Navipromo
Résolu
hitchy
Messages postés
24
Statut
Membre
-
Destrio5 Messages postés 99820 Date d'inscription Statut Modérateur Dernière intervention -
Destrio5 Messages postés 99820 Date d'inscription Statut Modérateur Dernière intervention -
Bonjour,
je suis les conseils et je vous poste mon analyse faites par navilog mon probleme est des fenetres de pub intempestives
qui s'ouvrent sous firefox et des pages qui m'affolent en me signalant que mon disque dur va etre efface,que j'ai des virus ... avast et spybot ne signale rien.je suis sous xp pro. bon je m'en remets aux experts. s'il vous plait pouvez vous m'aider? je vous remercie.Search Navipromo version 3.6.5 commencé le 09/09/2008 à 20:40:32,90
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "Administrateur"
Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : NTFS
Recherche executé en mode normal
*** Recherche Programmes installés ***
Favorit
*** Recherche dossiers dans "C:\WINDOWS" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***
*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Administrateur\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Administrateur\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Administrateur\menudm~1\progra~1" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\WINDOWS\system32" *
* Recherche dans "C:\Documents and Settings\Administrateur\locals~1\applic~1" *
Fichiers trouvés :
aoyswyk.exe trouvé !
aoyswyk.dat trouvé !
aoyswyk_nav.dat trouvé !
aoyswyk_navps.dat trouvé !
*** Recherche fichiers ***
C:\WINDOWS\pack.epk trouvé !
*** Recherche clés spécifiques dans le Registre ***
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\WINDOWS\system32" :
* Dans "C:\Documents and Settings\Administrateur\locals~1\applic~1" :
aoyswyk.dat trouvé !
aoyswyk.exe trouvé !
aoyswyk_nav.dat trouvé !
aoyswyk_navps.dat trouvé !
3)Recherche Certificats :
Certificat Egroup trouvé !
Certificat Electronic-Group trouvé !
Certificat Montorgueil absent !
Certificat OOO-Favorit trouvé !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche fichiers connus :
*** Analyse terminée le 09/09/2008 à 20:46:36,56 ***
je suis les conseils et je vous poste mon analyse faites par navilog mon probleme est des fenetres de pub intempestives
qui s'ouvrent sous firefox et des pages qui m'affolent en me signalant que mon disque dur va etre efface,que j'ai des virus ... avast et spybot ne signale rien.je suis sous xp pro. bon je m'en remets aux experts. s'il vous plait pouvez vous m'aider? je vous remercie.Search Navipromo version 3.6.5 commencé le 09/09/2008 à 20:40:32,90
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "Administrateur"
Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : NTFS
Recherche executé en mode normal
*** Recherche Programmes installés ***
Favorit
*** Recherche dossiers dans "C:\WINDOWS" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***
*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Administrateur\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Administrateur\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Administrateur\menudm~1\progra~1" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\WINDOWS\system32" *
* Recherche dans "C:\Documents and Settings\Administrateur\locals~1\applic~1" *
Fichiers trouvés :
aoyswyk.exe trouvé !
aoyswyk.dat trouvé !
aoyswyk_nav.dat trouvé !
aoyswyk_navps.dat trouvé !
*** Recherche fichiers ***
C:\WINDOWS\pack.epk trouvé !
*** Recherche clés spécifiques dans le Registre ***
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\WINDOWS\system32" :
* Dans "C:\Documents and Settings\Administrateur\locals~1\applic~1" :
aoyswyk.dat trouvé !
aoyswyk.exe trouvé !
aoyswyk_nav.dat trouvé !
aoyswyk_navps.dat trouvé !
3)Recherche Certificats :
Certificat Egroup trouvé !
Certificat Electronic-Group trouvé !
Certificat Montorgueil absent !
Certificat OOO-Favorit trouvé !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche fichiers connus :
*** Analyse terminée le 09/09/2008 à 20:46:36,56 ***
17 réponses
Tu clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
Au menu principal, choisis 2 et valide.
(ne fais pas le choix ,3 ou 4 sans notre avis/accord)
Le fix va t'informer qu'il va alors redémarrer ton PC
Fermes toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
Appuies sur une touche comme demandé.
(si ton Pc ne redémarre pas automatiquement, fais le toi même)
Au redémarrage de ton PC, choisis ta session habituelle.
Patiente jusqu'au message :
*** Nettoyage Termine le ..... ***
Le bloc-notes va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver
Referme le bloc-notes. Ton bureau va réapparaitre
PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
Tape explorer et valide. Celà te fera apparaitre ton bureau.
Poste le rapport
Au menu principal, choisis 2 et valide.
(ne fais pas le choix ,3 ou 4 sans notre avis/accord)
Le fix va t'informer qu'il va alors redémarrer ton PC
Fermes toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
Appuies sur une touche comme demandé.
(si ton Pc ne redémarre pas automatiquement, fais le toi même)
Au redémarrage de ton PC, choisis ta session habituelle.
Patiente jusqu'au message :
*** Nettoyage Termine le ..... ***
Le bloc-notes va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver
Referme le bloc-notes. Ton bureau va réapparaitre
PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
Tape explorer et valide. Celà te fera apparaitre ton bureau.
Poste le rapport
hitchy
merci pour ta reponse on m'avais conseillé de ne pas faire la deuxieme etape sans avis . bon je te fais cofiance je tente tout de suite a +
Salut,
- Télécharge HijackThis V 2.02 (HijackThis Installer) :
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
- Fais un double-clic sur HJTInstall.exe afin de lancer l'installation
- Clique sur Install ensuite sur I Accept
- Clique sur Do a scan system and save log file
- Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
- Télécharge HijackThis V 2.02 (HijackThis Installer) :
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
- Fais un double-clic sur HJTInstall.exe afin de lancer l'installation
- Clique sur Install ensuite sur I Accept
- Clique sur Do a scan system and save log file
- Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
Ça en est où ?
rebonjour je te poste mon rapport hijackthisLogfile of Trend Micro HijackThis v2.0.2 merci a toi d'y jeter un oeil.
Scan saved at 12:34:14, on 17/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
R3 - URLSearchHook: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SoundMan] "C:\WINDOWS\SOUNDMAN.EXE"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Pixs\JRE\bin\jusched.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [LWBMOUSE] "C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe"
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "C:\WINDOWS\system32\rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [CursorXP] "C:\Program Files\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Erreur.lnk = ?
O4 - Startup: ExtConfig.lnk = C:\Mageos.com\Config\ExtConf.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.libertysurf.fr
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15034/CTPID.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - http://bl102w.blu102.mail.live.com/mail/SafeRedirect.aspx?hm__tg=http://65.55.183.87/att/GetAttachment.aspx&hm__qs=file%3da8470c13-d10d-47f9-97bd-334ef9828160.jpg%26ct%3daW1hZ2UvanBlZw_3d_3d%26name%3daW1hZ2UwMDEuanBn%26inline%3d1%26rfc%3d0%26empty%3dFalse%26imgsrc%3dcid%253aimage001.jpg%254001C82328.EB998530&oneredir=1&ip=10.6.0.135&d=d1999&mf=0
Scan saved at 12:34:14, on 17/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
R3 - URLSearchHook: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SoundMan] "C:\WINDOWS\SOUNDMAN.EXE"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Pixs\JRE\bin\jusched.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [LWBMOUSE] "C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe"
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "C:\WINDOWS\system32\rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [CursorXP] "C:\Program Files\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Erreur.lnk = ?
O4 - Startup: ExtConfig.lnk = C:\Mageos.com\Config\ExtConf.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.libertysurf.fr
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15034/CTPID.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - http://bl102w.blu102.mail.live.com/mail/SafeRedirect.aspx?hm__tg=http://65.55.183.87/att/GetAttachment.aspx&hm__qs=file%3da8470c13-d10d-47f9-97bd-334ef9828160.jpg%26ct%3daW1hZ2UvanBlZw_3d_3d%26name%3daW1hZ2UwMDEuanBn%26inline%3d1%26rfc%3d0%26empty%3dFalse%26imgsrc%3dcid%253aimage001.jpg%254001C82328.EB998530&oneredir=1&ip=10.6.0.135&d=d1999&mf=0
bonjour
le probleme semble resolu depuis l'etape 2 de navilog . par contre le pc me semble un peu ralenti . mais peut-être est ce du a mon disque dur pratiquement plein.desolee pour la reponse tardive j'etais en vacances.
le probleme semble resolu depuis l'etape 2 de navilog . par contre le pc me semble un peu ralenti . mais peut-être est ce du a mon disque dur pratiquement plein.desolee pour la reponse tardive j'etais en vacances.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
---> Télécharge AD-Remover (de Cyrildu17 / C_XX) sur ton bureau :
http://sd-1.archive-host.com/membres/up/197122637410686155/AD-R.exe
! Déconnecte-toi du net et ferme toutes les applications en cours !
* Double-clique sur le programme d'installation et installe-le dans son emplacement par défaut (le bureau).
* Ouvre le dossier AD-Remover présent sur ton bureau et double-clique sur AD-Remover.bat.
* Au menu principal, choisis l'option "A"
--> Poste le rapport qui apparaît à la fin.
(Le rapport est sauvegardé aussi sous C:\Ad-report.log)
(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller )
http://sd-1.archive-host.com/membres/up/197122637410686155/AD-R.exe
! Déconnecte-toi du net et ferme toutes les applications en cours !
* Double-clique sur le programme d'installation et installe-le dans son emplacement par défaut (le bureau).
* Ouvre le dossier AD-Remover présent sur ton bureau et double-clique sur AD-Remover.bat.
* Au menu principal, choisis l'option "A"
--> Poste le rapport qui apparaît à la fin.
(Le rapport est sauvegardé aussi sous C:\Ad-report.log)
(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller )
voici le rapport merci
F --------- Logfile of AD-Remover 1.0.1.7 by C_XX ---------
START at: 10:11:53 | 18/09/2008
ON: Windows_NT (Windows XP)
OPTION: Scan
EXECUTED FROM: C:\Documents and Settings\Administrateur\Bureau\Ad-remover\AD-Remover.bat
USER: Administrateur | PC: A-IOHHQ7DO9WMW8
BOOT MODE: Normal
DRIVE(S): C:\
--------- [ PROCESSES ] ---------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\update\update.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\WScript.exe
---------------------------- [ 43 ]
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> CHECKING SERVICES
Found ! - "Boonty Games"
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> REGISTRY
Found ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Macrogaming"
Found ! - "HKEY_LOCAL_MACHINE\Software\Boonty"
Found ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0"
Found ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E"
Found ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9"
Found ! - "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Boonty Games"
Found ! - "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Boonty Games"
Found ! - "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Boonty Games"
Found ! - "HKEY_CURRENT_USER\Software\SWEETIE"
Found ! - "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Upgradecodes\A97CEC23332751B47BA4B95BAA50C9D0"
Found ! - "HKEY_CLASSES_ROOT\SWEETIE.IEToolbar"
Found ! - "HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1"
Found ! - "HKEY_CLASSES_ROOT\SWEETIE.SWEETIE"
Found ! - "HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.1"
Found ! - "HKEY_CLASSES_ROOT\ToolBand.SWEETIE"
Found ! - "HKEY_CLASSES_ROOT\ToolBand.SWEETIE.1"
Found ! - "HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}"
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> FILES\FOLDERS
Found ! - "C:\Program Files\Macrogaming"
Found ! - "C:\Program Files\Fichiers communs\BOONTY Shared"
Found ! - "C:\Documents and Settings\All Users\Application Data\BOONTY"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\112.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\212.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\57B4E612.TMP"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IEC2.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IEC6E.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Set1.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2A0C.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFC00F.tmp"
+---- Scanning prefs.js ... ( # Mozilla User Preferences ) ----+
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\92sfykgs.default\prefs.js :
STARTPAGE: "http://www.google.com/search?hl=fr&ie=UTF-8&oe=UTF-8&q=%s"
+-----+
+--------------------------------------------------------------+
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> [ EOF - 103 lines ]
F --------- Logfile of AD-Remover 1.0.1.7 by C_XX ---------
START at: 10:11:53 | 18/09/2008
ON: Windows_NT (Windows XP)
OPTION: Scan
EXECUTED FROM: C:\Documents and Settings\Administrateur\Bureau\Ad-remover\AD-Remover.bat
USER: Administrateur | PC: A-IOHHQ7DO9WMW8
BOOT MODE: Normal
DRIVE(S): C:\
--------- [ PROCESSES ] ---------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\update\update.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\WScript.exe
---------------------------- [ 43 ]
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> CHECKING SERVICES
Found ! - "Boonty Games"
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> REGISTRY
Found ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Macrogaming"
Found ! - "HKEY_LOCAL_MACHINE\Software\Boonty"
Found ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0"
Found ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E"
Found ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9"
Found ! - "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Boonty Games"
Found ! - "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Boonty Games"
Found ! - "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Boonty Games"
Found ! - "HKEY_CURRENT_USER\Software\SWEETIE"
Found ! - "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Upgradecodes\A97CEC23332751B47BA4B95BAA50C9D0"
Found ! - "HKEY_CLASSES_ROOT\SWEETIE.IEToolbar"
Found ! - "HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1"
Found ! - "HKEY_CLASSES_ROOT\SWEETIE.SWEETIE"
Found ! - "HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.1"
Found ! - "HKEY_CLASSES_ROOT\ToolBand.SWEETIE"
Found ! - "HKEY_CLASSES_ROOT\ToolBand.SWEETIE.1"
Found ! - "HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}"
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> FILES\FOLDERS
Found ! - "C:\Program Files\Macrogaming"
Found ! - "C:\Program Files\Fichiers communs\BOONTY Shared"
Found ! - "C:\Documents and Settings\All Users\Application Data\BOONTY"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\112.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\212.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\57B4E612.TMP"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IEC2.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IEC6E.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Set1.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2A0C.tmp"
Found ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFC00F.tmp"
+---- Scanning prefs.js ... ( # Mozilla User Preferences ) ----+
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\92sfykgs.default\prefs.js :
STARTPAGE: "http://www.google.com/search?hl=fr&ie=UTF-8&oe=UTF-8&q=%s"
+-----+
+--------------------------------------------------------------+
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> [ EOF - 103 lines ]
! Déconnecte-toi et ferme toutes les applications en cours !
* Relance "AD-Remover" : au menu principal, choisis l'option "B".
--> le programme va travailler...
* Poste le rapport qui apparait à la fin
(Le rapport est sauvegardé aussi sous C:\Ad-report.log)
/!\ Si le Bureau ne réapparait pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valide /!\
* Relance "AD-Remover" : au menu principal, choisis l'option "B".
--> le programme va travailler...
* Poste le rapport qui apparait à la fin
(Le rapport est sauvegardé aussi sous C:\Ad-report.log)
/!\ Si le Bureau ne réapparait pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valide /!\
je ne comprend rien a tous cela peux tu m'expliquer ce que tu vois dans cette page je te remercie
F --------- Logfile of AD-Remover 1.0.1.7 by C_XX ---------
START at: 9:49:33 | 19/09/2008
ON: Windows_NT (Windows XP)
OPTION: Clean
EXECUTED FROM: C:\Documents and Settings\Administrateur\Bureau\Ad-remover\AD-Remover.bat
USER: Administrateur | PC: A-IOHHQ7DO9WMW8
BOOT MODE: Normal
DRIVE(S): C:\
--------- [ PROCESSES ] ---------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\WScript.exe
---------------------------- [ 39 ]
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> CHECKING SERVICES
Deleted successfully ! - "Boonty Games"
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> REGISTRY
Deleted ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Macrogaming"
Deleted ! - "HKEY_LOCAL_MACHINE\Software\Boonty"
Deleted ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0"
Deleted ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E"
Deleted ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9"
Deleted ! - "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Boonty Games"
Deleted ! - "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_BOONTY_GAMES"
Deleted ! - "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Boonty Games"
Deleted ! - "HKEY_CURRENT_USER\Software\SWEETIE"
Deleted ! - "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Upgradecodes\A97CEC23332751B47BA4B95BAA50C9D0"
Deleted ! - "HKEY_CLASSES_ROOT\SWEETIE.IEToolbar"
Deleted ! - "HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1"
Deleted ! - "HKEY_CLASSES_ROOT\SWEETIE.SWEETIE"
Deleted ! - "HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.1"
Deleted ! - "HKEY_CLASSES_ROOT\ToolBand.SWEETIE"
Deleted ! - "HKEY_CLASSES_ROOT\ToolBand.SWEETIE.1"
Deleted ! - "HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}"
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> FILES\FOLDERS
Deleted ! - "C:\Program Files\Macrogaming"
Deleted ! - "C:\Program Files\Fichiers communs\BOONTY Shared"
Deleted ! - "C:\Documents and Settings\All Users\Application Data\BOONTY"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\112.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\212.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IEC2.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IEC6E.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Set1.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF1CB3.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2A0C.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFC00F.tmp"
NOT deleted ! - "C:\WINDOWS\temp\~DFE70E.tmp"
+---- Scanning prefs.js ... ( # Mozilla User Preferences ) ----+
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\92sfykgs.default\prefs.js\92sfykgs.default\prefs.js :
+-----+
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> [ EOF - 97 lines ]
F --------- Logfile of AD-Remover 1.0.1.7 by C_XX ---------
START at: 9:49:33 | 19/09/2008
ON: Windows_NT (Windows XP)
OPTION: Clean
EXECUTED FROM: C:\Documents and Settings\Administrateur\Bureau\Ad-remover\AD-Remover.bat
USER: Administrateur | PC: A-IOHHQ7DO9WMW8
BOOT MODE: Normal
DRIVE(S): C:\
--------- [ PROCESSES ] ---------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\WScript.exe
---------------------------- [ 39 ]
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> CHECKING SERVICES
Deleted successfully ! - "Boonty Games"
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> REGISTRY
Deleted ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Macrogaming"
Deleted ! - "HKEY_LOCAL_MACHINE\Software\Boonty"
Deleted ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0"
Deleted ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E"
Deleted ! - "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9"
Deleted ! - "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Boonty Games"
Deleted ! - "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_BOONTY_GAMES"
Deleted ! - "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Boonty Games"
Deleted ! - "HKEY_CURRENT_USER\Software\SWEETIE"
Deleted ! - "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Upgradecodes\A97CEC23332751B47BA4B95BAA50C9D0"
Deleted ! - "HKEY_CLASSES_ROOT\SWEETIE.IEToolbar"
Deleted ! - "HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1"
Deleted ! - "HKEY_CLASSES_ROOT\SWEETIE.SWEETIE"
Deleted ! - "HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.1"
Deleted ! - "HKEY_CLASSES_ROOT\ToolBand.SWEETIE"
Deleted ! - "HKEY_CLASSES_ROOT\ToolBand.SWEETIE.1"
Deleted ! - "HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}"
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> FILES\FOLDERS
Deleted ! - "C:\Program Files\Macrogaming"
Deleted ! - "C:\Program Files\Fichiers communs\BOONTY Shared"
Deleted ! - "C:\Documents and Settings\All Users\Application Data\BOONTY"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\112.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\212.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IEC2.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IEC6E.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Set1.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF1CB3.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2A0C.tmp"
Deleted ! - "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFC00F.tmp"
NOT deleted ! - "C:\WINDOWS\temp\~DFE70E.tmp"
+---- Scanning prefs.js ... ( # Mozilla User Preferences ) ----+
C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\92sfykgs.default\prefs.js\92sfykgs.default\prefs.js :
+-----+
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> [ EOF - 97 lines ]
"je n'ai rien pour desinstaller ad-remover dois-je le mettre directement dans la poubelle?"
---> Oui.
---> Oui.
voici le rapport
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:42:00, on 20/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
R3 - URLSearchHook: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SoundMan] "C:\WINDOWS\SOUNDMAN.EXE"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Pixs\JRE\bin\jusched.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [LWBMOUSE] "C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe"
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "C:\WINDOWS\system32\rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [CursorXP] "C:\Program Files\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Erreur.lnk = ?
O4 - Startup: ExtConfig.lnk = C:\Mageos.com\Config\ExtConf.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.libertysurf.fr
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15034/CTPID.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - http://bl102w.blu102.mail.live.com/mail/SafeRedirect.aspx?hm__tg=http://65.55.183.87/att/GetAttachment.aspx&hm__qs=file%3da8470c13-d10d-47f9-97bd-334ef9828160.jpg%26ct%3daW1hZ2UvanBlZw_3d_3d%26name%3daW1hZ2UwMDEuanBn%26inline%3d1%26rfc%3d0%26empty%3dFalse%26imgsrc%3dcid%253aimage001.jpg%254001C82328.EB998530&oneredir=1&ip=10.6.0.135&d=d1999&mf=0
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:42:00, on 20/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
R3 - URLSearchHook: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SoundMan] "C:\WINDOWS\SOUNDMAN.EXE"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Pixs\JRE\bin\jusched.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [LWBMOUSE] "C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe"
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "C:\WINDOWS\system32\rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [CursorXP] "C:\Program Files\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Erreur.lnk = ?
O4 - Startup: ExtConfig.lnk = C:\Mageos.com\Config\ExtConf.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.libertysurf.fr
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15034/CTPID.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - http://bl102w.blu102.mail.live.com/mail/SafeRedirect.aspx?hm__tg=http://65.55.183.87/att/GetAttachment.aspx&hm__qs=file%3da8470c13-d10d-47f9-97bd-334ef9828160.jpg%26ct%3daW1hZ2UvanBlZw_3d_3d%26name%3daW1hZ2UwMDEuanBn%26inline%3d1%26rfc%3d0%26empty%3dFalse%26imgsrc%3dcid%253aimage001.jpg%254001C82328.EB998530&oneredir=1&ip=10.6.0.135&d=d1999&mf=0
---> Télécharge Lop S&D sur ton Bureau
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
---> Double-clique dessus pour lancer l'installation
---> Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
---> Séléctionne la langue souhaitée, puis choisis l'option 1 (Recherche)
---> Patiente jusqu'à la fin du scan
---> Poste le rapport généré (C:\lopR.txt)
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
---> Double-clique dessus pour lancer l'installation
---> Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
---> Séléctionne la langue souhaitée, puis choisis l'option 1 (Recherche)
---> Patiente jusqu'à la fin du scan
---> Poste le rapport généré (C:\lopR.txt)
--------------------\\ Lop S&D 4.2.4-4 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1201 [VPS 080908-0] 4.8.1201 (Activated)
Firewall : Look 'n' Stop 2.05p2 (Soft4Ever) 2.05p2 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 74 Go Free : 9 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [1] ( 20/09/2008|10:33 )
--------------------\\ Listing des dossiers dans APPLIC~1
[13/04/2008|08:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[20/11/2007|13:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[20/04/2007|11:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[06/09/2007|07:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\Axialis
[03/08/2007|07:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\Babylon
[25/01/2008|10:34] C:\DOCUME~1\ADMINI~1\APPLIC~1\Creative
[29/04/2007|15:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[20/11/2007|17:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Datalayer
[24/05/2007|15:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[20/05/2008|13:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\dvdcss
[13/08/2008|16:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\EmailNotifier
[03/08/2008|13:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\GlarySoft
[11/10/2007|13:42] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[03/02/2004|20:13] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[05/07/2007|10:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[20/08/2008|13:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[11/11/2007|12:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[07/09/2008|15:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\InstallShield
[18/06/2008|11:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\InstallShield Installation Information
[09/07/2008|16:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\iWin
[13/07/2008|09:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\JAM Software
[30/11/2007|16:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[16/04/2007|12:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[13/08/2008|16:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Megaupload
[20/08/2008|13:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\MegauploadToolbar
[19/08/2008|16:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[11/09/2008|09:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[29/06/2007|07:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Nikon
[20/11/2007|18:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\Nokia
[20/11/2007|13:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\PC Suite
[05/09/2007|10:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[20/08/2007|12:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
[14/10/2007|11:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\Screenshot Sender
[22/07/2008|20:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sign sixth locks
[16/04/2007|12:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[22/02/2008|10:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\SystemRequirementsLab
[02/02/2004|22:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[02/05/2007|08:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\vlc
[08/09/2008|09:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\Webroot
[05/02/2004|17:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\WinRAR
[09/07/2008|16:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Zylom
[06/02/2008|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[01/02/2004|18:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[03/08/2007|07:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Babylon
[22/07/2008|20:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
[24/01/2008|19:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[23/04/2007|10:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[30/11/2007|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[07/08/2008|15:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[20/08/2008|13:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EmailNotifier
[02/02/2004|23:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[05/07/2007|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[20/11/2007|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[27/03/2008|10:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[14/05/2007|07:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[02/03/2008|21:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[31/03/2007|09:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[24/06/2007|09:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[02/03/2008|20:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
[20/11/2007|13:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[01/02/2004|18:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[14/06/2008|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecretsOfOlympus
[08/09/2008|09:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[17/09/2008|11:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[30/03/2008|10:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TERMINAL Studio
[21/08/2007|09:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[08/09/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
[16/03/2008|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[16/03/2008|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage(3)
[04/07/2007|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[02/03/2008|21:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/09/2008|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[13/02/2008|18:25] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[04/07/2007|15:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[09/06/2008|14:41] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[08/09/2008|09:46] C:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot
[01/02/2004|14:05] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[18/09/2008 09:45][--a------] C:\WINDOWS\tasks\wrSpySweeperFullSweep.job
[20/09/2008 08:39][--a------] C:\WINDOWS\tasks\GlaryInitialize.job
[20/09/2008 08:39][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[03/02/2004|16:35] C:\Program Files\_ArcadeDownloadFolder
[05/07/2008|11:53] C:\Program Files\Adobe
[18/06/2008|11:15] C:\Program Files\AGEIA Technologies
[31/05/2007|19:00] C:\Program Files\Alcohol Soft
[05/06/2007|22:18] C:\Program Files\Alcohol Toolbar
[02/02/2004|21:55] C:\Program Files\Alwil Software
[29/06/2007|07:38] C:\Program Files\ArcSoft
[23/05/2007|09:44] C:\Program Files\AskTBar
[17/06/2008|14:42] C:\Program Files\Atlantis
[28/01/2008|18:44] C:\Program Files\Audible
[01/02/2004|16:05] C:\Program Files\AvRack
[06/09/2007|07:39] C:\Program Files\Axialis
[21/07/2007|07:04] C:\Program Files\Babylon
[13/07/2008|09:57] C:\Program Files\Bejeweled 2 Deluxe
[28/03/2008|21:02] C:\Program Files\BFG
[16/03/2008|10:59] C:\Program Files\Blip Blop
[21/10/2007|15:06] C:\Program Files\Browser Mouse
[13/04/2008|10:09] C:\Program Files\Circle Developement
[17/09/2008|10:24] C:\Program Files\click-pool
[01/02/2004|14:03] C:\Program Files\ComPlus Applications
[25/03/2007|17:02] C:\Program Files\Core Design
[24/01/2008|15:49] C:\Program Files\Creative
[24/01/2008|15:43] C:\Program Files\Creative Installation Information
[07/09/2007|09:17] C:\Program Files\CursorXP
[29/04/2007|15:42] C:\Program Files\CyberLink
[31/05/2007|15:47] C:\Program Files\DaemonTools_WhenUSave_Installer
[03/02/2004|16:47] C:\Program Files\DemonStarSM1_Shareware
[20/11/2007|13:29] C:\Program Files\DIFX
[31/03/2007|10:13] C:\Program Files\directx
[28/08/2008|10:50] C:\Program Files\DivX
[24/08/2007|10:42] C:\Program Files\DVD Shrink
[13/04/2008|11:00] C:\Program Files\dvdSanta
[05/09/2008|08:42] C:\Program Files\eMule
[05/09/2008|08:41] C:\Program Files\eToro
[19/09/2008|10:06] C:\Program Files\Fichiers communs
[16/04/2007|12:08] C:\Program Files\Free
[28/03/2008|19:09] C:\Program Files\GameHouse
[08/02/2008|18:51] C:\Program Files\Gamenext
[23/07/2008|09:05] C:\Program Files\Glary Utilities
[13/04/2008|11:31] C:\Program Files\Google
[11/04/2008|11:25] C:\Program Files\Hewlett-Packard
[06/07/2007|20:15] C:\Program Files\HP
[11/04/2008|13:14] C:\Program Files\hp deskjet 656c series
[14/06/2007|12:52] C:\Program Files\id Software
[17/12/2007|14:46] C:\Program Files\Inca Ball
[16/05/2008|15:07] C:\Program Files\inKline Global
[07/09/2008|15:52] C:\Program Files\InstallShield Installation Information
[20/08/2008|23:53] C:\Program Files\Internet Explorer
[19/09/2008|19:42] C:\Program Files\Jewel Quest
[19/09/2008|17:30] C:\Program Files\Jewel Quest 2
[13/08/2008|16:01] C:\Program Files\Megaupload
[18/09/2008|11:25] C:\Program Files\Messenger
[07/09/2008|17:57] C:\Program Files\Messenger Plus! Live
[05/04/2008|11:09] C:\Program Files\Micro Application
[17/06/2008|14:43] C:\Program Files\Microids
[01/02/2004|14:06] C:\Program Files\microsoft frontpage
[16/06/2007|11:32] C:\Program Files\Microsoft Games
[03/02/2004|18:34] C:\Program Files\Microsoft Office
[03/02/2004|18:34] C:\Program Files\Microsoft.NET
[14/06/2007|19:33] C:\Program Files\MOTYS 2001
[18/09/2008|11:20] C:\Program Files\Movie Maker
[20/09/2008|10:21] C:\Program Files\Mozilla Firefox
[31/03/2007|07:13] C:\Program Files\Mplayer
[01/02/2004|16:17] C:\Program Files\MSI
[18/09/2008|11:20] C:\Program Files\msn
[01/02/2004|14:03] C:\Program Files\MSN Gaming Zone
[21/04/2007|16:47] C:\Program Files\MSXML 4.0
[18/11/2007|14:06] C:\Program Files\Multi_Media_France
[26/09/2007|10:27] C:\Program Files\MultiMedia France Toolbar
[10/09/2008|18:14] C:\Program Files\Navilog1
[24/04/2007|18:26] C:\Program Files\Nero
[18/09/2008|11:14] C:\Program Files\NetMeeting
[29/06/2007|07:40] C:\Program Files\Nikon
[20/11/2007|19:17] C:\Program Files\Nokia
[18/09/2008|11:14] C:\Program Files\Outlook Express
[20/11/2007|21:24] C:\Program Files\PC Connectivity Solution
[06/02/2008|19:21] C:\Program Files\Pixs
[21/08/2007|09:33] C:\Program Files\PopCap Games
[18/02/2008|11:16] C:\Program Files\PowerPoint Viewer
[19/06/2008|11:18] C:\Program Files\Project64 1.6
[07/02/2004|11:10] C:\Program Files\Real
[01/02/2004|16:05] C:\Program Files\Realtek AC97
[01/02/2004|16:05] C:\Program Files\Realtek Sound Manager
[28/08/2007|11:12] C:\Program Files\ReflexiveArcade
[13/04/2008|11:01] C:\Program Files\Ricochet Xtreme
[09/05/2008|09:55] C:\Program Files\Secrets Of Olympus
[01/02/2004|14:05] C:\Program Files\Services en ligne
[01/02/2004|16:50] C:\Program Files\Setup Files
[24/12/2007|11:15] C:\Program Files\Sign sixth locks
[31/05/2007|14:46] C:\Program Files\SlySoft
[18/05/2007|09:23] C:\Program Files\Soft4Ever
[28/10/2007|12:30] C:\Program Files\Space Invaders OpenGL
[07/09/2008|17:43] C:\Program Files\Spybot - Search & Destroy
[17/09/2008|12:29] C:\Program Files\Trend Micro
[01/02/2004|14:25] C:\Program Files\Uninstall Information
[18/06/2008|11:17] C:\Program Files\Unreal Tournament 3
[18/05/2007|13:15] C:\Program Files\UT
[01/01/2008|19:32] C:\Program Files\Veoh Networks
[02/05/2007|08:18] C:\Program Files\VideoLAN
[08/09/2008|09:43] C:\Program Files\Webroot
[29/10/2007|19:47] C:\Program Files\WIDCOMM
[17/04/2007|14:34] C:\Program Files\WinAVIVideoConverter
[04/07/2007|15:40] C:\Program Files\Windows Live
[02/06/2008|18:03] C:\Program Files\Windows Media Connect 2
[18/09/2008|11:14] C:\Program Files\Windows Media Player
[18/09/2008|11:14] C:\Program Files\Windows NT
[20/04/2007|11:21] C:\Program Files\WindowsUpdate
[17/04/2007|07:47] C:\Program Files\WinHTTrack
[29/04/2007|12:39] C:\Program Files\WinRAR
[06/06/2007|13:22] C:\Program Files\Xbox Controller
[01/02/2004|14:06] C:\Program Files\xerox
[10/07/2008|11:13] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[06/02/2008|19:21] C:\Program Files\Fichiers communs\Adobe
[24/04/2007|16:53] C:\Program Files\Fichiers communs\Ahead
[24/01/2008|15:42] C:\Program Files\Fichiers communs\Creative
[03/02/2004|18:34] C:\Program Files\Fichiers communs\DESIGNER
[05/07/2007|10:01] C:\Program Files\Fichiers communs\Hewlett-Packard
[14/06/2007|11:38] C:\Program Files\Fichiers communs\InstallShield
[01/02/2004|17:29] C:\Program Files\Fichiers communs\Java
[23/07/2008|08:58] C:\Program Files\Fichiers communs\Microsoft Shared
[01/02/2004|14:04] C:\Program Files\Fichiers communs\MSSoap
[29/06/2007|07:47] C:\Program Files\Fichiers communs\Nikon
[01/02/2004|18:10] C:\Program Files\Fichiers communs\NSV
[01/02/2004|13:57] C:\Program Files\Fichiers communs\ODBC
[14/09/2007|16:39] C:\Program Files\Fichiers communs\Real
[01/02/2004|14:04] C:\Program Files\Fichiers communs\Services
[01/02/2004|13:57] C:\Program Files\Fichiers communs\SpeechEngines
[18/09/2008|11:14] C:\Program Files\Fichiers communs\System
[16/03/2008|10:27] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[18/06/2008|11:15] C:\Program Files\Fichiers communs\Wise Installation Wizard
[14/09/2007|16:39] C:\Program Files\Fichiers communs\xing shared
--------------------\\ Process
( 49 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
C:\Program Files\Circle Developement
C:\Program Files\Multi_Media_France
C:\Program Files\Multi_Media_France\INSTALL.LOG
C:\Program Files\Multi_Media_France\tbMul0.dll
C:\Program Files\Multi_Media_France\tbMul1.dll
C:\Program Files\Multi_Media_France\tbMult.dll
C:\Program Files\Multi_Media_France\toolbar.cfg
C:\Program Files\Multi_Media_France\UNWISE.EXE
C:\Program Files\Multi_Media_France\UNWISE.INI
C:\Program Files\Multi_Media_France
C:\Program Files\Multi_Media_France\INSTALL.LOG
C:\Program Files\Multi_Media_France\tbMul0.dll
C:\Program Files\Multi_Media_France\tbMul1.dll
C:\Program Files\Multi_Media_France\tbMult.dll
C:\Program Files\Multi_Media_France\toolbar.cfg
C:\Program Files\Multi_Media_France\UNWISE.EXE
C:\Program Files\Multi_Media_France\UNWISE.INI
C:\Program Files\MultiMedia France Toolbar
C:\Program Files\MultiMedia France Toolbar\INSTALL.LOG
C:\Program Files\MultiMedia France Toolbar\MultiMedia - Installer.exe
C:\Program Files\MultiMedia France Toolbar\Multi_Media_France.exe
C:\Program Files\MultiMedia France Toolbar\Multi_Media_France.xpi
C:\Program Files\MultiMedia France Toolbar\UNWISE.EXE
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts MODIFIE
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD
-> 9255 [ 70 ## added by CiD ]
/!\ 2 Not 127.0.0.1 !!
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 10:42:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 63
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Atlantis - Big Fish Games - Reflexive Arcade + Keygen.rar
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel Quest 2 02Keygen.exe
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel.Quest.II.v2.02.WinALL.Incl.Keygen-ECLiPSE=.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\divX converter 6.2 keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look N Stop v2.05p2 With Keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look'n'Stop 2.05_FR_keygen_par_PiStOuDaMoUr.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\adobelm.dll
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\lisezmoi.txt
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\tw10122.dat
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Cdrwin v6.1.1.0 Incl Keygen.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\CloneCD 5.2.9.1 - Crack.exe
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Nero Vision Express 3.1.0.21 Keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\CJA6KEJS\Crack2[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\GHFJIY05\Crack[1].html
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\N8QLJX6B\Crack[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\Mes fichiers re‡us\quake 4\quake.4.keygen-tsrh.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\keygen.nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\Quake.4-DEViANCE.ShadowCast.[shareprovider.com].nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 06 - La patrouille de douane (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 09 - Le jour de no‰l (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 11 - L'avalanche (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 01_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 02_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 03_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et Sebastien 04 Le Feuilleton Des Nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 05 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 07 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 08 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 10 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 12 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 13 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Colargol - 01 - Un Matin Au Bois Joli - By Chrix.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les aventures de Poly - 01 de 13 - L'arriv‚e au cirque.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les_Idiots.avi
[F:13][D:2]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
[F:2][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
[F:4342][D:6]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 20/09/2008|10:48 - Option : [1]
--------------------\\ Fin du rapport a 10:48:37
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1201 [VPS 080908-0] 4.8.1201 (Activated)
Firewall : Look 'n' Stop 2.05p2 (Soft4Ever) 2.05p2 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 74 Go Free : 9 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [1] ( 20/09/2008|10:33 )
--------------------\\ Listing des dossiers dans APPLIC~1
[13/04/2008|08:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[20/11/2007|13:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[20/04/2007|11:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[06/09/2007|07:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\Axialis
[03/08/2007|07:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\Babylon
[25/01/2008|10:34] C:\DOCUME~1\ADMINI~1\APPLIC~1\Creative
[29/04/2007|15:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[20/11/2007|17:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Datalayer
[24/05/2007|15:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[20/05/2008|13:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\dvdcss
[13/08/2008|16:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\EmailNotifier
[03/08/2008|13:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\GlarySoft
[11/10/2007|13:42] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[03/02/2004|20:13] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[05/07/2007|10:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[20/08/2008|13:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[11/11/2007|12:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[07/09/2008|15:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\InstallShield
[18/06/2008|11:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\InstallShield Installation Information
[09/07/2008|16:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\iWin
[13/07/2008|09:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\JAM Software
[30/11/2007|16:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[16/04/2007|12:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[13/08/2008|16:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Megaupload
[20/08/2008|13:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\MegauploadToolbar
[19/08/2008|16:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[11/09/2008|09:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[29/06/2007|07:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Nikon
[20/11/2007|18:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\Nokia
[20/11/2007|13:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\PC Suite
[05/09/2007|10:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[20/08/2007|12:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
[14/10/2007|11:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\Screenshot Sender
[22/07/2008|20:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sign sixth locks
[16/04/2007|12:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[22/02/2008|10:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\SystemRequirementsLab
[02/02/2004|22:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[02/05/2007|08:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\vlc
[08/09/2008|09:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\Webroot
[05/02/2004|17:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\WinRAR
[09/07/2008|16:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Zylom
[06/02/2008|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[01/02/2004|18:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[03/08/2007|07:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Babylon
[22/07/2008|20:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
[24/01/2008|19:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[23/04/2007|10:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[30/11/2007|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[07/08/2008|15:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[20/08/2008|13:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EmailNotifier
[02/02/2004|23:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[05/07/2007|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[20/11/2007|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[27/03/2008|10:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[14/05/2007|07:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[02/03/2008|21:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[31/03/2007|09:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[24/06/2007|09:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[02/03/2008|20:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
[20/11/2007|13:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[01/02/2004|18:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[14/06/2008|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecretsOfOlympus
[08/09/2008|09:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[17/09/2008|11:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[30/03/2008|10:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TERMINAL Studio
[21/08/2007|09:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[08/09/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
[16/03/2008|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[16/03/2008|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage(3)
[04/07/2007|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[02/03/2008|21:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/09/2008|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[13/02/2008|18:25] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[04/07/2007|15:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[09/06/2008|14:41] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[08/09/2008|09:46] C:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot
[01/02/2004|14:05] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[18/09/2008 09:45][--a------] C:\WINDOWS\tasks\wrSpySweeperFullSweep.job
[20/09/2008 08:39][--a------] C:\WINDOWS\tasks\GlaryInitialize.job
[20/09/2008 08:39][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[03/02/2004|16:35] C:\Program Files\_ArcadeDownloadFolder
[05/07/2008|11:53] C:\Program Files\Adobe
[18/06/2008|11:15] C:\Program Files\AGEIA Technologies
[31/05/2007|19:00] C:\Program Files\Alcohol Soft
[05/06/2007|22:18] C:\Program Files\Alcohol Toolbar
[02/02/2004|21:55] C:\Program Files\Alwil Software
[29/06/2007|07:38] C:\Program Files\ArcSoft
[23/05/2007|09:44] C:\Program Files\AskTBar
[17/06/2008|14:42] C:\Program Files\Atlantis
[28/01/2008|18:44] C:\Program Files\Audible
[01/02/2004|16:05] C:\Program Files\AvRack
[06/09/2007|07:39] C:\Program Files\Axialis
[21/07/2007|07:04] C:\Program Files\Babylon
[13/07/2008|09:57] C:\Program Files\Bejeweled 2 Deluxe
[28/03/2008|21:02] C:\Program Files\BFG
[16/03/2008|10:59] C:\Program Files\Blip Blop
[21/10/2007|15:06] C:\Program Files\Browser Mouse
[13/04/2008|10:09] C:\Program Files\Circle Developement
[17/09/2008|10:24] C:\Program Files\click-pool
[01/02/2004|14:03] C:\Program Files\ComPlus Applications
[25/03/2007|17:02] C:\Program Files\Core Design
[24/01/2008|15:49] C:\Program Files\Creative
[24/01/2008|15:43] C:\Program Files\Creative Installation Information
[07/09/2007|09:17] C:\Program Files\CursorXP
[29/04/2007|15:42] C:\Program Files\CyberLink
[31/05/2007|15:47] C:\Program Files\DaemonTools_WhenUSave_Installer
[03/02/2004|16:47] C:\Program Files\DemonStarSM1_Shareware
[20/11/2007|13:29] C:\Program Files\DIFX
[31/03/2007|10:13] C:\Program Files\directx
[28/08/2008|10:50] C:\Program Files\DivX
[24/08/2007|10:42] C:\Program Files\DVD Shrink
[13/04/2008|11:00] C:\Program Files\dvdSanta
[05/09/2008|08:42] C:\Program Files\eMule
[05/09/2008|08:41] C:\Program Files\eToro
[19/09/2008|10:06] C:\Program Files\Fichiers communs
[16/04/2007|12:08] C:\Program Files\Free
[28/03/2008|19:09] C:\Program Files\GameHouse
[08/02/2008|18:51] C:\Program Files\Gamenext
[23/07/2008|09:05] C:\Program Files\Glary Utilities
[13/04/2008|11:31] C:\Program Files\Google
[11/04/2008|11:25] C:\Program Files\Hewlett-Packard
[06/07/2007|20:15] C:\Program Files\HP
[11/04/2008|13:14] C:\Program Files\hp deskjet 656c series
[14/06/2007|12:52] C:\Program Files\id Software
[17/12/2007|14:46] C:\Program Files\Inca Ball
[16/05/2008|15:07] C:\Program Files\inKline Global
[07/09/2008|15:52] C:\Program Files\InstallShield Installation Information
[20/08/2008|23:53] C:\Program Files\Internet Explorer
[19/09/2008|19:42] C:\Program Files\Jewel Quest
[19/09/2008|17:30] C:\Program Files\Jewel Quest 2
[13/08/2008|16:01] C:\Program Files\Megaupload
[18/09/2008|11:25] C:\Program Files\Messenger
[07/09/2008|17:57] C:\Program Files\Messenger Plus! Live
[05/04/2008|11:09] C:\Program Files\Micro Application
[17/06/2008|14:43] C:\Program Files\Microids
[01/02/2004|14:06] C:\Program Files\microsoft frontpage
[16/06/2007|11:32] C:\Program Files\Microsoft Games
[03/02/2004|18:34] C:\Program Files\Microsoft Office
[03/02/2004|18:34] C:\Program Files\Microsoft.NET
[14/06/2007|19:33] C:\Program Files\MOTYS 2001
[18/09/2008|11:20] C:\Program Files\Movie Maker
[20/09/2008|10:21] C:\Program Files\Mozilla Firefox
[31/03/2007|07:13] C:\Program Files\Mplayer
[01/02/2004|16:17] C:\Program Files\MSI
[18/09/2008|11:20] C:\Program Files\msn
[01/02/2004|14:03] C:\Program Files\MSN Gaming Zone
[21/04/2007|16:47] C:\Program Files\MSXML 4.0
[18/11/2007|14:06] C:\Program Files\Multi_Media_France
[26/09/2007|10:27] C:\Program Files\MultiMedia France Toolbar
[10/09/2008|18:14] C:\Program Files\Navilog1
[24/04/2007|18:26] C:\Program Files\Nero
[18/09/2008|11:14] C:\Program Files\NetMeeting
[29/06/2007|07:40] C:\Program Files\Nikon
[20/11/2007|19:17] C:\Program Files\Nokia
[18/09/2008|11:14] C:\Program Files\Outlook Express
[20/11/2007|21:24] C:\Program Files\PC Connectivity Solution
[06/02/2008|19:21] C:\Program Files\Pixs
[21/08/2007|09:33] C:\Program Files\PopCap Games
[18/02/2008|11:16] C:\Program Files\PowerPoint Viewer
[19/06/2008|11:18] C:\Program Files\Project64 1.6
[07/02/2004|11:10] C:\Program Files\Real
[01/02/2004|16:05] C:\Program Files\Realtek AC97
[01/02/2004|16:05] C:\Program Files\Realtek Sound Manager
[28/08/2007|11:12] C:\Program Files\ReflexiveArcade
[13/04/2008|11:01] C:\Program Files\Ricochet Xtreme
[09/05/2008|09:55] C:\Program Files\Secrets Of Olympus
[01/02/2004|14:05] C:\Program Files\Services en ligne
[01/02/2004|16:50] C:\Program Files\Setup Files
[24/12/2007|11:15] C:\Program Files\Sign sixth locks
[31/05/2007|14:46] C:\Program Files\SlySoft
[18/05/2007|09:23] C:\Program Files\Soft4Ever
[28/10/2007|12:30] C:\Program Files\Space Invaders OpenGL
[07/09/2008|17:43] C:\Program Files\Spybot - Search & Destroy
[17/09/2008|12:29] C:\Program Files\Trend Micro
[01/02/2004|14:25] C:\Program Files\Uninstall Information
[18/06/2008|11:17] C:\Program Files\Unreal Tournament 3
[18/05/2007|13:15] C:\Program Files\UT
[01/01/2008|19:32] C:\Program Files\Veoh Networks
[02/05/2007|08:18] C:\Program Files\VideoLAN
[08/09/2008|09:43] C:\Program Files\Webroot
[29/10/2007|19:47] C:\Program Files\WIDCOMM
[17/04/2007|14:34] C:\Program Files\WinAVIVideoConverter
[04/07/2007|15:40] C:\Program Files\Windows Live
[02/06/2008|18:03] C:\Program Files\Windows Media Connect 2
[18/09/2008|11:14] C:\Program Files\Windows Media Player
[18/09/2008|11:14] C:\Program Files\Windows NT
[20/04/2007|11:21] C:\Program Files\WindowsUpdate
[17/04/2007|07:47] C:\Program Files\WinHTTrack
[29/04/2007|12:39] C:\Program Files\WinRAR
[06/06/2007|13:22] C:\Program Files\Xbox Controller
[01/02/2004|14:06] C:\Program Files\xerox
[10/07/2008|11:13] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[06/02/2008|19:21] C:\Program Files\Fichiers communs\Adobe
[24/04/2007|16:53] C:\Program Files\Fichiers communs\Ahead
[24/01/2008|15:42] C:\Program Files\Fichiers communs\Creative
[03/02/2004|18:34] C:\Program Files\Fichiers communs\DESIGNER
[05/07/2007|10:01] C:\Program Files\Fichiers communs\Hewlett-Packard
[14/06/2007|11:38] C:\Program Files\Fichiers communs\InstallShield
[01/02/2004|17:29] C:\Program Files\Fichiers communs\Java
[23/07/2008|08:58] C:\Program Files\Fichiers communs\Microsoft Shared
[01/02/2004|14:04] C:\Program Files\Fichiers communs\MSSoap
[29/06/2007|07:47] C:\Program Files\Fichiers communs\Nikon
[01/02/2004|18:10] C:\Program Files\Fichiers communs\NSV
[01/02/2004|13:57] C:\Program Files\Fichiers communs\ODBC
[14/09/2007|16:39] C:\Program Files\Fichiers communs\Real
[01/02/2004|14:04] C:\Program Files\Fichiers communs\Services
[01/02/2004|13:57] C:\Program Files\Fichiers communs\SpeechEngines
[18/09/2008|11:14] C:\Program Files\Fichiers communs\System
[16/03/2008|10:27] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[18/06/2008|11:15] C:\Program Files\Fichiers communs\Wise Installation Wizard
[14/09/2007|16:39] C:\Program Files\Fichiers communs\xing shared
--------------------\\ Process
( 49 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
C:\Program Files\Circle Developement
C:\Program Files\Multi_Media_France
C:\Program Files\Multi_Media_France\INSTALL.LOG
C:\Program Files\Multi_Media_France\tbMul0.dll
C:\Program Files\Multi_Media_France\tbMul1.dll
C:\Program Files\Multi_Media_France\tbMult.dll
C:\Program Files\Multi_Media_France\toolbar.cfg
C:\Program Files\Multi_Media_France\UNWISE.EXE
C:\Program Files\Multi_Media_France\UNWISE.INI
C:\Program Files\Multi_Media_France
C:\Program Files\Multi_Media_France\INSTALL.LOG
C:\Program Files\Multi_Media_France\tbMul0.dll
C:\Program Files\Multi_Media_France\tbMul1.dll
C:\Program Files\Multi_Media_France\tbMult.dll
C:\Program Files\Multi_Media_France\toolbar.cfg
C:\Program Files\Multi_Media_France\UNWISE.EXE
C:\Program Files\Multi_Media_France\UNWISE.INI
C:\Program Files\MultiMedia France Toolbar
C:\Program Files\MultiMedia France Toolbar\INSTALL.LOG
C:\Program Files\MultiMedia France Toolbar\MultiMedia - Installer.exe
C:\Program Files\MultiMedia France Toolbar\Multi_Media_France.exe
C:\Program Files\MultiMedia France Toolbar\Multi_Media_France.xpi
C:\Program Files\MultiMedia France Toolbar\UNWISE.EXE
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts MODIFIE
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD
-> 9255 [ 70 ## added by CiD ]
/!\ 2 Not 127.0.0.1 !!
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 10:42:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 63
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Atlantis - Big Fish Games - Reflexive Arcade + Keygen.rar
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel Quest 2 02Keygen.exe
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel.Quest.II.v2.02.WinALL.Incl.Keygen-ECLiPSE=.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\divX converter 6.2 keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look N Stop v2.05p2 With Keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look'n'Stop 2.05_FR_keygen_par_PiStOuDaMoUr.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\adobelm.dll
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\lisezmoi.txt
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\tw10122.dat
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Cdrwin v6.1.1.0 Incl Keygen.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\CloneCD 5.2.9.1 - Crack.exe
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Nero Vision Express 3.1.0.21 Keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\CJA6KEJS\Crack2[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\GHFJIY05\Crack[1].html
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\N8QLJX6B\Crack[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\Mes fichiers re‡us\quake 4\quake.4.keygen-tsrh.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\keygen.nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\Quake.4-DEViANCE.ShadowCast.[shareprovider.com].nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 06 - La patrouille de douane (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 09 - Le jour de no‰l (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 11 - L'avalanche (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 01_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 02_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 03_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et Sebastien 04 Le Feuilleton Des Nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 05 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 07 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 08 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 10 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 12 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 13 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Colargol - 01 - Un Matin Au Bois Joli - By Chrix.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les aventures de Poly - 01 de 13 - L'arriv‚e au cirque.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les_Idiots.avi
[F:13][D:2]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
[F:2][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
[F:4342][D:6]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 20/09/2008|10:48 - Option : [1]
--------------------\\ Fin du rapport a 10:48:37
Les cracks et keygens peuvent infecter ton PC.
---> Relance Lop S&D
---> Choisis cette fois-ci l'option 2 (Suppression)
---> Ne ferme pas la fenêtre lors de la suppression !
---> Poste le rapport généré (C:\lopR.txt)
---> Relance Lop S&D
---> Choisis cette fois-ci l'option 2 (Suppression)
---> Ne ferme pas la fenêtre lors de la suppression !
---> Poste le rapport généré (C:\lopR.txt)
--------------------\\ Lop S&D 4.2.4-4 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1201 [VPS 080908-0] 4.8.1201 (Activated)
Firewall : Look 'n' Stop 2.05p2 (Soft4Ever) 2.05p2 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 74 Go Free : 9 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [2] ( 20/09/2008|11:18 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\Program Files\Multi_Media_France\INSTALL.LOG
Supprime! - C:\Program Files\Multi_Media_France\tbMul0.dll
Supprime! - C:\Program Files\Multi_Media_France\tbMul1.dll
Supprime! - C:\Program Files\Multi_Media_France\tbMult.dll
Supprime! - C:\Program Files\Multi_Media_France\toolbar.cfg
Supprime! - C:\Program Files\Multi_Media_France\UNWISE.EXE
Supprime! - C:\Program Files\Multi_Media_France\UNWISE.INI
Supprime! - C:\Program Files\MultiMedia France Toolbar\INSTALL.LOG
Supprime! - C:\Program Files\MultiMedia France Toolbar\MultiMedia - Installer.exe
Supprime! - C:\Program Files\MultiMedia France Toolbar\Multi_Media_France.exe
Supprime! - C:\Program Files\MultiMedia France Toolbar\Multi_Media_France.xpi
Supprime! - C:\Program Files\MultiMedia France Toolbar\UNWISE.EXE
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
Supprime! - C:\Program Files\Circle Developement
Supprime! - C:\Program Files\Multi_Media_France
Supprime! - C:\Program Files\MultiMedia France Toolbar
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[13/04/2008|08:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[20/11/2007|13:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[20/04/2007|11:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[06/09/2007|07:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\Axialis
[03/08/2007|07:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\Babylon
[25/01/2008|10:34] C:\DOCUME~1\ADMINI~1\APPLIC~1\Creative
[29/04/2007|15:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[20/11/2007|17:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Datalayer
[24/05/2007|15:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[20/05/2008|13:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\dvdcss
[13/08/2008|16:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\EmailNotifier
[03/08/2008|13:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\GlarySoft
[11/10/2007|13:42] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[03/02/2004|20:13] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[05/07/2007|10:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[20/08/2008|13:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[11/11/2007|12:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[07/09/2008|15:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\InstallShield
[18/06/2008|11:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\InstallShield Installation Information
[09/07/2008|16:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\iWin
[13/07/2008|09:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\JAM Software
[30/11/2007|16:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[16/04/2007|12:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[13/08/2008|16:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Megaupload
[20/08/2008|13:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\MegauploadToolbar
[19/08/2008|16:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[11/09/2008|09:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[29/06/2007|07:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Nikon
[20/11/2007|18:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\Nokia
[20/11/2007|13:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\PC Suite
[05/09/2007|10:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[20/08/2007|12:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
[14/10/2007|11:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\Screenshot Sender
[22/07/2008|20:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sign sixth locks
[16/04/2007|12:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[22/02/2008|10:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\SystemRequirementsLab
[02/02/2004|22:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[02/05/2007|08:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\vlc
[08/09/2008|09:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\Webroot
[05/02/2004|17:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\WinRAR
[09/07/2008|16:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Zylom
[06/02/2008|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[01/02/2004|18:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[03/08/2007|07:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Babylon
[24/01/2008|19:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[23/04/2007|10:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[30/11/2007|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[07/08/2008|15:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[20/08/2008|13:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EmailNotifier
[02/02/2004|23:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[05/07/2007|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[20/11/2007|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[27/03/2008|10:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[14/05/2007|07:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[02/03/2008|21:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[31/03/2007|09:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[24/06/2007|09:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[02/03/2008|20:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
[20/11/2007|13:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[01/02/2004|18:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[14/06/2008|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecretsOfOlympus
[08/09/2008|09:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[17/09/2008|11:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[30/03/2008|10:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TERMINAL Studio
[21/08/2007|09:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[08/09/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
[16/03/2008|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[16/03/2008|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage(3)
[04/07/2007|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[02/03/2008|21:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/09/2008|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[13/02/2008|18:25] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[04/07/2007|15:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[09/06/2008|14:41] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[08/09/2008|09:46] C:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot
[01/02/2004|14:05] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[18/09/2008 09:45][--a------] C:\WINDOWS\tasks\wrSpySweeperFullSweep.job
[20/09/2008 08:39][--a------] C:\WINDOWS\tasks\GlaryInitialize.job
[20/09/2008 08:39][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[03/02/2004|16:35] C:\Program Files\_ArcadeDownloadFolder
[05/07/2008|11:53] C:\Program Files\Adobe
[18/06/2008|11:15] C:\Program Files\AGEIA Technologies
[31/05/2007|19:00] C:\Program Files\Alcohol Soft
[05/06/2007|22:18] C:\Program Files\Alcohol Toolbar
[02/02/2004|21:55] C:\Program Files\Alwil Software
[29/06/2007|07:38] C:\Program Files\ArcSoft
[23/05/2007|09:44] C:\Program Files\AskTBar
[17/06/2008|14:42] C:\Program Files\Atlantis
[28/01/2008|18:44] C:\Program Files\Audible
[01/02/2004|16:05] C:\Program Files\AvRack
[06/09/2007|07:39] C:\Program Files\Axialis
[21/07/2007|07:04] C:\Program Files\Babylon
[13/07/2008|09:57] C:\Program Files\Bejeweled 2 Deluxe
[28/03/2008|21:02] C:\Program Files\BFG
[16/03/2008|10:59] C:\Program Files\Blip Blop
[21/10/2007|15:06] C:\Program Files\Browser Mouse
[17/09/2008|10:24] C:\Program Files\click-pool
[01/02/2004|14:03] C:\Program Files\ComPlus Applications
[25/03/2007|17:02] C:\Program Files\Core Design
[24/01/2008|15:49] C:\Program Files\Creative
[24/01/2008|15:43] C:\Program Files\Creative Installation Information
[07/09/2007|09:17] C:\Program Files\CursorXP
[29/04/2007|15:42] C:\Program Files\CyberLink
[31/05/2007|15:47] C:\Program Files\DaemonTools_WhenUSave_Installer
[03/02/2004|16:47] C:\Program Files\DemonStarSM1_Shareware
[20/11/2007|13:29] C:\Program Files\DIFX
[31/03/2007|10:13] C:\Program Files\directx
[28/08/2008|10:50] C:\Program Files\DivX
[24/08/2007|10:42] C:\Program Files\DVD Shrink
[13/04/2008|11:00] C:\Program Files\dvdSanta
[05/09/2008|08:42] C:\Program Files\eMule
[05/09/2008|08:41] C:\Program Files\eToro
[19/09/2008|10:06] C:\Program Files\Fichiers communs
[16/04/2007|12:08] C:\Program Files\Free
[28/03/2008|19:09] C:\Program Files\GameHouse
[08/02/2008|18:51] C:\Program Files\Gamenext
[23/07/2008|09:05] C:\Program Files\Glary Utilities
[13/04/2008|11:31] C:\Program Files\Google
[11/04/2008|11:25] C:\Program Files\Hewlett-Packard
[06/07/2007|20:15] C:\Program Files\HP
[11/04/2008|13:14] C:\Program Files\hp deskjet 656c series
[14/06/2007|12:52] C:\Program Files\id Software
[17/12/2007|14:46] C:\Program Files\Inca Ball
[16/05/2008|15:07] C:\Program Files\inKline Global
[07/09/2008|15:52] C:\Program Files\InstallShield Installation Information
[20/08/2008|23:53] C:\Program Files\Internet Explorer
[19/09/2008|19:42] C:\Program Files\Jewel Quest
[19/09/2008|17:30] C:\Program Files\Jewel Quest 2
[13/08/2008|16:01] C:\Program Files\Megaupload
[18/09/2008|11:25] C:\Program Files\Messenger
[07/09/2008|17:57] C:\Program Files\Messenger Plus! Live
[05/04/2008|11:09] C:\Program Files\Micro Application
[17/06/2008|14:43] C:\Program Files\Microids
[01/02/2004|14:06] C:\Program Files\microsoft frontpage
[16/06/2007|11:32] C:\Program Files\Microsoft Games
[03/02/2004|18:34] C:\Program Files\Microsoft Office
[03/02/2004|18:34] C:\Program Files\Microsoft.NET
[14/06/2007|19:33] C:\Program Files\MOTYS 2001
[18/09/2008|11:20] C:\Program Files\Movie Maker
[20/09/2008|11:15] C:\Program Files\Mozilla Firefox
[31/03/2007|07:13] C:\Program Files\Mplayer
[01/02/2004|16:17] C:\Program Files\MSI
[18/09/2008|11:20] C:\Program Files\msn
[01/02/2004|14:03] C:\Program Files\MSN Gaming Zone
[21/04/2007|16:47] C:\Program Files\MSXML 4.0
[10/09/2008|18:14] C:\Program Files\Navilog1
[24/04/2007|18:26] C:\Program Files\Nero
[18/09/2008|11:14] C:\Program Files\NetMeeting
[29/06/2007|07:40] C:\Program Files\Nikon
[20/11/2007|19:17] C:\Program Files\Nokia
[18/09/2008|11:14] C:\Program Files\Outlook Express
[20/11/2007|21:24] C:\Program Files\PC Connectivity Solution
[06/02/2008|19:21] C:\Program Files\Pixs
[21/08/2007|09:33] C:\Program Files\PopCap Games
[18/02/2008|11:16] C:\Program Files\PowerPoint Viewer
[19/06/2008|11:18] C:\Program Files\Project64 1.6
[07/02/2004|11:10] C:\Program Files\Real
[01/02/2004|16:05] C:\Program Files\Realtek AC97
[01/02/2004|16:05] C:\Program Files\Realtek Sound Manager
[28/08/2007|11:12] C:\Program Files\ReflexiveArcade
[13/04/2008|11:01] C:\Program Files\Ricochet Xtreme
[09/05/2008|09:55] C:\Program Files\Secrets Of Olympus
[01/02/2004|14:05] C:\Program Files\Services en ligne
[01/02/2004|16:50] C:\Program Files\Setup Files
[24/12/2007|11:15] C:\Program Files\Sign sixth locks
[31/05/2007|14:46] C:\Program Files\SlySoft
[18/05/2007|09:23] C:\Program Files\Soft4Ever
[28/10/2007|12:30] C:\Program Files\Space Invaders OpenGL
[07/09/2008|17:43] C:\Program Files\Spybot - Search & Destroy
[17/09/2008|12:29] C:\Program Files\Trend Micro
[01/02/2004|14:25] C:\Program Files\Uninstall Information
[18/06/2008|11:17] C:\Program Files\Unreal Tournament 3
[18/05/2007|13:15] C:\Program Files\UT
[01/01/2008|19:32] C:\Program Files\Veoh Networks
[02/05/2007|08:18] C:\Program Files\VideoLAN
[08/09/2008|09:43] C:\Program Files\Webroot
[29/10/2007|19:47] C:\Program Files\WIDCOMM
[17/04/2007|14:34] C:\Program Files\WinAVIVideoConverter
[04/07/2007|15:40] C:\Program Files\Windows Live
[02/06/2008|18:03] C:\Program Files\Windows Media Connect 2
[18/09/2008|11:14] C:\Program Files\Windows Media Player
[18/09/2008|11:14] C:\Program Files\Windows NT
[20/04/2007|11:21] C:\Program Files\WindowsUpdate
[17/04/2007|07:47] C:\Program Files\WinHTTrack
[29/04/2007|12:39] C:\Program Files\WinRAR
[06/06/2007|13:22] C:\Program Files\Xbox Controller
[01/02/2004|14:06] C:\Program Files\xerox
[10/07/2008|11:13] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[06/02/2008|19:21] C:\Program Files\Fichiers communs\Adobe
[24/04/2007|16:53] C:\Program Files\Fichiers communs\Ahead
[24/01/2008|15:42] C:\Program Files\Fichiers communs\Creative
[03/02/2004|18:34] C:\Program Files\Fichiers communs\DESIGNER
[05/07/2007|10:01] C:\Program Files\Fichiers communs\Hewlett-Packard
[14/06/2007|11:38] C:\Program Files\Fichiers communs\InstallShield
[01/02/2004|17:29] C:\Program Files\Fichiers communs\Java
[23/07/2008|08:58] C:\Program Files\Fichiers communs\Microsoft Shared
[01/02/2004|14:04] C:\Program Files\Fichiers communs\MSSoap
[29/06/2007|07:47] C:\Program Files\Fichiers communs\Nikon
[01/02/2004|18:10] C:\Program Files\Fichiers communs\NSV
[01/02/2004|13:57] C:\Program Files\Fichiers communs\ODBC
[14/09/2007|16:39] C:\Program Files\Fichiers communs\Real
[01/02/2004|14:04] C:\Program Files\Fichiers communs\Services
[01/02/2004|13:57] C:\Program Files\Fichiers communs\SpeechEngines
[18/09/2008|11:14] C:\Program Files\Fichiers communs\System
[16/03/2008|10:27] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[18/06/2008|11:15] C:\Program Files\Fichiers communs\Wise Installation Wizard
[14/09/2007|16:39] C:\Program Files\Fichiers communs\xing shared
--------------------\\ Process
( 48 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 11:27:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 63
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Atlantis - Big Fish Games - Reflexive Arcade + Keygen.rar
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel Quest 2 02Keygen.exe
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel.Quest.II.v2.02.WinALL.Incl.Keygen-ECLiPSE=.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\divX converter 6.2 keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look N Stop v2.05p2 With Keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look'n'Stop 2.05_FR_keygen_par_PiStOuDaMoUr.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\adobelm.dll
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\lisezmoi.txt
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\tw10122.dat
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Cdrwin v6.1.1.0 Incl Keygen.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\CloneCD 5.2.9.1 - Crack.exe
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Nero Vision Express 3.1.0.21 Keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\CJA6KEJS\Crack2[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\GHFJIY05\Crack[1].html
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\N8QLJX6B\Crack[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\Mes fichiers re‡us\quake 4\quake.4.keygen-tsrh.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\keygen.nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\Quake.4-DEViANCE.ShadowCast.[shareprovider.com].nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 06 - La patrouille de douane (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 09 - Le jour de no‰l (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 11 - L'avalanche (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 01_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 02_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 03_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et Sebastien 04 Le Feuilleton Des Nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 05 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 07 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 08 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 10 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 12 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 13 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Colargol - 01 - Un Matin Au Bois Joli - By Chrix.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les aventures de Poly - 01 de 13 - L'arriv‚e au cirque.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les_Idiots.avi
[F:13][D:2]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
[F:2][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
[F:4334][D:6]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 20/09/2008|10:48 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 20/09/2008|11:33 - Option : [2]
--------------------\\ Fin du rapport a 11:33:55
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1201 [VPS 080908-0] 4.8.1201 (Activated)
Firewall : Look 'n' Stop 2.05p2 (Soft4Ever) 2.05p2 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 74 Go Free : 9 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [2] ( 20/09/2008|11:18 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\Program Files\Multi_Media_France\INSTALL.LOG
Supprime! - C:\Program Files\Multi_Media_France\tbMul0.dll
Supprime! - C:\Program Files\Multi_Media_France\tbMul1.dll
Supprime! - C:\Program Files\Multi_Media_France\tbMult.dll
Supprime! - C:\Program Files\Multi_Media_France\toolbar.cfg
Supprime! - C:\Program Files\Multi_Media_France\UNWISE.EXE
Supprime! - C:\Program Files\Multi_Media_France\UNWISE.INI
Supprime! - C:\Program Files\MultiMedia France Toolbar\INSTALL.LOG
Supprime! - C:\Program Files\MultiMedia France Toolbar\MultiMedia - Installer.exe
Supprime! - C:\Program Files\MultiMedia France Toolbar\Multi_Media_France.exe
Supprime! - C:\Program Files\MultiMedia France Toolbar\Multi_Media_France.xpi
Supprime! - C:\Program Files\MultiMedia France Toolbar\UNWISE.EXE
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
Supprime! - C:\Program Files\Circle Developement
Supprime! - C:\Program Files\Multi_Media_France
Supprime! - C:\Program Files\MultiMedia France Toolbar
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[13/04/2008|08:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[20/11/2007|13:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[20/04/2007|11:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[06/09/2007|07:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\Axialis
[03/08/2007|07:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\Babylon
[25/01/2008|10:34] C:\DOCUME~1\ADMINI~1\APPLIC~1\Creative
[29/04/2007|15:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[20/11/2007|17:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Datalayer
[24/05/2007|15:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[20/05/2008|13:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\dvdcss
[13/08/2008|16:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\EmailNotifier
[03/08/2008|13:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\GlarySoft
[11/10/2007|13:42] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[03/02/2004|20:13] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[05/07/2007|10:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[20/08/2008|13:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[11/11/2007|12:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[07/09/2008|15:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\InstallShield
[18/06/2008|11:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\InstallShield Installation Information
[09/07/2008|16:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\iWin
[13/07/2008|09:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\JAM Software
[30/11/2007|16:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[16/04/2007|12:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[13/08/2008|16:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Megaupload
[20/08/2008|13:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\MegauploadToolbar
[19/08/2008|16:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[11/09/2008|09:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[29/06/2007|07:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Nikon
[20/11/2007|18:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\Nokia
[20/11/2007|13:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\PC Suite
[05/09/2007|10:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[20/08/2007|12:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
[14/10/2007|11:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\Screenshot Sender
[22/07/2008|20:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sign sixth locks
[16/04/2007|12:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[22/02/2008|10:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\SystemRequirementsLab
[02/02/2004|22:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[02/05/2007|08:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\vlc
[08/09/2008|09:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\Webroot
[05/02/2004|17:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\WinRAR
[09/07/2008|16:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Zylom
[06/02/2008|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[01/02/2004|18:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[03/08/2007|07:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Babylon
[24/01/2008|19:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[23/04/2007|10:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[30/11/2007|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[07/08/2008|15:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[20/08/2008|13:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EmailNotifier
[02/02/2004|23:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[05/07/2007|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[20/11/2007|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[27/03/2008|10:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[14/05/2007|07:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[02/03/2008|21:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[31/03/2007|09:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[24/06/2007|09:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[02/03/2008|20:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
[20/11/2007|13:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[01/02/2004|18:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[14/06/2008|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecretsOfOlympus
[08/09/2008|09:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[17/09/2008|11:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[30/03/2008|10:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TERMINAL Studio
[21/08/2007|09:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[08/09/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
[16/03/2008|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[16/03/2008|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage(3)
[04/07/2007|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[02/03/2008|21:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/09/2008|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[13/02/2008|18:25] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[04/07/2007|15:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[09/06/2008|14:41] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[08/09/2008|09:46] C:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot
[01/02/2004|14:05] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[18/09/2008 09:45][--a------] C:\WINDOWS\tasks\wrSpySweeperFullSweep.job
[20/09/2008 08:39][--a------] C:\WINDOWS\tasks\GlaryInitialize.job
[20/09/2008 08:39][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[03/02/2004|16:35] C:\Program Files\_ArcadeDownloadFolder
[05/07/2008|11:53] C:\Program Files\Adobe
[18/06/2008|11:15] C:\Program Files\AGEIA Technologies
[31/05/2007|19:00] C:\Program Files\Alcohol Soft
[05/06/2007|22:18] C:\Program Files\Alcohol Toolbar
[02/02/2004|21:55] C:\Program Files\Alwil Software
[29/06/2007|07:38] C:\Program Files\ArcSoft
[23/05/2007|09:44] C:\Program Files\AskTBar
[17/06/2008|14:42] C:\Program Files\Atlantis
[28/01/2008|18:44] C:\Program Files\Audible
[01/02/2004|16:05] C:\Program Files\AvRack
[06/09/2007|07:39] C:\Program Files\Axialis
[21/07/2007|07:04] C:\Program Files\Babylon
[13/07/2008|09:57] C:\Program Files\Bejeweled 2 Deluxe
[28/03/2008|21:02] C:\Program Files\BFG
[16/03/2008|10:59] C:\Program Files\Blip Blop
[21/10/2007|15:06] C:\Program Files\Browser Mouse
[17/09/2008|10:24] C:\Program Files\click-pool
[01/02/2004|14:03] C:\Program Files\ComPlus Applications
[25/03/2007|17:02] C:\Program Files\Core Design
[24/01/2008|15:49] C:\Program Files\Creative
[24/01/2008|15:43] C:\Program Files\Creative Installation Information
[07/09/2007|09:17] C:\Program Files\CursorXP
[29/04/2007|15:42] C:\Program Files\CyberLink
[31/05/2007|15:47] C:\Program Files\DaemonTools_WhenUSave_Installer
[03/02/2004|16:47] C:\Program Files\DemonStarSM1_Shareware
[20/11/2007|13:29] C:\Program Files\DIFX
[31/03/2007|10:13] C:\Program Files\directx
[28/08/2008|10:50] C:\Program Files\DivX
[24/08/2007|10:42] C:\Program Files\DVD Shrink
[13/04/2008|11:00] C:\Program Files\dvdSanta
[05/09/2008|08:42] C:\Program Files\eMule
[05/09/2008|08:41] C:\Program Files\eToro
[19/09/2008|10:06] C:\Program Files\Fichiers communs
[16/04/2007|12:08] C:\Program Files\Free
[28/03/2008|19:09] C:\Program Files\GameHouse
[08/02/2008|18:51] C:\Program Files\Gamenext
[23/07/2008|09:05] C:\Program Files\Glary Utilities
[13/04/2008|11:31] C:\Program Files\Google
[11/04/2008|11:25] C:\Program Files\Hewlett-Packard
[06/07/2007|20:15] C:\Program Files\HP
[11/04/2008|13:14] C:\Program Files\hp deskjet 656c series
[14/06/2007|12:52] C:\Program Files\id Software
[17/12/2007|14:46] C:\Program Files\Inca Ball
[16/05/2008|15:07] C:\Program Files\inKline Global
[07/09/2008|15:52] C:\Program Files\InstallShield Installation Information
[20/08/2008|23:53] C:\Program Files\Internet Explorer
[19/09/2008|19:42] C:\Program Files\Jewel Quest
[19/09/2008|17:30] C:\Program Files\Jewel Quest 2
[13/08/2008|16:01] C:\Program Files\Megaupload
[18/09/2008|11:25] C:\Program Files\Messenger
[07/09/2008|17:57] C:\Program Files\Messenger Plus! Live
[05/04/2008|11:09] C:\Program Files\Micro Application
[17/06/2008|14:43] C:\Program Files\Microids
[01/02/2004|14:06] C:\Program Files\microsoft frontpage
[16/06/2007|11:32] C:\Program Files\Microsoft Games
[03/02/2004|18:34] C:\Program Files\Microsoft Office
[03/02/2004|18:34] C:\Program Files\Microsoft.NET
[14/06/2007|19:33] C:\Program Files\MOTYS 2001
[18/09/2008|11:20] C:\Program Files\Movie Maker
[20/09/2008|11:15] C:\Program Files\Mozilla Firefox
[31/03/2007|07:13] C:\Program Files\Mplayer
[01/02/2004|16:17] C:\Program Files\MSI
[18/09/2008|11:20] C:\Program Files\msn
[01/02/2004|14:03] C:\Program Files\MSN Gaming Zone
[21/04/2007|16:47] C:\Program Files\MSXML 4.0
[10/09/2008|18:14] C:\Program Files\Navilog1
[24/04/2007|18:26] C:\Program Files\Nero
[18/09/2008|11:14] C:\Program Files\NetMeeting
[29/06/2007|07:40] C:\Program Files\Nikon
[20/11/2007|19:17] C:\Program Files\Nokia
[18/09/2008|11:14] C:\Program Files\Outlook Express
[20/11/2007|21:24] C:\Program Files\PC Connectivity Solution
[06/02/2008|19:21] C:\Program Files\Pixs
[21/08/2007|09:33] C:\Program Files\PopCap Games
[18/02/2008|11:16] C:\Program Files\PowerPoint Viewer
[19/06/2008|11:18] C:\Program Files\Project64 1.6
[07/02/2004|11:10] C:\Program Files\Real
[01/02/2004|16:05] C:\Program Files\Realtek AC97
[01/02/2004|16:05] C:\Program Files\Realtek Sound Manager
[28/08/2007|11:12] C:\Program Files\ReflexiveArcade
[13/04/2008|11:01] C:\Program Files\Ricochet Xtreme
[09/05/2008|09:55] C:\Program Files\Secrets Of Olympus
[01/02/2004|14:05] C:\Program Files\Services en ligne
[01/02/2004|16:50] C:\Program Files\Setup Files
[24/12/2007|11:15] C:\Program Files\Sign sixth locks
[31/05/2007|14:46] C:\Program Files\SlySoft
[18/05/2007|09:23] C:\Program Files\Soft4Ever
[28/10/2007|12:30] C:\Program Files\Space Invaders OpenGL
[07/09/2008|17:43] C:\Program Files\Spybot - Search & Destroy
[17/09/2008|12:29] C:\Program Files\Trend Micro
[01/02/2004|14:25] C:\Program Files\Uninstall Information
[18/06/2008|11:17] C:\Program Files\Unreal Tournament 3
[18/05/2007|13:15] C:\Program Files\UT
[01/01/2008|19:32] C:\Program Files\Veoh Networks
[02/05/2007|08:18] C:\Program Files\VideoLAN
[08/09/2008|09:43] C:\Program Files\Webroot
[29/10/2007|19:47] C:\Program Files\WIDCOMM
[17/04/2007|14:34] C:\Program Files\WinAVIVideoConverter
[04/07/2007|15:40] C:\Program Files\Windows Live
[02/06/2008|18:03] C:\Program Files\Windows Media Connect 2
[18/09/2008|11:14] C:\Program Files\Windows Media Player
[18/09/2008|11:14] C:\Program Files\Windows NT
[20/04/2007|11:21] C:\Program Files\WindowsUpdate
[17/04/2007|07:47] C:\Program Files\WinHTTrack
[29/04/2007|12:39] C:\Program Files\WinRAR
[06/06/2007|13:22] C:\Program Files\Xbox Controller
[01/02/2004|14:06] C:\Program Files\xerox
[10/07/2008|11:13] C:\Program Files\Zylom Games
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[06/02/2008|19:21] C:\Program Files\Fichiers communs\Adobe
[24/04/2007|16:53] C:\Program Files\Fichiers communs\Ahead
[24/01/2008|15:42] C:\Program Files\Fichiers communs\Creative
[03/02/2004|18:34] C:\Program Files\Fichiers communs\DESIGNER
[05/07/2007|10:01] C:\Program Files\Fichiers communs\Hewlett-Packard
[14/06/2007|11:38] C:\Program Files\Fichiers communs\InstallShield
[01/02/2004|17:29] C:\Program Files\Fichiers communs\Java
[23/07/2008|08:58] C:\Program Files\Fichiers communs\Microsoft Shared
[01/02/2004|14:04] C:\Program Files\Fichiers communs\MSSoap
[29/06/2007|07:47] C:\Program Files\Fichiers communs\Nikon
[01/02/2004|18:10] C:\Program Files\Fichiers communs\NSV
[01/02/2004|13:57] C:\Program Files\Fichiers communs\ODBC
[14/09/2007|16:39] C:\Program Files\Fichiers communs\Real
[01/02/2004|14:04] C:\Program Files\Fichiers communs\Services
[01/02/2004|13:57] C:\Program Files\Fichiers communs\SpeechEngines
[18/09/2008|11:14] C:\Program Files\Fichiers communs\System
[16/03/2008|10:27] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[18/06/2008|11:15] C:\Program Files\Fichiers communs\Wise Installation Wizard
[14/09/2007|16:39] C:\Program Files\Fichiers communs\xing shared
--------------------\\ Process
( 48 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 11:27:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 63
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Atlantis - Big Fish Games - Reflexive Arcade + Keygen.rar
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel Quest 2 02Keygen.exe
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel.Quest.II.v2.02.WinALL.Incl.Keygen-ECLiPSE=.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\divX converter 6.2 keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look N Stop v2.05p2 With Keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look'n'Stop 2.05_FR_keygen_par_PiStOuDaMoUr.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\adobelm.dll
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\lisezmoi.txt
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\tw10122.dat
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Cdrwin v6.1.1.0 Incl Keygen.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\CloneCD 5.2.9.1 - Crack.exe
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Nero Vision Express 3.1.0.21 Keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\CJA6KEJS\Crack2[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\GHFJIY05\Crack[1].html
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\N8QLJX6B\Crack[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\Mes fichiers re‡us\quake 4\quake.4.keygen-tsrh.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\keygen.nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\Quake.4-DEViANCE.ShadowCast.[shareprovider.com].nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 06 - La patrouille de douane (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 09 - Le jour de no‰l (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 11 - L'avalanche (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 01_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 02_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 03_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et Sebastien 04 Le Feuilleton Des Nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 05 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 07 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 08 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 10 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 12 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 13 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Colargol - 01 - Un Matin Au Bois Joli - By Chrix.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les aventures de Poly - 01 de 13 - L'arriv‚e au cirque.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les_Idiots.avi
[F:13][D:2]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
[F:2][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
[F:4334][D:6]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 20/09/2008|10:48 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 20/09/2008|11:33 - Option : [2]
--------------------\\ Fin du rapport a 11:33:55
---> Supprime Lop S&D
---> Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
---> Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
-----------\\ ToolBar S&D 1.2.0 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1201 [VPS 080908-0] 4.8.1201 (Activated)
Firewall : Look 'n' Stop 2.05p2 (Soft4Ever) 2.05p2 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 74 Go Free : 9 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 14-09-2008|23:30 )
Option : [1] ( 20/09/2008|12:10 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskTBar
C:\Program Files\AskTBar\bar
C:\Program Files\AskTBar\PopSwatr
C:\Program Files\AskTBar\SrchAstt
C:\DOCUME~1\ADMINI~1\Cookies\administrateur@mysearch[1].txt
\...\{7009fcd4-05be-44f4-9583-93fe419ab7b0} - (multi_media_france)
-----------\\ Extensions
(Administrateur) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Administrateur) - {7009fcd4-05be-44f4-9583-93fe419ab7b0} => multi_media_france
(Administrateur) - {991A772A-BA13-4c1d-A9EF-F897F31DEC7D} => megaupload
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Update_Check_Page"="http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update"
"Search Bar"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Atlantis - Big Fish Games - Reflexive Arcade + Keygen.rar
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel Quest 2 02Keygen.exe
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel.Quest.II.v2.02.WinALL.Incl.Keygen-ECLiPSE=.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\divX converter 6.2 keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look N Stop v2.05p2 With Keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look'n'Stop 2.05_FR_keygen_par_PiStOuDaMoUr.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\adobelm.dll
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\lisezmoi.txt
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\tw10122.dat
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Cdrwin v6.1.1.0 Incl Keygen.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\CloneCD 5.2.9.1 - Crack.exe
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Nero Vision Express 3.1.0.21 Keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\CJA6KEJS\Crack2[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\GHFJIY05\Crack[1].html
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\N8QLJX6B\Crack[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\Mes fichiers re‡us\quake 4\quake.4.keygen-tsrh.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\keygen.nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\Quake.4-DEViANCE.ShadowCast.[shareprovider.com].nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 06 - La patrouille de douane (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 09 - Le jour de no‰l (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 11 - L'avalanche (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 01_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 02_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 03_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et Sebastien 04 Le Feuilleton Des Nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 05 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 07 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 08 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 10 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 12 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 13 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Colargol - 01 - Un Matin Au Bois Joli - By Chrix.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les aventures de Poly - 01 de 13 - L'arriv‚e au cirque.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les_Idiots.avi
1 - "C:\ToolBar SD\TB_1.txt" - 20/09/2008|12:16 - Option : [1]
-----------\\ Fin du rapport a 12:16:44,23
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1201 [VPS 080908-0] 4.8.1201 (Activated)
Firewall : Look 'n' Stop 2.05p2 (Soft4Ever) 2.05p2 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 74 Go Free : 9 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 14-09-2008|23:30 )
Option : [1] ( 20/09/2008|12:10 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskTBar
C:\Program Files\AskTBar\bar
C:\Program Files\AskTBar\PopSwatr
C:\Program Files\AskTBar\SrchAstt
C:\DOCUME~1\ADMINI~1\Cookies\administrateur@mysearch[1].txt
\...\{7009fcd4-05be-44f4-9583-93fe419ab7b0} - (multi_media_france)
-----------\\ Extensions
(Administrateur) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Administrateur) - {7009fcd4-05be-44f4-9583-93fe419ab7b0} => multi_media_france
(Administrateur) - {991A772A-BA13-4c1d-A9EF-F897F31DEC7D} => megaupload
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Update_Check_Page"="http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update"
"Search Bar"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Atlantis - Big Fish Games - Reflexive Arcade + Keygen.rar
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel Quest 2 02Keygen.exe
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel.Quest.II.v2.02.WinALL.Incl.Keygen-ECLiPSE=.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\divX converter 6.2 keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look N Stop v2.05p2 With Keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look'n'Stop 2.05_FR_keygen_par_PiStOuDaMoUr.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\adobelm.dll
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\lisezmoi.txt
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\tw10122.dat
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Cdrwin v6.1.1.0 Incl Keygen.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\CloneCD 5.2.9.1 - Crack.exe
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Nero Vision Express 3.1.0.21 Keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\CJA6KEJS\Crack2[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\GHFJIY05\Crack[1].html
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\N8QLJX6B\Crack[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\Mes fichiers re‡us\quake 4\quake.4.keygen-tsrh.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\keygen.nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\Quake.4-DEViANCE.ShadowCast.[shareprovider.com].nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 06 - La patrouille de douane (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 09 - Le jour de no‰l (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 11 - L'avalanche (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 01_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 02_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 03_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et Sebastien 04 Le Feuilleton Des Nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 05 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 07 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 08 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 10 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 12 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 13 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Colargol - 01 - Un Matin Au Bois Joli - By Chrix.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les aventures de Poly - 01 de 13 - L'arriv‚e au cirque.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les_Idiots.avi
1 - "C:\ToolBar SD\TB_1.txt" - 20/09/2008|12:16 - Option : [1]
-----------\\ Fin du rapport a 12:16:44,23
Fais l'option 2 de ToolBar S&D.
-----------\\ ToolBar S&D 1.2.0 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1201 [VPS 080908-0] 4.8.1201 (Activated)
Firewall : Look 'n' Stop 2.05p2 (Soft4Ever) 2.05p2 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 74 Go Free : 9 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 14-09-2008|23:30 )
Option : [2] ( 20/09/2008|12:34 )
-----------\\ SUPPRESSION
Supprime! - C:\Program Files\AskTBar\bar
Supprime! - C:\Program Files\AskTBar\PopSwatr
Supprime! - C:\Program Files\AskTBar\SrchAstt
Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrateur@mysearch[1].txt
Supprime! - C:\Program Files\AskTBar
Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\92SFYK~1.DEF\EXTENS~1\{7009fcd4-05be-44f4-9583-93fe419ab7b0}
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(Administrateur) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Administrateur) - {991A772A-BA13-4c1d-A9EF-F897F31DEC7D} => megaupload
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Update_Check_Page"="http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update"
"Search Bar"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Atlantis - Big Fish Games - Reflexive Arcade + Keygen.rar
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel Quest 2 02Keygen.exe
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel.Quest.II.v2.02.WinALL.Incl.Keygen-ECLiPSE=.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\divX converter 6.2 keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look N Stop v2.05p2 With Keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look'n'Stop 2.05_FR_keygen_par_PiStOuDaMoUr.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\adobelm.dll
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\lisezmoi.txt
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\tw10122.dat
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Cdrwin v6.1.1.0 Incl Keygen.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\CloneCD 5.2.9.1 - Crack.exe
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Nero Vision Express 3.1.0.21 Keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\CJA6KEJS\Crack2[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\GHFJIY05\Crack[1].html
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\N8QLJX6B\Crack[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\Mes fichiers re‡us\quake 4\quake.4.keygen-tsrh.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\keygen.nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\Quake.4-DEViANCE.ShadowCast.[shareprovider.com].nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 06 - La patrouille de douane (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 09 - Le jour de no‰l (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 11 - L'avalanche (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 01_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 02_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 03_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et Sebastien 04 Le Feuilleton Des Nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 05 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 07 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 08 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 10 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 12 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 13 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Colargol - 01 - Un Matin Au Bois Joli - By Chrix.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les aventures de Poly - 01 de 13 - L'arriv‚e au cirque.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les_Idiots.avi
1 - "C:\ToolBar SD\TB_1.txt" - 20/09/2008|12:16 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 20/09/2008|12:42 - Option : [2]
-----------\\ Fin du rapport a 12:42:34,50
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1201 [VPS 080908-0] 4.8.1201 (Activated)
Firewall : Look 'n' Stop 2.05p2 (Soft4Ever) 2.05p2 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 74 Go Free : 9 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 14-09-2008|23:30 )
Option : [2] ( 20/09/2008|12:34 )
-----------\\ SUPPRESSION
Supprime! - C:\Program Files\AskTBar\bar
Supprime! - C:\Program Files\AskTBar\PopSwatr
Supprime! - C:\Program Files\AskTBar\SrchAstt
Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrateur@mysearch[1].txt
Supprime! - C:\Program Files\AskTBar
Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\92SFYK~1.DEF\EXTENS~1\{7009fcd4-05be-44f4-9583-93fe419ab7b0}
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(Administrateur) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Administrateur) - {991A772A-BA13-4c1d-A9EF-F897F31DEC7D} => megaupload
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Update_Check_Page"="http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update"
"Search Bar"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fsearch%2flobby%2fsearch.asp%3f"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Atlantis - Big Fish Games - Reflexive Arcade + Keygen.rar
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel Quest 2 02Keygen.exe
C:\DOCUME~1\ADMINI~1\Bureau\Raccourcis Bureau non utilis‚s\Jewel.Quest.II.v2.02.WinALL.Incl.Keygen-ECLiPSE=.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\divX converter 6.2 keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look N Stop v2.05p2 With Keygen
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\Look'n'Stop 2.05_FR_keygen_par_PiStOuDaMoUr.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\adobelm.dll
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\lisezmoi.txt
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel\ADOBE_PHOTOSHOP_8_CS_FR_LE_\crack\tw10122.dat
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Cdrwin v6.1.1.0 Incl Keygen.rar
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\CloneCD 5.2.9.1 - Crack.exe
C:\DOCUME~1\ADMINI~1\Mes documents\logiciel 2\Nero Vision Express 3.1.0.21 Keygen.zip
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\CJA6KEJS\Crack2[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\GHFJIY05\Crack[1].html
C:\DOCUME~1\ADMINI~1\Mes documents\LOR\WINDOWS\Temporary Internet Files\Content.IE5\N8QLJX6B\Crack[1].jpg
C:\DOCUME~1\ADMINI~1\Mes documents\Mes fichiers re‡us\quake 4\quake.4.keygen-tsrh.zip
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\keygen.nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\Quake.4-DEViANCE.ShadowCast.[shareprovider.com].nfo
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 06 - La patrouille de douane (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 09 - Le jour de no‰l (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\(S‚rie) Belle et S‚bastien (Medhi (1967)) - 11 - L'avalanche (by Ilove).avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 01_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 02_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 03_le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et Sebastien 04 Le Feuilleton Des Nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 05 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 07 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 08 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 10 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 12 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Belle et sebastien 13 le feuilleton des nostalgiques.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Colargol - 01 - Un Matin Au Bois Joli - By Chrix.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les aventures de Poly - 01 de 13 - L'arriv‚e au cirque.avi
C:\DOCUME~1\ADMINI~1\Mes documents\Quake 4 serial keygen\films convertis\Les_Idiots.avi
1 - "C:\ToolBar SD\TB_1.txt" - 20/09/2008|12:16 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 20/09/2008|12:42 - Option : [2]
-----------\\ Fin du rapport a 12:42:34,50
---> Supprime ToolBar S&D
---> Poste un nouveau rapport HijackThis
---> Poste un nouveau rapport HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:11:00, on 20/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SoundMan] "C:\WINDOWS\SOUNDMAN.EXE"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Pixs\JRE\bin\jusched.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [LWBMOUSE] "C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe"
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "C:\WINDOWS\system32\rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [CursorXP] "C:\Program Files\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Erreur.lnk = ?
O4 - Startup: ExtConfig.lnk = C:\Mageos.com\Config\ExtConf.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.libertysurf.fr
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15034/CTPID.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - http://bl102w.blu102.mail.live.com/mail/SafeRedirect.aspx?hm__tg=http://65.55.183.87/att/GetAttachment.aspx&hm__qs=file%3da8470c13-d10d-47f9-97bd-334ef9828160.jpg%26ct%3daW1hZ2UvanBlZw_3d_3d%26name%3daW1hZ2UwMDEuanBn%26inline%3d1%26rfc%3d0%26empty%3dFalse%26imgsrc%3dcid%253aimage001.jpg%254001C82328.EB998530&oneredir=1&ip=10.6.0.135&d=d1999&mf=0
Scan saved at 20:11:00, on 20/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SoundMan] "C:\WINDOWS\SOUNDMAN.EXE"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Pixs\JRE\bin\jusched.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [LWBMOUSE] "C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe"
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "C:\WINDOWS\system32\rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [CursorXP] "C:\Program Files\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Erreur.lnk = ?
O4 - Startup: ExtConfig.lnk = C:\Mageos.com\Config\ExtConf.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Pixs\JRE\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.libertysurf.fr
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15034/CTPID.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - http://bl102w.blu102.mail.live.com/mail/SafeRedirect.aspx?hm__tg=http://65.55.183.87/att/GetAttachment.aspx&hm__qs=file%3da8470c13-d10d-47f9-97bd-334ef9828160.jpg%26ct%3daW1hZ2UvanBlZw_3d_3d%26name%3daW1hZ2UwMDEuanBn%26inline%3d1%26rfc%3d0%26empty%3dFalse%26imgsrc%3dcid%253aimage001.jpg%254001C82328.EB998530&oneredir=1&ip=10.6.0.135&d=d1999&mf=0
---> Mets à jour Java :
https://www.java.com/fr/download/manual.jsp
---> Relance HijackThis et choisis Do a system scan only
---> Coche les cases qui sont devant les lignes suivantes :
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SoundMan] "C:\WINDOWS\SOUNDMAN.EXE"
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Pixs\JRE\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.
---> Redémarre ton PC et poste un nouveau rapport HijackThis
https://www.java.com/fr/download/manual.jsp
---> Relance HijackThis et choisis Do a system scan only
---> Coche les cases qui sont devant les lignes suivantes :
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SoundMan] "C:\WINDOWS\SOUNDMAN.EXE"
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Pixs\JRE\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.
---> Redémarre ton PC et poste un nouveau rapport HijackThis
voici le rapport merci pour ton aideLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:04:26, on 22/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [LWBMOUSE] "C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe"
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "C:\WINDOWS\system32\rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [CursorXP] "C:\Program Files\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Startup: Erreur.lnk = ?
O4 - Startup: ExtConfig.lnk = C:\Mageos.com\Config\ExtConf.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.libertysurf.fr
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15034/CTPID.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - http://bl102w.blu102.mail.live.com/mail/SafeRedirect.aspx?hm__tg=http://65.55.183.87/att/GetAttachment.aspx&hm__qs=file%3da8470c13-d10d-47f9-97bd-334ef9828160.jpg%26ct%3daW1hZ2UvanBlZw_3d_3d%26name%3daW1hZ2UwMDEuanBn%26inline%3d1%26rfc%3d0%26empty%3dFalse%26imgsrc%3dcid%253aimage001.jpg%254001C82328.EB998530&oneredir=1&ip=10.6.0.135&d=d1999&mf=0
Scan saved at 13:04:26, on 22/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [LWBMOUSE] "C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe"
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "C:\WINDOWS\system32\rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Pixs\Reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [CursorXP] "C:\Program Files\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Startup: Erreur.lnk = ?
O4 - Startup: ExtConfig.lnk = C:\Mageos.com\Config\ExtConf.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.libertysurf.fr
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15034/CTPID.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - http://bl102w.blu102.mail.live.com/mail/SafeRedirect.aspx?hm__tg=http://65.55.183.87/att/GetAttachment.aspx&hm__qs=file%3da8470c13-d10d-47f9-97bd-334ef9828160.jpg%26ct%3daW1hZ2UvanBlZw_3d_3d%26name%3daW1hZ2UwMDEuanBn%26inline%3d1%26rfc%3d0%26empty%3dFalse%26imgsrc%3dcid%253aimage001.jpg%254001C82328.EB998530&oneredir=1&ip=10.6.0.135&d=d1999&mf=0