Files\Movie Maker
[05/05/2008|17:54] C:\Program Files\Mozilla Firefox
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[18/04/2007|10:43] C:\Program Files\MSXML 4.0
[17/05/2008|12:46] C:\Program Files\Nero
[16/05/2008|19:49] C:\Program Files\Neuf
[05/05/2008|20:46] C:\Program Files\neuf Talk
[12/05/2008|16:02] C:\Program Files\Nokia
[05/05/2008|17:14] C:\Program Files\Norton Internet Security
[05/05/2008|16:15] C:\Program Files\P4G
[05/05/2008|16:20] C:\Program Files\P4P
[12/05/2008|15:59] C:\Program Files\PC Connectivity Solution
[22/05/2008|02:48] C:\Program Files\Pinnacle
[05/05/2008|16:15] C:\Program Files\Power4Gear eXtreme
[05/05/2008|15:49] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[22/05/2008|00:49] C:\Program Files\Sony
[22/05/2008|00:45] C:\Program Files\Sony Setup
[25/05/2008|03:27] C:\Program Files\Spybot - Search & Destroy
[23/05/2008|17:29] C:\Program Files\Spyware Doctor
[05/05/2008|17:10] C:\Program Files\Symantec
[05/05/2008|16:18] C:\Program Files\Synaptics
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[22/05/2008|00:49] C:\Program Files\Vstplugins
[06/05/2008|04:15] C:\Program Files\Windows Calendar
[18/04/2007|11:24] C:\Program Files\Windows Collaboration
[06/05/2008|04:15] C:\Program Files\Windows Defender
[18/04/2007|11:24] C:\Program Files\Windows Journal
[05/05/2008|18:45] C:\Program Files\Windows Live
[06/05/2008|01:13] C:\Program Files\Windows Live Safety Center
[14/05/2008|18:29] C:\Program Files\Windows Mail
[06/05/2008|04:15] C:\Program Files\Windows Media Player
[02/11/2006|14:37] C:\Program Files\Windows NT
[18/04/2007|11:24] C:\Program Files\Windows Photo Gallery
[06/05/2008|04:15] C:\Program Files\Windows Sidebar
[08/05/2008|17:34] C:\Program Files\WinRAR
[05/05/2008|16:03] C:\Program Files\Wireless Console 2
[07/05/2008|00:44] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Common Files ]------
[09/05/2008|14:46] C:\Program Files\Common Files\Adobe
[17/05/2008|12:47] C:\Program Files\Common Files\Ahead
[22/05/2008|00:54] C:\Program Files\Common Files\AVSMedia
[07/05/2008|17:13] C:\Program Files\Common Files\DESIGNER
[15/05/2008|13:15] C:\Program Files\Common Files\InstallShield
[05/05/2008|20:13] C:\Program Files\Common Files\Java
[17/05/2008|12:50] C:\Program Files\Common Files\LightScribe
[21/05/2008|23:58] C:\Program Files\Common Files\MAGIX Shared
[22/05/2008|00:47] C:\Program Files\Common Files\microsoft shared
[12/05/2008|16:01] C:\Program Files\Common Files\PCSuite
[07/05/2008|02:54] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[05/05/2008|18:32] C:\Program Files\Common Files\Symantec Shared
[06/05/2008|04:15] C:\Program Files\Common Files\System
[05/05/2008|18:45] C:\Program Files\Common Files\WindowsLiveInstaller
[22/05/2008|02:48] C:\Program Files\Common Files\Yahoo!
---------------------------[ Process ]--------------------------
... 82
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-25 03:33:32
Windows 6.0.6000 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\Spyware Doctor Serial - Crack - Keygen (All Version).lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\Spyware.Doctor.v5.5.1.321.Multilangages.Incl-Crack.lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\thirdmovies-crack-addict-6-41.lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\[New] Sony Vegas Movie Studio Platinum Edition 2008 v8.0d Build 139 + Crack (2).lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\[New] Sony Vegas Movie Studio Platinum Edition 2008 v8.0d Build 139 + Crack.lnk
=> C:\Users\deuf\Downloads\eMule\Incoming\Spyware.Doctor.v5.5.1.321.Multilangages.Incl-Crack.rar
=> C:\Users\deuf\Downloads\eMule\Incoming\~$yware Doctor Serial - Crack - Keygen (All Version).doc
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\Spyware Doctor Serial - Crack - Keygen (All Version).lnk
=> C:\Users\deuf\Downloads\eMule\Incoming\~$yware Doctor Serial - Crack - Keygen (All Version).doc
[F:208][D:32]-> C:\Users\deuf\AppData\Local\Temp
[F:159][D:1]-> C:\Users\deuf\AppData\Roaming\MICROS~1\Windows\Cookies
[F:840][D:8]-> C:\Users\deuf\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:2][D:2]-> C:\$Recycle.Bin
[ UAC => 1 ]
--------------------[ Fin du rapport a 3:36:02,47 ]----------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:38:03, on 25/05/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\ACEngSvr.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATK Hotkey\KBFiltr.exe
C:\Program Files\ATK Hotkey\WDC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\P4P\P4P.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\HiJackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {54BF3340-AE49-4710-81BD-64576FC0A45D} - C:\Users\deuf\AppData\Local\Temp\opnnmJbX.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [TrayServer] C:\Program Files\MAGIX\Video_deluxe_2008_e-version\TrayServer.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\mlJYsqno.dll,#1
O4 - HKLM\..\Run: [f0b4d9fd] rundll32.exe "C:\Users\deuf\AppData\Local\Temp\vnbrdewk.dll",b
O4 - HKLM\..\Run: [BMf387ea61] Rundll32.exe "C:\Users\deuf\AppData\Local\Temp\mhseqsbs.dll",s
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Users\deuf\AppData\Local\Temp\E_S32C7.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\deuf\AppData\Local\Temp\khfEWQHw.dll,#1
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\deuf\AppData\Local\Temp\opnnmJbX.dll,c
O4 - HKCU\..\Run: [BMf387ea61] Rundll32.exe "C:\Users\deuf\AppData\Local\Temp\mhseqsbs.dll",s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
1) PC DE PORTABLE rapport généré (C:\lopR.txt) ET log hijackthis
-----------------------[ Lop S&D 4.2.0-9 XP/Vista ]---------------------
[ Windows 'Longhorn' (NT 6.0) Workstation Build 6000 ]
[ USER : deuf ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 25/05/2008 | 3:31:40,57 ] [ PC : PC-DE-DEUF ]
[ MAJ : 16-05-2008 | 23:35 ]
[ UAC => 0 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
Restauré! - Fichier Hosts
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans Application Data ]------------
[12/05/2008|18:47] C:\Users\deuf\AppData\Roaming\Adobe\AUM
[12/05/2008|18:47] C:\Users\deuf\AppData\Roaming\Adobe\Online Services
[12/05/2008|16:03] C:\Users\deuf\AppData\Roaming\Adobe\Photoshop Album
[08/05/2008|12:16] C:\Users\deuf\AppData\Roaming\Adobe\Linguistics
[05/05/2008|17:27] C:\Users\deuf\AppData\Roaming\Adobe\Flash Player
[05/05/2008|16:53] C:\Users\deuf\AppData\Roaming\Adobe\Acrobat
[17/05/2008|14:09] C:\Users\deuf\AppData\Roaming\Ahead\Nero Burning ROM
[05/05/2008|16:54] C:\Users\deuf\AppData\Roaming\ATI\ACE
[22/05/2008|00:27] C:\Users\deuf\AppData\Roaming\AVSMedia\AVS Video Editor
[24/05/2008|20:56] C:\Users\deuf\AppData\Roaming\Azureus\active
[24/05/2008|20:56] C:\Users\deuf\AppData\Roaming\Azureus\dht
[24/05/2008|20:56] C:\Users\deuf\AppData\Roaming\Azureus\net
[24/05/2008|20:50] C:\Users\deuf\AppData\Roaming\Azureus\tmp
[24/05/2008|20:47] C:\Users\deuf\AppData\Roaming\Azureus\torrents
[22/05/2008|15:45] C:\Users\deuf\AppData\Roaming\Azureus\logs
[05/05/2008|21:48] C:\Users\deuf\AppData\Roaming\Azureus\media
[05/05/2008|20:01] C:\Users\deuf\AppData\Roaming\Azureus\shares
[05/05/2008|20:01] C:\Users\deuf\AppData\Roaming\Azureus\plugins
[07/05/2008|03:20] C:\Users\deuf\AppData\Roaming\DivX\DivX Codec
[21/05/2008|23:52] C:\Users\deuf\AppData\Roaming\eMule\config
[24/05/2008|17:24] C:\Users\deuf\AppData\Roaming\EPSON\Creativity Suite
[24/05/2008|16:50] C:\Users\deuf\AppData\Roaming\EPSON\ESCNDV
[16/05/2008|20:58] C:\Users\deuf\AppData\Roaming\Google\Local Search History
[05/05/2008|16:53] C:\Users\deuf\AppData\Roaming\Identities\{93891547-46FC-4EB3-A045-FD4FCB73E0A3}
[12/05/2008|23:43] C:\Users\deuf\AppData\Roaming\InstallShield\ISEngine12.0
[17/05/2008|13:54] C:\Users\deuf\AppData\Roaming\LimeWire\.AppSpecialShare
[06/05/2008|00:54] C:\Users\deuf\AppData\Roaming\LimeWire\xml
[06/05/2008|00:53] C:\Users\deuf\AppData\Roaming\LimeWire\themes
[05/05/2008|17:27] C:\Users\deuf\AppData\Roaming\Macromedia\Flash Player
[22/05/2008|00:06] C:\Users\deuf\AppData\Roaming\MAGIX\Video_deluxe_2008_e-version
[23/05/2008|15:39] C:\Users\deuf\AppData\Roaming\Microsoft\ModŠles
[21/05/2008|16:32] C:\Users\deuf\AppData\Roaming\Microsoft\Windows Photo Gallery
[18/05/2008|20:17] C:\Users\deuf\AppData\Roaming\Microsoft\preuve
[16/05/2008|00:25] C:\Users\deuf\AppData\Roaming\Microsoft\HTML Help
[15/05/2008|17:12] C:\Users\deuf\AppData\Roaming\Microsoft\Word
[14/05/2008|14:06] C:\Users\deuf\AppData\Roaming\Microsoft\Network
[12/05/2008|19:01] C:\Users\deuf\AppData\Roaming\Microsoft\Office
[12/05/2008|19:01] C:\Users\deuf\AppData\Roaming\Microsoft\OIS
[08/05/2008|01:26] C:\Users\deuf\AppData\Roaming\Microsoft\Macros compl‚mentaires
[07/05/2008|17:00] C:\Users\deuf\AppData\Roaming\Microsoft\Installer
[06/05/2008|01:09] C:\Users\deuf\AppData\Roaming\Microsoft\Crypto
[05/05/2008|20:23] C:\Users\deuf\AppData\Roaming\Microsoft\MSN Messenger
[05/05/2008|19:03] C:\Users\deuf\AppData\Roaming\Microsoft\eHome
[05/05/2008|18:54] C:\Users\deuf\AppData\Roaming\Microsoft\Internet Explorer
[05/05/2008|18:46] C:\Users\deuf\AppData\Roaming\Microsoft\IdentityCRL
[05/05/2008|18:39] C:\Users\deuf\AppData\Roaming\Microsoft\MMC
[05/05/2008|17:32] C:\Users\deuf\AppData\Roaming\Microsoft\Windows
[05/05/2008|16:54] C:\Users\deuf\AppData\Roaming\Microsoft\SystemCertificates
[05/05/2008|16:52] C:\Users\deuf\AppData\Roaming\Microsoft\Protect
[05/05/2008|16:49] C:\Users\deuf\AppData\Roaming\Microsoft\Credentials
[05/05/2008|17:55] C:\Users\deuf\AppData\Roaming\Mozilla\Firefox
[12/05/2008|16:44] C:\Users\deuf\AppData\Roaming\Nokia\Nseries Update Manager
[12/05/2008|16:02] C:\Users\deuf\AppData\Roaming\Nokia\NSLauncher
[12/05/2008|16:03] C:\Users\deuf\AppData\Roaming\PC Suite\Settings
[23/05/2008|17:15] C:\Users\deuf\AppData\Roaming\PC Tools\Spyware Doctor
[22/05/2008|02:17] C:\Users\deuf\AppData\Roaming\Sony\Vegas Movie Studio Platinum
[21/05/2008|23:49] C:\Users\deuf\AppData\Roaming\Sony Corporation\Sony Picture Utility
[05/05/2008|17:55] C:\Users\deuf\AppData\Roaming\Talkback\MozillaOrg
[07/05/2008|00:44] C:\Users\deuf\AppData\Roaming\Yahoo!\Companion
----------------[ Tâches planifiées dans C:\Windows\tasks ]---------------
[24/05/2008 16:02][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{EFDFF894-FCB5-4EFE-AAFD-8FA72E20235E}.job
[19/05/2008 20:31][--a------] C:\Windows\tasks\Norton Internet Security - Run Full System Scan - deuf.job
[25/05/2008 03:27][--ah-----] C:\Windows\tasks\SA.DAT
[25/05/2008 03:26][--a------] C:\Windows\tasks\SCHEDLGU.TXT
------[ Listing des dossiers dans C:\ProgramData ]------
[12/05/2008|16:03] C:\ProgramData\Adobe
[02/11/2006|15:02] C:\ProgramData\Application Data
[05/05/2008|16:08] C:\ProgramData\ASUS
[05/05/2008|20:01] C:\ProgramData\Azureus
[23/05/2008|00:53] C:\ProgramData\BMf387ea61.txt
[25/05/2008|01:49] C:\ProgramData\BMf387ea61.xml
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[21/05/2008|23:53] C:\ProgramData\eMule
[15/05/2008|13:06] C:\ProgramData\EPSON
[02/11/2006|15:02] C:\ProgramData\Favorites
[05/05/2008|20:20] C:\ProgramData\Google
[17/05/2008|12:59] C:\ProgramData\LightScribe
[21/05/2008|23:58] C:\ProgramData\MAGIX
[05/05/2008|20:29] C:\ProgramData\Messenger Plus!
[07/05/2008|17:12] C:\ProgramData\Microsoft
[17/05/2008|12:46] C:\ProgramData\Nero
[05/05/2008|16:15] C:\ProgramData\P4G
[12/05/2008|16:03] C:\ProgramData\PC Suite
[22/05/2008|02:42] C:\ProgramData\Pinnacle
[22/05/2008|02:55] C:\ProgramData\Pinnacle VideoSpin
[25/05/2008|03:30] C:\ProgramData\pskt.ini
[22/05/2008|00:49] C:\ProgramData\Sony
[19/05/2008|18:54] C:\ProgramData\Sony Corporation
[25/05/2008|03:18] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[24/05/2008|18:58] C:\ProgramData\Symantec
[25/05/2008|03:31] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[15/05/2008|13:12] C:\ProgramData\UDL
[22/05/2008|02:48] C:\ProgramData\VideoSpin
[05/05/2008|18:33] C:\ProgramData\WLInstaller
[07/05/2008|00:45] C:\ProgramData\Yahoo!
[07/05/2008|02:00] C:\ProgramData\Yahoo! Companion
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[12/05/2008|16:03] C:\Program Files\Adobe
[07/05/2008|17:01] C:\Program Files\ASUS
[05/05/2008|15:39] C:\Program Files\ATI
[05/05/2008|15:41] C:\Program Files\ATI Technologies
[05/05/2008|15:52] C:\Program Files\ATK Hotkey
[05/05/2008|15:52] C:\Program Files\ATKGFNEX
[05/05/2008|15:53] C:\Program Files\ATKOSD2
[22/05/2008|00:53] C:\Program Files\AVSVideo
[05/05/2008|19:53] C:\Program Files\Azureus
[22/05/2008|02:48] C:\Program Files\Common Files
[06/05/2008|04:20] C:\Program Files\desktop.ini
[07/05/2008|02:54] C:\Program Files\DivX
[21/05/2008|23:51] C:\Program Files\eMule
[15/05/2008|13:10] C:\Program Files\epson
[07/05/2008|14:06] C:\Program Files\Google
[19/05/2008|18:59] C:\Program Files\InstallShield Installation Information
[05/05/2008|15:35] C:\Program Files\Intel
[06/05/2008|04:15] C:\Program Files\Internet Explorer
[05/05/2008|20:15] C:\Program Files\Java
[05/05/2008|20:12] C:\Program Files\LimeWire
[21/05/2008|23:57] C:\Program Files\MAGIX
[05/05/2008|20:22] C:\Program Files\Messenger Plus! Live
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[07/05/2008|17:13] C:\Program Files\Microsoft Office
[08/05/2008|20:39] C:\Program Files\Microsoft Silverlight
[07/05/2008|17:12] C:\Program Files\Microsoft.NET
[05/05/2008|15:31] C:\Program Files\Motorola
[18/04/2007|11:24] C:\Program Files\Movie Maker
[05/05/2008|17:54] C:\Program Files\Mozilla Firefox
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[18/04/2007|10:43] C:\Program Files\MSXML 4.0
[17/05/2008|12:46] C:\Program Files\Nero
[16/05/2008|19:49] C:\Program Files\Neuf
[05/05/2008|20:46] C:\Program Files\neuf Talk
[12/05/2008|16:02] C:\Program Files\Nokia
[05/05/2008|17:14] C:\Program Files\Norton Internet Security
[05/05/2008|16:15] C:\Program Files\P4G
[05/05/2008|16:20] C:\Program Files\P4P
[12/05/2008|15:59] C:\Program Files\PC Connectivity Solution
[22/05/2008|02:48] C:\Program Files\Pinnacle
[05/05/2008|16:15] C:\Program Files\Power4Gear eXtreme
[05/05/2008|15:49] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[22/05/2008|00:49] C:\Program Files\Sony
[22/05/2008|00:45] C:\Program Files\Sony Setup
[25/05/2008|03:27] C:\Program Files\Spybot - Search & Destroy
[23/05/2008|17:29] C:\Program Files\Spyware Doctor
[05/05/2008|17:10] C:\Program Files\Symantec
[05/05/2008|16:18] C:\Program Files\Synaptics
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[22/05/2008|00:49] C:\Program Files\Vstplugins
[06/05/2008|04:15] C:\Program Files\Windows Calendar
[18/04/2007|11:24] C:\Program Files\Windows Collaboration
[06/05/2008|04:15] C:\Program Files\Windows Defender
[18/04/2007|11:24] C:\Program Files\Windows Journal
[05/05/2008|18:45] C:\Program Files\Windows Live
[06/05/2008|01:13] C:\Program Files\Windows Live Safety Center
[14/05/2008|18:29] C:\Program Files\Windows Mail
[06/05/2008|04:15] C:\Program Files\Windows Media Player
[02/11/2006|14:37] C:\Program Files\Windows NT
[18/04/2007|11:24] C:\Program Files\Windows Photo Gallery
[06/05/2008|04:15] C:\Program Files\Windows Sidebar
[08/05/2008|17:34] C:\Program Files\WinRAR
[05/05/2008|16:03] C:\Program Files\Wireless Console 2
[07/05/2008|00:44] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Common Files ]------
[09/05/2008|14:46] C:\Program Files\Common Files\Adobe
[17/05/2008|12:47] C:\Program Files\Common Files\Ahead
[22/05/2008|00:54] C:\Program Files\Common Files\AVSMedia
[07/05/2008|17:13] C:\Program Files\Common Files\DESIGNER
[15/05/2008|13:15] C:\Program Files\Common Files\InstallShield
[05/05/2008|20:13] C:\Program Files\Common Files\Java
[17/05/2008|12:50] C:\Program Files\Common Files\LightScribe
[21/05/2008|23:58] C:\Program Files\Common Files\MAGIX Shared
[22/05/2008|00:47] C:\Program Files\Common Files\microsoft shared
[12/05/2008|16:01] C:\Program Files\Common Files\PCSuite
[07/05/2008|02:54] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[05/05/2008|18:32] C:\Program Files\Common Files\Symantec Shared
[06/05/2008|04:15] C:\Program Files\Common Files\System
[05/05/2008|18:45] C:\Program Files\Common Files\WindowsLiveInstaller
[22/05/2008|02:48] C:\Program Files\Common Files\Yahoo!
---------------------------[ Process ]--------------------------
... 82
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-25 03:33:32
Windows 6.0.6000 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\Spyware Doctor Serial - Crack - Keygen (All Version).lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\Spyware.Doctor.v5.5.1.321.Multilangages.Incl-Crack.lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\thirdmovies-crack-addict-6-41.lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\[New] Sony Vegas Movie Studio Platinum Edition 2008 v8.0d Build 139 + Crack (2).lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\[New] Sony Vegas Movie Studio Platinum Edition 2008 v8.0d Build 139 + Crack.lnk
=> C:\Users\deuf\Downloads\eMule\Incoming\Spyware.Doctor.v5.5.1.321.Multilangages.Incl-Crack.rar
=> C:\Users\deuf\Downloads\eMule\Incoming\~$yware Doctor Serial - Crack - Keygen (All Version).doc
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\Spyware Doctor Serial - Crack - Keygen (All Version).lnk
=> C:\Users\deuf\Downloads\eMule\Incoming\~$yware Doctor Serial - Crack - Keygen (All Version).doc
[F:208][D:32]-> C:\Users\deuf\AppData\Local\Temp
[F:159][D:1]-> C:\Users\deuf\AppData\Roaming\MICROS~1\Windows\Cookies
[F:840][D:8]-> C:\Users\deuf\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:2][D:2]-> C:\$Recycle.Bin
[ UAC => 1 ]
--------------------[ Fin du rapport a 3:36:02,47 ]----------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:38:03, on 25/05/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\ACEngSvr.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATK Hotkey\KBFiltr.exe
C:\Program Files\ATK Hotkey\WDC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\P4P\P4P.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\HiJackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {54BF3340-AE49-4710-81BD-64576FC0A45D} - C:\Users\deuf\AppData\Local\Temp\opnnmJbX.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [TrayServer] C:\Program Files\MAGIX\Video_deluxe_2008_e-version\TrayServer.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\mlJYsqno.dll,#1
O4 - HKLM\..\Run: [f0b4d9fd] rundll32.exe "C:\Users\deuf\AppData\Local\Temp\vnbrdewk.dll",b
O4 - HKLM\..\Run: [BMf387ea61] Rundll32.exe "C:\Users\deuf\AppData\Local\Temp\mhseqsbs.dll",s
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Users\deuf\AppData\Local\Temp\E_S32C7.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\deuf\AppData\Local\Temp\khfEWQHw.dll,#1
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\deuf\AppData\Local\Temp\opnnmJbX.dll,c
O4 - HKCU\..\Run: [BMf387ea61] Rundll32.exe "C:\Users\deuf\AppData\Local\Temp\mhseqsbs.dll",s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
ok pour les 2 pc fais ca :
Fais un clic droit sur ce lien : (IL-MAFIOSO)
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).
Laisse-toi guider. Au menu principal, choisis 1 et valides.
(ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
Patiente jusqu'au message :
*** Analyse Termine le ..... ***
Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
Copie-colle l'intégralité dans une réponse. Referme le blocnote.
Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
Fais un clic droit sur ce lien : (IL-MAFIOSO)
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).
Laisse-toi guider. Au menu principal, choisis 1 et valides.
(ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
Patiente jusqu'au message :
*** Analyse Termine le ..... ***
Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
Copie-colle l'intégralité dans une réponse. Referme le blocnote.
Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
et merci !
1° RAPPORT PC DE BUREAU
-----------------------[ Lop S&D 4.2.0-9 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : deuf ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 24/05/2008 | 18:26:22,14 ] [ PC : DEUF-BARAK ]
[ MAJ : 16-05-2008 | 23:35 ]
-------------[ Listing des dossiers dans Application Data ]------------
[05/04/2008|21:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[01/03/2008|02:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[02/02/2008|20:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[02/02/2008|20:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[19/01/2008|19:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
[20/01/2008|16:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Corel
[18/01/2008|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[13/04/2008|04:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EPSON
[19/01/2008|16:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[01/02/2008|13:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[20/01/2008|18:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\LogiShrd
[20/01/2008|18:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[26/02/2008|21:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MAGIX
[20/01/2008|13:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[13/02/2008|23:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[08/04/2008|10:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[19/01/2008|18:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[31/01/2008|20:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nokia
[31/01/2008|20:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[19/01/2008|17:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[22/01/2008|20:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[12/02/2008|23:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[13/04/2008|04:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[28/03/2008|21:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Uniblue
[19/01/2008|17:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[23/01/2008|13:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[21/01/2008|20:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
[18/01/2008|01:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[01/02/2008|13:31] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[05/03/2008|11:17] C:\DOCUME~1\deuf\APPLIC~1\Adobe
[29/02/2008|10:01] C:\DOCUME~1\deuf\APPLIC~1\AdobeUM
[26/01/2008|00:02] C:\DOCUME~1\deuf\APPLIC~1\Ahead
[03/02/2008|00:33] C:\DOCUME~1\deuf\APPLIC~1\Apple Computer
[22/05/2008|22:21] C:\DOCUME~1\deuf\APPLIC~1\Azureus
[04/02/2008|22:56] C:\DOCUME~1\deuf\APPLIC~1\Barak's SignMe!
[26/01/2008|13:54] C:\DOCUME~1\deuf\APPLIC~1\CopyToDvd
[31/03/2008|22:03] C:\DOCUME~1\deuf\APPLIC~1\Corel
[17/02/2008|21:09] C:\DOCUME~1\deuf\APPLIC~1\depotfile.c2c
[18/01/2008|01:21] C:\DOCUME~1\deuf\APPLIC~1\desktop.ini
[28/03/2008|18:57] C:\DOCUME~1\deuf\APPLIC~1\Download Manager
[22/04/2008|16:49] C:\DOCUME~1\deuf\APPLIC~1\EPSON
[22/05/2008|20:37] C:\DOCUME~1\deuf\APPLIC~1\GARMIN
[30/03/2008|14:45] C:\DOCUME~1\deuf\APPLIC~1\GetRightToGo
[18/01/2008|00:57] C:\DOCUME~1\deuf\APPLIC~1\Identities
[03/05/2008|16:14] C:\DOCUME~1\deuf\APPLIC~1\inst.exe
[20/01/2008|18:18] C:\DOCUME~1\deuf\APPLIC~1\InstallShield
[05/03/2008|11:20] C:\DOCUME~1\deuf\APPLIC~1\Leadertech
[18/03/2008|22:15] C:\DOCUME~1\deuf\APPLIC~1\LimeWire
[20/01/2008|18:21] C:\DOCUME~1\deuf\APPLIC~1\Logitech
[19/01/2008|14:44] C:\DOCUME~1\deuf\APPLIC~1\Macromedia
[06/04/2008|02:14] C:\DOCUME~1\deuf\APPLIC~1\Microsoft
[18/01/2008|14:21] C:\DOCUME~1\deuf\APPLIC~1\Mozilla
[07/02/2008|22:42] C:\DOCUME~1\deuf\APPLIC~1\NMM-MetaData.db
[05/02/2008|23:32] C:\DOCUME~1\deuf\APPLIC~1\Nokia
[07/02/2008|19:40] C:\DOCUME~1\deuf\APPLIC~1\Nokia Multimedia Player
[31/01/2008|21:09] C:\DOCUME~1\deuf\APPLIC~1\NSeries
[31/01/2008|21:10] C:\DOCUME~1\deuf\APPLIC~1\PC Suite
[03/05/2008|16:14] C:\DOCUME~1\deuf\APPLIC~1\pcouffin.cat
[03/05/2008|16:14] C:\DOCUME~1\deuf\APPLIC~1\pcouffin.inf
[03/05/2008|16:14] C:\DOCUME~1\deuf\APPLIC~1\pcouffin.log
[03/05/2008|16:14] C:\DOCUME~1\deuf\APPLIC~1\pcouffin.sys
[18/02/2008|15:52] C:\DOCUME~1\deuf\APPLIC~1\Real
[10/02/2008|13:40] C:\DOCUME~1\deuf\APPLIC~1\Sun
[21/02/2008|20:37] C:\DOCUME~1\deuf\APPLIC~1\TomTom
[03/05/2008|16:11] C:\DOCUME~1\deuf\APPLIC~1\Uniblue
[23/01/2008|14:54] C:\DOCUME~1\deuf\APPLIC~1\vlc
[12/02/2008|15:12] C:\DOCUME~1\deuf\APPLIC~1\VoipBuster
[03/05/2008|16:14] C:\DOCUME~1\deuf\APPLIC~1\Vso
[19/01/2008|18:17] C:\DOCUME~1\deuf\APPLIC~1\WinRAR
[10/02/2008|14:55] C:\DOCUME~1\INVIT~1\APPLIC~1\Adobe
[18/01/2008|01:21] C:\DOCUME~1\INVIT~1\APPLIC~1\desktop.ini
[29/01/2008|13:09] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[29/01/2008|13:11] C:\DOCUME~1\INVIT~1\APPLIC~1\Logitech
[10/02/2008|14:55] C:\DOCUME~1\INVIT~1\APPLIC~1\Macromedia
[20/04/2008|18:39] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[10/02/2008|14:54] C:\DOCUME~1\INVIT~1\APPLIC~1\Mozilla
[10/02/2008|14:54] C:\DOCUME~1\INVIT~1\APPLIC~1\Nokia
[10/02/2008|14:53] C:\DOCUME~1\INVIT~1\APPLIC~1\PC Suite
[06/03/2008|20:13] C:\DOCUME~1\INVIT~1\APPLIC~1\Real
[06/04/2008|02:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[06/04/2008|02:14] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[06/03/2008|23:20] C:\DOCUME~1\RimK\APPLIC~1\Adobe
[22/01/2008|23:25] C:\DOCUME~1\RimK\APPLIC~1\Ahead
[29/03/2008|23:07] C:\DOCUME~1\RimK\APPLIC~1\Apple Computer
[18/01/2008|01:21] C:\DOCUME~1\RimK\APPLIC~1\desktop.ini
[22/01/2008|22:27] C:\DOCUME~1\RimK\APPLIC~1\Identities
[24/02/2008|13:30] C:\DOCUME~1\RimK\APPLIC~1\LimeWire
[22/01/2008|22:28] C:\DOCUME~1\RimK\APPLIC~1\Logitech
[22/01/2008|22:34] C:\DOCUME~1\RimK\APPLIC~1\Macromedia
[16/04/2008|23:45] C:\DOCUME~1\RimK\APPLIC~1\Microsoft
[22/01/2008|23:02] C:\DOCUME~1\RimK\APPLIC~1\Mozilla
[01/02/2008|22:38] C:\DOCUME~1\RimK\APPLIC~1\Nokia
[01/02/2008|22:39] C:\DOCUME~1\RimK\APPLIC~1\PC Suite
[21/02/2008|15:50] C:\DOCUME~1\RimK\APPLIC~1\Real
[29/03/2008|23:32] C:\DOCUME~1\RimK\APPLIC~1\Uniblue
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[08/04/2008 10:07][--a------] C:\WINDOWS\tasks\Uniblue SpyEraser.job
[07/04/2008 20:56][--a------] C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
[29/03/2008 04:16][--a------] C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
[28/03/2008 21:25][--a------] C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job
[29/03/2008 22:23][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[24/05/2008 18:07][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[05/03/2008|11:21] C:\Program Files\Adobe
[09/02/2008|14:26] C:\Program Files\Alcohol Soft
[09/04/2008|11:34] C:\Program Files\Alwil Software
[02/02/2008|20:37] C:\Program Files\Apple Software Update
[19/01/2008|13:59] C:\Program Files\AvRack
[03/05/2008|15:08] C:\Program Files\Azureus
[04/02/2008|22:56] C:\Program Files\Barak's SignME
[23/04/2008|15:03] C:\Program Files\Corel
[25/01/2008|18:58] C:\Program Files\Dictionnaire
[31/01/2008|20:41] C:\Program Files\DIFX
[19/01/2008|17:39] C:\Program Files\DivX
[24/05/2008|15:13] C:\Program Files\eMule
[13/04/2008|04:36] C:\Program Files\EPSON
[01/03/2008|00:31] C:\Program Files\ffdshow
[23/04/2008|15:03] C:\Program Files\Fichiers communs
[10/04/2008|20:25] C:\Program Files\Google
[13/04/2008|04:48] C:\Program Files\InstallShield Installation Information
[09/04/2008|17:30] C:\Program Files\Internet Explorer
[17/03/2008|09:06] C:\Program Files\iPod
[17/03/2008|09:06] C:\Program Files\iPod(2)
[17/03/2008|09:06] C:\Program Files\iTunes
[17/03/2008|09:06] C:\Program Files\iTunes(2)
[23/04/2008|15:08] C:\Program Files\Java
[19/01/2008|23:47] C:\Program Files\LimeWire
[20/01/2008|18:19] C:\Program Files\Logitech
[26/02/2008|21:35] C:\Program Files\MAGIX
[19/01/2008|16:06] C:\Program Files\Messenger
[29/03/2008|16:43] C:\Program Files\Messenger Plus! Live
[20/01/2008|18:31] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[18/01/2008|00:44] C:\Program Files\microsoft frontpage
[19/01/2008|17:16] C:\Program Files\Microsoft Office
[19/01/2008|17:34] C:\Program Files\Microsoft SQL Server
[19/01/2008|17:15] C:\Program Files\Microsoft.NET
[11/02/2008|00:03] C:\Program Files\Mobiola Web Camera 2 for S60 3rd Edition
[18/01/2008|00:41] C:\Program Files\Movie Maker
[24/05/2008|18:19] C:\Program Files\Mozilla Firefox
[18/01/2008|00:39] C:\Program Files\MSN
[18/01/2008|00:40] C:\Program Files\MSN Gaming Zone
[20/01/2008|18:27] C:\Program Files\MSXML 4.0
[19/01/2008|18:25] C:\Program Files\Nero
[18/01/2008|00:42] C:\Program Files\NetMeeting
[19/01/2008|13:14] C:\Program Files\Neuf
[12/02/2008|19:11] C:\Program Files\Nokia
[18/01/2008|00:40] C:\Program Files\Online Services
[19/01/2008|16:04] C:\Program Files\Outlook Express
[22/02/2008|23:59] C:\Program Files\Pando Networks
[31/01/2008|20:41] C:\Program Files\PC Connectivity Solution
[19/01/2008|19:00] C:\Program Files\PFConfig
[19/01/2008|17:33] C:\Program Files\Pinnacle
[18/03/2008|19:26] C:\Program Files\QuickTime
[17/03/2008|09:07] C:\Program Files\QuickTime(2)
[18/02/2008|15:49] C:\Program Files\Real
[19/01/2008|13:32] C:\Program Files\Realtek
[19/01/2008|13:59] C:\Program Files\Realtek Sound Manager
[16/02/2008|14:03] C:\Program Files\Red Five Labs
[18/01/2008|00:42] C:\Program Files\Services en ligne
[19/01/2008|14:19] C:\Program Files\SiS VGA Utilities V3.66
[19/01/2008|14:19] C:\Program Files\sisagp
[12/02/2008|20:51] C:\Program Files\Sony Ericsson
[23/01/2008|09:50] C:\Program Files\Spybot - Search & Destroy
[31/01/2008|00:11] C:\Program Files\Symbian OS Tools
[21/02/2008|20:34] C:\Program Files\TomTom DesktopSuite
[21/02/2008|20:36] C:\Program Files\TomTom HOME 2
[06/03/2008|17:06] C:\Program Files\Total Video Converter
[03/05/2008|16:11] C:\Program Files\Uniblue
[18/01/2008|00:57] C:\Program Files\Uninstall Information
[23/01/2008|14:54] C:\Program Files\VideoLAN
[03/05/2008|16:15] C:\Program Files\VSO
[06/03/2008|16:32] C:\Program Files\WinAVI MP4 Converter
[23/01/2008|13:45] C:\Program Files\Windows Live
[22/05/2008|19:47] C:\Program Files\Windows Live Safety Center
[19/01/2008|17:33] C:\Program Files\Windows Media Connect 2
[19/01/2008|17:33] C:\Program Files\Windows Media Player
[18/01/2008|00:40] C:\Program Files\Windows NT
[18/01/2008|00:42] C:\Program Files\WindowsUpdate
[19/01/2008|18:16] C:\Program Files\WinRAR
[18/01/2008|00:44] C:\Program Files\xerox
[22/01/2008|20:53] C:\Program Files\Yahoo!
[20/01/2008|13:58] C:\Program Files\Zone Labs
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[01/03/2008|02:44] C:\Program Files\Fichiers communs\Adobe
[19/01/2008|18:29] C:\Program Files\Fichiers communs\Ahead
[02/02/2008|20:37] C:\Program Files\Fichiers communs\Apple
[19/01/2008|17:16] C:\Program Files\Fichiers communs\DESIGNER
[13/04/2008|04:44] C:\Program Files\Fichiers communs\InstallShield
[19/01/2008|23:46] C:\Program Files\Fichiers communs\Java
[20/01/2008|18:20] C:\Program Files\Fichiers communs\logishrd
[19/01/2008|21:22] C:\Program Files\Fichiers communs\Logitech
[18/03/2008|14:54] C:\Program Files\Fichiers communs\Microsoft Shared
[18/01/2008|00:42] C:\Program Files\Fichiers communs\MSSoap
[12/02/2008|19:11] C:\Program Files\Fichiers communs\Nokia
[18/01/2008|01:21] C:\Program Files\Fichiers communs\ODBC
[31/01/2008|23:04] C:\Program Files\Fichiers communs\PCSuite
[18/02/2008|15:50] C:\Program Files\Fichiers communs\Real
[18/01/2008|00:42] C:\Program Files\Fichiers communs\Services
[18/01/2008|01:21] C:\Program Files\Fichiers communs\SpeechEngines
[31/01/2008|00:11] C:\Program Files\Fichiers communs\Symbian
[19/01/2008|16:04] C:\Program Files\Fichiers communs\System
[23/01/2008|13:49] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[18/02/2008|15:50] C:\Program Files\Fichiers communs\xing shared
---------------------------[ Process ]--------------------------
... 47
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-24 18:29:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
=> C:\Documents and Settings\deuf\Mes documents\Docs divers\Cracks,Serialnumbers,Keygenerators,Nero,Corel Draw,Antivirus,Adobe,Macromedia, Norton,Paint Shop Pro,Winrar,Winzip,X Win,Astalav.txt
=> C:\Documents and Settings\deuf\Mes documents\Docs divers\CRACKS.HTML
=> C:\Documents and Settings\deuf\Mes documents\Symbian\Applications Symbian\Signed\NTorch.Lite.v1.00.S60v3.SymbianOS9.1.Cracked-BiNPDA code 25600.sis
=> C:\Documents and Settings\deuf\Mes documents\Symbian\Applications Symbian\Unsigned\CoreCodec.CorePlayer.v1.1.1.S60v3.SymbianOS9.1.Cracked-BiNPDA.sis
=> C:\Documents and Settings\deuf\Mes documents\Symbian\Applications Symbian\Unsigned\OTStudio.NTorch.Lite.v1.00.S60v3.SymbianOS9.1.Cracked-BiNPDA.sis
=> C:\Documents and Settings\deuf\Mes documents\Docs divers\Cracks,Serialnumbers,Keygenerators,Nero,Corel Draw,Antivirus,Adobe,Macromedia, Norton,Paint Shop Pro,Winrar,Winzip,X Win,Astalav.txt
[F:67][D:17]-> C:\DOCUME~1\deuf\LOCALS~1\Temp
[F:36][D:0]-> C:\DOCUME~1\deuf\Cookies
[F:323][D:4]-> C:\DOCUME~1\deuf\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 18:30:24,87 ]----------------------
2° RAPPORT PC PORTABLE
-----------------------[ Lop S&D 4.2.0-9 XP/Vista ]---------------------
[ Windows 'Longhorn' (NT 6.0) Workstation Build 6000 ]
[ USER : deuf ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 24/05/2008 | 18:50:09,21 ] [ PC : PC-DE-DEUF ]
[ MAJ : 16-05-2008 | 23:35 ]
[ UAC => 0 ]
-------------[ Listing des dossiers dans Application Data ]------------
[12/05/2008|18:47] C:\Users\deuf\AppData\Roaming\Adobe\AUM
[12/05/2008|18:47] C:\Users\deuf\AppData\Roaming\Adobe\Online Services
[12/05/2008|16:03] C:\Users\deuf\AppData\Roaming\Adobe\Photoshop Album
[08/05/2008|12:16] C:\Users\deuf\AppData\Roaming\Adobe\Linguistics
[05/05/2008|17:27] C:\Users\deuf\AppData\Roaming\Adobe\Flash Player
[05/05/2008|16:53] C:\Users\deuf\AppData\Roaming\Adobe\Acrobat
[17/05/2008|14:09] C:\Users\deuf\AppData\Roaming\Ahead\Nero Burning ROM
[05/05/2008|16:54] C:\Users\deuf\AppData\Roaming\ATI\ACE
[22/05/2008|00:27] C:\Users\deuf\AppData\Roaming\AVSMedia\AVS Video Editor
[22/05/2008|16:31] C:\Users\deuf\AppData\Roaming\Azureus\active
[22/05/2008|16:31] C:\Users\deuf\AppData\Roaming\Azureus\dht
[22/05/2008|16:31] C:\Users\deuf\AppData\Roaming\Azureus\net
[22/05/2008|15:45] C:\Users\deuf\AppData\Roaming\Azureus\logs
[22/05/2008|12:59] C:\Users\deuf\AppData\Roaming\Azureus\tmp
[22/05/2008|12:57] C:\Users\deuf\AppData\Roaming\Azureus\torrents
[05/05/2008|21:48] C:\Users\deuf\AppData\Roaming\Azureus\media
[05/05/2008|20:01] C:\Users\deuf\AppData\Roaming\Azureus\shares
[05/05/2008|20:01] C:\Users\deuf\AppData\Roaming\Azureus\plugins
[07/05/2008|03:20] C:\Users\deuf\AppData\Roaming\DivX\DivX Codec
[21/05/2008|23:52] C:\Users\deuf\AppData\Roaming\eMule\config
[24/05/2008|17:24] C:\Users\deuf\AppData\Roaming\EPSON\Creativity Suite
[24/05/2008|16:50] C:\Users\deuf\AppData\Roaming\EPSON\ESCNDV
[16/05/2008|20:58] C:\Users\deuf\AppData\Roaming\Google\Local Search History
[05/05/2008|16:53] C:\Users\deuf\AppData\Roaming\Identities\{93891547-46FC-4EB3-A045-FD4FCB73E0A3}
[12/05/2008|23:43] C:\Users\deuf\AppData\Roaming\InstallShield\ISEngine12.0
[17/05/2008|13:54] C:\Users\deuf\AppData\Roaming\LimeWire\.AppSpecialShare
[06/05/2008|00:54] C:\Users\deuf\AppData\Roaming\LimeWire\xml
[06/05/2008|00:53] C:\Users\deuf\AppData\Roaming\LimeWire\themes
[05/05/2008|17:27] C:\Users\deuf\AppData\Roaming\Macromedia\Flash Player
[22/05/2008|00:06] C:\Users\deuf\AppData\Roaming\MAGIX\Video_deluxe_2008_e-version
[23/05/2008|15:39] C:\Users\deuf\AppData\Roaming\Microsoft\ModŠles
[21/05/2008|16:32] C:\Users\deuf\AppData\Roaming\Microsoft\Windows Photo Gallery
[18/05/2008|20:17] C:\Users\deuf\AppData\Roaming\Microsoft\preuve
[16/05/2008|00:25] C:\Users\deuf\AppData\Roaming\Microsoft\HTML Help
[15/05/2008|17:12] C:\Users\deuf\AppData\Roaming\Microsoft\Word
[14/05/2008|14:06] C:\Users\deuf\AppData\Roaming\Microsoft\Network
[12/05/2008|19:01] C:\Users\deuf\AppData\Roaming\Microsoft\Office
[12/05/2008|19:01] C:\Users\deuf\AppData\Roaming\Microsoft\OIS
[08/05/2008|01:26] C:\Users\deuf\AppData\Roaming\Microsoft\Macros compl‚mentaires
[07/05/2008|17:00] C:\Users\deuf\AppData\Roaming\Microsoft\Installer
[06/05/2008|01:09] C:\Users\deuf\AppData\Roaming\Microsoft\Crypto
[05/05/2008|20:23] C:\Users\deuf\AppData\Roaming\Microsoft\MSN Messenger
[05/05/2008|19:03] C:\Users\deuf\AppData\Roaming\Microsoft\eHome
[05/05/2008|18:54] C:\Users\deuf\AppData\Roaming\Microsoft\Internet Explorer
[05/05/2008|18:46] C:\Users\deuf\AppData\Roaming\Microsoft\IdentityCRL
[05/05/2008|18:39] C:\Users\deuf\AppData\Roaming\Microsoft\MMC
[05/05/2008|17:32] C:\Users\deuf\AppData\Roaming\Microsoft\Windows
[05/05/2008|16:54] C:\Users\deuf\AppData\Roaming\Microsoft\SystemCertificates
[05/05/2008|16:52] C:\Users\deuf\AppData\Roaming\Microsoft\Protect
[05/05/2008|16:49] C:\Users\deuf\AppData\Roaming\Microsoft\Credentials
[05/05/2008|17:55] C:\Users\deuf\AppData\Roaming\Mozilla\Firefox
[12/05/2008|16:44] C:\Users\deuf\AppData\Roaming\Nokia\Nseries Update Manager
[12/05/2008|16:02] C:\Users\deuf\AppData\Roaming\Nokia\NSLauncher
[12/05/2008|16:03] C:\Users\deuf\AppData\Roaming\PC Suite\Settings
[23/05/2008|17:15] C:\Users\deuf\AppData\Roaming\PC Tools\Spyware Doctor
[22/05/2008|02:17] C:\Users\deuf\AppData\Roaming\Sony\Vegas Movie Studio Platinum
[21/05/2008|23:49] C:\Users\deuf\AppData\Roaming\Sony Corporation\Sony Picture Utility
[05/05/2008|17:55] C:\Users\deuf\AppData\Roaming\Talkback\MozillaOrg
[07/05/2008|00:44] C:\Users\deuf\AppData\Roaming\Yahoo!\Companion
----------------[ Tâches planifiées dans C:\Windows\tasks ]---------------
[24/05/2008 16:02][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{EFDFF894-FCB5-4EFE-AAFD-8FA72E20235E}.job
[19/05/2008 20:31][--a------] C:\Windows\tasks\Norton Internet Security - Run Full System Scan - deuf.job
[24/05/2008 18:47][--ah-----] C:\Windows\tasks\SA.DAT
[24/05/2008 18:46][--a------] C:\Windows\tasks\SCHEDLGU.TXT
------[ Listing des dossiers dans C:\ProgramData ]------
[12/05/2008|16:03] C:\ProgramData\Adobe
[02/11/2006|15:02] C:\ProgramData\Application Data
[05/05/2008|16:08] C:\ProgramData\ASUS
[05/05/2008|20:01] C:\ProgramData\Azureus
[23/05/2008|00:53] C:\ProgramData\BMf387ea61.txt
[24/05/2008|18:41] C:\ProgramData\BMf387ea61.xml
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[21/05/2008|23:53] C:\ProgramData\eMule
[15/05/2008|13:06] C:\ProgramData\EPSON
[02/11/2006|15:02] C:\ProgramData\Favorites
[05/05/2008|20:20] C:\ProgramData\Google
[17/05/2008|12:59] C:\ProgramData\LightScribe
[21/05/2008|23:58] C:\ProgramData\MAGIX
[05/05/2008|20:29] C:\ProgramData\Messenger Plus!
[07/05/2008|17:12] C:\ProgramData\Microsoft
[17/05/2008|12:46] C:\ProgramData\Nero
[05/05/2008|16:15] C:\ProgramData\P4G
[12/05/2008|16:03] C:\ProgramData\PC Suite
[22/05/2008|02:42] C:\ProgramData\Pinnacle
[22/05/2008|02:55] C:\ProgramData\Pinnacle VideoSpin
[24/05/2008|18:44] C:\ProgramData\pskt.ini
[22/05/2008|00:49] C:\ProgramData\Sony
[19/05/2008|18:54] C:\ProgramData\Sony Corporation
[23/05/2008|23:40] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[23/05/2008|17:02] C:\ProgramData\Symantec
[24/05/2008|18:48] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[15/05/2008|13:12] C:\ProgramData\UDL
[22/05/2008|02:48] C:\ProgramData\VideoSpin
[05/05/2008|18:33] C:\ProgramData\WLInstaller
[07/05/2008|00:45] C:\ProgramData\Yahoo!
[07/05/2008|02:00] C:\ProgramData\Yahoo! Companion
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[12/05/2008|16:03] C:\Program Files\Adobe
[07/05/2008|17:01] C:\Program Files\ASUS
[05/05/2008|15:39] C:\Program Files\ATI
[05/05/2008|15:41] C:\Program Files\ATI Technologies
[05/05/2008|15:52] C:\Program Files\ATK Hotkey
[05/05/2008|15:52] C:\Program Files\ATKGFNEX
[05/05/2008|15:53] C:\Program Files\ATKOSD2
[22/05/2008|00:53] C:\Program Files\AVSVideo
[05/05/2008|19:53] C:\Program Files\Azureus
[22/05/2008|02:48] C:\Program Files\Common Files
[06/05/2008|04:20] C:\Program Files\desktop.ini
[07/05/2008|02:54] C:\Program Files\DivX
[21/05/2008|23:51] C:\Program Files\eMule
[15/05/2008|13:10] C:\Program Files\epson
[07/05/2008|14:06] C:\Program Files\Google
[19/05/2008|18:59] C:\Program Files\InstallShield Installation Information
[05/05/2008|15:35] C:\Program Files\Intel
[06/05/2008|04:15] C:\Program Files\Internet Explorer
[05/05/2008|20:15] C:\Program Files\Java
[05/05/2008|20:12] C:\Program Files\LimeWire
[21/05/2008|23:57] C:\Program Files\MAGIX
[05/05/2008|20:22] C:\Program Files\Messenger Plus! Live
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[07/05/2008|17:13] C:\Program Files\Microsoft Office
[08/05/2008|20:39] C:\Program Files\Microsoft Silverlight
[07/05/2008|17:12] C:\Program Files\Microsoft.NET
[05/05/2008|15:31] C:\Program Files\Motorola
[18/04/2007|11:24] C:\Program Files\Movie Maker
[05/05/2008|17:54] C:\Program Files\Mozilla Firefox
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[18/04/2007|10:43] C:\Program Files\MSXML 4.0
[17/05/2008|12:46] C:\Program Files\Nero
[16/05/2008|19:49] C:\Program Files\Neuf
[05/05/2008|20:46] C:\Program Files\neuf Talk
[12/05/2008|16:02] C:\Program Files\Nokia
[05/05/2008|17:14] C:\Program Files\Norton Internet Security
[05/05/2008|16:15] C:\Program Files\P4G
[05/05/2008|16:20] C:\Program Files\P4P
[12/05/2008|15:59] C:\Program Files\PC Connectivity Solution
[22/05/2008|02:48] C:\Program Files\Pinnacle
[05/05/2008|16:15] C:\Program Files\Power4Gear eXtreme
[05/05/2008|15:49] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[22/05/2008|00:49] C:\Program Files\Sony
[22/05/2008|00:45] C:\Program Files\Sony Setup
[23/05/2008|22:43] C:\Program Files\Spybot - Search & Destroy
[23/05/2008|17:29] C:\Program Files\Spyware Doctor
[05/05/2008|17:10] C:\Program Files\Symantec
[05/05/2008|16:18] C:\Program Files\Synaptics
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[22/05/2008|00:49] C:\Program Files\Vstplugins
[06/05/2008|04:15] C:\Program Files\Windows Calendar
[18/04/2007|11:24] C:\Program Files\Windows Collaboration
[06/05/2008|04:15] C:\Program Files\Windows Defender
[18/04/2007|11:24] C:\Program Files\Windows Journal
[05/05/2008|18:45] C:\Program Files\Windows Live
[06/05/2008|01:13] C:\Program Files\Windows Live Safety Center
[14/05/2008|18:29] C:\Program Files\Windows Mail
[06/05/2008|04:15] C:\Program Files\Windows Media Player
[02/11/2006|14:37] C:\Program Files\Windows NT
[18/04/2007|11:24] C:\Program Files\Windows Photo Gallery
[06/05/2008|04:15] C:\Program Files\Windows Sidebar
[08/05/2008|17:34] C:\Program Files\WinRAR
[05/05/2008|16:03] C:\Program Files\Wireless Console 2
[07/05/2008|00:44] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Common Files ]------
[09/05/2008|14:46] C:\Program Files\Common Files\Adobe
[17/05/2008|12:47] C:\Program Files\Common Files\Ahead
[22/05/2008|00:54] C:\Program Files\Common Files\AVSMedia
[07/05/2008|17:13] C:\Program Files\Common Files\DESIGNER
[15/05/2008|13:15] C:\Program Files\Common Files\InstallShield
[05/05/2008|20:13] C:\Program Files\Common Files\Java
[17/05/2008|12:50] C:\Program Files\Common Files\LightScribe
[21/05/2008|23:58] C:\Program Files\Common Files\MAGIX Shared
[22/05/2008|00:47] C:\Program Files\Common Files\microsoft shared
[12/05/2008|16:01] C:\Program Files\Common Files\PCSuite
[07/05/2008|02:54] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[05/05/2008|18:32] C:\Program Files\Common Files\Symantec Shared
[06/05/2008|04:15] C:\Program Files\Common Files\System
[05/05/2008|18:45] C:\Program Files\Common Files\WindowsLiveInstaller
[22/05/2008|02:48] C:\Program Files\Common Files\Yahoo!
---------------------------[ Process ]--------------------------
... 87
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-24 18:52:07
Windows 6.0.6000 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
=> C:\Users\deuf\AppData\Local\Temp\Rar$EX01.512\Crack
=> C:\Users\deuf\AppData\Local\Temp\Rar$EX01.512\Crack\patch.exe
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\Spyware Doctor Serial - Crack - Keygen (All Version).lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\Spyware.Doctor.v5.5.1.321.Multilangages.Incl-Crack.lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\thirdmovies-crack-addict-6-41.lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\[New] Sony Vegas Movie Studio Platinum Edition 2008 v8.0d Build 139 + Crack (2).lnk
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\[New] Sony Vegas Movie Studio Platinum Edition 2008 v8.0d Build 139 + Crack.lnk
=> C:\Users\deuf\Downloads\eMule\Incoming\Spyware.Doctor.v5.5.1.321.Multilangages.Incl-Crack.rar
=> C:\Users\deuf\Downloads\eMule\Incoming\~$yware Doctor Serial - Crack - Keygen (All Version).doc
=> C:\Users\deuf\AppData\Roaming\Microsoft\Windows\Recent\Spyware Doctor Serial - Crack - Keygen (All Version).lnk
=> C:\Users\deuf\Downloads\eMule\Incoming\~$yware Doctor Serial - Crack - Keygen (All Version).doc
[F:187][D:32]-> C:\Users\deuf\AppData\Local\Temp
[F:151][D:1]-> C:\Users\deuf\AppData\Roaming\MICROS~1\Windows\Cookies
[F:157][D:8]-> C:\Users\deuf\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:4][D:2]-> C:\$Recycle.Bin
[ UAC => 1 ]
--------------------[ Fin du rapport a 18:54:37,79 ]----------------------