Fenetres CID sous vista
sensationbidon
Messages postés
4
Statut
Membre
-
sensationbidon Messages postés 4 Statut Membre -
sensationbidon Messages postés 4 Statut Membre -
Bonjour,
depuis quelques jours des fenêtres CiD apparaissent quand j'ouvre une page internet. J'ai supprimé msn live +, rien à faire.
Je copie colle le rapport hijackthis, si quelqu'un pouvait me dire quelles lignes pourraient etre suspectes ? Merci
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:17:50, on 20/09/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Sony\WALKMAN Launcher\WMAAD.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Common Files\ACD Systems\FR\DevDetect.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.mini15.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [WMAAD] C:\Program Files\Sony\WALKMAN Launcher\WMAAD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [logo owns] "C:\ProgramData\web thunk thunk.5ca6s2"
O4 - HKCU\..\Run: [Bags Else Hole Lite] "C:\ProgramData\bags style junk.hudbbm"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
O13 - Gopher Prefix:
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Image Converter SCSI Service (ICScsiSV) - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe
O23 - Service: IcVzMonLauncher - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
depuis quelques jours des fenêtres CiD apparaissent quand j'ouvre une page internet. J'ai supprimé msn live +, rien à faire.
Je copie colle le rapport hijackthis, si quelqu'un pouvait me dire quelles lignes pourraient etre suspectes ? Merci
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:17:50, on 20/09/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Sony\WALKMAN Launcher\WMAAD.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Common Files\ACD Systems\FR\DevDetect.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.mini15.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [WMAAD] C:\Program Files\Sony\WALKMAN Launcher\WMAAD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [logo owns] "C:\ProgramData\web thunk thunk.5ca6s2"
O4 - HKCU\..\Run: [Bags Else Hole Lite] "C:\ProgramData\bags style junk.hudbbm"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
O13 - Gopher Prefix:
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Image Converter SCSI Service (ICScsiSV) - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe
O23 - Service: IcVzMonLauncher - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
A voir également:
- Fenetres CID sous vista
- Windows vista - Télécharger - Divers Utilitaires
- Clé windows vista - Guide
- Windows Vista SP1 - Télécharger - Divers Utilitaires
- Fermer toutes les fenetres windows - Guide
- Passer de vista à windows 7 gratuitement sans cd ✓ - Forum Windows 7
4 réponses
tu télécharge Lop S&D.exe sur ton Bureau.https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
* Double-clique dessus pour lancer l'installation
* Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
* Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)
* Double-clique dessus pour lancer l'installation
* Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
* Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)
voila !
--------------------\\ Lop S&D 4.2.4-4 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2310 @ 1.46GHz )
BIOS : Ver 1.00PARTTBL
USER : celine ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total : 93 Go Free : 6 Go
E:\ (Local Disk) - NTFS - Total : 91 Go Free : 82 Go
F:\ (CD or DVD) - CDFS - Total : 4 Go Free : 0 Go
"C:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [1] ( 20/09/2008|14:05 )
[ UAC => 1 ]
--------------------\\ Listing des dossiers dans Local
[05/04/2008|17:02] C:\Users\celine\AppData\Local\ACD Systems
[05/05/2008|12:47] C:\Users\celine\AppData\Local\Adobe
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Application Data
[15/11/2007|16:56] C:\Users\celine\AppData\Local\ATI
[12/07/2008|14:57] C:\Users\celine\AppData\Local\d3d9caps.dat
[16/08/2008|00:11] C:\Users\celine\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[05/04/2008|17:00] C:\Users\celine\AppData\Local\Downloaded Installations
[19/09/2008|20:39] C:\Users\celine\AppData\Local\eMule
[15/11/2007|19:45] C:\Users\celine\AppData\Local\GDIPFONTCACHEV1.DAT
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Historique
[20/09/2008|00:46] C:\Users\celine\AppData\Local\IconCache.db
[18/06/2008|18:15] C:\Users\celine\AppData\Local\LogMeIn
[09/03/2008|20:46] C:\Users\celine\AppData\Local\Microsoft
[23/02/2008|02:28] C:\Users\celine\AppData\Local\Microsoft Games
[23/11/2007|16:44] C:\Users\celine\AppData\Local\Mozilla
[09/03/2008|21:00] C:\Users\celine\AppData\Local\Netlog
[20/09/2008|14:03] C:\Users\celine\AppData\Local\Temp
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Temporary Internet Files
[15/11/2007|16:56] C:\Users\celine\AppData\Local\Toshiba
[15/11/2007|19:58] C:\Users\celine\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[20/09/2008 00:48][--ah-----] C:\Windows\tasks\SA.DAT
[20/09/2008 00:47][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[05/04/2008|17:01] C:\ProgramData\ACD Systems
[05/05/2008|12:46] C:\ProgramData\Adobe
[02/11/2006|15:02] C:\ProgramData\Application Data
[15/11/2007|15:42] C:\ProgramData\Atheros
[19/09/2008|20:54] C:\ProgramData\Avira
[20/09/2008|00:55] C:\ProgramData\bags style junk.hudbbm
[15/11/2007|16:45] C:\ProgramData\Bureau
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[19/09/2008|20:39] C:\ProgramData\eMule
[18/06/2008|18:26] C:\ProgramData\ESET
[01/03/2008|01:34] C:\ProgramData\ezsid.dat
[10/08/2008|20:19] C:\ProgramData\ezsidmv.dat
[15/11/2007|16:45] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[20/09/2008|00:55] C:\ProgramData\gram delete for
[20/09/2008|00:55] C:\ProgramData\Iso Web Bags Else
[18/06/2008|18:15] C:\ProgramData\LogMeIn
[15/11/2007|16:45] C:\ProgramData\Menu D‚marrer
[17/11/2007|15:18] C:\ProgramData\Microsoft
[15/11/2007|16:45] C:\ProgramData\ModŠles
[15/11/2007|17:30] C:\ProgramData\SBT
[16/09/2008|08:13] C:\ProgramData\Skype
[08/03/2008|19:48] C:\ProgramData\SonicStage
[08/03/2008|19:48] C:\ProgramData\Sony Corporation
[18/06/2008|18:09] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[22/12/2007|23:23] C:\ProgramData\Symantec
[20/09/2008|12:35] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[15/11/2007|16:54] C:\ProgramData\Toshiba
[15/11/2007|16:50] C:\ProgramData\ToshibaEurope
[10/07/2007|16:49] C:\ProgramData\Ulead Systems
[10/07/2007|16:36] C:\ProgramData\Vista64
[17/11/2007|18:44] C:\ProgramData\web thunk thunk.39yy4u
[20/09/2008|00:54] C:\ProgramData\web thunk thunk.5ca6s2
[17/11/2007|16:33] C:\ProgramData\web thunk thunk.5mlgrgp
[17/11/2007|20:12] C:\ProgramData\web thunk thunk.5z9eioo
[17/11/2007|19:50] C:\ProgramData\web thunk thunk.7j0nlb
[17/11/2007|18:01] C:\ProgramData\web thunk thunk.96x7g
[17/11/2007|20:49] C:\ProgramData\web thunk thunk.9dbyr80
[15/11/2007|20:44] C:\ProgramData\web thunk thunk.9mm3t
[17/11/2007|23:13] C:\ProgramData\web thunk thunk.9pbb9g
[20/09/2008|00:54] C:\ProgramData\web thunk thunk.9t5l8v
[17/11/2007|22:29] C:\ProgramData\web thunk thunk.cu0xx5f
[17/11/2007|17:39] C:\ProgramData\web thunk thunk.dqcyp
[17/11/2007|15:50] C:\ProgramData\web thunk thunk.ensw5yu
[17/11/2007|22:51] C:\ProgramData\web thunk thunk.ep5b8k
[20/12/2007|21:50] C:\ProgramData\web thunk thunk.fah8t
[17/11/2007|16:11] C:\ProgramData\web thunk thunk.fqjmm
[28/12/2007|12:29] C:\ProgramData\web thunk thunk.gtr5nuu
[17/11/2007|19:28] C:\ProgramData\web thunk thunk.ieg2i5m
[28/12/2007|11:00] C:\ProgramData\web thunk thunk.igf3r
[17/11/2007|18:23] C:\ProgramData\web thunk thunk.kvkcro
[17/11/2007|17:17] C:\ProgramData\web thunk thunk.lffm8
[18/11/2007|00:19] C:\ProgramData\web thunk thunk.n9fs1
[17/11/2007|22:08] C:\ProgramData\web thunk thunk.ni5q7
[17/11/2007|21:46] C:\ProgramData\web thunk thunk.odnenk
[17/11/2007|23:57] C:\ProgramData\web thunk thunk.pcuwtc
[17/11/2007|19:06] C:\ProgramData\web thunk thunk.ppc02
[17/11/2007|23:35] C:\ProgramData\web thunk thunk.px9q8n4
[17/11/2007|21:11] C:\ProgramData\web thunk thunk.qsabx
[28/12/2007|11:45] C:\ProgramData\web thunk thunk.rzzinl
[17/11/2007|16:55] C:\ProgramData\web thunk thunk.t2k99ec
[12/09/2008|05:17] C:\ProgramData\web thunk thunk.vbrse9h
[28/12/2007|12:51] C:\ProgramData\web thunk thunk.w54a8
[28/12/2007|11:00] C:\ProgramData\web thunk thunk.xc1squb
[28/12/2007|12:07] C:\ProgramData\web thunk thunk.z4zbw
[15/11/2007|20:44] C:\ProgramData\web thunk thunk.z7zgpuo
[28/12/2007|11:23] C:\ProgramData\web thunk thunk.zuq4dw
[16/06/2008|23:15] C:\ProgramData\WLInstaller
[10/07/2007|16:36] C:\ProgramData\XP
[20/09/2008|00:51] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[05/04/2008|17:01] C:\Program Files\ACD Systems
[05/05/2008|12:44] C:\Program Files\Adobe
[15/11/2007|19:14] C:\Program Files\Alwil Software
[20/09/2008|00:21] C:\Program Files\a-squared Free
[15/11/2007|15:42] C:\Program Files\Atheros
[15/11/2007|15:33] C:\Program Files\ATI
[15/11/2007|15:35] C:\Program Files\ATI Technologies
[19/09/2008|20:54] C:\Program Files\Avira
[15/11/2007|15:36] C:\Program Files\Camera Assistant Software for Toshiba
[20/09/2008|00:13] C:\Program Files\CCleaner
[16/09/2008|08:13] C:\Program Files\Common Files
[15/04/2008|19:20] C:\Program Files\DivX
[16/09/2008|08:12] C:\Program Files\eMule
[15/11/2007|16:45] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[18/04/2007|09:08] C:\Program Files\IDM
[16/09/2008|08:15] C:\Program Files\InstallShield Installation Information
[15/11/2007|16:53] C:\Program Files\Intel
[02/07/2008|16:08] C:\Program Files\Internet Explorer
[10/07/2007|16:49] C:\Program Files\InterVideo
[18/04/2007|07:44] C:\Program Files\Java
[18/04/2007|08:05] C:\Program Files\ltmoh
[16/11/2007|10:46] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[15/11/2007|17:30] C:\Program Files\Microsoft Office
[15/11/2007|20:41] C:\Program Files\Microsoft SQL Server Compact Edition
[02/07/2008|16:08] C:\Program Files\Movie Maker
[20/09/2008|12:34] C:\Program Files\Mozilla Firefox
[02/11/2006|14:37] C:\Program Files\MSBuild
[10/07/2007|15:49] C:\Program Files\MSXML 4.0
[18/04/2007|08:14] C:\Program Files\My Company Name
[18/04/2007|09:08] C:\Program Files\myphotobook
[18/06/2008|18:22] C:\Program Files\OrangeHSS
[10/07/2007|16:24] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[29/04/2008|10:20] C:\Program Files\Samsung
[15/11/2007|17:30] C:\Program Files\Snapshot Viewer
[06/03/2008|23:04] C:\Program Files\Sony
[19/06/2008|09:32] C:\Program Files\Spybot - Search & Destroy
[20/09/2008|12:35] C:\Program Files\Spyware Doctor
[15/11/2007|15:42] C:\Program Files\Synaptics
[15/11/2007|16:53] C:\Program Files\TOSHIBA
[20/09/2008|13:13] C:\Program Files\Trend Micro
[10/07/2007|16:46] C:\Program Files\Ulead Systems
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[16/11/2007|17:16] C:\Program Files\VideoLAN
[02/07/2008|16:08] C:\Program Files\Windows Calendar
[02/07/2008|16:08] C:\Program Files\Windows Collaboration
[02/07/2008|16:07] C:\Program Files\Windows Defender
[02/07/2008|16:08] C:\Program Files\Windows Journal
[17/09/2008|23:12] C:\Program Files\Windows Live
[13/08/2008|03:10] C:\Program Files\Windows Mail
[18/04/2007|08:46] C:\Program Files\Windows Media Components
[02/07/2008|16:08] C:\Program Files\Windows Media Player
[15/11/2007|16:45] C:\Program Files\Windows NT
[02/07/2008|16:07] C:\Program Files\Windows Photo Gallery
[02/07/2008|16:08] C:\Program Files\Windows Sidebar
[23/02/2008|11:58] C:\Program Files\WinRAR
[20/09/2008|00:13] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[05/04/2008|17:02] C:\Program Files\Common Files\ACD Systems
[05/05/2008|12:45] C:\Program Files\Common Files\Adobe
[15/11/2007|17:24] C:\Program Files\Common Files\Designer
[18/04/2007|08:47] C:\Program Files\Common Files\InstallShield
[18/04/2007|07:44] C:\Program Files\Common Files\Java
[15/11/2007|20:39] C:\Program Files\Common Files\microsoft shared
[23/11/2007|17:11] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[06/03/2008|23:06] C:\Program Files\Common Files\Sony Shared
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[22/12/2007|23:23] C:\Program Files\Common Files\Symantec Shared
[02/07/2008|16:07] C:\Program Files\Common Files\System
[15/11/2007|16:54] C:\Program Files\Common Files\Toshiba Shared
[10/07/2007|16:49] C:\Program Files\Common Files\Ulead Systems
[15/11/2007|20:39] C:\Program Files\Common Files\WindowsLiveInstaller
--------------------\\ Process
( 77 Processes )
iexplore.exe ~ [PID:6092]
iexplore.exe ~ [PID:4312]
--------------------\\ Recherche avec S_Lop
C:\ProgramData\web thunk thunk.96x7g
C:\ProgramData\web thunk thunk.9mm3t
C:\ProgramData\web thunk thunk.dqcyp
C:\ProgramData\web thunk thunk.fah8t
C:\ProgramData\web thunk thunk.fqjmm
C:\ProgramData\web thunk thunk.igf3r
C:\ProgramData\web thunk thunk.lffm8
C:\ProgramData\web thunk thunk.n9fs1
C:\ProgramData\web thunk thunk.ni5q7
C:\ProgramData\web thunk thunk.ppc02
C:\ProgramData\web thunk thunk.qsabx
C:\ProgramData\web thunk thunk.w54a8
C:\ProgramData\web thunk thunk.z4zbw
C:\ProgramData\bags style junk.hudbbm
C:\ProgramData\web thunk thunk.39yy4u
C:\ProgramData\web thunk thunk.5ca6s2
C:\ProgramData\web thunk thunk.7j0nlb
C:\ProgramData\web thunk thunk.9pbb9g
C:\ProgramData\web thunk thunk.9t5l8v
C:\ProgramData\web thunk thunk.ep5b8k
C:\ProgramData\web thunk thunk.kvkcro
C:\ProgramData\web thunk thunk.odnenk
C:\ProgramData\web thunk thunk.pcuwtc
C:\ProgramData\web thunk thunk.rzzinl
C:\ProgramData\web thunk thunk.zuq4dw
C:\ProgramData\web thunk thunk.5mlgrgp
C:\ProgramData\web thunk thunk.5z9eioo
C:\ProgramData\web thunk thunk.9dbyr80
C:\ProgramData\web thunk thunk.cu0xx5f
C:\ProgramData\web thunk thunk.ensw5yu
C:\ProgramData\web thunk thunk.gtr5nuu
C:\ProgramData\web thunk thunk.ieg2i5m
C:\ProgramData\web thunk thunk.px9q8n4
C:\ProgramData\web thunk thunk.t2k99ec
C:\ProgramData\web thunk thunk.vbrse9h
C:\ProgramData\web thunk thunk.xc1squb
C:\ProgramData\web thunk thunk.z7zgpuo
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\ProgramData\gram delete for
C:\ProgramData\gram delete for\HOLD SOFTWARE TONS.exe
C:\ProgramData\gram delete for\kaoucsqy.exe
C:\ProgramData\gram delete for\omrbqqff.exe
C:\ProgramData\gram delete for\Regs Mess Plus Fast.exe
C:\ProgramData\Iso Web Bags Else
C:\ProgramData\Iso Web Bags Else\Vga fast.exe
C:\Users\celine\AppData\Roaming\MICROS~1\Windows\Cookies\celine@adopt.euroclick[1].txt
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"logo owns"="\"C:\\ProgramData\\web thunk thunk.5ca6s2\""
"Bags Else Hole Lite"="\"C:\\ProgramData\\bags style junk.hudbbm\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 14:05:41
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 157
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:37][D:5]-> C:\Users\celine\AppData\Local\Temp
[F:29][D:1]-> C:\Users\celine\AppData\Roaming\MICROS~1\Windows\Cookies
[F:446][D:4]-> C:\Users\celine\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:5327][D:716]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 20/09/2008|14:07 - Option : [1]
--------------------\\ Fin du rapport a 14:07:27
[ UAC => 1 ]
--------------------\\ Lop S&D 4.2.4-4 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2310 @ 1.46GHz )
BIOS : Ver 1.00PARTTBL
USER : celine ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total : 93 Go Free : 6 Go
E:\ (Local Disk) - NTFS - Total : 91 Go Free : 82 Go
F:\ (CD or DVD) - CDFS - Total : 4 Go Free : 0 Go
"C:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [1] ( 20/09/2008|14:05 )
[ UAC => 1 ]
--------------------\\ Listing des dossiers dans Local
[05/04/2008|17:02] C:\Users\celine\AppData\Local\ACD Systems
[05/05/2008|12:47] C:\Users\celine\AppData\Local\Adobe
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Application Data
[15/11/2007|16:56] C:\Users\celine\AppData\Local\ATI
[12/07/2008|14:57] C:\Users\celine\AppData\Local\d3d9caps.dat
[16/08/2008|00:11] C:\Users\celine\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[05/04/2008|17:00] C:\Users\celine\AppData\Local\Downloaded Installations
[19/09/2008|20:39] C:\Users\celine\AppData\Local\eMule
[15/11/2007|19:45] C:\Users\celine\AppData\Local\GDIPFONTCACHEV1.DAT
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Historique
[20/09/2008|00:46] C:\Users\celine\AppData\Local\IconCache.db
[18/06/2008|18:15] C:\Users\celine\AppData\Local\LogMeIn
[09/03/2008|20:46] C:\Users\celine\AppData\Local\Microsoft
[23/02/2008|02:28] C:\Users\celine\AppData\Local\Microsoft Games
[23/11/2007|16:44] C:\Users\celine\AppData\Local\Mozilla
[09/03/2008|21:00] C:\Users\celine\AppData\Local\Netlog
[20/09/2008|14:03] C:\Users\celine\AppData\Local\Temp
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Temporary Internet Files
[15/11/2007|16:56] C:\Users\celine\AppData\Local\Toshiba
[15/11/2007|19:58] C:\Users\celine\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[20/09/2008 00:48][--ah-----] C:\Windows\tasks\SA.DAT
[20/09/2008 00:47][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[05/04/2008|17:01] C:\ProgramData\ACD Systems
[05/05/2008|12:46] C:\ProgramData\Adobe
[02/11/2006|15:02] C:\ProgramData\Application Data
[15/11/2007|15:42] C:\ProgramData\Atheros
[19/09/2008|20:54] C:\ProgramData\Avira
[20/09/2008|00:55] C:\ProgramData\bags style junk.hudbbm
[15/11/2007|16:45] C:\ProgramData\Bureau
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[19/09/2008|20:39] C:\ProgramData\eMule
[18/06/2008|18:26] C:\ProgramData\ESET
[01/03/2008|01:34] C:\ProgramData\ezsid.dat
[10/08/2008|20:19] C:\ProgramData\ezsidmv.dat
[15/11/2007|16:45] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[20/09/2008|00:55] C:\ProgramData\gram delete for
[20/09/2008|00:55] C:\ProgramData\Iso Web Bags Else
[18/06/2008|18:15] C:\ProgramData\LogMeIn
[15/11/2007|16:45] C:\ProgramData\Menu D‚marrer
[17/11/2007|15:18] C:\ProgramData\Microsoft
[15/11/2007|16:45] C:\ProgramData\ModŠles
[15/11/2007|17:30] C:\ProgramData\SBT
[16/09/2008|08:13] C:\ProgramData\Skype
[08/03/2008|19:48] C:\ProgramData\SonicStage
[08/03/2008|19:48] C:\ProgramData\Sony Corporation
[18/06/2008|18:09] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[22/12/2007|23:23] C:\ProgramData\Symantec
[20/09/2008|12:35] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[15/11/2007|16:54] C:\ProgramData\Toshiba
[15/11/2007|16:50] C:\ProgramData\ToshibaEurope
[10/07/2007|16:49] C:\ProgramData\Ulead Systems
[10/07/2007|16:36] C:\ProgramData\Vista64
[17/11/2007|18:44] C:\ProgramData\web thunk thunk.39yy4u
[20/09/2008|00:54] C:\ProgramData\web thunk thunk.5ca6s2
[17/11/2007|16:33] C:\ProgramData\web thunk thunk.5mlgrgp
[17/11/2007|20:12] C:\ProgramData\web thunk thunk.5z9eioo
[17/11/2007|19:50] C:\ProgramData\web thunk thunk.7j0nlb
[17/11/2007|18:01] C:\ProgramData\web thunk thunk.96x7g
[17/11/2007|20:49] C:\ProgramData\web thunk thunk.9dbyr80
[15/11/2007|20:44] C:\ProgramData\web thunk thunk.9mm3t
[17/11/2007|23:13] C:\ProgramData\web thunk thunk.9pbb9g
[20/09/2008|00:54] C:\ProgramData\web thunk thunk.9t5l8v
[17/11/2007|22:29] C:\ProgramData\web thunk thunk.cu0xx5f
[17/11/2007|17:39] C:\ProgramData\web thunk thunk.dqcyp
[17/11/2007|15:50] C:\ProgramData\web thunk thunk.ensw5yu
[17/11/2007|22:51] C:\ProgramData\web thunk thunk.ep5b8k
[20/12/2007|21:50] C:\ProgramData\web thunk thunk.fah8t
[17/11/2007|16:11] C:\ProgramData\web thunk thunk.fqjmm
[28/12/2007|12:29] C:\ProgramData\web thunk thunk.gtr5nuu
[17/11/2007|19:28] C:\ProgramData\web thunk thunk.ieg2i5m
[28/12/2007|11:00] C:\ProgramData\web thunk thunk.igf3r
[17/11/2007|18:23] C:\ProgramData\web thunk thunk.kvkcro
[17/11/2007|17:17] C:\ProgramData\web thunk thunk.lffm8
[18/11/2007|00:19] C:\ProgramData\web thunk thunk.n9fs1
[17/11/2007|22:08] C:\ProgramData\web thunk thunk.ni5q7
[17/11/2007|21:46] C:\ProgramData\web thunk thunk.odnenk
[17/11/2007|23:57] C:\ProgramData\web thunk thunk.pcuwtc
[17/11/2007|19:06] C:\ProgramData\web thunk thunk.ppc02
[17/11/2007|23:35] C:\ProgramData\web thunk thunk.px9q8n4
[17/11/2007|21:11] C:\ProgramData\web thunk thunk.qsabx
[28/12/2007|11:45] C:\ProgramData\web thunk thunk.rzzinl
[17/11/2007|16:55] C:\ProgramData\web thunk thunk.t2k99ec
[12/09/2008|05:17] C:\ProgramData\web thunk thunk.vbrse9h
[28/12/2007|12:51] C:\ProgramData\web thunk thunk.w54a8
[28/12/2007|11:00] C:\ProgramData\web thunk thunk.xc1squb
[28/12/2007|12:07] C:\ProgramData\web thunk thunk.z4zbw
[15/11/2007|20:44] C:\ProgramData\web thunk thunk.z7zgpuo
[28/12/2007|11:23] C:\ProgramData\web thunk thunk.zuq4dw
[16/06/2008|23:15] C:\ProgramData\WLInstaller
[10/07/2007|16:36] C:\ProgramData\XP
[20/09/2008|00:51] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[05/04/2008|17:01] C:\Program Files\ACD Systems
[05/05/2008|12:44] C:\Program Files\Adobe
[15/11/2007|19:14] C:\Program Files\Alwil Software
[20/09/2008|00:21] C:\Program Files\a-squared Free
[15/11/2007|15:42] C:\Program Files\Atheros
[15/11/2007|15:33] C:\Program Files\ATI
[15/11/2007|15:35] C:\Program Files\ATI Technologies
[19/09/2008|20:54] C:\Program Files\Avira
[15/11/2007|15:36] C:\Program Files\Camera Assistant Software for Toshiba
[20/09/2008|00:13] C:\Program Files\CCleaner
[16/09/2008|08:13] C:\Program Files\Common Files
[15/04/2008|19:20] C:\Program Files\DivX
[16/09/2008|08:12] C:\Program Files\eMule
[15/11/2007|16:45] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[18/04/2007|09:08] C:\Program Files\IDM
[16/09/2008|08:15] C:\Program Files\InstallShield Installation Information
[15/11/2007|16:53] C:\Program Files\Intel
[02/07/2008|16:08] C:\Program Files\Internet Explorer
[10/07/2007|16:49] C:\Program Files\InterVideo
[18/04/2007|07:44] C:\Program Files\Java
[18/04/2007|08:05] C:\Program Files\ltmoh
[16/11/2007|10:46] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[15/11/2007|17:30] C:\Program Files\Microsoft Office
[15/11/2007|20:41] C:\Program Files\Microsoft SQL Server Compact Edition
[02/07/2008|16:08] C:\Program Files\Movie Maker
[20/09/2008|12:34] C:\Program Files\Mozilla Firefox
[02/11/2006|14:37] C:\Program Files\MSBuild
[10/07/2007|15:49] C:\Program Files\MSXML 4.0
[18/04/2007|08:14] C:\Program Files\My Company Name
[18/04/2007|09:08] C:\Program Files\myphotobook
[18/06/2008|18:22] C:\Program Files\OrangeHSS
[10/07/2007|16:24] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[29/04/2008|10:20] C:\Program Files\Samsung
[15/11/2007|17:30] C:\Program Files\Snapshot Viewer
[06/03/2008|23:04] C:\Program Files\Sony
[19/06/2008|09:32] C:\Program Files\Spybot - Search & Destroy
[20/09/2008|12:35] C:\Program Files\Spyware Doctor
[15/11/2007|15:42] C:\Program Files\Synaptics
[15/11/2007|16:53] C:\Program Files\TOSHIBA
[20/09/2008|13:13] C:\Program Files\Trend Micro
[10/07/2007|16:46] C:\Program Files\Ulead Systems
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[16/11/2007|17:16] C:\Program Files\VideoLAN
[02/07/2008|16:08] C:\Program Files\Windows Calendar
[02/07/2008|16:08] C:\Program Files\Windows Collaboration
[02/07/2008|16:07] C:\Program Files\Windows Defender
[02/07/2008|16:08] C:\Program Files\Windows Journal
[17/09/2008|23:12] C:\Program Files\Windows Live
[13/08/2008|03:10] C:\Program Files\Windows Mail
[18/04/2007|08:46] C:\Program Files\Windows Media Components
[02/07/2008|16:08] C:\Program Files\Windows Media Player
[15/11/2007|16:45] C:\Program Files\Windows NT
[02/07/2008|16:07] C:\Program Files\Windows Photo Gallery
[02/07/2008|16:08] C:\Program Files\Windows Sidebar
[23/02/2008|11:58] C:\Program Files\WinRAR
[20/09/2008|00:13] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[05/04/2008|17:02] C:\Program Files\Common Files\ACD Systems
[05/05/2008|12:45] C:\Program Files\Common Files\Adobe
[15/11/2007|17:24] C:\Program Files\Common Files\Designer
[18/04/2007|08:47] C:\Program Files\Common Files\InstallShield
[18/04/2007|07:44] C:\Program Files\Common Files\Java
[15/11/2007|20:39] C:\Program Files\Common Files\microsoft shared
[23/11/2007|17:11] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[06/03/2008|23:06] C:\Program Files\Common Files\Sony Shared
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[22/12/2007|23:23] C:\Program Files\Common Files\Symantec Shared
[02/07/2008|16:07] C:\Program Files\Common Files\System
[15/11/2007|16:54] C:\Program Files\Common Files\Toshiba Shared
[10/07/2007|16:49] C:\Program Files\Common Files\Ulead Systems
[15/11/2007|20:39] C:\Program Files\Common Files\WindowsLiveInstaller
--------------------\\ Process
( 77 Processes )
iexplore.exe ~ [PID:6092]
iexplore.exe ~ [PID:4312]
--------------------\\ Recherche avec S_Lop
C:\ProgramData\web thunk thunk.96x7g
C:\ProgramData\web thunk thunk.9mm3t
C:\ProgramData\web thunk thunk.dqcyp
C:\ProgramData\web thunk thunk.fah8t
C:\ProgramData\web thunk thunk.fqjmm
C:\ProgramData\web thunk thunk.igf3r
C:\ProgramData\web thunk thunk.lffm8
C:\ProgramData\web thunk thunk.n9fs1
C:\ProgramData\web thunk thunk.ni5q7
C:\ProgramData\web thunk thunk.ppc02
C:\ProgramData\web thunk thunk.qsabx
C:\ProgramData\web thunk thunk.w54a8
C:\ProgramData\web thunk thunk.z4zbw
C:\ProgramData\bags style junk.hudbbm
C:\ProgramData\web thunk thunk.39yy4u
C:\ProgramData\web thunk thunk.5ca6s2
C:\ProgramData\web thunk thunk.7j0nlb
C:\ProgramData\web thunk thunk.9pbb9g
C:\ProgramData\web thunk thunk.9t5l8v
C:\ProgramData\web thunk thunk.ep5b8k
C:\ProgramData\web thunk thunk.kvkcro
C:\ProgramData\web thunk thunk.odnenk
C:\ProgramData\web thunk thunk.pcuwtc
C:\ProgramData\web thunk thunk.rzzinl
C:\ProgramData\web thunk thunk.zuq4dw
C:\ProgramData\web thunk thunk.5mlgrgp
C:\ProgramData\web thunk thunk.5z9eioo
C:\ProgramData\web thunk thunk.9dbyr80
C:\ProgramData\web thunk thunk.cu0xx5f
C:\ProgramData\web thunk thunk.ensw5yu
C:\ProgramData\web thunk thunk.gtr5nuu
C:\ProgramData\web thunk thunk.ieg2i5m
C:\ProgramData\web thunk thunk.px9q8n4
C:\ProgramData\web thunk thunk.t2k99ec
C:\ProgramData\web thunk thunk.vbrse9h
C:\ProgramData\web thunk thunk.xc1squb
C:\ProgramData\web thunk thunk.z7zgpuo
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\ProgramData\gram delete for
C:\ProgramData\gram delete for\HOLD SOFTWARE TONS.exe
C:\ProgramData\gram delete for\kaoucsqy.exe
C:\ProgramData\gram delete for\omrbqqff.exe
C:\ProgramData\gram delete for\Regs Mess Plus Fast.exe
C:\ProgramData\Iso Web Bags Else
C:\ProgramData\Iso Web Bags Else\Vga fast.exe
C:\Users\celine\AppData\Roaming\MICROS~1\Windows\Cookies\celine@adopt.euroclick[1].txt
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"logo owns"="\"C:\\ProgramData\\web thunk thunk.5ca6s2\""
"Bags Else Hole Lite"="\"C:\\ProgramData\\bags style junk.hudbbm\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 14:05:41
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 157
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:37][D:5]-> C:\Users\celine\AppData\Local\Temp
[F:29][D:1]-> C:\Users\celine\AppData\Roaming\MICROS~1\Windows\Cookies
[F:446][D:4]-> C:\Users\celine\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:5327][D:716]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 20/09/2008|14:07 - Option : [1]
--------------------\\ Fin du rapport a 14:07:27
[ UAC => 1 ]
ok relance lop sd et choisi l'option 2 et dis si encore des soucis et colle le rapport
--------------------\\ Lop S&D 4.2.4-4 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2310 @ 1.46GHz )
BIOS : Ver 1.00PARTTBL
USER : celine ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total : 93 Go Free : 6 Go
E:\ (Local Disk) - NTFS - Total : 91 Go Free : 82 Go
F:\ (CD or DVD) - CDFS - Total : 4 Go Free : 0 Go
"C:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [2] ( 20/09/2008|22:08 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\ProgramData\gram delete for\HOLD SOFTWARE TONS.exe
Supprime! - C:\ProgramData\gram delete for\kaoucsqy.exe
Supprime! - C:\ProgramData\gram delete for\omrbqqff.exe
Supprime! - C:\ProgramData\gram delete for\Regs Mess Plus Fast.exe
Supprime! - C:\ProgramData\Iso Web Bags Else\Vga fast.exe
Supprime! - C:\Users\celine\AppData\Roaming\MICROS~1\Windows\Cookies\celine@adopt.euroclick[1].txt
Supprime! - C:\ProgramData\web thunk thunk.96x7g
Supprime! - C:\ProgramData\web thunk thunk.9mm3t
Supprime! - C:\ProgramData\web thunk thunk.dqcyp
Supprime! - C:\ProgramData\web thunk thunk.fah8t
Supprime! - C:\ProgramData\web thunk thunk.fqjmm
Supprime! - C:\ProgramData\web thunk thunk.igf3r
Supprime! - C:\ProgramData\web thunk thunk.lffm8
Supprime! - C:\ProgramData\web thunk thunk.n9fs1
Supprime! - C:\ProgramData\web thunk thunk.ni5q7
Supprime! - C:\ProgramData\web thunk thunk.ppc02
Supprime! - C:\ProgramData\web thunk thunk.qsabx
Supprime! - C:\ProgramData\web thunk thunk.w54a8
Supprime! - C:\ProgramData\web thunk thunk.z4zbw
Supprime! - C:\ProgramData\bags style junk.hudbbm
Supprime! - C:\ProgramData\web thunk thunk.39yy4u
Supprime! - C:\ProgramData\web thunk thunk.5ca6s2
Supprime! - C:\ProgramData\web thunk thunk.7j0nlb
Supprime! - C:\ProgramData\web thunk thunk.9pbb9g
Supprime! - C:\ProgramData\web thunk thunk.9t5l8v
Supprime! - C:\ProgramData\web thunk thunk.ep5b8k
Supprime! - C:\ProgramData\web thunk thunk.kvkcro
Supprime! - C:\ProgramData\web thunk thunk.odnenk
Supprime! - C:\ProgramData\web thunk thunk.pcuwtc
Supprime! - C:\ProgramData\web thunk thunk.rzzinl
Supprime! - C:\ProgramData\web thunk thunk.zuq4dw
Supprime! - C:\ProgramData\web thunk thunk.5mlgrgp
Supprime! - C:\ProgramData\web thunk thunk.5z9eioo
Supprime! - C:\ProgramData\web thunk thunk.9dbyr80
Supprime! - C:\ProgramData\web thunk thunk.cu0xx5f
Supprime! - C:\ProgramData\web thunk thunk.ensw5yu
Supprime! - C:\ProgramData\web thunk thunk.gtr5nuu
Supprime! - C:\ProgramData\web thunk thunk.ieg2i5m
Supprime! - C:\ProgramData\web thunk thunk.px9q8n4
Supprime! - C:\ProgramData\web thunk thunk.t2k99ec
Supprime! - C:\ProgramData\web thunk thunk.vbrse9h
Supprime! - C:\ProgramData\web thunk thunk.xc1squb
Supprime! - C:\ProgramData\web thunk thunk.z7zgpuo
Supprime! - C:\ProgramData\gram delete for
Supprime! - C:\ProgramData\Iso Web Bags Else
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[05/04/2008|17:02] C:\Users\celine\AppData\Local\ACD Systems
[05/05/2008|12:47] C:\Users\celine\AppData\Local\Adobe
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Application Data
[15/11/2007|16:56] C:\Users\celine\AppData\Local\ATI
[12/07/2008|14:57] C:\Users\celine\AppData\Local\d3d9caps.dat
[16/08/2008|00:11] C:\Users\celine\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[05/04/2008|17:00] C:\Users\celine\AppData\Local\Downloaded Installations
[19/09/2008|20:39] C:\Users\celine\AppData\Local\eMule
[15/11/2007|19:45] C:\Users\celine\AppData\Local\GDIPFONTCACHEV1.DAT
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Historique
[20/09/2008|00:46] C:\Users\celine\AppData\Local\IconCache.db
[18/06/2008|18:15] C:\Users\celine\AppData\Local\LogMeIn
[09/03/2008|20:46] C:\Users\celine\AppData\Local\Microsoft
[23/02/2008|02:28] C:\Users\celine\AppData\Local\Microsoft Games
[23/11/2007|16:44] C:\Users\celine\AppData\Local\Mozilla
[09/03/2008|21:00] C:\Users\celine\AppData\Local\Netlog
[20/09/2008|22:08] C:\Users\celine\AppData\Local\Temp
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Temporary Internet Files
[15/11/2007|16:56] C:\Users\celine\AppData\Local\Toshiba
[15/11/2007|19:58] C:\Users\celine\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[20/09/2008 00:48][--ah-----] C:\Windows\tasks\SA.DAT
[20/09/2008 00:47][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[05/04/2008|17:01] C:\ProgramData\ACD Systems
[05/05/2008|12:46] C:\ProgramData\Adobe
[02/11/2006|15:02] C:\ProgramData\Application Data
[15/11/2007|15:42] C:\ProgramData\Atheros
[19/09/2008|20:54] C:\ProgramData\Avira
[15/11/2007|16:45] C:\ProgramData\Bureau
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[19/09/2008|20:39] C:\ProgramData\eMule
[18/06/2008|18:26] C:\ProgramData\ESET
[01/03/2008|01:34] C:\ProgramData\ezsid.dat
[10/08/2008|20:19] C:\ProgramData\ezsidmv.dat
[15/11/2007|16:45] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[18/06/2008|18:15] C:\ProgramData\LogMeIn
[15/11/2007|16:45] C:\ProgramData\Menu D‚marrer
[17/11/2007|15:18] C:\ProgramData\Microsoft
[15/11/2007|16:45] C:\ProgramData\ModŠles
[15/11/2007|17:30] C:\ProgramData\SBT
[16/09/2008|08:13] C:\ProgramData\Skype
[08/03/2008|19:48] C:\ProgramData\SonicStage
[08/03/2008|19:48] C:\ProgramData\Sony Corporation
[18/06/2008|18:09] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[22/12/2007|23:23] C:\ProgramData\Symantec
[20/09/2008|12:35] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[15/11/2007|16:54] C:\ProgramData\Toshiba
[15/11/2007|16:50] C:\ProgramData\ToshibaEurope
[10/07/2007|16:49] C:\ProgramData\Ulead Systems
[10/07/2007|16:36] C:\ProgramData\Vista64
[16/06/2008|23:15] C:\ProgramData\WLInstaller
[10/07/2007|16:36] C:\ProgramData\XP
[20/09/2008|00:51] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[05/04/2008|17:01] C:\Program Files\ACD Systems
[05/05/2008|12:44] C:\Program Files\Adobe
[15/11/2007|19:14] C:\Program Files\Alwil Software
[20/09/2008|00:21] C:\Program Files\a-squared Free
[15/11/2007|15:42] C:\Program Files\Atheros
[15/11/2007|15:33] C:\Program Files\ATI
[15/11/2007|15:35] C:\Program Files\ATI Technologies
[19/09/2008|20:54] C:\Program Files\Avira
[15/11/2007|15:36] C:\Program Files\Camera Assistant Software for Toshiba
[20/09/2008|00:13] C:\Program Files\CCleaner
[16/09/2008|08:13] C:\Program Files\Common Files
[15/04/2008|19:20] C:\Program Files\DivX
[16/09/2008|08:12] C:\Program Files\eMule
[15/11/2007|16:45] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[18/04/2007|09:08] C:\Program Files\IDM
[16/09/2008|08:15] C:\Program Files\InstallShield Installation Information
[15/11/2007|16:53] C:\Program Files\Intel
[02/07/2008|16:08] C:\Program Files\Internet Explorer
[10/07/2007|16:49] C:\Program Files\InterVideo
[18/04/2007|07:44] C:\Program Files\Java
[18/04/2007|08:05] C:\Program Files\ltmoh
[16/11/2007|10:46] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[15/11/2007|17:30] C:\Program Files\Microsoft Office
[15/11/2007|20:41] C:\Program Files\Microsoft SQL Server Compact Edition
[02/07/2008|16:08] C:\Program Files\Movie Maker
[20/09/2008|12:34] C:\Program Files\Mozilla Firefox
[02/11/2006|14:37] C:\Program Files\MSBuild
[10/07/2007|15:49] C:\Program Files\MSXML 4.0
[18/04/2007|08:14] C:\Program Files\My Company Name
[18/04/2007|09:08] C:\Program Files\myphotobook
[18/06/2008|18:22] C:\Program Files\OrangeHSS
[10/07/2007|16:24] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[29/04/2008|10:20] C:\Program Files\Samsung
[15/11/2007|17:30] C:\Program Files\Snapshot Viewer
[06/03/2008|23:04] C:\Program Files\Sony
[19/06/2008|09:32] C:\Program Files\Spybot - Search & Destroy
[20/09/2008|12:35] C:\Program Files\Spyware Doctor
[15/11/2007|15:42] C:\Program Files\Synaptics
[15/11/2007|16:53] C:\Program Files\TOSHIBA
[20/09/2008|13:13] C:\Program Files\Trend Micro
[10/07/2007|16:46] C:\Program Files\Ulead Systems
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[16/11/2007|17:16] C:\Program Files\VideoLAN
[02/07/2008|16:08] C:\Program Files\Windows Calendar
[02/07/2008|16:08] C:\Program Files\Windows Collaboration
[02/07/2008|16:07] C:\Program Files\Windows Defender
[02/07/2008|16:08] C:\Program Files\Windows Journal
[17/09/2008|23:12] C:\Program Files\Windows Live
[13/08/2008|03:10] C:\Program Files\Windows Mail
[18/04/2007|08:46] C:\Program Files\Windows Media Components
[02/07/2008|16:08] C:\Program Files\Windows Media Player
[15/11/2007|16:45] C:\Program Files\Windows NT
[02/07/2008|16:07] C:\Program Files\Windows Photo Gallery
[02/07/2008|16:08] C:\Program Files\Windows Sidebar
[23/02/2008|11:58] C:\Program Files\WinRAR
[20/09/2008|00:13] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[05/04/2008|17:02] C:\Program Files\Common Files\ACD Systems
[05/05/2008|12:45] C:\Program Files\Common Files\Adobe
[15/11/2007|17:24] C:\Program Files\Common Files\Designer
[18/04/2007|08:47] C:\Program Files\Common Files\InstallShield
[18/04/2007|07:44] C:\Program Files\Common Files\Java
[15/11/2007|20:39] C:\Program Files\Common Files\microsoft shared
[23/11/2007|17:11] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[06/03/2008|23:06] C:\Program Files\Common Files\Sony Shared
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[22/12/2007|23:23] C:\Program Files\Common Files\Symantec Shared
[02/07/2008|16:07] C:\Program Files\Common Files\System
[15/11/2007|16:54] C:\Program Files\Common Files\Toshiba Shared
[10/07/2007|16:49] C:\Program Files\Common Files\Ulead Systems
[15/11/2007|20:39] C:\Program Files\Common Files\WindowsLiveInstaller
--------------------\\ Process
( 78 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 22:09:19
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 157
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:47][D:5]-> C:\Users\celine\AppData\Local\Temp
[F:57][D:1]-> C:\Users\celine\AppData\Roaming\MICROS~1\Windows\Cookies
[F:431][D:4]-> C:\Users\celine\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:5327][D:716]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 20/09/2008|14:07 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 20/09/2008|22:11 - Option : [2]
--------------------\\ Fin du rapport a 22:11:08
[ UAC => 1 ]
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2310 @ 1.46GHz )
BIOS : Ver 1.00PARTTBL
USER : celine ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total : 93 Go Free : 6 Go
E:\ (Local Disk) - NTFS - Total : 91 Go Free : 82 Go
F:\ (CD or DVD) - CDFS - Total : 4 Go Free : 0 Go
"C:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [2] ( 20/09/2008|22:08 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\ProgramData\gram delete for\HOLD SOFTWARE TONS.exe
Supprime! - C:\ProgramData\gram delete for\kaoucsqy.exe
Supprime! - C:\ProgramData\gram delete for\omrbqqff.exe
Supprime! - C:\ProgramData\gram delete for\Regs Mess Plus Fast.exe
Supprime! - C:\ProgramData\Iso Web Bags Else\Vga fast.exe
Supprime! - C:\Users\celine\AppData\Roaming\MICROS~1\Windows\Cookies\celine@adopt.euroclick[1].txt
Supprime! - C:\ProgramData\web thunk thunk.96x7g
Supprime! - C:\ProgramData\web thunk thunk.9mm3t
Supprime! - C:\ProgramData\web thunk thunk.dqcyp
Supprime! - C:\ProgramData\web thunk thunk.fah8t
Supprime! - C:\ProgramData\web thunk thunk.fqjmm
Supprime! - C:\ProgramData\web thunk thunk.igf3r
Supprime! - C:\ProgramData\web thunk thunk.lffm8
Supprime! - C:\ProgramData\web thunk thunk.n9fs1
Supprime! - C:\ProgramData\web thunk thunk.ni5q7
Supprime! - C:\ProgramData\web thunk thunk.ppc02
Supprime! - C:\ProgramData\web thunk thunk.qsabx
Supprime! - C:\ProgramData\web thunk thunk.w54a8
Supprime! - C:\ProgramData\web thunk thunk.z4zbw
Supprime! - C:\ProgramData\bags style junk.hudbbm
Supprime! - C:\ProgramData\web thunk thunk.39yy4u
Supprime! - C:\ProgramData\web thunk thunk.5ca6s2
Supprime! - C:\ProgramData\web thunk thunk.7j0nlb
Supprime! - C:\ProgramData\web thunk thunk.9pbb9g
Supprime! - C:\ProgramData\web thunk thunk.9t5l8v
Supprime! - C:\ProgramData\web thunk thunk.ep5b8k
Supprime! - C:\ProgramData\web thunk thunk.kvkcro
Supprime! - C:\ProgramData\web thunk thunk.odnenk
Supprime! - C:\ProgramData\web thunk thunk.pcuwtc
Supprime! - C:\ProgramData\web thunk thunk.rzzinl
Supprime! - C:\ProgramData\web thunk thunk.zuq4dw
Supprime! - C:\ProgramData\web thunk thunk.5mlgrgp
Supprime! - C:\ProgramData\web thunk thunk.5z9eioo
Supprime! - C:\ProgramData\web thunk thunk.9dbyr80
Supprime! - C:\ProgramData\web thunk thunk.cu0xx5f
Supprime! - C:\ProgramData\web thunk thunk.ensw5yu
Supprime! - C:\ProgramData\web thunk thunk.gtr5nuu
Supprime! - C:\ProgramData\web thunk thunk.ieg2i5m
Supprime! - C:\ProgramData\web thunk thunk.px9q8n4
Supprime! - C:\ProgramData\web thunk thunk.t2k99ec
Supprime! - C:\ProgramData\web thunk thunk.vbrse9h
Supprime! - C:\ProgramData\web thunk thunk.xc1squb
Supprime! - C:\ProgramData\web thunk thunk.z7zgpuo
Supprime! - C:\ProgramData\gram delete for
Supprime! - C:\ProgramData\Iso Web Bags Else
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[05/04/2008|17:02] C:\Users\celine\AppData\Local\ACD Systems
[05/05/2008|12:47] C:\Users\celine\AppData\Local\Adobe
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Application Data
[15/11/2007|16:56] C:\Users\celine\AppData\Local\ATI
[12/07/2008|14:57] C:\Users\celine\AppData\Local\d3d9caps.dat
[16/08/2008|00:11] C:\Users\celine\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[05/04/2008|17:00] C:\Users\celine\AppData\Local\Downloaded Installations
[19/09/2008|20:39] C:\Users\celine\AppData\Local\eMule
[15/11/2007|19:45] C:\Users\celine\AppData\Local\GDIPFONTCACHEV1.DAT
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Historique
[20/09/2008|00:46] C:\Users\celine\AppData\Local\IconCache.db
[18/06/2008|18:15] C:\Users\celine\AppData\Local\LogMeIn
[09/03/2008|20:46] C:\Users\celine\AppData\Local\Microsoft
[23/02/2008|02:28] C:\Users\celine\AppData\Local\Microsoft Games
[23/11/2007|16:44] C:\Users\celine\AppData\Local\Mozilla
[09/03/2008|21:00] C:\Users\celine\AppData\Local\Netlog
[20/09/2008|22:08] C:\Users\celine\AppData\Local\Temp
[15/11/2007|16:50] C:\Users\celine\AppData\Local\Temporary Internet Files
[15/11/2007|16:56] C:\Users\celine\AppData\Local\Toshiba
[15/11/2007|19:58] C:\Users\celine\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[20/09/2008 00:48][--ah-----] C:\Windows\tasks\SA.DAT
[20/09/2008 00:47][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[05/04/2008|17:01] C:\ProgramData\ACD Systems
[05/05/2008|12:46] C:\ProgramData\Adobe
[02/11/2006|15:02] C:\ProgramData\Application Data
[15/11/2007|15:42] C:\ProgramData\Atheros
[19/09/2008|20:54] C:\ProgramData\Avira
[15/11/2007|16:45] C:\ProgramData\Bureau
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[19/09/2008|20:39] C:\ProgramData\eMule
[18/06/2008|18:26] C:\ProgramData\ESET
[01/03/2008|01:34] C:\ProgramData\ezsid.dat
[10/08/2008|20:19] C:\ProgramData\ezsidmv.dat
[15/11/2007|16:45] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[18/06/2008|18:15] C:\ProgramData\LogMeIn
[15/11/2007|16:45] C:\ProgramData\Menu D‚marrer
[17/11/2007|15:18] C:\ProgramData\Microsoft
[15/11/2007|16:45] C:\ProgramData\ModŠles
[15/11/2007|17:30] C:\ProgramData\SBT
[16/09/2008|08:13] C:\ProgramData\Skype
[08/03/2008|19:48] C:\ProgramData\SonicStage
[08/03/2008|19:48] C:\ProgramData\Sony Corporation
[18/06/2008|18:09] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[22/12/2007|23:23] C:\ProgramData\Symantec
[20/09/2008|12:35] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[15/11/2007|16:54] C:\ProgramData\Toshiba
[15/11/2007|16:50] C:\ProgramData\ToshibaEurope
[10/07/2007|16:49] C:\ProgramData\Ulead Systems
[10/07/2007|16:36] C:\ProgramData\Vista64
[16/06/2008|23:15] C:\ProgramData\WLInstaller
[10/07/2007|16:36] C:\ProgramData\XP
[20/09/2008|00:51] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[05/04/2008|17:01] C:\Program Files\ACD Systems
[05/05/2008|12:44] C:\Program Files\Adobe
[15/11/2007|19:14] C:\Program Files\Alwil Software
[20/09/2008|00:21] C:\Program Files\a-squared Free
[15/11/2007|15:42] C:\Program Files\Atheros
[15/11/2007|15:33] C:\Program Files\ATI
[15/11/2007|15:35] C:\Program Files\ATI Technologies
[19/09/2008|20:54] C:\Program Files\Avira
[15/11/2007|15:36] C:\Program Files\Camera Assistant Software for Toshiba
[20/09/2008|00:13] C:\Program Files\CCleaner
[16/09/2008|08:13] C:\Program Files\Common Files
[15/04/2008|19:20] C:\Program Files\DivX
[16/09/2008|08:12] C:\Program Files\eMule
[15/11/2007|16:45] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[18/04/2007|09:08] C:\Program Files\IDM
[16/09/2008|08:15] C:\Program Files\InstallShield Installation Information
[15/11/2007|16:53] C:\Program Files\Intel
[02/07/2008|16:08] C:\Program Files\Internet Explorer
[10/07/2007|16:49] C:\Program Files\InterVideo
[18/04/2007|07:44] C:\Program Files\Java
[18/04/2007|08:05] C:\Program Files\ltmoh
[16/11/2007|10:46] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[15/11/2007|17:30] C:\Program Files\Microsoft Office
[15/11/2007|20:41] C:\Program Files\Microsoft SQL Server Compact Edition
[02/07/2008|16:08] C:\Program Files\Movie Maker
[20/09/2008|12:34] C:\Program Files\Mozilla Firefox
[02/11/2006|14:37] C:\Program Files\MSBuild
[10/07/2007|15:49] C:\Program Files\MSXML 4.0
[18/04/2007|08:14] C:\Program Files\My Company Name
[18/04/2007|09:08] C:\Program Files\myphotobook
[18/06/2008|18:22] C:\Program Files\OrangeHSS
[10/07/2007|16:24] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[29/04/2008|10:20] C:\Program Files\Samsung
[15/11/2007|17:30] C:\Program Files\Snapshot Viewer
[06/03/2008|23:04] C:\Program Files\Sony
[19/06/2008|09:32] C:\Program Files\Spybot - Search & Destroy
[20/09/2008|12:35] C:\Program Files\Spyware Doctor
[15/11/2007|15:42] C:\Program Files\Synaptics
[15/11/2007|16:53] C:\Program Files\TOSHIBA
[20/09/2008|13:13] C:\Program Files\Trend Micro
[10/07/2007|16:46] C:\Program Files\Ulead Systems
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[16/11/2007|17:16] C:\Program Files\VideoLAN
[02/07/2008|16:08] C:\Program Files\Windows Calendar
[02/07/2008|16:08] C:\Program Files\Windows Collaboration
[02/07/2008|16:07] C:\Program Files\Windows Defender
[02/07/2008|16:08] C:\Program Files\Windows Journal
[17/09/2008|23:12] C:\Program Files\Windows Live
[13/08/2008|03:10] C:\Program Files\Windows Mail
[18/04/2007|08:46] C:\Program Files\Windows Media Components
[02/07/2008|16:08] C:\Program Files\Windows Media Player
[15/11/2007|16:45] C:\Program Files\Windows NT
[02/07/2008|16:07] C:\Program Files\Windows Photo Gallery
[02/07/2008|16:08] C:\Program Files\Windows Sidebar
[23/02/2008|11:58] C:\Program Files\WinRAR
[20/09/2008|00:13] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[05/04/2008|17:02] C:\Program Files\Common Files\ACD Systems
[05/05/2008|12:45] C:\Program Files\Common Files\Adobe
[15/11/2007|17:24] C:\Program Files\Common Files\Designer
[18/04/2007|08:47] C:\Program Files\Common Files\InstallShield
[18/04/2007|07:44] C:\Program Files\Common Files\Java
[15/11/2007|20:39] C:\Program Files\Common Files\microsoft shared
[23/11/2007|17:11] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[06/03/2008|23:06] C:\Program Files\Common Files\Sony Shared
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[22/12/2007|23:23] C:\Program Files\Common Files\Symantec Shared
[02/07/2008|16:07] C:\Program Files\Common Files\System
[15/11/2007|16:54] C:\Program Files\Common Files\Toshiba Shared
[10/07/2007|16:49] C:\Program Files\Common Files\Ulead Systems
[15/11/2007|20:39] C:\Program Files\Common Files\WindowsLiveInstaller
--------------------\\ Process
( 78 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 22:09:19
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 157
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:47][D:5]-> C:\Users\celine\AppData\Local\Temp
[F:57][D:1]-> C:\Users\celine\AppData\Roaming\MICROS~1\Windows\Cookies
[F:431][D:4]-> C:\Users\celine\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:5327][D:716]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 20/09/2008|14:07 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 20/09/2008|22:11 - Option : [2]
--------------------\\ Fin du rapport a 22:11:08
[ UAC => 1 ]