Mon PC rame ???
Résolu
MARIE83120
Messages postés
268
Statut
Membre
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour à tous et toutes,
voilà j'ai mon PC qui rame en ce moment et j'ai utilisé CCleaner tout est ok et SPYBOT n'arrive pas à tout nettoyer !!!
Je veux bien mettre un autre antivirus du style AVAST mais en FRANCAIS et gratuit (si possible) à moins que l'on puisse faire autre chose. Autre question comment faire pour supprimer automatiquement et sans faire de bétises les choses inutiles dans mon PC pour lui permettre de gagner de la performance.
Merci à tous et toutes
et bonnes vacances à ceux qui le sont...
voilà j'ai mon PC qui rame en ce moment et j'ai utilisé CCleaner tout est ok et SPYBOT n'arrive pas à tout nettoyer !!!
Je veux bien mettre un autre antivirus du style AVAST mais en FRANCAIS et gratuit (si possible) à moins que l'on puisse faire autre chose. Autre question comment faire pour supprimer automatiquement et sans faire de bétises les choses inutiles dans mon PC pour lui permettre de gagner de la performance.
Merci à tous et toutes
et bonnes vacances à ceux qui le sont...
A voir également:
- Mon PC rame ???
- Pc qui rame - Guide
- Reinitialiser pc - Guide
- Downloader for pc - Télécharger - Téléchargement & Transfert
- Plus de son sur mon pc - Guide
- Double ecran pc - Guide
79 réponses
bonjour
à lire jusqu'en bas
Clique sur ce lien
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
pour télécharger le fichier d'installation d'HijackThis.
Enregistre HJTInstall.exe sur ton bureau.
Double-clique sur HJTInstall.exe pour lancer le programme
Par défaut, il s'installera là :
C:\Program Files\Trend Micro\HijackThis
Accepte la license en cliquant sur le bouton "I Accept"
Choisis l'option "Do a system scan and save a log file"
Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport
Colle le rapport que tu viens de copier sur ce forum
Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement
Rends toi sur ton PC ici "C:\ programme file\Trend Micro\HijackThis\HijackThis.exe"<---clik droit sur ce dernier
et choisis "renommer" : tapes eden et valide .
Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm
à lire jusqu'en bas
Clique sur ce lien
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
pour télécharger le fichier d'installation d'HijackThis.
Enregistre HJTInstall.exe sur ton bureau.
Double-clique sur HJTInstall.exe pour lancer le programme
Par défaut, il s'installera là :
C:\Program Files\Trend Micro\HijackThis
Accepte la license en cliquant sur le bouton "I Accept"
Choisis l'option "Do a system scan and save a log file"
Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport
Colle le rapport que tu viens de copier sur ce forum
Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement
Rends toi sur ton PC ici "C:\ programme file\Trend Micro\HijackThis\HijackThis.exe"<---clik droit sur ce dernier
et choisis "renommer" : tapes eden et valide .
Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm
Telcharge MBAM
http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebyte s anti malware
1.1 met le a jour
1.2 fais une recherche COMPLETE
1.3 a la fin du scan click sur "afficher le resultat"
1.5 nettoit tout
1.6 poste le rapport sur ce forum.
http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebyte s anti malware
1.1 met le a jour
1.2 fais une recherche COMPLETE
1.3 a la fin du scan click sur "afficher le resultat"
1.5 nettoit tout
1.6 poste le rapport sur ce forum.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Rends toi sur ton PC ici "C:\ programme file\Trend Micro\HijackThis\HijackThis.exe"<---clik droit sur ce dernier
et choisis "renommer" : tapes eden et valide .
ensuite
Télécharges ToolBar S&D ( de Eric_71 ) :
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
( Tuto : https://sites.google.com/site/toolbarsd/aideenimages )
!! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!
* double-cliques sur l'.exe pour lancer l'installe et laisses toi guider ...
* Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .
* Choisis l'option 1 ( "recherche") et tapes "entrée" .
* Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité
de son contenu dans ta prochaine réponse ...
( le rapport est en outre sauvegardé ici -> C:\TB.txt )
et choisis "renommer" : tapes eden et valide .
ensuite
Télécharges ToolBar S&D ( de Eric_71 ) :
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
( Tuto : https://sites.google.com/site/toolbarsd/aideenimages )
!! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!
* double-cliques sur l'.exe pour lancer l'installe et laisses toi guider ...
* Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .
* Choisis l'option 1 ( "recherche") et tapes "entrée" .
* Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité
de son contenu dans ta prochaine réponse ...
( le rapport est en outre sauvegardé ici -> C:\TB.txt )
Merci de ton aide voilà le rapport :
-----------\\ ToolBar S&D 1.0.8 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : sam ] [ "C:\Toolbar SD" ] [ Selection : 1 ]
[ 05/08/2008 | 10:03:42,29 ] [ PC : ACER-29569F1E48 ]
[ MAJ : 04-08-2008 | 23:15 ]
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\Conduit
C:\Program Files\Conduit\Community Alerts
C:\Program Files\Crawler
C:\Program Files\Crawler\CToolbar.exe
C:\Program Files\Crawler\CUpdate.exe
C:\Program Files\Crawler\TempDir
C:\Program Files\Crawler\ctbcomm.dll
C:\Program Files\Crawler\services.dat
C:\Program Files\Crawler\rootmenu.dat
C:\Program Files\Crawler\ctbr.dll
C:\Program Files\Crawler\CTipsDef.dll
C:\Program Files\Crawler\Languages
C:\Program Files\Crawler\TBR5LanguageAct
C:\Program Files\Crawler\majorse.dat
C:\Program Files\Crawler\lookfor.dat
C:\Program Files\Crawler\confirm.dat
C:\Program Files\Crawler\firefox
C:\Program Files\Crawler\Update
C:\Program Files\Crawler\Download
C:\Program Files\Crawler\adrkeys.dat
C:\Program Files\Crawler\COMMON_FF.dat
C:\Program Files\Crawler\CTConf.dat
C:\Program Files\Crawler\svc_set.dat
C:\Program Files\Crawler\Cache
C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\Crawler Toolbar
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\partner.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\about.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\update.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sendafriend.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\feedback.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\help.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\uninstall.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search_goog.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\highlight.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_on.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_off.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\newGames.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\hells_kitchen16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\heart_of_egypt16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\ranch_rush16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\penguins_journey16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\vogue_tales16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\download.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\family_restaurant16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\peril_at_end_house16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\AliceGreenfingers16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\dream_day_first_home16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\pet_shop_hop16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\virtualvillagers16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\Cake_mania_216x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\Azada16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\west16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\puzzle.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-53-29.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-53-29
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-54-46.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-54-46
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-08-08.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-08-08
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-09-16.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-09-16
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-50-16.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-50-16
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-53-03.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-53-03
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\obSearchHistory.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-17-04.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-17-04
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-54-49.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-54-49
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-55-23.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-55-23
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-56-31.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-56-31
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\arcade.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-10-42-02.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-10-42-02
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-15-29-46.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-15-29-46
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-16-38-09.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-16-38-09
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-14-30.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-14-30
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-15-06.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-15-06
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-21-01.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-21-01
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-10-48-45.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-10-48-45
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-02-04.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-02-04
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-08-47.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-08-47
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-24-18-01-41.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-09-58-58.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-24-18-01-41
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\action.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\cards.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-09-39-07.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-09-39-07
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-17-55-57.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-17-55-57
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-21-54-58.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-21-54-58
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-29-19-26-42.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-29-19-26-42
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-04-01-18-54-04.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-09-58-58
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-10-48-08.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-10-48-08
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\eye_for_design16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-04-01-18-54-04
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\jigsaw.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mahjong.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sports.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\webgame.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\multiplayer.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mygames.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\buy.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\trial.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\deals.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-05-24-20-52-54.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-05-24-20-52-54
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-08-05-09-02-52.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\oberonconfig.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-08-05-09-02-52
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-03-05.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-03-05
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-22.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-22
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-35.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-35
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-44.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-44
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-45.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-45
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-14-22-46-19.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-14-22-46-19
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-47.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-47
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-56.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-56
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-14-05-07.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-14-05-07
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-16-44-59.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-16-44-59
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-18-57-22.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-18-57-22
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-17-19-17-57.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-17-19-17-57
C:\Program Files\GamesBar
C:\Program Files\GamesBar\Localization-French.ini
C:\Program Files\GamesBar\OBGet.exe
C:\Program Files\GamesBar\oberontb.dll
C:\Program Files\GamesBar\uninst.exe
C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\GamesBar
C:\WINDOWS\System32\uninst.exe
C:\Program Files\MSN Messenger\msimg32.dll
\...\{635abd67-4fe9-1b23-4f01-e679fa7484c1} - (ytoolbar)
-----------\\ Extensions
(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(sam) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
(sam) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(sam) - {D2A6A719-7CBC-4594-85FD-C36AD881424F} => blueorganizer
(sam) - {34ea1c70-42cc-42c5-aa29-ec58b95a343e} => mybabylon
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"SearchMigratedDefaultUrl"="http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNxmk142YYFR&fl=0&ptb=Y_qILLhKCx3a21.Vfp9Uiw&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}"
"Start Page"="http://mystart.magentic.com/english/"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66028"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"
"SearchAssistant"="http://www.crawler.com/search/ie.aspx?tb_id=66028"
"CustomizeSearch"="http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028"
-----------\\ Fin du rapport a 10:04:36,68
-----------\\ ToolBar S&D 1.0.8 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : sam ] [ "C:\Toolbar SD" ] [ Selection : 1 ]
[ 05/08/2008 | 10:03:42,29 ] [ PC : ACER-29569F1E48 ]
[ MAJ : 04-08-2008 | 23:15 ]
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\Conduit
C:\Program Files\Conduit\Community Alerts
C:\Program Files\Crawler
C:\Program Files\Crawler\CToolbar.exe
C:\Program Files\Crawler\CUpdate.exe
C:\Program Files\Crawler\TempDir
C:\Program Files\Crawler\ctbcomm.dll
C:\Program Files\Crawler\services.dat
C:\Program Files\Crawler\rootmenu.dat
C:\Program Files\Crawler\ctbr.dll
C:\Program Files\Crawler\CTipsDef.dll
C:\Program Files\Crawler\Languages
C:\Program Files\Crawler\TBR5LanguageAct
C:\Program Files\Crawler\majorse.dat
C:\Program Files\Crawler\lookfor.dat
C:\Program Files\Crawler\confirm.dat
C:\Program Files\Crawler\firefox
C:\Program Files\Crawler\Update
C:\Program Files\Crawler\Download
C:\Program Files\Crawler\adrkeys.dat
C:\Program Files\Crawler\COMMON_FF.dat
C:\Program Files\Crawler\CTConf.dat
C:\Program Files\Crawler\svc_set.dat
C:\Program Files\Crawler\Cache
C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\Crawler Toolbar
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\partner.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\about.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\update.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sendafriend.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\feedback.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\help.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\uninstall.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search_goog.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\highlight.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_on.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_off.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\newGames.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\hells_kitchen16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\heart_of_egypt16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\ranch_rush16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\penguins_journey16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\vogue_tales16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\download.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\family_restaurant16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\peril_at_end_house16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\AliceGreenfingers16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\dream_day_first_home16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\pet_shop_hop16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\virtualvillagers16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\Cake_mania_216x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\Azada16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\west16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\puzzle.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-53-29.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-53-29
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-54-46.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-54-46
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-08-08.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-08-08
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-09-16.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-09-16
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-50-16.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-50-16
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-53-03.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-53-03
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\obSearchHistory.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-17-04.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-17-04
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-54-49.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-54-49
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-55-23.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-55-23
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-56-31.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-56-31
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\arcade.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-10-42-02.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-10-42-02
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-15-29-46.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-15-29-46
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-16-38-09.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-16-38-09
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-14-30.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-14-30
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-15-06.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-15-06
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-21-01.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-21-01
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-10-48-45.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-10-48-45
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-02-04.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-02-04
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-08-47.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-08-47
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-24-18-01-41.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-09-58-58.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-24-18-01-41
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\action.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\cards.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-09-39-07.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-09-39-07
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-17-55-57.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-17-55-57
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-21-54-58.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-21-54-58
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-29-19-26-42.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-29-19-26-42
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-04-01-18-54-04.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-09-58-58
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-10-48-08.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-10-48-08
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\eye_for_design16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-04-01-18-54-04
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\jigsaw.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mahjong.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sports.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\webgame.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\multiplayer.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mygames.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\buy.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\trial.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\deals.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-05-24-20-52-54.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-05-24-20-52-54
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-08-05-09-02-52.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\oberonconfig.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-08-05-09-02-52
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-03-05.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-03-05
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-22.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-22
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-35.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-35
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-44.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-44
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-45.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-45
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-14-22-46-19.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-14-22-46-19
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-47.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-47
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-56.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-56
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-14-05-07.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-14-05-07
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-16-44-59.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-16-44-59
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-18-57-22.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-18-57-22
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-17-19-17-57.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-17-19-17-57
C:\Program Files\GamesBar
C:\Program Files\GamesBar\Localization-French.ini
C:\Program Files\GamesBar\OBGet.exe
C:\Program Files\GamesBar\oberontb.dll
C:\Program Files\GamesBar\uninst.exe
C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\GamesBar
C:\WINDOWS\System32\uninst.exe
C:\Program Files\MSN Messenger\msimg32.dll
\...\{635abd67-4fe9-1b23-4f01-e679fa7484c1} - (ytoolbar)
-----------\\ Extensions
(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(sam) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
(sam) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(sam) - {D2A6A719-7CBC-4594-85FD-C36AD881424F} => blueorganizer
(sam) - {34ea1c70-42cc-42c5-aa29-ec58b95a343e} => mybabylon
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"SearchMigratedDefaultUrl"="http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNxmk142YYFR&fl=0&ptb=Y_qILLhKCx3a21.Vfp9Uiw&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}"
"Start Page"="http://mystart.magentic.com/english/"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66028"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"
"SearchAssistant"="http://www.crawler.com/search/ie.aspx?tb_id=66028"
"CustomizeSearch"="http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028"
-----------\\ Fin du rapport a 10:04:36,68
Cà fait peur de faire SUPPRESSION quand on y connaît rien ...Voilà le rapport
-----------\\ ToolBar S&D 1.0.8 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : sam ] [ "C:\Toolbar SD" ] [ Selection : 2 ]
[ 05/08/2008 | 10:12:02,12 ] [ PC : ACER-29569F1E48 ]
[ MAJ : 04-08-2008 | 23:15 ]
-----------\\ SUPPRESSION
Supprime! - C:\Program Files\Conduit\Community Alerts
Supprime! - C:\Program Files\Crawler\CToolbar.exe
Supprime! - C:\Program Files\Crawler\CUpdate.exe
Supprime! - C:\Program Files\Crawler\TempDir
Supprime! - C:\Program Files\Crawler\ctbcomm.dll
Supprime! - C:\Program Files\Crawler\services.dat
Supprime! - C:\Program Files\Crawler\rootmenu.dat
Supprime! - C:\Program Files\Crawler\ctbr.dll
Supprime! - C:\Program Files\Crawler\CTipsDef.dll
Supprime! - C:\Program Files\Crawler\Languages
Supprime! - C:\Program Files\Crawler\TBR5LanguageAct
Supprime! - C:\Program Files\Crawler\majorse.dat
Supprime! - C:\Program Files\Crawler\lookfor.dat
Supprime! - C:\Program Files\Crawler\confirm.dat
Supprime! - C:\Program Files\Crawler\firefox
Supprime! - C:\Program Files\Crawler\Update
Supprime! - C:\Program Files\Crawler\Download
Supprime! - C:\Program Files\Crawler\adrkeys.dat
Supprime! - C:\Program Files\Crawler\COMMON_FF.dat
Supprime! - C:\Program Files\Crawler\CTConf.dat
Supprime! - C:\Program Files\Crawler\svc_set.dat
Supprime! - C:\Program Files\Crawler\Cache
Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\Crawler Toolbar
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\partner.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\about.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\update.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sendafriend.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\feedback.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\help.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\uninstall.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search_goog.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\highlight.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_on.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_off.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\newGames.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\hells_kitchen16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\heart_of_egypt16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\ranch_rush16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\penguins_journey16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\vogue_tales16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\download.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\family_restaurant16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\peril_at_end_house16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\AliceGreenfingers16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\dream_day_first_home16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\pet_shop_hop16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\virtualvillagers16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\Cake_mania_216x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\Azada16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\west16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\puzzle.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-53-29.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-53-29
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-54-46.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-54-46
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-08-08.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-08-08
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-09-16.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-09-16
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-50-16.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-50-16
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-53-03.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-53-03
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\obSearchHistory.dat
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-17-04.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-17-04
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-54-49.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-54-49
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-55-23.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-55-23
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-56-31.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-56-31
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\arcade.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-10-42-02.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-10-42-02
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-15-29-46.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-15-29-46
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-16-38-09.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-16-38-09
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-14-30.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-14-30
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-15-06.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-15-06
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-21-01.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-21-01
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-10-48-45.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-10-48-45
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-02-04.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-02-04
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-08-47.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-08-47
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-24-18-01-41.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-09-58-58.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-24-18-01-41
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\action.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\cards.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-09-39-07.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-09-39-07
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-17-55-57.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-17-55-57
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-21-54-58.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-21-54-58
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-29-19-26-42.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-29-19-26-42
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-04-01-18-54-04.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-09-58-58
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-10-48-08.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-10-48-08
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\eye_for_design16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-04-01-18-54-04
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\jigsaw.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mahjong.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sports.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\webgame.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\multiplayer.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mygames.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\buy.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\trial.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\deals.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-05-24-20-52-54.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-05-24-20-52-54
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-08-05-09-02-52.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\oberonconfig.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-08-05-09-02-52
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-03-05.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-03-05
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-22.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-22
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-35.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-35
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-44.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-44
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-45.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-45
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-14-22-46-19.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-14-22-46-19
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-47.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-47
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-56.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-56
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-14-05-07.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-14-05-07
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-16-44-59.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-16-44-59
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-18-57-22.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-18-57-22
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-17-19-17-57.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-17-19-17-57
Supprime! - C:\Program Files\GamesBar\Localization-French.ini
Supprime! - C:\Program Files\GamesBar\OBGet.exe
Supprime! - C:\Program Files\GamesBar\oberontb.dll
Supprime! - C:\Program Files\GamesBar\uninst.exe
Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\GamesBar
Supprime! - C:\WINDOWS\System32\uninst.exe
Supprime! - C:\Program Files\MSN Messenger\msimg32.dll
Supprime! - C:\Program Files\Conduit
Supprime! - C:\Program Files\Crawler
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
Supprime! - C:\Program Files\GamesBar
Supprime! - C:\DOCUME~1\sam\APPLIC~1\MOZILLA\FIREFOX\PROFILES\7J6R67~1.DEF\EXTENS~1\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(sam) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(sam) - {D2A6A719-7CBC-4594-85FD-C36AD881424F} => blueorganizer
(sam) - {34ea1c70-42cc-42c5-aa29-ec58b95a343e} => mybabylon
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"SearchMigratedDefaultUrl"="http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNxmk142YYFR&fl=0&ptb=Y_qILLhKCx3a21.Vfp9Uiw&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}"
"Start Page"="http://mystart.magentic.com/english/"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66028"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"
"SearchAssistant"="http://www.crawler.com/search/ie.aspx?tb_id=66028"
"CustomizeSearch"="http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028"
-----------\\ Fin du rapport a 10:16:57,53
-----------\\ ToolBar S&D 1.0.8 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : sam ] [ "C:\Toolbar SD" ] [ Selection : 2 ]
[ 05/08/2008 | 10:12:02,12 ] [ PC : ACER-29569F1E48 ]
[ MAJ : 04-08-2008 | 23:15 ]
-----------\\ SUPPRESSION
Supprime! - C:\Program Files\Conduit\Community Alerts
Supprime! - C:\Program Files\Crawler\CToolbar.exe
Supprime! - C:\Program Files\Crawler\CUpdate.exe
Supprime! - C:\Program Files\Crawler\TempDir
Supprime! - C:\Program Files\Crawler\ctbcomm.dll
Supprime! - C:\Program Files\Crawler\services.dat
Supprime! - C:\Program Files\Crawler\rootmenu.dat
Supprime! - C:\Program Files\Crawler\ctbr.dll
Supprime! - C:\Program Files\Crawler\CTipsDef.dll
Supprime! - C:\Program Files\Crawler\Languages
Supprime! - C:\Program Files\Crawler\TBR5LanguageAct
Supprime! - C:\Program Files\Crawler\majorse.dat
Supprime! - C:\Program Files\Crawler\lookfor.dat
Supprime! - C:\Program Files\Crawler\confirm.dat
Supprime! - C:\Program Files\Crawler\firefox
Supprime! - C:\Program Files\Crawler\Update
Supprime! - C:\Program Files\Crawler\Download
Supprime! - C:\Program Files\Crawler\adrkeys.dat
Supprime! - C:\Program Files\Crawler\COMMON_FF.dat
Supprime! - C:\Program Files\Crawler\CTConf.dat
Supprime! - C:\Program Files\Crawler\svc_set.dat
Supprime! - C:\Program Files\Crawler\Cache
Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\Crawler Toolbar
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\partner.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\about.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\update.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sendafriend.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\feedback.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\help.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\uninstall.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search_goog.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\highlight.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_on.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_off.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\newGames.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\hells_kitchen16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\heart_of_egypt16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\ranch_rush16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\penguins_journey16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\vogue_tales16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\download.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\family_restaurant16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\peril_at_end_house16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\AliceGreenfingers16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\dream_day_first_home16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\pet_shop_hop16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\virtualvillagers16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\Cake_mania_216x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\Azada16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\west16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\puzzle.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-53-29.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-53-29
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-54-46.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-12-54-46
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-08-08.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-08-08
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-09-16.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-09-16
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-50-16.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-50-16
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-53-03.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-13-53-03
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\obSearchHistory.dat
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-17-04.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-17-04
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-54-49.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-54-49
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-55-23.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-55-23
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-56-31.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-09-22-56-31
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\arcade.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-10-42-02.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-10-42-02
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-15-29-46.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-15-29-46
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-16-38-09.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-19-16-38-09
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-14-30.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-14-30
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-15-06.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-15-06
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-21-01.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-09-21-01
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-10-48-45.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-10-48-45
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-02-04.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-02-04
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-08-47.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-20-11-08-47
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-24-18-01-41.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-09-58-58.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-24-18-01-41
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\action.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\cards.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-09-39-07.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-09-39-07
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-17-55-57.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-17-55-57
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-21-54-58.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-11-21-54-58
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-29-19-26-42.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-29-19-26-42
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-04-01-18-54-04.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-09-58-58
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-10-48-08.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-31-10-48-08
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\eye_for_design16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-04-01-18-54-04
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\jigsaw.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mahjong.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sports.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\webgame.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\multiplayer.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mygames.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\buy.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\trial.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\deals.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-05-24-20-52-54.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-05-24-20-52-54
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-08-05-09-02-52.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\oberonconfig.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-08-05-09-02-52
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-03-05.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-03-05
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-22.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-22
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-35.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-35
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-44.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-44
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-45.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-13-21-06-45
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-14-22-46-19.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-14-22-46-19
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-47.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-47
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-56.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-15-07-39-56
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-14-05-07.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-14-05-07
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-16-44-59.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-16-44-59
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-18-57-22.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-16-18-57-22
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-17-19-17-57.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\08-03-17-19-17-57
Supprime! - C:\Program Files\GamesBar\Localization-French.ini
Supprime! - C:\Program Files\GamesBar\OBGet.exe
Supprime! - C:\Program Files\GamesBar\oberontb.dll
Supprime! - C:\Program Files\GamesBar\uninst.exe
Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\GamesBar
Supprime! - C:\WINDOWS\System32\uninst.exe
Supprime! - C:\Program Files\MSN Messenger\msimg32.dll
Supprime! - C:\Program Files\Conduit
Supprime! - C:\Program Files\Crawler
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
Supprime! - C:\Program Files\GamesBar
Supprime! - C:\DOCUME~1\sam\APPLIC~1\MOZILLA\FIREFOX\PROFILES\7J6R67~1.DEF\EXTENS~1\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(sam) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(sam) - {D2A6A719-7CBC-4594-85FD-C36AD881424F} => blueorganizer
(sam) - {34ea1c70-42cc-42c5-aa29-ec58b95a343e} => mybabylon
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"SearchMigratedDefaultUrl"="http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNxmk142YYFR&fl=0&ptb=Y_qILLhKCx3a21.Vfp9Uiw&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}"
"Start Page"="http://mystart.magentic.com/english/"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66028"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"
"SearchAssistant"="http://www.crawler.com/search/ie.aspx?tb_id=66028"
"CustomizeSearch"="http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028"
-----------\\ Fin du rapport a 10:16:57,53
pourquoi peur ? tu avais Crawler qui est une saloperie donc on la supprime
ensuite
1) Télécharge et installe Malwarebyte's Anti-Malware:
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée. >>> clique sur OK
Lance Malwarebyte's Anti-Malware en double-cliquant sur l'icône sur ton Bureau.
Au premier lancement, une fenêtre t'annonce que la version est Free >>> clique sur OK
Laisse les Mises à jour se télécharger
*** Referme le programme ***
2) Redémarre en "Mode sans échec"
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : https://www.malekal.com/demarrer-windows-mode-sans-echec/
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
3) Scan avec Malwarebyte's Anti-Malware
Lance Malwarebyte's Anti-Malware
Onglet "Recherche" >>> coche Executer un exame complet >>> Rechercher sélectionne tes disques durs puis clique sur Lancer l’examen
A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
Suppression des éléments détectés >>>>
supprime ce qu'il a trouvé vide également les éléments de la quarantaine
S'il t'es demandé de redémarrer >>> clique sur "Yes"
--> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.
quand tu demande une analyse, demande en mode sans échec.
Pourquoi en mode sans échec:
*Car déjà l'analyse cherche plus de fichiers en mode sans échec que en mode normal.
*Et aussi en mode normal les virus ( trojans, cheval de troie, vers, spywares , malwares et autres ... sont actif) donc ne se supprimes pas donc ils faut le faire en mode sans échec .1) Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
et ensuite un log hijackthis stp
ensuite
1) Télécharge et installe Malwarebyte's Anti-Malware:
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée. >>> clique sur OK
Lance Malwarebyte's Anti-Malware en double-cliquant sur l'icône sur ton Bureau.
Au premier lancement, une fenêtre t'annonce que la version est Free >>> clique sur OK
Laisse les Mises à jour se télécharger
*** Referme le programme ***
2) Redémarre en "Mode sans échec"
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : https://www.malekal.com/demarrer-windows-mode-sans-echec/
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
3) Scan avec Malwarebyte's Anti-Malware
Lance Malwarebyte's Anti-Malware
Onglet "Recherche" >>> coche Executer un exame complet >>> Rechercher sélectionne tes disques durs puis clique sur Lancer l’examen
A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
Suppression des éléments détectés >>>>
supprime ce qu'il a trouvé vide également les éléments de la quarantaine
S'il t'es demandé de redémarrer >>> clique sur "Yes"
--> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.
quand tu demande une analyse, demande en mode sans échec.
Pourquoi en mode sans échec:
*Car déjà l'analyse cherche plus de fichiers en mode sans échec que en mode normal.
*Et aussi en mode normal les virus ( trojans, cheval de troie, vers, spywares , malwares et autres ... sont actif) donc ne se supprimes pas donc ils faut le faire en mode sans échec .1) Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
et ensuite un log hijackthis stp
Rapport hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:29:44, on 05/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\FreezeScreenSaver.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\WANADOO\TaskBarIcon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Atheros\ACU.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\orange\player orange\Orange Player.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Hotmail Popper\hotpop.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66028
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.magentic.com/english/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {fa4acd63-fdbf-4ee2-85e1-cad95e77cdf0} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PAC7311_Monitor] C:\WINDOWS\PixArt\PAC7311\Monitor.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\WANADOO\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\WANADOO\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [OrangePlayer] c:\program files\orange\player orange\Orange Player.exe /systray
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [uqeqc] c:\documents and settings\sam\local settings\application data\uqeqc.exe uqeqc
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [OrangePlayer] c:\program files\orange\player orange\Orange Player.exe /systray (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: Hotmail Popper.lnk = C:\Program Files\Hotmail Popper\hotpop.exe
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {2D37B9E8-C14C-482C-B1CF-939C5440E179} (VTToolkit Control) - http://videomessages.orange.fr/VTToolkit.ocx
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/ImageUploader5.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game13.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - https://www.photobox.fr/?channel=1005
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:29:44, on 05/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\FreezeScreenSaver.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\WANADOO\TaskBarIcon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Atheros\ACU.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\orange\player orange\Orange Player.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Hotmail Popper\hotpop.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66028
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.magentic.com/english/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {fa4acd63-fdbf-4ee2-85e1-cad95e77cdf0} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PAC7311_Monitor] C:\WINDOWS\PixArt\PAC7311\Monitor.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\WANADOO\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\WANADOO\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [OrangePlayer] c:\program files\orange\player orange\Orange Player.exe /systray
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [uqeqc] c:\documents and settings\sam\local settings\application data\uqeqc.exe uqeqc
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [OrangePlayer] c:\program files\orange\player orange\Orange Player.exe /systray (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: Hotmail Popper.lnk = C:\Program Files\Hotmail Popper\hotpop.exe
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {2D37B9E8-C14C-482C-B1CF-939C5440E179} (VTToolkit Control) - http://videomessages.orange.fr/VTToolkit.ocx
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/ImageUploader5.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game13.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - https://www.photobox.fr/?channel=1005
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
Rends toi sur ton PC ici "C:\ programme file\Trend Micro\HijackThis\HijackThis.exe"<---clik droit sur ce dernier
et choisis "renommer" : tapes eden et valide .
le rapport de Mbam se trouve dans logs hijackthis tu l'a fait avant ou apres Mbam ( Malwarebyte)
et choisis "renommer" : tapes eden et valide .
le rapport de Mbam se trouve dans logs hijackthis tu l'a fait avant ou apres Mbam ( Malwarebyte)
Je l'ai trouvé ouf :
Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1026
Windows 5.1.2600 Service Pack 2
12:10:15 05/08/2008
mbam-log-8-5-2008 (12-10-15).txt
Type de recherche: Examen complet (C:\|D:\|E:\|)
Eléments examinés: 91705
Temps écoulé: 1 hour(s), 29 minute(s), 49 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 6
Valeur(s) du Registre infectée(s): 3
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 9
Fichier(s) infecté(s): 17
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webmediaplayer (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Casino Tropez (Adware.Casino) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Casino Tropez (Adware.Casino) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UninstallSXS (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ssnipe (Rogue.SpySnipe) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Products\rdomain (Rogue.PCVirusless) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\prodname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\compname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\WebMediaPlayer (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\skins (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\updates (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\Antivirus2008 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMon (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMon\Data (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Application Data\Antivirus (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc_navps.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc_nav.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc.exe (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Program Files\Antivirus2008\Antvrs.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{39138AFC-2562-464E-ABA0-3F3BA0BC3ED9}\RP157\A0029570.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Toolbar SD\Backup-TB\Program Files\MSN Messenger\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\sqlite3.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\uninst.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources\languages_v2.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources\webmedias (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\skins\classic.skn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008\Antivirus 2008.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008\Uninstall Antivirus.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Application Data\config.cfg (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Bureau\WebMediaPlayer.lnk (Adware.EGDAccess) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1026
Windows 5.1.2600 Service Pack 2
12:10:15 05/08/2008
mbam-log-8-5-2008 (12-10-15).txt
Type de recherche: Examen complet (C:\|D:\|E:\|)
Eléments examinés: 91705
Temps écoulé: 1 hour(s), 29 minute(s), 49 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 6
Valeur(s) du Registre infectée(s): 3
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 9
Fichier(s) infecté(s): 17
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webmediaplayer (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Casino Tropez (Adware.Casino) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Casino Tropez (Adware.Casino) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UninstallSXS (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ssnipe (Rogue.SpySnipe) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Products\rdomain (Rogue.PCVirusless) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\prodname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\compname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\WebMediaPlayer (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\skins (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\updates (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\Antivirus2008 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMon (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMon\Data (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Application Data\Antivirus (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc_navps.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc_nav.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc.exe (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Program Files\Antivirus2008\Antvrs.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{39138AFC-2562-464E-ABA0-3F3BA0BC3ED9}\RP157\A0029570.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Toolbar SD\Backup-TB\Program Files\MSN Messenger\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\sqlite3.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\uninst.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources\languages_v2.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources\webmedias (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\skins\classic.skn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008\Antivirus 2008.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008\Uninstall Antivirus.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Application Data\config.cfg (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Bureau\WebMediaPlayer.lnk (Adware.EGDAccess) -> Quarantined and deleted successfully.
Hourra j'ai trouvé le rapport :
Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1026
Windows 5.1.2600 Service Pack 2
12:10:15 05/08/2008
mbam-log-8-5-2008 (12-10-15).txt
Type de recherche: Examen complet (C:\|D:\|E:\|)
Eléments examinés: 91705
Temps écoulé: 1 hour(s), 29 minute(s), 49 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 6
Valeur(s) du Registre infectée(s): 3
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 9
Fichier(s) infecté(s): 17
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webmediaplayer (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Casino Tropez (Adware.Casino) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Casino Tropez (Adware.Casino) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UninstallSXS (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ssnipe (Rogue.SpySnipe) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Products\rdomain (Rogue.PCVirusless) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\prodname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\compname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\WebMediaPlayer (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\skins (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\updates (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\Antivirus2008 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMon (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMon\Data (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Application Data\Antivirus (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc_navps.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc_nav.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc.exe (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Program Files\Antivirus2008\Antvrs.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{39138AFC-2562-464E-ABA0-3F3BA0BC3ED9}\RP157\A0029570.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Toolbar SD\Backup-TB\Program Files\MSN Messenger\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\sqlite3.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\uninst.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources\languages_v2.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources\webmedias (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\skins\classic.skn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008\Antivirus 2008.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008\Uninstall Antivirus.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Application Data\config.cfg (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Bureau\WebMediaPlayer.lnk (Adware.EGDAccess) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1026
Windows 5.1.2600 Service Pack 2
12:10:15 05/08/2008
mbam-log-8-5-2008 (12-10-15).txt
Type de recherche: Examen complet (C:\|D:\|E:\|)
Eléments examinés: 91705
Temps écoulé: 1 hour(s), 29 minute(s), 49 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 6
Valeur(s) du Registre infectée(s): 3
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 9
Fichier(s) infecté(s): 17
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webmediaplayer (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Casino Tropez (Adware.Casino) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Casino Tropez (Adware.Casino) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UninstallSXS (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ssnipe (Rogue.SpySnipe) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Products\rdomain (Rogue.PCVirusless) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\prodname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\compname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\WebMediaPlayer (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\skins (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\updates (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\Antivirus2008 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMon (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMon\Data (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Application Data\Antivirus (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc_navps.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc_nav.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Local Settings\Application Data\uqeqc.exe (Adware.Navipromo) -> Quarantined and deleted successfully.
C:\Program Files\Antivirus2008\Antvrs.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{39138AFC-2562-464E-ABA0-3F3BA0BC3ED9}\RP157\A0029570.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Toolbar SD\Backup-TB\Program Files\MSN Messenger\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\sqlite3.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\uninst.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources\languages_v2.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\resources\webmedias (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\WebMediaPlayer\skins\classic.skn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008\Antivirus 2008.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Menu Démarrer\Antivirus2008\Uninstall Antivirus.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\sam\Application Data\config.cfg (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Bureau\WebMediaPlayer.lnk (Adware.EGDAccess) -> Quarantined and deleted successfully.
ensuite
Clique sur ce lien :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
Clique sur navilog1.exe pour télécharger navilog1
Choisis Enregistrer
et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).
Laisse-toi guider. Au menu principal, choisis 1 et valides.
(ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
Patiente jusqu'au message :
*** Analyse Termine le ..... ***
Appuie sur une touche comme demandé, le bloc note va s'ouvrir.
Copie-colle l'intégralité dans une réponse. Referme le bloc note.
Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
poste les rapports obtenus
c'est pas un dossier pour hijackthis il faut renomer hijackthis.exe en eden.exe
Clique sur ce lien :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
Clique sur navilog1.exe pour télécharger navilog1
Choisis Enregistrer
et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).
Laisse-toi guider. Au menu principal, choisis 1 et valides.
(ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
Patiente jusqu'au message :
*** Analyse Termine le ..... ***
Appuie sur une touche comme demandé, le bloc note va s'ouvrir.
Copie-colle l'intégralité dans une réponse. Referme le bloc note.
Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
poste les rapports obtenus
c'est pas un dossier pour hijackthis il faut renomer hijackthis.exe en eden.exe
Merci de prendre du temps pour m'aider...vive la solidarité
voilà le rapport :
Search Navipromo version 3.6.1 commencé le 05/08/2008 à 15:30:11,23
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "sam"
Mise à jour le 19.07.2008 à 20h00 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : FAT32
Recherche executé en mode normal
*** Recherche Programmes installés ***
*** Recherche dossiers dans "C:\WINDOWS" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudÉ~1\progra~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudÉ~1" ***
*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\sam\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\INVITÉ\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\sam\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\INVITÉ\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\sam\menud+~1\progra~1" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
Aucun Fichier Navipromo trouvé
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\WINDOWS\system32" *
* Recherche dans "C:\Documents and Settings\sam\locals~1\applic~1" *
Fichiers trouvés :
owgem.exe trouvé !
owgem.dat trouvé !
Fichiers suspects :
ljoflr.exe trouvé !
ljoflr.exe trouvé !
owgem.exe trouvé !
owgem.dat trouvé !
* Recherche dans "C:\DOCUME~1\INVITÉ\locals~1\applic~1" *
*** Recherche fichiers ***
*** Recherche clés spécifiques dans le Registre ***
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\WINDOWS\system32" :
* Dans "C:\Documents and Settings\sam\locals~1\applic~1" :
* Dans "C:\DOCUME~1\INVITÉ\locals~1\applic~1" :
3)Recherche Certificats :
Certificat Egroup trouvé !
Certificat Electronic-Group trouvé !
Certificat OOO-Favorit trouvé !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche fichiers connus :
*** Analyse terminée le 05/08/2008 à 15:31:46,10 ***
voilà le rapport :
Search Navipromo version 3.6.1 commencé le 05/08/2008 à 15:30:11,23
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "sam"
Mise à jour le 19.07.2008 à 20h00 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : FAT32
Recherche executé en mode normal
*** Recherche Programmes installés ***
*** Recherche dossiers dans "C:\WINDOWS" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudÉ~1\progra~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudÉ~1" ***
*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\sam\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\INVITÉ\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\sam\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\INVITÉ\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\sam\menud+~1\progra~1" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
Aucun Fichier Navipromo trouvé
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\WINDOWS\system32" *
* Recherche dans "C:\Documents and Settings\sam\locals~1\applic~1" *
Fichiers trouvés :
owgem.exe trouvé !
owgem.dat trouvé !
Fichiers suspects :
ljoflr.exe trouvé !
ljoflr.exe trouvé !
owgem.exe trouvé !
owgem.dat trouvé !
* Recherche dans "C:\DOCUME~1\INVITÉ\locals~1\applic~1" *
*** Recherche fichiers ***
*** Recherche clés spécifiques dans le Registre ***
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\WINDOWS\system32" :
* Dans "C:\Documents and Settings\sam\locals~1\applic~1" :
* Dans "C:\DOCUME~1\INVITÉ\locals~1\applic~1" :
3)Recherche Certificats :
Certificat Egroup trouvé !
Certificat Electronic-Group trouvé !
Certificat OOO-Favorit trouvé !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche fichiers connus :
*** Analyse terminée le 05/08/2008 à 15:31:46,10 ***
ok
tu cliques sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
Au menu principal, choisis 2 et valides.
(ne fais pas le choix ,3 ou 4 sans notre avis/accord)
Le fix va t'informer qu'il va alors redémarrer ton PC
Fermes toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
Appuies sur une touche comme demandé.
(si ton Pc ne redémarre pas automatiquement, fais le toi même)
Au redémarrage de ton PC, choisis ta session habituelle.
Patiente jusqu'au message :
*** Nettoyage Termine le ..... ***
Le bloc-notes va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver
Referme le bloc-notes. Ton bureau va réapparaitre
PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
Tape explorer et valide. Celà te fera apparaitre ton bureau.
Poste le rapport
tu cliques sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
Au menu principal, choisis 2 et valides.
(ne fais pas le choix ,3 ou 4 sans notre avis/accord)
Le fix va t'informer qu'il va alors redémarrer ton PC
Fermes toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
Appuies sur une touche comme demandé.
(si ton Pc ne redémarre pas automatiquement, fais le toi même)
Au redémarrage de ton PC, choisis ta session habituelle.
Patiente jusqu'au message :
*** Nettoyage Termine le ..... ***
Le bloc-notes va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver
Referme le bloc-notes. Ton bureau va réapparaitre
PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
Tape explorer et valide. Celà te fera apparaitre ton bureau.
Poste le rapport
Clean Navipromo version 3.6.1 commencé le 05/08/2008 à 15:54:49,73
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "sam"
Mise à jour le 19.07.2008 à 20h00 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : FAT32
Mode suppression automatique
avec prise en charge résultats Catchme et GNS
Nettoyage exécuté au redémarrage de l'ordinateur
*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)
*** Suppression avec sauvegardes résultats GenericNaviSearch ***
* Suppression dans "C:\WINDOWS\System32" *
* Suppression dans "C:\Documents and Settings\sam\locals~1\applic~1" *
owgem.exe trouvé !
Copie owgem.exe réalisée avec succès !
owgem.exe supprimé !
owgem.dat trouvé !
Copie owgem.dat réalisée avec succès !
owgem.dat supprimé !
ljoflr.exe trouvé !
Copie ljoflr.exe réalisée avec succès !
ljoflr.exe supprimé !
ljoflr_m2s.xml trouvé !
Copie ljoflr_m2s.xml réalisée avec succès !
ljoflr_m2s.xml supprimé !
Autres Suppressions :
* Suppression dans "C:\DOCUME~1\INVIT+\locals~1\applic~1" *
*** Suppression dossiers dans "C:\WINDOWS" ***
*** Suppression dossiers dans "C:\Program Files" ***
*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudÉ~1\progra~1" ***
...\WebMediaPlayer ...suppression...
...\WebMediaPlayer supprimé !
*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudÉ~1" ***
*** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\sam\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\INVIT+\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\sam\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\INVIT+\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\sam\menud+~1\progra~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\INVIT+\menud+~1\progra~1" ***
*** Suppression fichiers ***
*** Suppression fichiers temporaires ***
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\sam\locals~1\Temp effectué !
*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Suppression avec sauvegardes nouveaux fichiers Instant Access :
2)Recherche, création sauvegardes et suppression Heuristique :
* Dans "C:\WINDOWS\system32" *
* Dans "C:\Documents and Settings\sam\locals~1\applic~1" *
* Dans "C:\DOCUME~1\INVIT+\locals~1\applic~1" *
*** Sauvegarde du Registre vers dossier Safebackup ***
sauvegarde du Registre réalisée avec succès !
*** Nettoyage Registre ***
Nettoyage Registre Ok
*** Certificats ***
Certificat Egroup supprimé !
Certificat Electronic-Group supprimé !
Certificat OOO-Favorit supprimé !
Certificat Sunny-Day-Design-Ltdt absent !
*** Recherche clés RUN orphelines Navipromo ***
!! Résultats temporairement non pris en charge !!
!! Les clés trouvées ne sont pas forcément infectées !!
Clés trouvés :
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uqeqc"="c:\\documents and settings\\sam\\local settings\\application data\\uqeqc.exe uqeqc"
*** Nettoyage terminé le 05/08/2008 à 15:58:45,67 ***
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "sam"
Mise à jour le 19.07.2008 à 20h00 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : FAT32
Mode suppression automatique
avec prise en charge résultats Catchme et GNS
Nettoyage exécuté au redémarrage de l'ordinateur
*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)
*** Suppression avec sauvegardes résultats GenericNaviSearch ***
* Suppression dans "C:\WINDOWS\System32" *
* Suppression dans "C:\Documents and Settings\sam\locals~1\applic~1" *
owgem.exe trouvé !
Copie owgem.exe réalisée avec succès !
owgem.exe supprimé !
owgem.dat trouvé !
Copie owgem.dat réalisée avec succès !
owgem.dat supprimé !
ljoflr.exe trouvé !
Copie ljoflr.exe réalisée avec succès !
ljoflr.exe supprimé !
ljoflr_m2s.xml trouvé !
Copie ljoflr_m2s.xml réalisée avec succès !
ljoflr_m2s.xml supprimé !
Autres Suppressions :
* Suppression dans "C:\DOCUME~1\INVIT+\locals~1\applic~1" *
*** Suppression dossiers dans "C:\WINDOWS" ***
*** Suppression dossiers dans "C:\Program Files" ***
*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudÉ~1\progra~1" ***
...\WebMediaPlayer ...suppression...
...\WebMediaPlayer supprimé !
*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudÉ~1" ***
*** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\sam\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\INVIT+\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\sam\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\INVIT+\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\sam\menud+~1\progra~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\INVIT+\menud+~1\progra~1" ***
*** Suppression fichiers ***
*** Suppression fichiers temporaires ***
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\sam\locals~1\Temp effectué !
*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Suppression avec sauvegardes nouveaux fichiers Instant Access :
2)Recherche, création sauvegardes et suppression Heuristique :
* Dans "C:\WINDOWS\system32" *
* Dans "C:\Documents and Settings\sam\locals~1\applic~1" *
* Dans "C:\DOCUME~1\INVIT+\locals~1\applic~1" *
*** Sauvegarde du Registre vers dossier Safebackup ***
sauvegarde du Registre réalisée avec succès !
*** Nettoyage Registre ***
Nettoyage Registre Ok
*** Certificats ***
Certificat Egroup supprimé !
Certificat Electronic-Group supprimé !
Certificat OOO-Favorit supprimé !
Certificat Sunny-Day-Design-Ltdt absent !
*** Recherche clés RUN orphelines Navipromo ***
!! Résultats temporairement non pris en charge !!
!! Les clés trouvées ne sont pas forcément infectées !!
Clés trouvés :
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uqeqc"="c:\\documents and settings\\sam\\local settings\\application data\\uqeqc.exe uqeqc"
*** Nettoyage terminé le 05/08/2008 à 15:58:45,67 ***
il en reste 1
prend ce lien
https://sites.google.com/site/eric71mespages/lop.sd.exe
et fait l'option 1 ensuite poste le rapport
prend ce lien
https://sites.google.com/site/eric71mespages/lop.sd.exe
et fait l'option 1 ensuite poste le rapport
--------------------\\ Lop S&D 4.2.2-5 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : sam ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 05/08/2008 | 16:13:24,93 ] [ PC : ACER-29569F1E48 ]
[ MAJ : 01-08-2008 | 01:40 ]
--------------------\\ Listing des dossiers dans APPLIC~1
[24/08/2005|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[24/08/2005|03:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[24/08/2005|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[01/06/2007|07:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\118300.34
[02/03/2008|21:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\addr_file.html
[22/08/2007|10:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[12/03/2007|17:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[12/12/2007|13:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Arovax
[11/07/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Astar Games
[14/04/2007|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avery
[01/03/2008|21:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[25/07/2008|13:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
[09/03/2008|20:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[25/07/2008|13:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Christmasville
[25/08/2005|08:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[24/08/2005|03:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[29/03/2007|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FaxCtr
[26/06/2008|21:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[07/03/2008|14:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[13/07/2008|16:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fugazo
[14/08/2007|11:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[20/08/2007|22:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[12/12/2007|17:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[14/07/2008|15:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HiddenSecretsNightmare
[24/07/2008|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[24/07/2008|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[02/02/2008|19:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[22/07/2006|17:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Intel
[28/02/2008|15:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InternetAnonymizer
[28/06/2008|20:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[18/01/2008|16:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[14/07/2008|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[01/03/2008|21:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[05/08/2008|10:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[24/08/2005|03:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[18/03/2008|12:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MonContenuassistant
[28/06/2008|19:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MonteCristo
[20/08/2007|22:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[23/06/2008|10:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[19/06/2008|19:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MythPeople
[05/07/2008|12:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games
[02/02/2008|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[02/04/2007|23:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\pixelStorm
[11/05/2008|12:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[09/04/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[14/04/2008|20:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Registry Helper
[23/07/2006|17:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBT
[27/02/2008|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SITEguard
[19/04/2008|11:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[27/02/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\STOPzilla!
[23/07/2006|01:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[06/05/2007|01:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[08/01/2008|18:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[09/04/2007|21:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[29/03/2007|20:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[26/01/2008|17:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[18/02/2008|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[24/08/2005|03:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[12/03/2008|11:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[14/02/2008|08:54] C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
[19/04/2007|11:13] C:\DOCUME~1\LOCALS~1\APPLIC~1\Help
[24/08/2005|03:27] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[27/01/2008|14:18] C:\DOCUME~1\sam\APPLIC~1\.purple
[01/07/2008|14:32] C:\DOCUME~1\sam\APPLIC~1\Abra Academy2
[23/07/2006|04:07] C:\DOCUME~1\sam\APPLIC~1\Adobe
[29/07/2006|17:02] C:\DOCUME~1\sam\APPLIC~1\AdobeUM
[21/03/2007|20:31] C:\DOCUME~1\sam\APPLIC~1\Apple Computer
[07/01/2008|16:57] C:\DOCUME~1\sam\APPLIC~1\ArcSoft
[23/06/2008|21:43] C:\DOCUME~1\sam\APPLIC~1\Big Fish Games
[21/06/2008|16:12] C:\DOCUME~1\sam\APPLIC~1\cerasus.media
[04/12/2007|21:24] C:\DOCUME~1\sam\APPLIC~1\cs
[24/07/2006|13:57] C:\DOCUME~1\sam\APPLIC~1\CyberLink
[24/08/2005|03:27] C:\DOCUME~1\sam\APPLIC~1\desktop.ini
[05/01/2008|14:52] C:\DOCUME~1\sam\APPLIC~1\DivX
[20/08/2007|22:24] C:\DOCUME~1\sam\APPLIC~1\EoRezo
[29/03/2007|21:23] C:\DOCUME~1\sam\APPLIC~1\FaxCtr
[26/06/2008|21:15] C:\DOCUME~1\sam\APPLIC~1\Flood Light Games
[07/03/2008|14:03] C:\DOCUME~1\sam\APPLIC~1\FloodLightGames
[25/06/2008|12:37] C:\DOCUME~1\sam\APPLIC~1\Friday's games
[01/12/2007|13:12] C:\DOCUME~1\sam\APPLIC~1\F-Secure
[20/08/2007|22:47] C:\DOCUME~1\sam\APPLIC~1\Google
[12/12/2007|17:54] C:\DOCUME~1\sam\APPLIC~1\Grisoft
[27/01/2008|14:22] C:\DOCUME~1\sam\APPLIC~1\gtk-2.0
[27/07/2006|11:51] C:\DOCUME~1\sam\APPLIC~1\Help
[24/08/2005|03:39] C:\DOCUME~1\sam\APPLIC~1\Identities
[15/09/2006|15:07] C:\DOCUME~1\sam\APPLIC~1\Intel
[28/02/2008|15:21] C:\DOCUME~1\sam\APPLIC~1\InternetAnonymizer
[01/12/2007|13:08] C:\DOCUME~1\sam\APPLIC~1\ispnews
[01/06/2007|21:14] C:\DOCUME~1\sam\APPLIC~1\Lavasoft
[01/04/2007|17:04] C:\DOCUME~1\sam\APPLIC~1\LG Electronics
[28/03/2007|10:07] C:\DOCUME~1\sam\APPLIC~1\Macromedia
[05/08/2008|10:34] C:\DOCUME~1\sam\APPLIC~1\Malwarebytes
[24/08/2005|03:27] C:\DOCUME~1\sam\APPLIC~1\Microsoft
[23/07/2006|17:41] C:\DOCUME~1\sam\APPLIC~1\Microsoft Web Folders
[27/02/2008|17:38] C:\DOCUME~1\sam\APPLIC~1\Mozilla
[31/03/2007|23:01] C:\DOCUME~1\sam\APPLIC~1\MSNInstaller
[01/04/2008|18:00] C:\DOCUME~1\sam\APPLIC~1\NMM-MetaData.db
[02/02/2008|19:09] C:\DOCUME~1\sam\APPLIC~1\Nokia
[02/02/2008|19:19] C:\DOCUME~1\sam\APPLIC~1\Nokia Multimedia Player
[05/07/2008|12:01] C:\DOCUME~1\sam\APPLIC~1\Oberon Games
[02/02/2008|19:05] C:\DOCUME~1\sam\APPLIC~1\PC Suite
[01/12/2007|13:11] C:\DOCUME~1\sam\APPLIC~1\PEX
[22/06/2008|13:39] C:\DOCUME~1\sam\APPLIC~1\Pirateville
[23/04/2007|21:16] C:\DOCUME~1\sam\APPLIC~1\Player Orange
[11/05/2008|12:32] C:\DOCUME~1\sam\APPLIC~1\PlayFirst
[14/04/2007|19:25] C:\DOCUME~1\sam\APPLIC~1\Serif
[17/05/2007|19:38] C:\DOCUME~1\sam\APPLIC~1\Sony Corporation
[31/05/2007|22:09] C:\DOCUME~1\sam\APPLIC~1\SPAMfighter
[27/06/2008|11:19] C:\DOCUME~1\sam\APPLIC~1\SprillBermudeFr
[22/04/2007|18:59] C:\DOCUME~1\sam\APPLIC~1\Sun
[23/07/2006|01:19] C:\DOCUME~1\sam\APPLIC~1\Symantec
[20/08/2007|22:41] C:\DOCUME~1\sam\APPLIC~1\Talkback
[22/07/2006|23:00] C:\DOCUME~1\sam\APPLIC~1\Template
[23/03/2008|21:58] C:\DOCUME~1\sam\APPLIC~1\TuneUp Software
[13/07/2008|18:34] C:\DOCUME~1\sam\APPLIC~1\Wildfire
[24/07/2008|16:05] C:\DOCUME~1\sam\APPLIC~1\wklnhst.dat
[09/05/2007|21:53] C:\DOCUME~1\sam\APPLIC~1\Zylom
[24/08/2005|03:27] C:\DOCUME~1\INVIT\APPLIC~1\desktop.ini
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\EoRezo
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\FaxCtr
[01/12/2007|15:28] C:\DOCUME~1\INVIT\APPLIC~1\F-Secure
[02/09/2007|09:00] C:\DOCUME~1\INVIT\APPLIC~1\Google
[24/08/2005|03:39] C:\DOCUME~1\INVIT\APPLIC~1\Identities
[01/12/2007|15:28] C:\DOCUME~1\INVIT\APPLIC~1\ispnews
[01/12/2007|15:33] C:\DOCUME~1\INVIT\APPLIC~1\Macromedia
[24/08/2005|03:27] C:\DOCUME~1\INVIT\APPLIC~1\Microsoft
[02/09/2007|09:21] C:\DOCUME~1\INVIT\APPLIC~1\Mozilla
[28/02/2008|18:06] C:\DOCUME~1\INVIT\APPLIC~1\PC Suite
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\Player Orange
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[05/08/2008 16:00][--a------] C:\WINDOWS\tasks\Maintenance en 1 clic.job
[15/04/2008 08:49][--a------] C:\WINDOWS\tasks\Norton Security Scan.job
[05/08/2008 15:57][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 05:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[29/03/2007|18:40] C:\Program Files\Abbyy FineReader 6.0 Sprint
[25/08/2005|08:29] C:\Program Files\Acer
[24/08/2005|03:49] C:\Program Files\Acer Inc
[24/08/2005|03:49] C:\Program Files\Adobe
[23/12/2007|20:25] C:\Program Files\Ahead
[01/06/2007|22:14] C:\Program Files\Alwil Software
[27/02/2008|17:38] C:\Program Files\AntivirusFirewall
[07/01/2008|16:55] C:\Program Files\ArcSoft
[26/07/2008|09:30] C:\Program Files\Ares
[19/06/2008|22:27] C:\Program Files\Atheros
[14/04/2007|19:42] C:\Program Files\Avery Dennison
[17/03/2008|15:41] C:\Program Files\AVPersonal
[30/06/2008|22:20] C:\Program Files\Babylon
[25/07/2008|13:50] C:\Program Files\bfgclient
[29/07/2006|16:39] C:\Program Files\BitComet
[09/03/2008|20:50] C:\Program Files\Boonty
[09/03/2008|20:50] C:\Program Files\BoontyGames
[07/07/2008|15:49] C:\Program Files\CA Yahoo! Anti-Spy
[20/03/2008|10:43] C:\Program Files\CCleaner
[29/07/2006|16:41] C:\Program Files\CodeStuff
[19/08/2007|15:30] C:\Program Files\Common Files
[24/08/2005|03:33] C:\Program Files\ComPlus Applications
[24/08/2005|03:46] C:\Program Files\CONEXANT
[25/08/2005|08:27] C:\Program Files\CyberLink
[30/06/2007|23:15] C:\Program Files\denouvel
[10/09/2007|17:14] C:\Program Files\DialMessenger
[02/02/2008|19:09] C:\Program Files\DIFX
[05/01/2008|14:52] C:\Program Files\DivX
[16/03/2008|19:53] C:\Program Files\douniamusic.com
[05/01/2008|20:21] C:\Program Files\DSCN0097.JPG
[17/05/2007|10:48] C:\Program Files\eAcceleration
[20/08/2007|22:24] C:\Program Files\EoRezo
[29/02/2008|15:23] C:\Program Files\EsetOnlineScanner
[18/09/2002|02:28] C:\Program Files\F.msi
[24/08/2005|03:28] C:\Program Files\Fichiers communs
[21/06/2008|21:05] C:\Program Files\Freeze.com
[07/03/2008|14:03] C:\Program Files\Gamenext
[14/08/2007|11:13] C:\Program Files\Google
[21/06/2007|18:02] C:\Program Files\green label
[27/02/2008|17:38] C:\Program Files\Horloge
[20/04/2007|23:02] C:\Program Files\Hotmail Popper
[27/02/2008|17:38] C:\Program Files\Hot-TV
[24/08/2005|03:41] C:\Program Files\InstallShield Installation Information
[24/08/2005|03:42] C:\Program Files\Intel
[24/08/2005|03:33] C:\Program Files\Internet Explorer
[05/03/2008|11:34] C:\Program Files\InternetAnonymizer
[23/11/2007|12:40] C:\Program Files\Inventel
[20/08/2007|22:24] C:\Program Files\ItsLabel
[23/04/2007|16:37] C:\Program Files\Java
[22/07/2006|17:31] C:\Program Files\Launch Manager
[29/03/2007|18:24] C:\Program Files\Lexmark 2300 Series
[29/03/2007|18:39] C:\Program Files\Lexmark Fax Solutions
[12/03/2007|17:28] C:\Program Files\LG PC Suite
[12/04/2007|21:28] C:\Program Files\Logiciel Photo Orange
[29/03/2007|18:26] C:\Program Files\Lx_cats
[14/07/2008|20:21] C:\Program Files\ma-config.com
[16/09/2007|23:38] C:\Program Files\MagicPic4
[05/08/2008|10:34] C:\Program Files\Malwarebytes' Anti-Malware
[24/08/2005|03:32] C:\Program Files\Messenger
[14/04/2007|19:24] C:\Program Files\Micro Application
[24/08/2005|03:35] C:\Program Files\microsoft frontpage
[22/07/2006|22:24] C:\Program Files\Microsoft Office
[23/07/2006|17:47] C:\Program Files\Microsoft Visual Studio
[28/01/2008|16:46] C:\Program Files\Microsoft Windows OneCare Live
[22/07/2006|22:22] C:\Program Files\Microsoft Works
[05/09/2007|16:46] C:\Program Files\Mindscape
[24/08/2005|03:33] C:\Program Files\Movie Maker
[27/02/2008|17:38] C:\Program Files\Mozilla Firefox
[24/08/2005|03:32] C:\Program Files\MSN
[24/08/2005|03:32] C:\Program Files\MSN Gaming Zone
[08/04/2007|14:22] C:\Program Files\MSN Messenger
[29/03/2007|23:21] C:\Program Files\MSXML 4.0
[25/08/2005|08:27] C:\Program Files\MyWorks
[05/08/2008|15:28] C:\Program Files\Navilog1
[24/08/2005|03:33] C:\Program Files\NetMeeting
[24/08/2005|03:51] C:\Program Files\NewTech Infosystems
[02/02/2008|19:04] C:\Program Files\Nokia
[15/12/2007|14:12] C:\Program Files\Norton Security Scan
[24/08/2005|03:32] C:\Program Files\Online Services
[24/03/2008|14:47] C:\Program Files\Ontrack
[23/04/2007|21:15] C:\Program Files\Orange
[24/08/2005|03:33] C:\Program Files\Outlook Express
[02/02/2008|19:05] C:\Program Files\PC Connectivity Solution
[24/07/2008|19:50] C:\Program Files\PC VGA Camer@
[26/07/2006|13:47] C:\Program Files\Phototool
[05/01/2008|14:36] C:\Program Files\Picasa2
[07/06/2007|22:15] C:\Program Files\Power IE
[12/03/2007|17:25] C:\Program Files\QuickTime
[24/08/2005|03:45] C:\Program Files\Realtek
[12/10/2007|13:57] C:\Program Files\Redoubt
[10/07/2007|10:08] C:\Program Files\ReflexiveArcade
[18/05/2007|22:15] C:\Program Files\RegCleaner
[03/12/2007|18:56] C:\Program Files\ScreenMates
[30/11/2007|11:31] C:\Program Files\Securitoo
[24/08/2005|03:34] C:\Program Files\Services en ligne
[15/06/2008|16:13] C:\Program Files\SIW
[23/07/2006|17:56] C:\Program Files\Snapshot Viewer
[17/05/2007|19:28] C:\Program Files\Sony
[19/04/2008|11:03] C:\Program Files\Spybot - Search & Destroy
[14/06/2008|17:35] C:\Program Files\Sun
[01/03/2008|23:14] C:\Program Files\Sunbelt Software
[23/07/2006|01:19] C:\Program Files\Symantec
[24/08/2005|03:47] C:\Program Files\Synaptics
[20/06/2008|15:19] C:\Program Files\temp01
[16/02/2008|21:55] C:\Program Files\Thumbs.db
[29/02/2008|17:14] C:\Program Files\Trend Micro
[07/01/2008|15:58] C:\Program Files\Trust
[08/01/2008|18:02] C:\Program Files\Ulead Systems
[24/08/2005|03:39] C:\Program Files\Uninstall Information
[16/10/2006|00:47] C:\Program Files\USBDisk
[29/03/2007|22:06] C:\Program Files\Wanadoo
[26/07/2006|13:54] C:\Program Files\Winamp
[26/01/2008|17:16] C:\Program Files\Windows Live
[28/01/2008|15:05] C:\Program Files\Windows Live Safety Center
[29/03/2007|20:12] C:\Program Files\Windows Live Toolbar
[19/05/2007|00:27] C:\Program Files\Windows Media Connect 2
[24/08/2005|03:32] C:\Program Files\Windows Media Player
[24/08/2005|03:32] C:\Program Files\Windows NT
[24/08/2005|03:34] C:\Program Files\WindowsUpdate
[22/07/2006|17:29] C:\Program Files\WinPCap
[29/07/2006|16:37] C:\Program Files\WinRAR
[24/08/2005|03:35] C:\Program Files\xerox
[15/06/2008|17:10] C:\Program Files\Yahoo!
[29/04/2007|20:10] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[22/08/2007|10:25] C:\Program Files\Fichiers communs\Adobe
[23/12/2007|20:25] C:\Program Files\Fichiers communs\Ahead
[07/01/2008|16:55] C:\Program Files\Fichiers communs\ArcSoft
[09/03/2008|20:52] C:\Program Files\Fichiers communs\BOONTY Shared
[23/07/2006|17:47] C:\Program Files\Fichiers communs\Designer
[21/06/2007|18:01] C:\Program Files\Fichiers communs\gst
[27/01/2008|14:17] C:\Program Files\Fichiers communs\GTK
[24/08/2005|03:41] C:\Program Files\Fichiers communs\InstallShield
[28/02/2008|15:21] C:\Program Files\Fichiers communs\InternetAnonymizer
[27/02/2008|15:27] C:\Program Files\Fichiers communs\iS3
[22/04/2007|18:56] C:\Program Files\Fichiers communs\Java
[24/03/2008|09:27] C:\Program Files\Fichiers communs\LightScribe
[24/08/2005|03:28] C:\Program Files\Fichiers communs\Microsoft Shared
[24/08/2005|03:33] C:\Program Files\Fichiers communs\MSSoap
[24/08/2005|03:51] C:\Program Files\Fichiers communs\muvee Technologies
[24/08/2005|03:51] C:\Program Files\Fichiers communs\NewTech Infosystems
[02/02/2008|19:09] C:\Program Files\Fichiers communs\Nokia
[24/08/2005|03:28] C:\Program Files\Fichiers communs\ODBC
[24/07/2008|19:50] C:\Program Files\Fichiers communs\PCCamera
[02/02/2008|19:09] C:\Program Files\Fichiers communs\PCSuite
[28/02/2008|15:05] C:\Program Files\Fichiers communs\ReparateurDeSysteme
[07/07/2008|15:49] C:\Program Files\Fichiers communs\Scanner
[24/08/2005|03:33] C:\Program Files\Fichiers communs\Services
[24/08/2005|03:28] C:\Program Files\Fichiers communs\SpeechEngines
[23/07/2006|01:19] C:\Program Files\Fichiers communs\Symantec Shared
[24/08/2005|03:33] C:\Program Files\Fichiers communs\System
[08/01/2008|18:04] C:\Program Files\Fichiers communs\Ulead Systems
[26/01/2008|17:16] C:\Program Files\Fichiers communs\WindowsLiveInstaller
--------------------\\ Process
( 66 Processus )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-05 16:17:22
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uqeqc"="c:\\documents and settings\\sam\\local settings\\application data\\uqeqc.exe uqeqc"
[b]==> EGDACCESS <==/b
[F:26][D:0]-> C:\DOCUME~1\sam\LOCALS~1\Temp
[F:3][D:0]-> C:\DOCUME~1\sam\Cookies
[F:23][D:4]-> C:\DOCUME~1\sam\LOCALS~1\TEMPOR~1\content.IE5
[F:3][D:0]-> C:\Recycled
--------------------\\ Fin du rapport a 16:18:25,59
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : sam ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 05/08/2008 | 16:13:24,93 ] [ PC : ACER-29569F1E48 ]
[ MAJ : 01-08-2008 | 01:40 ]
--------------------\\ Listing des dossiers dans APPLIC~1
[24/08/2005|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[24/08/2005|03:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[24/08/2005|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[01/06/2007|07:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\118300.34
[02/03/2008|21:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\addr_file.html
[22/08/2007|10:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[12/03/2007|17:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[12/12/2007|13:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Arovax
[11/07/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Astar Games
[14/04/2007|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avery
[01/03/2008|21:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[25/07/2008|13:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
[09/03/2008|20:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[25/07/2008|13:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Christmasville
[25/08/2005|08:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[24/08/2005|03:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[29/03/2007|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FaxCtr
[26/06/2008|21:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[07/03/2008|14:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[13/07/2008|16:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fugazo
[14/08/2007|11:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[20/08/2007|22:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[12/12/2007|17:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[14/07/2008|15:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HiddenSecretsNightmare
[24/07/2008|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[24/07/2008|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[02/02/2008|19:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[22/07/2006|17:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Intel
[28/02/2008|15:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InternetAnonymizer
[28/06/2008|20:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[18/01/2008|16:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[14/07/2008|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[01/03/2008|21:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[05/08/2008|10:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[24/08/2005|03:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[18/03/2008|12:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MonContenuassistant
[28/06/2008|19:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MonteCristo
[20/08/2007|22:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[23/06/2008|10:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[19/06/2008|19:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MythPeople
[05/07/2008|12:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games
[02/02/2008|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[02/04/2007|23:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\pixelStorm
[11/05/2008|12:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[09/04/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[14/04/2008|20:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Registry Helper
[23/07/2006|17:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBT
[27/02/2008|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SITEguard
[19/04/2008|11:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[27/02/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\STOPzilla!
[23/07/2006|01:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[06/05/2007|01:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[08/01/2008|18:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[09/04/2007|21:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[29/03/2007|20:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[26/01/2008|17:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[18/02/2008|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[24/08/2005|03:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[12/03/2008|11:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[14/02/2008|08:54] C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
[19/04/2007|11:13] C:\DOCUME~1\LOCALS~1\APPLIC~1\Help
[24/08/2005|03:27] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[27/01/2008|14:18] C:\DOCUME~1\sam\APPLIC~1\.purple
[01/07/2008|14:32] C:\DOCUME~1\sam\APPLIC~1\Abra Academy2
[23/07/2006|04:07] C:\DOCUME~1\sam\APPLIC~1\Adobe
[29/07/2006|17:02] C:\DOCUME~1\sam\APPLIC~1\AdobeUM
[21/03/2007|20:31] C:\DOCUME~1\sam\APPLIC~1\Apple Computer
[07/01/2008|16:57] C:\DOCUME~1\sam\APPLIC~1\ArcSoft
[23/06/2008|21:43] C:\DOCUME~1\sam\APPLIC~1\Big Fish Games
[21/06/2008|16:12] C:\DOCUME~1\sam\APPLIC~1\cerasus.media
[04/12/2007|21:24] C:\DOCUME~1\sam\APPLIC~1\cs
[24/07/2006|13:57] C:\DOCUME~1\sam\APPLIC~1\CyberLink
[24/08/2005|03:27] C:\DOCUME~1\sam\APPLIC~1\desktop.ini
[05/01/2008|14:52] C:\DOCUME~1\sam\APPLIC~1\DivX
[20/08/2007|22:24] C:\DOCUME~1\sam\APPLIC~1\EoRezo
[29/03/2007|21:23] C:\DOCUME~1\sam\APPLIC~1\FaxCtr
[26/06/2008|21:15] C:\DOCUME~1\sam\APPLIC~1\Flood Light Games
[07/03/2008|14:03] C:\DOCUME~1\sam\APPLIC~1\FloodLightGames
[25/06/2008|12:37] C:\DOCUME~1\sam\APPLIC~1\Friday's games
[01/12/2007|13:12] C:\DOCUME~1\sam\APPLIC~1\F-Secure
[20/08/2007|22:47] C:\DOCUME~1\sam\APPLIC~1\Google
[12/12/2007|17:54] C:\DOCUME~1\sam\APPLIC~1\Grisoft
[27/01/2008|14:22] C:\DOCUME~1\sam\APPLIC~1\gtk-2.0
[27/07/2006|11:51] C:\DOCUME~1\sam\APPLIC~1\Help
[24/08/2005|03:39] C:\DOCUME~1\sam\APPLIC~1\Identities
[15/09/2006|15:07] C:\DOCUME~1\sam\APPLIC~1\Intel
[28/02/2008|15:21] C:\DOCUME~1\sam\APPLIC~1\InternetAnonymizer
[01/12/2007|13:08] C:\DOCUME~1\sam\APPLIC~1\ispnews
[01/06/2007|21:14] C:\DOCUME~1\sam\APPLIC~1\Lavasoft
[01/04/2007|17:04] C:\DOCUME~1\sam\APPLIC~1\LG Electronics
[28/03/2007|10:07] C:\DOCUME~1\sam\APPLIC~1\Macromedia
[05/08/2008|10:34] C:\DOCUME~1\sam\APPLIC~1\Malwarebytes
[24/08/2005|03:27] C:\DOCUME~1\sam\APPLIC~1\Microsoft
[23/07/2006|17:41] C:\DOCUME~1\sam\APPLIC~1\Microsoft Web Folders
[27/02/2008|17:38] C:\DOCUME~1\sam\APPLIC~1\Mozilla
[31/03/2007|23:01] C:\DOCUME~1\sam\APPLIC~1\MSNInstaller
[01/04/2008|18:00] C:\DOCUME~1\sam\APPLIC~1\NMM-MetaData.db
[02/02/2008|19:09] C:\DOCUME~1\sam\APPLIC~1\Nokia
[02/02/2008|19:19] C:\DOCUME~1\sam\APPLIC~1\Nokia Multimedia Player
[05/07/2008|12:01] C:\DOCUME~1\sam\APPLIC~1\Oberon Games
[02/02/2008|19:05] C:\DOCUME~1\sam\APPLIC~1\PC Suite
[01/12/2007|13:11] C:\DOCUME~1\sam\APPLIC~1\PEX
[22/06/2008|13:39] C:\DOCUME~1\sam\APPLIC~1\Pirateville
[23/04/2007|21:16] C:\DOCUME~1\sam\APPLIC~1\Player Orange
[11/05/2008|12:32] C:\DOCUME~1\sam\APPLIC~1\PlayFirst
[14/04/2007|19:25] C:\DOCUME~1\sam\APPLIC~1\Serif
[17/05/2007|19:38] C:\DOCUME~1\sam\APPLIC~1\Sony Corporation
[31/05/2007|22:09] C:\DOCUME~1\sam\APPLIC~1\SPAMfighter
[27/06/2008|11:19] C:\DOCUME~1\sam\APPLIC~1\SprillBermudeFr
[22/04/2007|18:59] C:\DOCUME~1\sam\APPLIC~1\Sun
[23/07/2006|01:19] C:\DOCUME~1\sam\APPLIC~1\Symantec
[20/08/2007|22:41] C:\DOCUME~1\sam\APPLIC~1\Talkback
[22/07/2006|23:00] C:\DOCUME~1\sam\APPLIC~1\Template
[23/03/2008|21:58] C:\DOCUME~1\sam\APPLIC~1\TuneUp Software
[13/07/2008|18:34] C:\DOCUME~1\sam\APPLIC~1\Wildfire
[24/07/2008|16:05] C:\DOCUME~1\sam\APPLIC~1\wklnhst.dat
[09/05/2007|21:53] C:\DOCUME~1\sam\APPLIC~1\Zylom
[24/08/2005|03:27] C:\DOCUME~1\INVIT\APPLIC~1\desktop.ini
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\EoRezo
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\FaxCtr
[01/12/2007|15:28] C:\DOCUME~1\INVIT\APPLIC~1\F-Secure
[02/09/2007|09:00] C:\DOCUME~1\INVIT\APPLIC~1\Google
[24/08/2005|03:39] C:\DOCUME~1\INVIT\APPLIC~1\Identities
[01/12/2007|15:28] C:\DOCUME~1\INVIT\APPLIC~1\ispnews
[01/12/2007|15:33] C:\DOCUME~1\INVIT\APPLIC~1\Macromedia
[24/08/2005|03:27] C:\DOCUME~1\INVIT\APPLIC~1\Microsoft
[02/09/2007|09:21] C:\DOCUME~1\INVIT\APPLIC~1\Mozilla
[28/02/2008|18:06] C:\DOCUME~1\INVIT\APPLIC~1\PC Suite
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\Player Orange
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[05/08/2008 16:00][--a------] C:\WINDOWS\tasks\Maintenance en 1 clic.job
[15/04/2008 08:49][--a------] C:\WINDOWS\tasks\Norton Security Scan.job
[05/08/2008 15:57][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 05:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[29/03/2007|18:40] C:\Program Files\Abbyy FineReader 6.0 Sprint
[25/08/2005|08:29] C:\Program Files\Acer
[24/08/2005|03:49] C:\Program Files\Acer Inc
[24/08/2005|03:49] C:\Program Files\Adobe
[23/12/2007|20:25] C:\Program Files\Ahead
[01/06/2007|22:14] C:\Program Files\Alwil Software
[27/02/2008|17:38] C:\Program Files\AntivirusFirewall
[07/01/2008|16:55] C:\Program Files\ArcSoft
[26/07/2008|09:30] C:\Program Files\Ares
[19/06/2008|22:27] C:\Program Files\Atheros
[14/04/2007|19:42] C:\Program Files\Avery Dennison
[17/03/2008|15:41] C:\Program Files\AVPersonal
[30/06/2008|22:20] C:\Program Files\Babylon
[25/07/2008|13:50] C:\Program Files\bfgclient
[29/07/2006|16:39] C:\Program Files\BitComet
[09/03/2008|20:50] C:\Program Files\Boonty
[09/03/2008|20:50] C:\Program Files\BoontyGames
[07/07/2008|15:49] C:\Program Files\CA Yahoo! Anti-Spy
[20/03/2008|10:43] C:\Program Files\CCleaner
[29/07/2006|16:41] C:\Program Files\CodeStuff
[19/08/2007|15:30] C:\Program Files\Common Files
[24/08/2005|03:33] C:\Program Files\ComPlus Applications
[24/08/2005|03:46] C:\Program Files\CONEXANT
[25/08/2005|08:27] C:\Program Files\CyberLink
[30/06/2007|23:15] C:\Program Files\denouvel
[10/09/2007|17:14] C:\Program Files\DialMessenger
[02/02/2008|19:09] C:\Program Files\DIFX
[05/01/2008|14:52] C:\Program Files\DivX
[16/03/2008|19:53] C:\Program Files\douniamusic.com
[05/01/2008|20:21] C:\Program Files\DSCN0097.JPG
[17/05/2007|10:48] C:\Program Files\eAcceleration
[20/08/2007|22:24] C:\Program Files\EoRezo
[29/02/2008|15:23] C:\Program Files\EsetOnlineScanner
[18/09/2002|02:28] C:\Program Files\F.msi
[24/08/2005|03:28] C:\Program Files\Fichiers communs
[21/06/2008|21:05] C:\Program Files\Freeze.com
[07/03/2008|14:03] C:\Program Files\Gamenext
[14/08/2007|11:13] C:\Program Files\Google
[21/06/2007|18:02] C:\Program Files\green label
[27/02/2008|17:38] C:\Program Files\Horloge
[20/04/2007|23:02] C:\Program Files\Hotmail Popper
[27/02/2008|17:38] C:\Program Files\Hot-TV
[24/08/2005|03:41] C:\Program Files\InstallShield Installation Information
[24/08/2005|03:42] C:\Program Files\Intel
[24/08/2005|03:33] C:\Program Files\Internet Explorer
[05/03/2008|11:34] C:\Program Files\InternetAnonymizer
[23/11/2007|12:40] C:\Program Files\Inventel
[20/08/2007|22:24] C:\Program Files\ItsLabel
[23/04/2007|16:37] C:\Program Files\Java
[22/07/2006|17:31] C:\Program Files\Launch Manager
[29/03/2007|18:24] C:\Program Files\Lexmark 2300 Series
[29/03/2007|18:39] C:\Program Files\Lexmark Fax Solutions
[12/03/2007|17:28] C:\Program Files\LG PC Suite
[12/04/2007|21:28] C:\Program Files\Logiciel Photo Orange
[29/03/2007|18:26] C:\Program Files\Lx_cats
[14/07/2008|20:21] C:\Program Files\ma-config.com
[16/09/2007|23:38] C:\Program Files\MagicPic4
[05/08/2008|10:34] C:\Program Files\Malwarebytes' Anti-Malware
[24/08/2005|03:32] C:\Program Files\Messenger
[14/04/2007|19:24] C:\Program Files\Micro Application
[24/08/2005|03:35] C:\Program Files\microsoft frontpage
[22/07/2006|22:24] C:\Program Files\Microsoft Office
[23/07/2006|17:47] C:\Program Files\Microsoft Visual Studio
[28/01/2008|16:46] C:\Program Files\Microsoft Windows OneCare Live
[22/07/2006|22:22] C:\Program Files\Microsoft Works
[05/09/2007|16:46] C:\Program Files\Mindscape
[24/08/2005|03:33] C:\Program Files\Movie Maker
[27/02/2008|17:38] C:\Program Files\Mozilla Firefox
[24/08/2005|03:32] C:\Program Files\MSN
[24/08/2005|03:32] C:\Program Files\MSN Gaming Zone
[08/04/2007|14:22] C:\Program Files\MSN Messenger
[29/03/2007|23:21] C:\Program Files\MSXML 4.0
[25/08/2005|08:27] C:\Program Files\MyWorks
[05/08/2008|15:28] C:\Program Files\Navilog1
[24/08/2005|03:33] C:\Program Files\NetMeeting
[24/08/2005|03:51] C:\Program Files\NewTech Infosystems
[02/02/2008|19:04] C:\Program Files\Nokia
[15/12/2007|14:12] C:\Program Files\Norton Security Scan
[24/08/2005|03:32] C:\Program Files\Online Services
[24/03/2008|14:47] C:\Program Files\Ontrack
[23/04/2007|21:15] C:\Program Files\Orange
[24/08/2005|03:33] C:\Program Files\Outlook Express
[02/02/2008|19:05] C:\Program Files\PC Connectivity Solution
[24/07/2008|19:50] C:\Program Files\PC VGA Camer@
[26/07/2006|13:47] C:\Program Files\Phototool
[05/01/2008|14:36] C:\Program Files\Picasa2
[07/06/2007|22:15] C:\Program Files\Power IE
[12/03/2007|17:25] C:\Program Files\QuickTime
[24/08/2005|03:45] C:\Program Files\Realtek
[12/10/2007|13:57] C:\Program Files\Redoubt
[10/07/2007|10:08] C:\Program Files\ReflexiveArcade
[18/05/2007|22:15] C:\Program Files\RegCleaner
[03/12/2007|18:56] C:\Program Files\ScreenMates
[30/11/2007|11:31] C:\Program Files\Securitoo
[24/08/2005|03:34] C:\Program Files\Services en ligne
[15/06/2008|16:13] C:\Program Files\SIW
[23/07/2006|17:56] C:\Program Files\Snapshot Viewer
[17/05/2007|19:28] C:\Program Files\Sony
[19/04/2008|11:03] C:\Program Files\Spybot - Search & Destroy
[14/06/2008|17:35] C:\Program Files\Sun
[01/03/2008|23:14] C:\Program Files\Sunbelt Software
[23/07/2006|01:19] C:\Program Files\Symantec
[24/08/2005|03:47] C:\Program Files\Synaptics
[20/06/2008|15:19] C:\Program Files\temp01
[16/02/2008|21:55] C:\Program Files\Thumbs.db
[29/02/2008|17:14] C:\Program Files\Trend Micro
[07/01/2008|15:58] C:\Program Files\Trust
[08/01/2008|18:02] C:\Program Files\Ulead Systems
[24/08/2005|03:39] C:\Program Files\Uninstall Information
[16/10/2006|00:47] C:\Program Files\USBDisk
[29/03/2007|22:06] C:\Program Files\Wanadoo
[26/07/2006|13:54] C:\Program Files\Winamp
[26/01/2008|17:16] C:\Program Files\Windows Live
[28/01/2008|15:05] C:\Program Files\Windows Live Safety Center
[29/03/2007|20:12] C:\Program Files\Windows Live Toolbar
[19/05/2007|00:27] C:\Program Files\Windows Media Connect 2
[24/08/2005|03:32] C:\Program Files\Windows Media Player
[24/08/2005|03:32] C:\Program Files\Windows NT
[24/08/2005|03:34] C:\Program Files\WindowsUpdate
[22/07/2006|17:29] C:\Program Files\WinPCap
[29/07/2006|16:37] C:\Program Files\WinRAR
[24/08/2005|03:35] C:\Program Files\xerox
[15/06/2008|17:10] C:\Program Files\Yahoo!
[29/04/2007|20:10] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[22/08/2007|10:25] C:\Program Files\Fichiers communs\Adobe
[23/12/2007|20:25] C:\Program Files\Fichiers communs\Ahead
[07/01/2008|16:55] C:\Program Files\Fichiers communs\ArcSoft
[09/03/2008|20:52] C:\Program Files\Fichiers communs\BOONTY Shared
[23/07/2006|17:47] C:\Program Files\Fichiers communs\Designer
[21/06/2007|18:01] C:\Program Files\Fichiers communs\gst
[27/01/2008|14:17] C:\Program Files\Fichiers communs\GTK
[24/08/2005|03:41] C:\Program Files\Fichiers communs\InstallShield
[28/02/2008|15:21] C:\Program Files\Fichiers communs\InternetAnonymizer
[27/02/2008|15:27] C:\Program Files\Fichiers communs\iS3
[22/04/2007|18:56] C:\Program Files\Fichiers communs\Java
[24/03/2008|09:27] C:\Program Files\Fichiers communs\LightScribe
[24/08/2005|03:28] C:\Program Files\Fichiers communs\Microsoft Shared
[24/08/2005|03:33] C:\Program Files\Fichiers communs\MSSoap
[24/08/2005|03:51] C:\Program Files\Fichiers communs\muvee Technologies
[24/08/2005|03:51] C:\Program Files\Fichiers communs\NewTech Infosystems
[02/02/2008|19:09] C:\Program Files\Fichiers communs\Nokia
[24/08/2005|03:28] C:\Program Files\Fichiers communs\ODBC
[24/07/2008|19:50] C:\Program Files\Fichiers communs\PCCamera
[02/02/2008|19:09] C:\Program Files\Fichiers communs\PCSuite
[28/02/2008|15:05] C:\Program Files\Fichiers communs\ReparateurDeSysteme
[07/07/2008|15:49] C:\Program Files\Fichiers communs\Scanner
[24/08/2005|03:33] C:\Program Files\Fichiers communs\Services
[24/08/2005|03:28] C:\Program Files\Fichiers communs\SpeechEngines
[23/07/2006|01:19] C:\Program Files\Fichiers communs\Symantec Shared
[24/08/2005|03:33] C:\Program Files\Fichiers communs\System
[08/01/2008|18:04] C:\Program Files\Fichiers communs\Ulead Systems
[26/01/2008|17:16] C:\Program Files\Fichiers communs\WindowsLiveInstaller
--------------------\\ Process
( 66 Processus )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-05 16:17:22
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uqeqc"="c:\\documents and settings\\sam\\local settings\\application data\\uqeqc.exe uqeqc"
[b]==> EGDACCESS <==/b
[F:26][D:0]-> C:\DOCUME~1\sam\LOCALS~1\Temp
[F:3][D:0]-> C:\DOCUME~1\sam\Cookies
[F:23][D:4]-> C:\DOCUME~1\sam\LOCALS~1\TEMPOR~1\content.IE5
[F:3][D:0]-> C:\Recycled
--------------------\\ Fin du rapport a 16:18:25,59
ET VOILA...
--------------------\\ Lop S&D 4.2.2-5 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : sam ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 05/08/2008 | 16:34:05,70 ] [ PC : ACER-29569F1E48 ]
[ MAJ : 01-08-2008 | 01:40 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
RestaurÚ! - Fichier Hosts
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[24/08/2005|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[24/08/2005|03:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[24/08/2005|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[01/06/2007|07:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\118300.34
[02/03/2008|21:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\addr_file.html
[22/08/2007|10:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[12/03/2007|17:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[12/12/2007|13:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Arovax
[11/07/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Astar Games
[14/04/2007|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avery
[01/03/2008|21:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[25/07/2008|13:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
[09/03/2008|20:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[25/07/2008|13:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Christmasville
[25/08/2005|08:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[24/08/2005|03:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[29/03/2007|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FaxCtr
[26/06/2008|21:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[07/03/2008|14:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[13/07/2008|16:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fugazo
[14/08/2007|11:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[20/08/2007|22:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[12/12/2007|17:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[14/07/2008|15:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HiddenSecretsNightmare
[24/07/2008|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[24/07/2008|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[02/02/2008|19:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[22/07/2006|17:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Intel
[28/02/2008|15:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InternetAnonymizer
[28/06/2008|20:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[18/01/2008|16:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[14/07/2008|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[01/03/2008|21:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[05/08/2008|10:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[24/08/2005|03:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[18/03/2008|12:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MonContenuassistant
[28/06/2008|19:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MonteCristo
[20/08/2007|22:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[23/06/2008|10:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[19/06/2008|19:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MythPeople
[05/07/2008|12:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games
[02/02/2008|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[02/04/2007|23:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\pixelStorm
[11/05/2008|12:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[09/04/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[14/04/2008|20:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Registry Helper
[23/07/2006|17:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBT
[27/02/2008|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SITEguard
[19/04/2008|11:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[27/02/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\STOPzilla!
[23/07/2006|01:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[06/05/2007|01:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[08/01/2008|18:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[09/04/2007|21:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[29/03/2007|20:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[26/01/2008|17:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[18/02/2008|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[24/08/2005|03:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[12/03/2008|11:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[14/02/2008|08:54] C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
[19/04/2007|11:13] C:\DOCUME~1\LOCALS~1\APPLIC~1\Help
[24/08/2005|03:27] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[27/01/2008|14:18] C:\DOCUME~1\sam\APPLIC~1\.purple
[01/07/2008|14:32] C:\DOCUME~1\sam\APPLIC~1\Abra Academy2
[23/07/2006|04:07] C:\DOCUME~1\sam\APPLIC~1\Adobe
[29/07/2006|17:02] C:\DOCUME~1\sam\APPLIC~1\AdobeUM
[21/03/2007|20:31] C:\DOCUME~1\sam\APPLIC~1\Apple Computer
[07/01/2008|16:57] C:\DOCUME~1\sam\APPLIC~1\ArcSoft
[23/06/2008|21:43] C:\DOCUME~1\sam\APPLIC~1\Big Fish Games
[21/06/2008|16:12] C:\DOCUME~1\sam\APPLIC~1\cerasus.media
[04/12/2007|21:24] C:\DOCUME~1\sam\APPLIC~1\cs
[24/07/2006|13:57] C:\DOCUME~1\sam\APPLIC~1\CyberLink
[24/08/2005|03:27] C:\DOCUME~1\sam\APPLIC~1\desktop.ini
[05/01/2008|14:52] C:\DOCUME~1\sam\APPLIC~1\DivX
[20/08/2007|22:24] C:\DOCUME~1\sam\APPLIC~1\EoRezo
[29/03/2007|21:23] C:\DOCUME~1\sam\APPLIC~1\FaxCtr
[26/06/2008|21:15] C:\DOCUME~1\sam\APPLIC~1\Flood Light Games
[07/03/2008|14:03] C:\DOCUME~1\sam\APPLIC~1\FloodLightGames
[25/06/2008|12:37] C:\DOCUME~1\sam\APPLIC~1\Friday's games
[01/12/2007|13:12] C:\DOCUME~1\sam\APPLIC~1\F-Secure
[20/08/2007|22:47] C:\DOCUME~1\sam\APPLIC~1\Google
[12/12/2007|17:54] C:\DOCUME~1\sam\APPLIC~1\Grisoft
[27/01/2008|14:22] C:\DOCUME~1\sam\APPLIC~1\gtk-2.0
[27/07/2006|11:51] C:\DOCUME~1\sam\APPLIC~1\Help
[24/08/2005|03:39] C:\DOCUME~1\sam\APPLIC~1\Identities
[15/09/2006|15:07] C:\DOCUME~1\sam\APPLIC~1\Intel
[28/02/2008|15:21] C:\DOCUME~1\sam\APPLIC~1\InternetAnonymizer
[01/12/2007|13:08] C:\DOCUME~1\sam\APPLIC~1\ispnews
[01/06/2007|21:14] C:\DOCUME~1\sam\APPLIC~1\Lavasoft
[01/04/2007|17:04] C:\DOCUME~1\sam\APPLIC~1\LG Electronics
[28/03/2007|10:07] C:\DOCUME~1\sam\APPLIC~1\Macromedia
[05/08/2008|10:34] C:\DOCUME~1\sam\APPLIC~1\Malwarebytes
[24/08/2005|03:27] C:\DOCUME~1\sam\APPLIC~1\Microsoft
[23/07/2006|17:41] C:\DOCUME~1\sam\APPLIC~1\Microsoft Web Folders
[27/02/2008|17:38] C:\DOCUME~1\sam\APPLIC~1\Mozilla
[31/03/2007|23:01] C:\DOCUME~1\sam\APPLIC~1\MSNInstaller
[01/04/2008|18:00] C:\DOCUME~1\sam\APPLIC~1\NMM-MetaData.db
[02/02/2008|19:09] C:\DOCUME~1\sam\APPLIC~1\Nokia
[02/02/2008|19:19] C:\DOCUME~1\sam\APPLIC~1\Nokia Multimedia Player
[05/07/2008|12:01] C:\DOCUME~1\sam\APPLIC~1\Oberon Games
[02/02/2008|19:05] C:\DOCUME~1\sam\APPLIC~1\PC Suite
[01/12/2007|13:11] C:\DOCUME~1\sam\APPLIC~1\PEX
[22/06/2008|13:39] C:\DOCUME~1\sam\APPLIC~1\Pirateville
[23/04/2007|21:16] C:\DOCUME~1\sam\APPLIC~1\Player Orange
[11/05/2008|12:32] C:\DOCUME~1\sam\APPLIC~1\PlayFirst
[14/04/2007|19:25] C:\DOCUME~1\sam\APPLIC~1\Serif
[17/05/2007|19:38] C:\DOCUME~1\sam\APPLIC~1\Sony Corporation
[31/05/2007|22:09] C:\DOCUME~1\sam\APPLIC~1\SPAMfighter
[27/06/2008|11:19] C:\DOCUME~1\sam\APPLIC~1\SprillBermudeFr
[22/04/2007|18:59] C:\DOCUME~1\sam\APPLIC~1\Sun
[23/07/2006|01:19] C:\DOCUME~1\sam\APPLIC~1\Symantec
[20/08/2007|22:41] C:\DOCUME~1\sam\APPLIC~1\Talkback
[22/07/2006|23:00] C:\DOCUME~1\sam\APPLIC~1\Template
[23/03/2008|21:58] C:\DOCUME~1\sam\APPLIC~1\TuneUp Software
[13/07/2008|18:34] C:\DOCUME~1\sam\APPLIC~1\Wildfire
[24/07/2008|16:05] C:\DOCUME~1\sam\APPLIC~1\wklnhst.dat
[09/05/2007|21:53] C:\DOCUME~1\sam\APPLIC~1\Zylom
[24/08/2005|03:27] C:\DOCUME~1\INVIT\APPLIC~1\desktop.ini
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\EoRezo
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\FaxCtr
[01/12/2007|15:28] C:\DOCUME~1\INVIT\APPLIC~1\F-Secure
[02/09/2007|09:00] C:\DOCUME~1\INVIT\APPLIC~1\Google
[24/08/2005|03:39] C:\DOCUME~1\INVIT\APPLIC~1\Identities
[01/12/2007|15:28] C:\DOCUME~1\INVIT\APPLIC~1\ispnews
[01/12/2007|15:33] C:\DOCUME~1\INVIT\APPLIC~1\Macromedia
[24/08/2005|03:27] C:\DOCUME~1\INVIT\APPLIC~1\Microsoft
[02/09/2007|09:21] C:\DOCUME~1\INVIT\APPLIC~1\Mozilla
[28/02/2008|18:06] C:\DOCUME~1\INVIT\APPLIC~1\PC Suite
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\Player Orange
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[05/08/2008 16:00][--a------] C:\WINDOWS\tasks\Maintenance en 1 clic.job
[15/04/2008 08:49][--a------] C:\WINDOWS\tasks\Norton Security Scan.job
[05/08/2008 15:57][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 05:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[29/03/2007|18:40] C:\Program Files\Abbyy FineReader 6.0 Sprint
[25/08/2005|08:29] C:\Program Files\Acer
[24/08/2005|03:49] C:\Program Files\Acer Inc
[24/08/2005|03:49] C:\Program Files\Adobe
[23/12/2007|20:25] C:\Program Files\Ahead
[01/06/2007|22:14] C:\Program Files\Alwil Software
[27/02/2008|17:38] C:\Program Files\AntivirusFirewall
[07/01/2008|16:55] C:\Program Files\ArcSoft
[26/07/2008|09:30] C:\Program Files\Ares
[19/06/2008|22:27] C:\Program Files\Atheros
[14/04/2007|19:42] C:\Program Files\Avery Dennison
[17/03/2008|15:41] C:\Program Files\AVPersonal
[30/06/2008|22:20] C:\Program Files\Babylon
[25/07/2008|13:50] C:\Program Files\bfgclient
[29/07/2006|16:39] C:\Program Files\BitComet
[09/03/2008|20:50] C:\Program Files\Boonty
[09/03/2008|20:50] C:\Program Files\BoontyGames
[07/07/2008|15:49] C:\Program Files\CA Yahoo! Anti-Spy
[20/03/2008|10:43] C:\Program Files\CCleaner
[29/07/2006|16:41] C:\Program Files\CodeStuff
[19/08/2007|15:30] C:\Program Files\Common Files
[24/08/2005|03:33] C:\Program Files\ComPlus Applications
[24/08/2005|03:46] C:\Program Files\CONEXANT
[25/08/2005|08:27] C:\Program Files\CyberLink
[30/06/2007|23:15] C:\Program Files\denouvel
[10/09/2007|17:14] C:\Program Files\DialMessenger
[02/02/2008|19:09] C:\Program Files\DIFX
[05/01/2008|14:52] C:\Program Files\DivX
[16/03/2008|19:53] C:\Program Files\douniamusic.com
[05/01/2008|20:21] C:\Program Files\DSCN0097.JPG
[17/05/2007|10:48] C:\Program Files\eAcceleration
[20/08/2007|22:24] C:\Program Files\EoRezo
[29/02/2008|15:23] C:\Program Files\EsetOnlineScanner
[18/09/2002|02:28] C:\Program Files\F.msi
[24/08/2005|03:28] C:\Program Files\Fichiers communs
[21/06/2008|21:05] C:\Program Files\Freeze.com
[07/03/2008|14:03] C:\Program Files\Gamenext
[14/08/2007|11:13] C:\Program Files\Google
[21/06/2007|18:02] C:\Program Files\green label
[27/02/2008|17:38] C:\Program Files\Horloge
[20/04/2007|23:02] C:\Program Files\Hotmail Popper
[27/02/2008|17:38] C:\Program Files\Hot-TV
[24/08/2005|03:41] C:\Program Files\InstallShield Installation Information
[24/08/2005|03:42] C:\Program Files\Intel
[24/08/2005|03:33] C:\Program Files\Internet Explorer
[05/03/2008|11:34] C:\Program Files\InternetAnonymizer
[23/11/2007|12:40] C:\Program Files\Inventel
[20/08/2007|22:24] C:\Program Files\ItsLabel
[23/04/2007|16:37] C:\Program Files\Java
[22/07/2006|17:31] C:\Program Files\Launch Manager
[29/03/2007|18:24] C:\Program Files\Lexmark 2300 Series
[29/03/2007|18:39] C:\Program Files\Lexmark Fax Solutions
[12/03/2007|17:28] C:\Program Files\LG PC Suite
[12/04/2007|21:28] C:\Program Files\Logiciel Photo Orange
[29/03/2007|18:26] C:\Program Files\Lx_cats
[14/07/2008|20:21] C:\Program Files\ma-config.com
[16/09/2007|23:38] C:\Program Files\MagicPic4
[05/08/2008|10:34] C:\Program Files\Malwarebytes' Anti-Malware
[24/08/2005|03:32] C:\Program Files\Messenger
[14/04/2007|19:24] C:\Program Files\Micro Application
[24/08/2005|03:35] C:\Program Files\microsoft frontpage
[22/07/2006|22:24] C:\Program Files\Microsoft Office
[23/07/2006|17:47] C:\Program Files\Microsoft Visual Studio
[28/01/2008|16:46] C:\Program Files\Microsoft Windows OneCare Live
[22/07/2006|22:22] C:\Program Files\Microsoft Works
[05/09/2007|16:46] C:\Program Files\Mindscape
[24/08/2005|03:33] C:\Program Files\Movie Maker
[27/02/2008|17:38] C:\Program Files\Mozilla Firefox
[24/08/2005|03:32] C:\Program Files\MSN
[24/08/2005|03:32] C:\Program Files\MSN Gaming Zone
[08/04/2007|14:22] C:\Program Files\MSN Messenger
[29/03/2007|23:21] C:\Program Files\MSXML 4.0
[25/08/2005|08:27] C:\Program Files\MyWorks
[05/08/2008|15:28] C:\Program Files\Navilog1
[24/08/2005|03:33] C:\Program Files\NetMeeting
[24/08/2005|03:51] C:\Program Files\NewTech Infosystems
[02/02/2008|19:04] C:\Program Files\Nokia
[15/12/2007|14:12] C:\Program Files\Norton Security Scan
[24/08/2005|03:32] C:\Program Files\Online Services
[24/03/2008|14:47] C:\Program Files\Ontrack
[23/04/2007|21:15] C:\Program Files\Orange
[24/08/2005|03:33] C:\Program Files\Outlook Express
[02/02/2008|19:05] C:\Program Files\PC Connectivity Solution
[24/07/2008|19:50] C:\Program Files\PC VGA Camer@
[26/07/2006|13:47] C:\Program Files\Phototool
[05/01/2008|14:36] C:\Program Files\Picasa2
[07/06/2007|22:15] C:\Program Files\Power IE
[12/03/2007|17:25] C:\Program Files\QuickTime
[24/08/2005|03:45] C:\Program Files\Realtek
[12/10/2007|13:57] C:\Program Files\Redoubt
[10/07/2007|10:08] C:\Program Files\ReflexiveArcade
[18/05/2007|22:15] C:\Program Files\RegCleaner
[03/12/2007|18:56] C:\Program Files\ScreenMates
[30/11/2007|11:31] C:\Program Files\Securitoo
[24/08/2005|03:34] C:\Program Files\Services en ligne
[15/06/2008|16:13] C:\Program Files\SIW
[23/07/2006|17:56] C:\Program Files\Snapshot Viewer
[17/05/2007|19:28] C:\Program Files\Sony
[19/04/2008|11:03] C:\Program Files\Spybot - Search & Destroy
[14/06/2008|17:35] C:\Program Files\Sun
[01/03/2008|23:14] C:\Program Files\Sunbelt Software
[23/07/2006|01:19] C:\Program Files\Symantec
[24/08/2005|03:47] C:\Program Files\Synaptics
[20/06/2008|15:19] C:\Program Files\temp01
[16/02/2008|21:55] C:\Program Files\Thumbs.db
[29/02/2008|17:14] C:\Program Files\Trend Micro
[07/01/2008|15:58] C:\Program Files\Trust
[08/01/2008|18:02] C:\Program Files\Ulead Systems
[24/08/2005|03:39] C:\Program Files\Uninstall Information
[16/10/2006|00:47] C:\Program Files\USBDisk
[29/03/2007|22:06] C:\Program Files\Wanadoo
[26/07/2006|13:54] C:\Program Files\Winamp
[26/01/2008|17:16] C:\Program Files\Windows Live
[28/01/2008|15:05] C:\Program Files\Windows Live Safety Center
[29/03/2007|20:12] C:\Program Files\Windows Live Toolbar
[19/05/2007|00:27] C:\Program Files\Windows Media Connect 2
[24/08/2005|03:32] C:\Program Files\Windows Media Player
[24/08/2005|03:32] C:\Program Files\Windows NT
[24/08/2005|03:34] C:\Program Files\WindowsUpdate
[22/07/2006|17:29] C:\Program Files\WinPCap
[29/07/2006|16:37] C:\Program Files\WinRAR
[24/08/2005|03:35] C:\Program Files\xerox
[15/06/2008|17:10] C:\Program Files\Yahoo!
[29/04/2007|20:10] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[22/08/2007|10:25] C:\Program Files\Fichiers communs\Adobe
[23/12/2007|20:25] C:\Program Files\Fichiers communs\Ahead
[07/01/2008|16:55] C:\Program Files\Fichiers communs\ArcSoft
[09/03/2008|20:52] C:\Program Files\Fichiers communs\BOONTY Shared
[23/07/2006|17:47] C:\Program Files\Fichiers communs\Designer
[21/06/2007|18:01] C:\Program Files\Fichiers communs\gst
[27/01/2008|14:17] C:\Program Files\Fichiers communs\GTK
[24/08/2005|03:41] C:\Program Files\Fichiers communs\InstallShield
[28/02/2008|15:21] C:\Program Files\Fichiers communs\InternetAnonymizer
[27/02/2008|15:27] C:\Program Files\Fichiers communs\iS3
[22/04/2007|18:56] C:\Program Files\Fichiers communs\Java
[24/03/2008|09:27] C:\Program Files\Fichiers communs\LightScribe
[24/08/2005|03:28] C:\Program Files\Fichiers communs\Microsoft Shared
[24/08/2005|03:33] C:\Program Files\Fichiers communs\MSSoap
[24/08/2005|03:51] C:\Program Files\Fichiers communs\muvee Technologies
[24/08/2005|03:51] C:\Program Files\Fichiers communs\NewTech Infosystems
[02/02/2008|19:09] C:\Program Files\Fichiers communs\Nokia
[24/08/2005|03:28] C:\Program Files\Fichiers communs\ODBC
[24/07/2008|19:50] C:\Program Files\Fichiers communs\PCCamera
[02/02/2008|19:09] C:\Program Files\Fichiers communs\PCSuite
[28/02/2008|15:05] C:\Program Files\Fichiers communs\ReparateurDeSysteme
[07/07/2008|15:49] C:\Program Files\Fichiers communs\Scanner
[24/08/2005|03:33] C:\Program Files\Fichiers communs\Services
[24/08/2005|03:28] C:\Program Files\Fichiers communs\SpeechEngines
[23/07/2006|01:19] C:\Program Files\Fichiers communs\Symantec Shared
[24/08/2005|03:33] C:\Program Files\Fichiers communs\System
[08/01/2008|18:04] C:\Program Files\Fichiers communs\Ulead Systems
[26/01/2008|17:16] C:\Program Files\Fichiers communs\WindowsLiveInstaller
--------------------\\ Process
( 67 Processus )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-05 16:41:07
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uqeqc"="c:\\documents and settings\\sam\\local settings\\application data\\uqeqc.exe uqeqc"
[b]==> EGDACCESS <==/b
[F:26][D:1]-> C:\DOCUME~1\sam\LOCALS~1\Temp
[F:3][D:0]-> C:\DOCUME~1\sam\Cookies
[F:38][D:4]-> C:\DOCUME~1\sam\LOCALS~1\TEMPOR~1\content.IE5
[F:3][D:0]-> C:\Recycled
--------------------\\ Fin du rapport a 16:41:59,90
--------------------\\ Lop S&D 4.2.2-5 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : sam ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 05/08/2008 | 16:34:05,70 ] [ PC : ACER-29569F1E48 ]
[ MAJ : 01-08-2008 | 01:40 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
RestaurÚ! - Fichier Hosts
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[24/08/2005|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[24/08/2005|03:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[24/08/2005|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[01/06/2007|07:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\118300.34
[02/03/2008|21:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\addr_file.html
[22/08/2007|10:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[12/03/2007|17:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[12/12/2007|13:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Arovax
[11/07/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Astar Games
[14/04/2007|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avery
[01/03/2008|21:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[25/07/2008|13:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
[09/03/2008|20:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[25/07/2008|13:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Christmasville
[25/08/2005|08:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[24/08/2005|03:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[29/03/2007|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FaxCtr
[26/06/2008|21:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[07/03/2008|14:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[13/07/2008|16:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Fugazo
[14/08/2007|11:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[20/08/2007|22:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[12/12/2007|17:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[14/07/2008|15:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HiddenSecretsNightmare
[24/07/2008|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[24/07/2008|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[02/02/2008|19:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[22/07/2006|17:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Intel
[28/02/2008|15:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InternetAnonymizer
[28/06/2008|20:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[18/01/2008|16:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[14/07/2008|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[01/03/2008|21:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[05/08/2008|10:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[24/08/2005|03:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[18/03/2008|12:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MonContenuassistant
[28/06/2008|19:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MonteCristo
[20/08/2007|22:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[23/06/2008|10:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[19/06/2008|19:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MythPeople
[05/07/2008|12:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games
[02/02/2008|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[02/04/2007|23:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\pixelStorm
[11/05/2008|12:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[09/04/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[14/04/2008|20:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Registry Helper
[23/07/2006|17:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBT
[27/02/2008|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SITEguard
[19/04/2008|11:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[27/02/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\STOPzilla!
[23/07/2006|01:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[06/05/2007|01:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[08/01/2008|18:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[09/04/2007|21:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[29/03/2007|20:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[26/01/2008|17:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[18/02/2008|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[24/08/2005|03:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[12/03/2008|11:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[14/02/2008|08:54] C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
[19/04/2007|11:13] C:\DOCUME~1\LOCALS~1\APPLIC~1\Help
[24/08/2005|03:27] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[27/01/2008|14:18] C:\DOCUME~1\sam\APPLIC~1\.purple
[01/07/2008|14:32] C:\DOCUME~1\sam\APPLIC~1\Abra Academy2
[23/07/2006|04:07] C:\DOCUME~1\sam\APPLIC~1\Adobe
[29/07/2006|17:02] C:\DOCUME~1\sam\APPLIC~1\AdobeUM
[21/03/2007|20:31] C:\DOCUME~1\sam\APPLIC~1\Apple Computer
[07/01/2008|16:57] C:\DOCUME~1\sam\APPLIC~1\ArcSoft
[23/06/2008|21:43] C:\DOCUME~1\sam\APPLIC~1\Big Fish Games
[21/06/2008|16:12] C:\DOCUME~1\sam\APPLIC~1\cerasus.media
[04/12/2007|21:24] C:\DOCUME~1\sam\APPLIC~1\cs
[24/07/2006|13:57] C:\DOCUME~1\sam\APPLIC~1\CyberLink
[24/08/2005|03:27] C:\DOCUME~1\sam\APPLIC~1\desktop.ini
[05/01/2008|14:52] C:\DOCUME~1\sam\APPLIC~1\DivX
[20/08/2007|22:24] C:\DOCUME~1\sam\APPLIC~1\EoRezo
[29/03/2007|21:23] C:\DOCUME~1\sam\APPLIC~1\FaxCtr
[26/06/2008|21:15] C:\DOCUME~1\sam\APPLIC~1\Flood Light Games
[07/03/2008|14:03] C:\DOCUME~1\sam\APPLIC~1\FloodLightGames
[25/06/2008|12:37] C:\DOCUME~1\sam\APPLIC~1\Friday's games
[01/12/2007|13:12] C:\DOCUME~1\sam\APPLIC~1\F-Secure
[20/08/2007|22:47] C:\DOCUME~1\sam\APPLIC~1\Google
[12/12/2007|17:54] C:\DOCUME~1\sam\APPLIC~1\Grisoft
[27/01/2008|14:22] C:\DOCUME~1\sam\APPLIC~1\gtk-2.0
[27/07/2006|11:51] C:\DOCUME~1\sam\APPLIC~1\Help
[24/08/2005|03:39] C:\DOCUME~1\sam\APPLIC~1\Identities
[15/09/2006|15:07] C:\DOCUME~1\sam\APPLIC~1\Intel
[28/02/2008|15:21] C:\DOCUME~1\sam\APPLIC~1\InternetAnonymizer
[01/12/2007|13:08] C:\DOCUME~1\sam\APPLIC~1\ispnews
[01/06/2007|21:14] C:\DOCUME~1\sam\APPLIC~1\Lavasoft
[01/04/2007|17:04] C:\DOCUME~1\sam\APPLIC~1\LG Electronics
[28/03/2007|10:07] C:\DOCUME~1\sam\APPLIC~1\Macromedia
[05/08/2008|10:34] C:\DOCUME~1\sam\APPLIC~1\Malwarebytes
[24/08/2005|03:27] C:\DOCUME~1\sam\APPLIC~1\Microsoft
[23/07/2006|17:41] C:\DOCUME~1\sam\APPLIC~1\Microsoft Web Folders
[27/02/2008|17:38] C:\DOCUME~1\sam\APPLIC~1\Mozilla
[31/03/2007|23:01] C:\DOCUME~1\sam\APPLIC~1\MSNInstaller
[01/04/2008|18:00] C:\DOCUME~1\sam\APPLIC~1\NMM-MetaData.db
[02/02/2008|19:09] C:\DOCUME~1\sam\APPLIC~1\Nokia
[02/02/2008|19:19] C:\DOCUME~1\sam\APPLIC~1\Nokia Multimedia Player
[05/07/2008|12:01] C:\DOCUME~1\sam\APPLIC~1\Oberon Games
[02/02/2008|19:05] C:\DOCUME~1\sam\APPLIC~1\PC Suite
[01/12/2007|13:11] C:\DOCUME~1\sam\APPLIC~1\PEX
[22/06/2008|13:39] C:\DOCUME~1\sam\APPLIC~1\Pirateville
[23/04/2007|21:16] C:\DOCUME~1\sam\APPLIC~1\Player Orange
[11/05/2008|12:32] C:\DOCUME~1\sam\APPLIC~1\PlayFirst
[14/04/2007|19:25] C:\DOCUME~1\sam\APPLIC~1\Serif
[17/05/2007|19:38] C:\DOCUME~1\sam\APPLIC~1\Sony Corporation
[31/05/2007|22:09] C:\DOCUME~1\sam\APPLIC~1\SPAMfighter
[27/06/2008|11:19] C:\DOCUME~1\sam\APPLIC~1\SprillBermudeFr
[22/04/2007|18:59] C:\DOCUME~1\sam\APPLIC~1\Sun
[23/07/2006|01:19] C:\DOCUME~1\sam\APPLIC~1\Symantec
[20/08/2007|22:41] C:\DOCUME~1\sam\APPLIC~1\Talkback
[22/07/2006|23:00] C:\DOCUME~1\sam\APPLIC~1\Template
[23/03/2008|21:58] C:\DOCUME~1\sam\APPLIC~1\TuneUp Software
[13/07/2008|18:34] C:\DOCUME~1\sam\APPLIC~1\Wildfire
[24/07/2008|16:05] C:\DOCUME~1\sam\APPLIC~1\wklnhst.dat
[09/05/2007|21:53] C:\DOCUME~1\sam\APPLIC~1\Zylom
[24/08/2005|03:27] C:\DOCUME~1\INVIT\APPLIC~1\desktop.ini
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\EoRezo
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\FaxCtr
[01/12/2007|15:28] C:\DOCUME~1\INVIT\APPLIC~1\F-Secure
[02/09/2007|09:00] C:\DOCUME~1\INVIT\APPLIC~1\Google
[24/08/2005|03:39] C:\DOCUME~1\INVIT\APPLIC~1\Identities
[01/12/2007|15:28] C:\DOCUME~1\INVIT\APPLIC~1\ispnews
[01/12/2007|15:33] C:\DOCUME~1\INVIT\APPLIC~1\Macromedia
[24/08/2005|03:27] C:\DOCUME~1\INVIT\APPLIC~1\Microsoft
[02/09/2007|09:21] C:\DOCUME~1\INVIT\APPLIC~1\Mozilla
[28/02/2008|18:06] C:\DOCUME~1\INVIT\APPLIC~1\PC Suite
[02/09/2007|08:43] C:\DOCUME~1\INVIT\APPLIC~1\Player Orange
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[05/08/2008 16:00][--a------] C:\WINDOWS\tasks\Maintenance en 1 clic.job
[15/04/2008 08:49][--a------] C:\WINDOWS\tasks\Norton Security Scan.job
[05/08/2008 15:57][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 05:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[29/03/2007|18:40] C:\Program Files\Abbyy FineReader 6.0 Sprint
[25/08/2005|08:29] C:\Program Files\Acer
[24/08/2005|03:49] C:\Program Files\Acer Inc
[24/08/2005|03:49] C:\Program Files\Adobe
[23/12/2007|20:25] C:\Program Files\Ahead
[01/06/2007|22:14] C:\Program Files\Alwil Software
[27/02/2008|17:38] C:\Program Files\AntivirusFirewall
[07/01/2008|16:55] C:\Program Files\ArcSoft
[26/07/2008|09:30] C:\Program Files\Ares
[19/06/2008|22:27] C:\Program Files\Atheros
[14/04/2007|19:42] C:\Program Files\Avery Dennison
[17/03/2008|15:41] C:\Program Files\AVPersonal
[30/06/2008|22:20] C:\Program Files\Babylon
[25/07/2008|13:50] C:\Program Files\bfgclient
[29/07/2006|16:39] C:\Program Files\BitComet
[09/03/2008|20:50] C:\Program Files\Boonty
[09/03/2008|20:50] C:\Program Files\BoontyGames
[07/07/2008|15:49] C:\Program Files\CA Yahoo! Anti-Spy
[20/03/2008|10:43] C:\Program Files\CCleaner
[29/07/2006|16:41] C:\Program Files\CodeStuff
[19/08/2007|15:30] C:\Program Files\Common Files
[24/08/2005|03:33] C:\Program Files\ComPlus Applications
[24/08/2005|03:46] C:\Program Files\CONEXANT
[25/08/2005|08:27] C:\Program Files\CyberLink
[30/06/2007|23:15] C:\Program Files\denouvel
[10/09/2007|17:14] C:\Program Files\DialMessenger
[02/02/2008|19:09] C:\Program Files\DIFX
[05/01/2008|14:52] C:\Program Files\DivX
[16/03/2008|19:53] C:\Program Files\douniamusic.com
[05/01/2008|20:21] C:\Program Files\DSCN0097.JPG
[17/05/2007|10:48] C:\Program Files\eAcceleration
[20/08/2007|22:24] C:\Program Files\EoRezo
[29/02/2008|15:23] C:\Program Files\EsetOnlineScanner
[18/09/2002|02:28] C:\Program Files\F.msi
[24/08/2005|03:28] C:\Program Files\Fichiers communs
[21/06/2008|21:05] C:\Program Files\Freeze.com
[07/03/2008|14:03] C:\Program Files\Gamenext
[14/08/2007|11:13] C:\Program Files\Google
[21/06/2007|18:02] C:\Program Files\green label
[27/02/2008|17:38] C:\Program Files\Horloge
[20/04/2007|23:02] C:\Program Files\Hotmail Popper
[27/02/2008|17:38] C:\Program Files\Hot-TV
[24/08/2005|03:41] C:\Program Files\InstallShield Installation Information
[24/08/2005|03:42] C:\Program Files\Intel
[24/08/2005|03:33] C:\Program Files\Internet Explorer
[05/03/2008|11:34] C:\Program Files\InternetAnonymizer
[23/11/2007|12:40] C:\Program Files\Inventel
[20/08/2007|22:24] C:\Program Files\ItsLabel
[23/04/2007|16:37] C:\Program Files\Java
[22/07/2006|17:31] C:\Program Files\Launch Manager
[29/03/2007|18:24] C:\Program Files\Lexmark 2300 Series
[29/03/2007|18:39] C:\Program Files\Lexmark Fax Solutions
[12/03/2007|17:28] C:\Program Files\LG PC Suite
[12/04/2007|21:28] C:\Program Files\Logiciel Photo Orange
[29/03/2007|18:26] C:\Program Files\Lx_cats
[14/07/2008|20:21] C:\Program Files\ma-config.com
[16/09/2007|23:38] C:\Program Files\MagicPic4
[05/08/2008|10:34] C:\Program Files\Malwarebytes' Anti-Malware
[24/08/2005|03:32] C:\Program Files\Messenger
[14/04/2007|19:24] C:\Program Files\Micro Application
[24/08/2005|03:35] C:\Program Files\microsoft frontpage
[22/07/2006|22:24] C:\Program Files\Microsoft Office
[23/07/2006|17:47] C:\Program Files\Microsoft Visual Studio
[28/01/2008|16:46] C:\Program Files\Microsoft Windows OneCare Live
[22/07/2006|22:22] C:\Program Files\Microsoft Works
[05/09/2007|16:46] C:\Program Files\Mindscape
[24/08/2005|03:33] C:\Program Files\Movie Maker
[27/02/2008|17:38] C:\Program Files\Mozilla Firefox
[24/08/2005|03:32] C:\Program Files\MSN
[24/08/2005|03:32] C:\Program Files\MSN Gaming Zone
[08/04/2007|14:22] C:\Program Files\MSN Messenger
[29/03/2007|23:21] C:\Program Files\MSXML 4.0
[25/08/2005|08:27] C:\Program Files\MyWorks
[05/08/2008|15:28] C:\Program Files\Navilog1
[24/08/2005|03:33] C:\Program Files\NetMeeting
[24/08/2005|03:51] C:\Program Files\NewTech Infosystems
[02/02/2008|19:04] C:\Program Files\Nokia
[15/12/2007|14:12] C:\Program Files\Norton Security Scan
[24/08/2005|03:32] C:\Program Files\Online Services
[24/03/2008|14:47] C:\Program Files\Ontrack
[23/04/2007|21:15] C:\Program Files\Orange
[24/08/2005|03:33] C:\Program Files\Outlook Express
[02/02/2008|19:05] C:\Program Files\PC Connectivity Solution
[24/07/2008|19:50] C:\Program Files\PC VGA Camer@
[26/07/2006|13:47] C:\Program Files\Phototool
[05/01/2008|14:36] C:\Program Files\Picasa2
[07/06/2007|22:15] C:\Program Files\Power IE
[12/03/2007|17:25] C:\Program Files\QuickTime
[24/08/2005|03:45] C:\Program Files\Realtek
[12/10/2007|13:57] C:\Program Files\Redoubt
[10/07/2007|10:08] C:\Program Files\ReflexiveArcade
[18/05/2007|22:15] C:\Program Files\RegCleaner
[03/12/2007|18:56] C:\Program Files\ScreenMates
[30/11/2007|11:31] C:\Program Files\Securitoo
[24/08/2005|03:34] C:\Program Files\Services en ligne
[15/06/2008|16:13] C:\Program Files\SIW
[23/07/2006|17:56] C:\Program Files\Snapshot Viewer
[17/05/2007|19:28] C:\Program Files\Sony
[19/04/2008|11:03] C:\Program Files\Spybot - Search & Destroy
[14/06/2008|17:35] C:\Program Files\Sun
[01/03/2008|23:14] C:\Program Files\Sunbelt Software
[23/07/2006|01:19] C:\Program Files\Symantec
[24/08/2005|03:47] C:\Program Files\Synaptics
[20/06/2008|15:19] C:\Program Files\temp01
[16/02/2008|21:55] C:\Program Files\Thumbs.db
[29/02/2008|17:14] C:\Program Files\Trend Micro
[07/01/2008|15:58] C:\Program Files\Trust
[08/01/2008|18:02] C:\Program Files\Ulead Systems
[24/08/2005|03:39] C:\Program Files\Uninstall Information
[16/10/2006|00:47] C:\Program Files\USBDisk
[29/03/2007|22:06] C:\Program Files\Wanadoo
[26/07/2006|13:54] C:\Program Files\Winamp
[26/01/2008|17:16] C:\Program Files\Windows Live
[28/01/2008|15:05] C:\Program Files\Windows Live Safety Center
[29/03/2007|20:12] C:\Program Files\Windows Live Toolbar
[19/05/2007|00:27] C:\Program Files\Windows Media Connect 2
[24/08/2005|03:32] C:\Program Files\Windows Media Player
[24/08/2005|03:32] C:\Program Files\Windows NT
[24/08/2005|03:34] C:\Program Files\WindowsUpdate
[22/07/2006|17:29] C:\Program Files\WinPCap
[29/07/2006|16:37] C:\Program Files\WinRAR
[24/08/2005|03:35] C:\Program Files\xerox
[15/06/2008|17:10] C:\Program Files\Yahoo!
[29/04/2007|20:10] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[22/08/2007|10:25] C:\Program Files\Fichiers communs\Adobe
[23/12/2007|20:25] C:\Program Files\Fichiers communs\Ahead
[07/01/2008|16:55] C:\Program Files\Fichiers communs\ArcSoft
[09/03/2008|20:52] C:\Program Files\Fichiers communs\BOONTY Shared
[23/07/2006|17:47] C:\Program Files\Fichiers communs\Designer
[21/06/2007|18:01] C:\Program Files\Fichiers communs\gst
[27/01/2008|14:17] C:\Program Files\Fichiers communs\GTK
[24/08/2005|03:41] C:\Program Files\Fichiers communs\InstallShield
[28/02/2008|15:21] C:\Program Files\Fichiers communs\InternetAnonymizer
[27/02/2008|15:27] C:\Program Files\Fichiers communs\iS3
[22/04/2007|18:56] C:\Program Files\Fichiers communs\Java
[24/03/2008|09:27] C:\Program Files\Fichiers communs\LightScribe
[24/08/2005|03:28] C:\Program Files\Fichiers communs\Microsoft Shared
[24/08/2005|03:33] C:\Program Files\Fichiers communs\MSSoap
[24/08/2005|03:51] C:\Program Files\Fichiers communs\muvee Technologies
[24/08/2005|03:51] C:\Program Files\Fichiers communs\NewTech Infosystems
[02/02/2008|19:09] C:\Program Files\Fichiers communs\Nokia
[24/08/2005|03:28] C:\Program Files\Fichiers communs\ODBC
[24/07/2008|19:50] C:\Program Files\Fichiers communs\PCCamera
[02/02/2008|19:09] C:\Program Files\Fichiers communs\PCSuite
[28/02/2008|15:05] C:\Program Files\Fichiers communs\ReparateurDeSysteme
[07/07/2008|15:49] C:\Program Files\Fichiers communs\Scanner
[24/08/2005|03:33] C:\Program Files\Fichiers communs\Services
[24/08/2005|03:28] C:\Program Files\Fichiers communs\SpeechEngines
[23/07/2006|01:19] C:\Program Files\Fichiers communs\Symantec Shared
[24/08/2005|03:33] C:\Program Files\Fichiers communs\System
[08/01/2008|18:04] C:\Program Files\Fichiers communs\Ulead Systems
[26/01/2008|17:16] C:\Program Files\Fichiers communs\WindowsLiveInstaller
--------------------\\ Process
( 67 Processus )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-05 16:41:07
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uqeqc"="c:\\documents and settings\\sam\\local settings\\application data\\uqeqc.exe uqeqc"
[b]==> EGDACCESS <==/b
[F:26][D:1]-> C:\DOCUME~1\sam\LOCALS~1\Temp
[F:3][D:0]-> C:\DOCUME~1\sam\Cookies
[F:38][D:4]-> C:\DOCUME~1\sam\LOCALS~1\TEMPOR~1\content.IE5
[F:3][D:0]-> C:\Recycled
--------------------\\ Fin du rapport a 16:41:59,90
il résiste
1) Télécharge et installe Malwarebyte's Anti-Malware:
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée. >>> clique sur OK
Lance Malwarebyte's Anti-Malware en double-cliquant sur l'icône sur ton Bureau.
Au premier lancement, une fenêtre t'annonce que la version est Free >>> clique sur OK
Laisse les Mises à jour se télécharger
*** Referme le programme ***
2) Redémarre en "Mode sans échec"
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : https://www.malekal.com/demarrer-windows-mode-sans-echec/
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
3) Scan avec Malwarebyte's Anti-Malware
Lance Malwarebyte's Anti-Malware
Onglet "Recherche" >>> coche Executer un exame complet >>> Rechercher sélectionne tes disques durs puis clique sur Lancer l’examen
A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
Suppression des éléments détectés >>>>
supprime ce qu'il a trouvé vide également les éléments de la quarantaine
S'il t'es demandé de redémarrer >>> clique sur "Yes"
--> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.
quand tu demande une analyse, demande en mode sans échec.
Pourquoi en mode sans échec:
*Car déjà l'analyse cherche plus de fichiers en mode sans échec que en mode normal.
*Et aussi en mode normal les virus ( trojans, cheval de troie, vers, spywares , malwares et autres ... sont actif) donc ne se supprimes pas donc ils faut le faire en mode sans échec .1) Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
1) Télécharge et installe Malwarebyte's Anti-Malware:
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée. >>> clique sur OK
Lance Malwarebyte's Anti-Malware en double-cliquant sur l'icône sur ton Bureau.
Au premier lancement, une fenêtre t'annonce que la version est Free >>> clique sur OK
Laisse les Mises à jour se télécharger
*** Referme le programme ***
2) Redémarre en "Mode sans échec"
Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
Sélectionner "Mode sans échec" et appuie sur [Entrée]
Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
Regarde ici si besoin : https://www.malekal.com/demarrer-windows-mode-sans-echec/
Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.
3) Scan avec Malwarebyte's Anti-Malware
Lance Malwarebyte's Anti-Malware
Onglet "Recherche" >>> coche Executer un exame complet >>> Rechercher sélectionne tes disques durs puis clique sur Lancer l’examen
A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
Suppression des éléments détectés >>>>
supprime ce qu'il a trouvé vide également les éléments de la quarantaine
S'il t'es demandé de redémarrer >>> clique sur "Yes"
--> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.
quand tu demande une analyse, demande en mode sans échec.
Pourquoi en mode sans échec:
*Car déjà l'analyse cherche plus de fichiers en mode sans échec que en mode normal.
*Et aussi en mode normal les virus ( trojans, cheval de troie, vers, spywares , malwares et autres ... sont actif) donc ne se supprimes pas donc ils faut le faire en mode sans échec .1) Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1026
Windows 5.1.2600 Service Pack 2
18:32:31 05/08/2008
mbam-log-8-5-2008 (18-31-45).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 91624
Temps écoulé: 1 hour(s), 27 minute(s), 49 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 2
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
et voilà...c'est trop long à faire....
J'espére qu'on va réussir...
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\System Volume Information\_restore{39138AFC-2562-464E-ABA0-3F3BA0BC3ED9}\RP157\A0029578.exe (Rogue.Installer) -> No action taken.
C:\System Volume Information\_restore{39138AFC-2562-464E-ABA0-3F3BA0BC3ED9}\RP157\A0029579.dll (Adware.MyWebSearch) -> No action taken.
Version de la base de données: 1026
Windows 5.1.2600 Service Pack 2
18:32:31 05/08/2008
mbam-log-8-5-2008 (18-31-45).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 91624
Temps écoulé: 1 hour(s), 27 minute(s), 49 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 2
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
et voilà...c'est trop long à faire....
J'espére qu'on va réussir...
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\System Volume Information\_restore{39138AFC-2562-464E-ABA0-3F3BA0BC3ED9}\RP157\A0029578.exe (Rogue.Installer) -> No action taken.
C:\System Volume Information\_restore{39138AFC-2562-464E-ABA0-3F3BA0BC3ED9}\RP157\A0029579.dll (Adware.MyWebSearch) -> No action taken.
bonjour
desoler je n'ai pas pu me connecter hier soir
la saloperie est ensore la
Ouvre ce lien :
http://sosvirus.changelog.fr/Green_day/Lopxpsetup.exe
pour télécharger lopxp de moe.
Enregistre le fichier Lopxpsetup.exe sur ton bureau.
Double clic sur son icône pour lancer l'installation
Sur ton bureau, une nouvelle icône est apparue : lopxp (avec une petite roue dentée).
Double clique sur lopxp.
Au menu, choisir l'option 1
Patiente jusqu'à que l'on demande d'appuyer sur une touche. Appuye !
Le bloc-notes s'ouvre. Copie/colle le contenu dans ta réponse.
desoler je n'ai pas pu me connecter hier soir
la saloperie est ensore la
Ouvre ce lien :
http://sosvirus.changelog.fr/Green_day/Lopxpsetup.exe
pour télécharger lopxp de moe.
Enregistre le fichier Lopxpsetup.exe sur ton bureau.
Double clic sur son icône pour lancer l'installation
Sur ton bureau, une nouvelle icône est apparue : lopxp (avec une petite roue dentée).
Double clique sur lopxp.
Au menu, choisir l'option 1
Patiente jusqu'à que l'on demande d'appuyer sur une touche. Appuye !
Le bloc-notes s'ouvre. Copie/colle le contenu dans ta réponse.
Scan saved at 09:42:29, on 05/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\WANADOO\TaskBarIcon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Atheros\ACU.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\orange\player orange\Orange Player.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\WANADOO\GestionnaireInternet.exe
C:\PROGRA~1\WANADOO\ComComp.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\PROGRA~1\WANADOO\Toaster.exe
C:\PROGRA~1\WANADOO\Inactivity.exe
C:\PROGRA~1\WANADOO\PollingModule.exe
C:\Acer\eManager\anbmServ.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Hotmail Popper\hotpop.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\FreezeScreenSaver.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\PROGRA~1\WANADOO\Watch.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66028
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.magentic.com/english/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66028
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {fa4acd63-fdbf-4ee2-85e1-cad95e77cdf0} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PAC7311_Monitor] C:\WINDOWS\PixArt\PAC7311\Monitor.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\WANADOO\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\WANADOO\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [OrangePlayer] c:\program files\orange\player orange\Orange Player.exe /systray
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [OrangePlayer] c:\program files\orange\player orange\Orange Player.exe /systray (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: Hotmail Popper.lnk = C:\Program Files\Hotmail Popper\hotpop.exe
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {2D37B9E8-C14C-482C-B1CF-939C5440E179} (VTToolkit Control) - http://videomessages.orange.fr/VTToolkit.ocx
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/ImageUploader5.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game13.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - https://www.photobox.fr/?channel=1005
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe