Fenetres publicitaires indesirables
Fermé
trebz30
Messages postés
15
Date d'inscription
samedi 4 octobre 2008
Statut
Membre
Dernière intervention
26 février 2010
-
4 oct. 2008 à 11:26
benurrr Messages postés 9638 Date d'inscription samedi 24 mai 2008 Statut Contributeur sécurité Dernière intervention 11 janvier 2012 - 10 oct. 2008 à 09:22
benurrr Messages postés 9638 Date d'inscription samedi 24 mai 2008 Statut Contributeur sécurité Dernière intervention 11 janvier 2012 - 10 oct. 2008 à 09:22
A voir également:
- Fenetres publicitaires indesirables
- Clavier qui ouvre des fenetres ✓ - Forum Windows Vista
- Comment bloquer les annonces publicitaires - Guide
- Comment bloquer les appels indésirables sur téléphone portable - Guide
- Gestion des fenêtres windows 10 - Guide
- Ouvrir deux fenetres excel ✓ - Forum Excel
3 réponses
benurrr
Messages postés
9638
Date d'inscription
samedi 24 mai 2008
Statut
Contributeur sécurité
Dernière intervention
11 janvier 2012
107
4 oct. 2008 à 11:34
4 oct. 2008 à 11:34
salut
on constate déjà du vundo
on va déjà voir pour les pub
Télécharge LOP S&D d'Eric71 ici https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
Double-clique dessus pour lancer l'installation.
Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
Séléctionne la langue souhaitée , puis choisis l'Option 1 ( Recherche )
Patiente jusqu'à la fin du scan.
Poste le rapport généré (situé aussi ici C:\lopR.txt )
( Si le Bureau ne réapparaît pas, lance le gestionnaire des tâches en cliquant sur Ctrl + Alt + Suppr , puis Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )
on constate déjà du vundo
on va déjà voir pour les pub
Télécharge LOP S&D d'Eric71 ici https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
Double-clique dessus pour lancer l'installation.
Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
Séléctionne la langue souhaitée , puis choisis l'Option 1 ( Recherche )
Patiente jusqu'à la fin du scan.
Poste le rapport généré (situé aussi ici C:\lopR.txt )
( Si le Bureau ne réapparaît pas, lance le gestionnaire des tâches en cliquant sur Ctrl + Alt + Suppr , puis Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )
trebz30
Messages postés
15
Date d'inscription
samedi 4 octobre 2008
Statut
Membre
Dernière intervention
26 février 2010
4 oct. 2008 à 11:48
4 oct. 2008 à 11:48
merci benurr pour ta reponse aussi rapide
Juste une petite question, que veux tu dire par "on constate deja du vundo". Qu'est ce qu"un vundo? dois je le supprimer?
voici le fichier d'analyse LOP S&D
--------------------\\ Lop S&D 4.2.4-5 XP/Vista
( : )
USER : Trebz ( Administrator )
Antivirus : Bitdefender Antivirus 8.0 (Activated)
Firewall : Bitdefender Firewall 8.0 (Activated)
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 04/10/2008|11:39 )
--------------------\\ Listing des dossiers dans APPLIC~1
[22/06/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ableton
[15/08/2008|13:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[26/01/2008|18:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/01/2008|18:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[30/09/2008|19:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[30/12/2007|12:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[29/12/2007|18:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[06/08/2008|19:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[06/08/2008|19:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[28/06/2008|13:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[12/07/2008|17:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Line 6
[25/06/2008|22:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[22/04/2007|11:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[30/10/2005|21:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[22/06/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[09/11/2005|21:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[09/11/2005|20:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle Studio
[15/02/2007|22:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[04/12/2005|19:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[17/09/2006|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[14/09/2008|12:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[06/11/2006|22:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[17/09/2006|18:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Teleca
[13/09/2008|14:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/12/2006|21:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[30/10/2005|18:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[13/12/2006|20:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[30/10/2005|18:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[22/06/2008|22:32] C:\DOCUME~1\Trebz\APPLIC~1\Ableton
[15/06/2008|21:38] C:\DOCUME~1\Trebz\APPLIC~1\Adobe
[17/09/2006|18:51] C:\DOCUME~1\Trebz\APPLIC~1\AdobeUM
[27/01/2008|21:21] C:\DOCUME~1\Trebz\APPLIC~1\Apple Computer
[30/09/2008|19:38] C:\DOCUME~1\Trebz\APPLIC~1\Bitdefender
[30/12/2007|12:08] C:\DOCUME~1\Trebz\APPLIC~1\CyberLink
[15/04/2007|11:23] C:\DOCUME~1\Trebz\APPLIC~1\DivX
[07/11/2005|20:05] C:\DOCUME~1\Trebz\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[07/11/2005|20:06] C:\DOCUME~1\Trebz\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[06/08/2008|21:13] C:\DOCUME~1\Trebz\APPLIC~1\Help
[30/10/2005|18:16] C:\DOCUME~1\Trebz\APPLIC~1\Identities
[25/06/2008|20:18] C:\DOCUME~1\Trebz\APPLIC~1\InstallShield
[30/10/2005|18:47] C:\DOCUME~1\Trebz\APPLIC~1\InterTrust
[04/09/2007|20:04] C:\DOCUME~1\Trebz\APPLIC~1\Jasc Software Inc
[17/09/2006|18:34] C:\DOCUME~1\Trebz\APPLIC~1\Leadertech
[12/07/2008|17:51] C:\DOCUME~1\Trebz\APPLIC~1\Line 6
[04/11/2005|23:21] C:\DOCUME~1\Trebz\APPLIC~1\Macromedia
[15/08/2006|12:42] C:\DOCUME~1\Trebz\APPLIC~1\Media Player Classic
[14/06/2007|20:26] C:\DOCUME~1\Trebz\APPLIC~1\Microsoft
[23/09/2006|19:47] C:\DOCUME~1\Trebz\APPLIC~1\Mobile Master
[14/02/2006|20:58] C:\DOCUME~1\Trebz\APPLIC~1\MSN6
[19/02/2006|20:28] C:\DOCUME~1\Trebz\APPLIC~1\Real
[10/11/2007|19:48] C:\DOCUME~1\Trebz\APPLIC~1\Skype
[10/06/2008|18:45] C:\DOCUME~1\Trebz\APPLIC~1\Steinberg
[29/05/2007|22:10] C:\DOCUME~1\Trebz\APPLIC~1\Sun
[30/10/2005|19:04] C:\DOCUME~1\Trebz\APPLIC~1\Symantec
[17/09/2006|18:28] C:\DOCUME~1\Trebz\APPLIC~1\Teleca
[02/06/2008|21:48] C:\DOCUME~1\Trebz\APPLIC~1\vlc
[09/06/2008|19:01] C:\DOCUME~1\Trebz\APPLIC~1\Waves Audio
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/09/2008 15:33][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[04/10/2008 09:27][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[23/06/2008|17:40] C:\Program Files\Ableton
[04/10/2008|11:02] C:\Program Files\Adobe
[21/09/2008|17:37] C:\Program Files\adslTV
[13/11/2006|22:43] C:\Program Files\Ahead
[20/05/2008|20:05] C:\Program Files\Alwil Software
[26/04/2008|15:12] C:\Program Files\Antares
[26/01/2008|18:26] C:\Program Files\Apple Software Update
[24/09/2006|11:44] C:\Program Files\AviSynth 2.5
[30/09/2008|19:37] C:\Program Files\BitDefender
[26/05/2008|20:22] C:\Program Files\BitLord
[10/03/2008|23:23] C:\Program Files\Bonjour
[10/04/2008|18:14] C:\Program Files\brainspawn
[13/11/2006|20:08] C:\Program Files\CCleaner
[05/07/2008|16:08] C:\Program Files\Common Files
[30/12/2007|12:03] C:\Program Files\CyberLink
[01/05/2008|13:27] C:\Program Files\directx
[24/06/2008|19:37] C:\Program Files\DivX
[25/04/2008|16:18] C:\Program Files\DSPFX
[30/10/2005|22:16] C:\Program Files\D-Tools
[12/11/2005|11:55] C:\Program Files\DVD Decrypter
[30/10/2005|23:18] C:\Program Files\DVD Shrink
[03/06/2007|17:56] C:\Program Files\EarMaster
[24/09/2006|14:57] C:\Program Files\eRightSoft
[30/09/2008|19:36] C:\Program Files\Fichiers communs
[27/01/2008|19:22] C:\Program Files\Free iPod Video Converter
[03/11/2005|17:58] C:\Program Files\Guitar Pro 4
[03/10/2008|20:26] C:\Program Files\Hercules
[07/11/2005|20:04] C:\Program Files\Hewlett-Packard
[17/08/2007|17:28] C:\Program Files\Hofmann
[11/06/2007|19:45] C:\Program Files\HP
[06/08/2008|19:33] C:\Program Files\IncrediMail
[03/10/2008|20:26] C:\Program Files\InstallShield Installation Information
[15/09/2007|20:49] C:\Program Files\InterLok
[15/08/2008|19:11] C:\Program Files\Internet Explorer
[26/01/2008|18:33] C:\Program Files\iPod
[26/01/2008|18:33] C:\Program Files\iTunes
[04/09/2007|20:04] C:\Program Files\Jasc Software Inc
[19/10/2007|19:14] C:\Program Files\Java
[24/08/2008|12:05] C:\Program Files\Jibege Freq
[07/11/2006|21:36] C:\Program Files\Lavasoft
[12/07/2008|17:48] C:\Program Files\Line6
[22/06/2008|22:09] C:\Program Files\Logitech
[25/06/2008|22:20] C:\Program Files\ma-config.com
[30/10/2005|18:23] C:\Program Files\Marvell
[02/11/2005|21:07] C:\Program Files\Matroska Playback Pack
[25/06/2008|20:22] C:\Program Files\M-Audio
[15/02/2007|22:06] C:\Program Files\Media Player Classic
[26/08/2008|20:58] C:\Program Files\Messenger
[30/10/2005|18:13] C:\Program Files\microsoft frontpage
[22/04/2007|11:50] C:\Program Files\Microsoft Office
[08/09/2008|23:50] C:\Program Files\Microsoft Picture It! PhotoPub
[23/11/2005|22:11] C:\Program Files\Microsoft Works
[23/11/2005|22:08] C:\Program Files\Microsoft Works Suite 2001
[16/02/2007|18:00] C:\Program Files\Mio Technology
[26/08/2008|20:54] C:\Program Files\Movie Maker
[30/10/2005|21:28] C:\Program Files\MSN
[30/10/2005|18:10] C:\Program Files\MSN Gaming Zone
[11/11/2005|13:05] C:\Program Files\MSN Messenger
[17/11/2006|18:57] C:\Program Files\MSXML 4.0
[12/09/2008|13:17] C:\Program Files\Native Instruments
[04/10/2008|11:15] C:\Program Files\Navilog1
[26/08/2008|20:54] C:\Program Files\NetMeeting
[03/10/2008|21:34] C:\Program Files\Neuf
[27/01/2008|15:44] C:\Program Files\nutri
[19/11/2005|19:27] C:\Program Files\NVIDIA Corporation
[26/08/2008|20:54] C:\Program Files\Outlook Express
[12/09/2008|20:04] C:\Program Files\Pianoteq 2.2
[09/11/2005|21:08] C:\Program Files\Pinnacle
[09/11/2005|23:27] C:\Program Files\PowerQuest
[01/05/2008|13:29] C:\Program Files\QuickTime
[15/02/2007|22:06] C:\Program Files\Real Alternative
[24/06/2008|21:18] C:\Program Files\Realtek AC97
[24/09/2006|16:07] C:\Program Files\Ripp-it_AM
[15/08/2006|12:23] C:\Program Files\Satsuki Decoder Pack
[30/10/2005|18:12] C:\Program Files\Services en ligne
[26/09/2007|19:18] C:\Program Files\Sierra On-Line
[04/12/2005|19:27] C:\Program Files\Skype
[17/09/2006|18:20] C:\Program Files\Sony Ericsson
[10/04/2008|18:07] C:\Program Files\SpectralDesign
[14/09/2008|12:06] C:\Program Files\Spybot - Search & Destroy
[17/08/2008|18:55] C:\Program Files\Steinberg
[10/06/2008|18:40] C:\Program Files\Syncrosoft
[26/09/2008|21:20] C:\Program Files\Trend Micro
[01/05/2008|13:44] C:\Program Files\Uninstall Information
[15/08/2008|19:16] C:\Program Files\vst plugins
[25/04/2008|16:38] C:\Program Files\Waves
[13/12/2006|20:36] C:\Program Files\Windows Media Connect 2
[26/08/2008|20:54] C:\Program Files\Windows Media Player
[26/08/2008|20:54] C:\Program Files\Windows NT
[10/11/2005|01:43] C:\Program Files\WindowsUpdate
[29/08/2008|21:49] C:\Program Files\WinRAR
[30/10/2005|18:13] C:\Program Files\xerox
[09/06/2008|18:47] C:\Program Files\XLN Audio
[24/09/2006|11:22] C:\Program Files\XviD
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[17/09/2006|18:51] C:\Program Files\Fichiers communs\Adobe
[13/11/2006|22:43] C:\Program Files\Fichiers communs\Ahead
[26/01/2008|18:25] C:\Program Files\Fichiers communs\Apple
[30/09/2008|19:37] C:\Program Files\Fichiers communs\BitDefender
[22/04/2007|11:50] C:\Program Files\Fichiers communs\Designer
[07/11/2005|20:05] C:\Program Files\Fichiers communs\Hewlett-Packard
[28/06/2008|13:04] C:\Program Files\Fichiers communs\InstallShield
[29/05/2007|22:08] C:\Program Files\Fichiers communs\Java
[22/06/2008|22:11] C:\Program Files\Fichiers communs\Logitech
[01/05/2008|13:44] C:\Program Files\Fichiers communs\Microsoft Shared
[30/10/2005|18:11] C:\Program Files\Fichiers communs\MSSoap
[19/11/2005|19:27] C:\Program Files\Fichiers communs\NVIDIA Shared
[30/10/2005|18:05] C:\Program Files\Fichiers communs\ODBC
[09/11/2005|20:43] C:\Program Files\Fichiers communs\Services
[30/09/2008|19:32] C:\Program Files\Fichiers communs\Softwin
[30/10/2005|18:05] C:\Program Files\Fichiers communs\SpeechEngines
[06/11/2006|22:17] C:\Program Files\Fichiers communs\Symantec Shared
[26/08/2008|20:54] C:\Program Files\Fichiers communs\System
[17/09/2006|18:21] C:\Program Files\Fichiers communs\Teleca Shared
--------------------\\ Process
( 39 Processes )
IEXPLORE.EXE ~ [PID:1828]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\Trebz\Cookies\trebz@advertstream[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@adultfriendfinder[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@advertising[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@adin.bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@fr.seafight.bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@fr1.darkorbit.bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@banner.cotedazurpalace[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@cotedazurpalace[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@www.cotedazurpalace[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@adopt.euroclick[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@partypoker[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@fr.seafight.bigpoint[1].txt
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 11:41:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
C:\WINDOWS\system32\CMnmmUtv.ini
C:\WINDOWS\system32\CMnmmUtv.ini2
[b]==> VUNDO <==/b
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Trebz\Local Settings\Application Data\ApplicationHistory\serial bit defender v10 key keygen.exe.1a8ae99b.ini
C:\DOCUME~1\Trebz\Mes documents\Ableton\Library\Presets\Vinyl Distortion\Crack.adv
C:\DOCUME~1\Trebz\Recent\Addictive Drums Crack Install.lnk
C:\DOCUME~1\Trebz\Recent\Addictive Drums XLN Audio Keygen.lnk
C:\DOCUME~1\Trebz\Recent\BitDefender.Total.Security.2008.V11.0.15.+Keygen+.patch.by-Siegfried.lnk
C:\DOCUME~1\Trebz\Recent\Copy.of.crack.pianoteq.lnk
C:\DOCUME~1\Trebz\Recent\Native Instruments B4 II + KeyGen.lnk
C:\DOCUME~1\Trebz\Recent\Native Instruments b4 v2.0.0.7 Incl Keygen-h2O.lnk
C:\DOCUME~1\Trebz\Recent\total_crack.lnk
[F:136][D:566]-> C:\DOCUME~1\Trebz\LOCALS~1\Temp
[F:551][D:0]-> C:\DOCUME~1\Trebz\Cookies
[F:17745][D:38]-> C:\DOCUME~1\Trebz\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 04/10/2008|11:44 - Option : [1]
--------------------\\ Fin du rapport a 11:44:34
Juste une petite question, que veux tu dire par "on constate deja du vundo". Qu'est ce qu"un vundo? dois je le supprimer?
voici le fichier d'analyse LOP S&D
--------------------\\ Lop S&D 4.2.4-5 XP/Vista
( : )
USER : Trebz ( Administrator )
Antivirus : Bitdefender Antivirus 8.0 (Activated)
Firewall : Bitdefender Firewall 8.0 (Activated)
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 04/10/2008|11:39 )
--------------------\\ Listing des dossiers dans APPLIC~1
[22/06/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ableton
[15/08/2008|13:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[26/01/2008|18:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/01/2008|18:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[30/09/2008|19:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[30/12/2007|12:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[29/12/2007|18:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[06/08/2008|19:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[06/08/2008|19:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[28/06/2008|13:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[12/07/2008|17:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Line 6
[25/06/2008|22:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[22/04/2007|11:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[30/10/2005|21:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[22/06/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[09/11/2005|21:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[09/11/2005|20:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle Studio
[15/02/2007|22:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[04/12/2005|19:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[17/09/2006|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[14/09/2008|12:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[06/11/2006|22:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[17/09/2006|18:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Teleca
[13/09/2008|14:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/12/2006|21:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[30/10/2005|18:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[13/12/2006|20:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[30/10/2005|18:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[22/06/2008|22:32] C:\DOCUME~1\Trebz\APPLIC~1\Ableton
[15/06/2008|21:38] C:\DOCUME~1\Trebz\APPLIC~1\Adobe
[17/09/2006|18:51] C:\DOCUME~1\Trebz\APPLIC~1\AdobeUM
[27/01/2008|21:21] C:\DOCUME~1\Trebz\APPLIC~1\Apple Computer
[30/09/2008|19:38] C:\DOCUME~1\Trebz\APPLIC~1\Bitdefender
[30/12/2007|12:08] C:\DOCUME~1\Trebz\APPLIC~1\CyberLink
[15/04/2007|11:23] C:\DOCUME~1\Trebz\APPLIC~1\DivX
[07/11/2005|20:05] C:\DOCUME~1\Trebz\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[07/11/2005|20:06] C:\DOCUME~1\Trebz\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[06/08/2008|21:13] C:\DOCUME~1\Trebz\APPLIC~1\Help
[30/10/2005|18:16] C:\DOCUME~1\Trebz\APPLIC~1\Identities
[25/06/2008|20:18] C:\DOCUME~1\Trebz\APPLIC~1\InstallShield
[30/10/2005|18:47] C:\DOCUME~1\Trebz\APPLIC~1\InterTrust
[04/09/2007|20:04] C:\DOCUME~1\Trebz\APPLIC~1\Jasc Software Inc
[17/09/2006|18:34] C:\DOCUME~1\Trebz\APPLIC~1\Leadertech
[12/07/2008|17:51] C:\DOCUME~1\Trebz\APPLIC~1\Line 6
[04/11/2005|23:21] C:\DOCUME~1\Trebz\APPLIC~1\Macromedia
[15/08/2006|12:42] C:\DOCUME~1\Trebz\APPLIC~1\Media Player Classic
[14/06/2007|20:26] C:\DOCUME~1\Trebz\APPLIC~1\Microsoft
[23/09/2006|19:47] C:\DOCUME~1\Trebz\APPLIC~1\Mobile Master
[14/02/2006|20:58] C:\DOCUME~1\Trebz\APPLIC~1\MSN6
[19/02/2006|20:28] C:\DOCUME~1\Trebz\APPLIC~1\Real
[10/11/2007|19:48] C:\DOCUME~1\Trebz\APPLIC~1\Skype
[10/06/2008|18:45] C:\DOCUME~1\Trebz\APPLIC~1\Steinberg
[29/05/2007|22:10] C:\DOCUME~1\Trebz\APPLIC~1\Sun
[30/10/2005|19:04] C:\DOCUME~1\Trebz\APPLIC~1\Symantec
[17/09/2006|18:28] C:\DOCUME~1\Trebz\APPLIC~1\Teleca
[02/06/2008|21:48] C:\DOCUME~1\Trebz\APPLIC~1\vlc
[09/06/2008|19:01] C:\DOCUME~1\Trebz\APPLIC~1\Waves Audio
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/09/2008 15:33][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[04/10/2008 09:27][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[23/06/2008|17:40] C:\Program Files\Ableton
[04/10/2008|11:02] C:\Program Files\Adobe
[21/09/2008|17:37] C:\Program Files\adslTV
[13/11/2006|22:43] C:\Program Files\Ahead
[20/05/2008|20:05] C:\Program Files\Alwil Software
[26/04/2008|15:12] C:\Program Files\Antares
[26/01/2008|18:26] C:\Program Files\Apple Software Update
[24/09/2006|11:44] C:\Program Files\AviSynth 2.5
[30/09/2008|19:37] C:\Program Files\BitDefender
[26/05/2008|20:22] C:\Program Files\BitLord
[10/03/2008|23:23] C:\Program Files\Bonjour
[10/04/2008|18:14] C:\Program Files\brainspawn
[13/11/2006|20:08] C:\Program Files\CCleaner
[05/07/2008|16:08] C:\Program Files\Common Files
[30/12/2007|12:03] C:\Program Files\CyberLink
[01/05/2008|13:27] C:\Program Files\directx
[24/06/2008|19:37] C:\Program Files\DivX
[25/04/2008|16:18] C:\Program Files\DSPFX
[30/10/2005|22:16] C:\Program Files\D-Tools
[12/11/2005|11:55] C:\Program Files\DVD Decrypter
[30/10/2005|23:18] C:\Program Files\DVD Shrink
[03/06/2007|17:56] C:\Program Files\EarMaster
[24/09/2006|14:57] C:\Program Files\eRightSoft
[30/09/2008|19:36] C:\Program Files\Fichiers communs
[27/01/2008|19:22] C:\Program Files\Free iPod Video Converter
[03/11/2005|17:58] C:\Program Files\Guitar Pro 4
[03/10/2008|20:26] C:\Program Files\Hercules
[07/11/2005|20:04] C:\Program Files\Hewlett-Packard
[17/08/2007|17:28] C:\Program Files\Hofmann
[11/06/2007|19:45] C:\Program Files\HP
[06/08/2008|19:33] C:\Program Files\IncrediMail
[03/10/2008|20:26] C:\Program Files\InstallShield Installation Information
[15/09/2007|20:49] C:\Program Files\InterLok
[15/08/2008|19:11] C:\Program Files\Internet Explorer
[26/01/2008|18:33] C:\Program Files\iPod
[26/01/2008|18:33] C:\Program Files\iTunes
[04/09/2007|20:04] C:\Program Files\Jasc Software Inc
[19/10/2007|19:14] C:\Program Files\Java
[24/08/2008|12:05] C:\Program Files\Jibege Freq
[07/11/2006|21:36] C:\Program Files\Lavasoft
[12/07/2008|17:48] C:\Program Files\Line6
[22/06/2008|22:09] C:\Program Files\Logitech
[25/06/2008|22:20] C:\Program Files\ma-config.com
[30/10/2005|18:23] C:\Program Files\Marvell
[02/11/2005|21:07] C:\Program Files\Matroska Playback Pack
[25/06/2008|20:22] C:\Program Files\M-Audio
[15/02/2007|22:06] C:\Program Files\Media Player Classic
[26/08/2008|20:58] C:\Program Files\Messenger
[30/10/2005|18:13] C:\Program Files\microsoft frontpage
[22/04/2007|11:50] C:\Program Files\Microsoft Office
[08/09/2008|23:50] C:\Program Files\Microsoft Picture It! PhotoPub
[23/11/2005|22:11] C:\Program Files\Microsoft Works
[23/11/2005|22:08] C:\Program Files\Microsoft Works Suite 2001
[16/02/2007|18:00] C:\Program Files\Mio Technology
[26/08/2008|20:54] C:\Program Files\Movie Maker
[30/10/2005|21:28] C:\Program Files\MSN
[30/10/2005|18:10] C:\Program Files\MSN Gaming Zone
[11/11/2005|13:05] C:\Program Files\MSN Messenger
[17/11/2006|18:57] C:\Program Files\MSXML 4.0
[12/09/2008|13:17] C:\Program Files\Native Instruments
[04/10/2008|11:15] C:\Program Files\Navilog1
[26/08/2008|20:54] C:\Program Files\NetMeeting
[03/10/2008|21:34] C:\Program Files\Neuf
[27/01/2008|15:44] C:\Program Files\nutri
[19/11/2005|19:27] C:\Program Files\NVIDIA Corporation
[26/08/2008|20:54] C:\Program Files\Outlook Express
[12/09/2008|20:04] C:\Program Files\Pianoteq 2.2
[09/11/2005|21:08] C:\Program Files\Pinnacle
[09/11/2005|23:27] C:\Program Files\PowerQuest
[01/05/2008|13:29] C:\Program Files\QuickTime
[15/02/2007|22:06] C:\Program Files\Real Alternative
[24/06/2008|21:18] C:\Program Files\Realtek AC97
[24/09/2006|16:07] C:\Program Files\Ripp-it_AM
[15/08/2006|12:23] C:\Program Files\Satsuki Decoder Pack
[30/10/2005|18:12] C:\Program Files\Services en ligne
[26/09/2007|19:18] C:\Program Files\Sierra On-Line
[04/12/2005|19:27] C:\Program Files\Skype
[17/09/2006|18:20] C:\Program Files\Sony Ericsson
[10/04/2008|18:07] C:\Program Files\SpectralDesign
[14/09/2008|12:06] C:\Program Files\Spybot - Search & Destroy
[17/08/2008|18:55] C:\Program Files\Steinberg
[10/06/2008|18:40] C:\Program Files\Syncrosoft
[26/09/2008|21:20] C:\Program Files\Trend Micro
[01/05/2008|13:44] C:\Program Files\Uninstall Information
[15/08/2008|19:16] C:\Program Files\vst plugins
[25/04/2008|16:38] C:\Program Files\Waves
[13/12/2006|20:36] C:\Program Files\Windows Media Connect 2
[26/08/2008|20:54] C:\Program Files\Windows Media Player
[26/08/2008|20:54] C:\Program Files\Windows NT
[10/11/2005|01:43] C:\Program Files\WindowsUpdate
[29/08/2008|21:49] C:\Program Files\WinRAR
[30/10/2005|18:13] C:\Program Files\xerox
[09/06/2008|18:47] C:\Program Files\XLN Audio
[24/09/2006|11:22] C:\Program Files\XviD
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[17/09/2006|18:51] C:\Program Files\Fichiers communs\Adobe
[13/11/2006|22:43] C:\Program Files\Fichiers communs\Ahead
[26/01/2008|18:25] C:\Program Files\Fichiers communs\Apple
[30/09/2008|19:37] C:\Program Files\Fichiers communs\BitDefender
[22/04/2007|11:50] C:\Program Files\Fichiers communs\Designer
[07/11/2005|20:05] C:\Program Files\Fichiers communs\Hewlett-Packard
[28/06/2008|13:04] C:\Program Files\Fichiers communs\InstallShield
[29/05/2007|22:08] C:\Program Files\Fichiers communs\Java
[22/06/2008|22:11] C:\Program Files\Fichiers communs\Logitech
[01/05/2008|13:44] C:\Program Files\Fichiers communs\Microsoft Shared
[30/10/2005|18:11] C:\Program Files\Fichiers communs\MSSoap
[19/11/2005|19:27] C:\Program Files\Fichiers communs\NVIDIA Shared
[30/10/2005|18:05] C:\Program Files\Fichiers communs\ODBC
[09/11/2005|20:43] C:\Program Files\Fichiers communs\Services
[30/09/2008|19:32] C:\Program Files\Fichiers communs\Softwin
[30/10/2005|18:05] C:\Program Files\Fichiers communs\SpeechEngines
[06/11/2006|22:17] C:\Program Files\Fichiers communs\Symantec Shared
[26/08/2008|20:54] C:\Program Files\Fichiers communs\System
[17/09/2006|18:21] C:\Program Files\Fichiers communs\Teleca Shared
--------------------\\ Process
( 39 Processes )
IEXPLORE.EXE ~ [PID:1828]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\Trebz\Cookies\trebz@advertstream[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@adultfriendfinder[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@advertising[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@adin.bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@fr.seafight.bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@fr1.darkorbit.bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@banner.cotedazurpalace[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@cotedazurpalace[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@www.cotedazurpalace[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@adopt.euroclick[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@partypoker[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@fr.seafight.bigpoint[1].txt
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 11:41:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
C:\WINDOWS\system32\CMnmmUtv.ini
C:\WINDOWS\system32\CMnmmUtv.ini2
[b]==> VUNDO <==/b
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Trebz\Local Settings\Application Data\ApplicationHistory\serial bit defender v10 key keygen.exe.1a8ae99b.ini
C:\DOCUME~1\Trebz\Mes documents\Ableton\Library\Presets\Vinyl Distortion\Crack.adv
C:\DOCUME~1\Trebz\Recent\Addictive Drums Crack Install.lnk
C:\DOCUME~1\Trebz\Recent\Addictive Drums XLN Audio Keygen.lnk
C:\DOCUME~1\Trebz\Recent\BitDefender.Total.Security.2008.V11.0.15.+Keygen+.patch.by-Siegfried.lnk
C:\DOCUME~1\Trebz\Recent\Copy.of.crack.pianoteq.lnk
C:\DOCUME~1\Trebz\Recent\Native Instruments B4 II + KeyGen.lnk
C:\DOCUME~1\Trebz\Recent\Native Instruments b4 v2.0.0.7 Incl Keygen-h2O.lnk
C:\DOCUME~1\Trebz\Recent\total_crack.lnk
[F:136][D:566]-> C:\DOCUME~1\Trebz\LOCALS~1\Temp
[F:551][D:0]-> C:\DOCUME~1\Trebz\Cookies
[F:17745][D:38]-> C:\DOCUME~1\Trebz\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 04/10/2008|11:44 - Option : [1]
--------------------\\ Fin du rapport a 11:44:34
benurrr
Messages postés
9638
Date d'inscription
samedi 24 mai 2008
Statut
Contributeur sécurité
Dernière intervention
11 janvier 2012
107
4 oct. 2008 à 12:06
4 oct. 2008 à 12:06
ok
Relance LOP S&D d'Eric71
Choisis cette fois ci l'option 3 ( Suppression )
Ne ferme pas la fenêtre lors de la suppression !
Poste le rapport généré (situé aussi ici C:\lopR.txt )
un vundo c'est un trojan
il y'a des outil spécifique pour le suprimmer
Relance LOP S&D d'Eric71
Choisis cette fois ci l'option 3 ( Suppression )
Ne ferme pas la fenêtre lors de la suppression !
Poste le rapport généré (situé aussi ici C:\lopR.txt )
un vundo c'est un trojan
il y'a des outil spécifique pour le suprimmer
trebz30
Messages postés
15
Date d'inscription
samedi 4 octobre 2008
Statut
Membre
Dernière intervention
26 février 2010
>
benurrr
Messages postés
9638
Date d'inscription
samedi 24 mai 2008
Statut
Contributeur sécurité
Dernière intervention
11 janvier 2012
4 oct. 2008 à 12:29
4 oct. 2008 à 12:29
Voici le fichier d'analyse :
--------------------\\ Lop S&D 4.2.4-5 XP/Vista
( : )
USER : Trebz ( Administrator )
Antivirus : Bitdefender Antivirus 8.0 (Activated)
Firewall : Bitdefender Firewall 8.0 (Activated)
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [3] ( 04/10/2008|12:21 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@advertstream[2].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@adultfriendfinder[2].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@advertising[2].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@adin.bigpoint[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@bigpoint[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@fr.seafight.bigpoint[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@fr1.darkorbit.bigpoint[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@banner.cotedazurpalace[2].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@cotedazurpalace[2].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@www.cotedazurpalace[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@adopt.euroclick[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@partypoker[2].txt
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[22/06/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ableton
[15/08/2008|13:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[26/01/2008|18:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/01/2008|18:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[30/09/2008|19:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[30/12/2007|12:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[29/12/2007|18:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[06/08/2008|19:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[06/08/2008|19:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[28/06/2008|13:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[12/07/2008|17:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Line 6
[25/06/2008|22:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[22/04/2007|11:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[30/10/2005|21:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[22/06/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[09/11/2005|21:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[09/11/2005|20:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle Studio
[15/02/2007|22:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[04/12/2005|19:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[17/09/2006|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[14/09/2008|12:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[06/11/2006|22:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[17/09/2006|18:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Teleca
[13/09/2008|14:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/12/2006|21:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[30/10/2005|18:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[13/12/2006|20:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[30/10/2005|18:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[22/06/2008|22:32] C:\DOCUME~1\Trebz\APPLIC~1\Ableton
[15/06/2008|21:38] C:\DOCUME~1\Trebz\APPLIC~1\Adobe
[17/09/2006|18:51] C:\DOCUME~1\Trebz\APPLIC~1\AdobeUM
[27/01/2008|21:21] C:\DOCUME~1\Trebz\APPLIC~1\Apple Computer
[30/09/2008|19:38] C:\DOCUME~1\Trebz\APPLIC~1\Bitdefender
[30/12/2007|12:08] C:\DOCUME~1\Trebz\APPLIC~1\CyberLink
[15/04/2007|11:23] C:\DOCUME~1\Trebz\APPLIC~1\DivX
[07/11/2005|20:05] C:\DOCUME~1\Trebz\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[07/11/2005|20:06] C:\DOCUME~1\Trebz\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[06/08/2008|21:13] C:\DOCUME~1\Trebz\APPLIC~1\Help
[30/10/2005|18:16] C:\DOCUME~1\Trebz\APPLIC~1\Identities
[25/06/2008|20:18] C:\DOCUME~1\Trebz\APPLIC~1\InstallShield
[30/10/2005|18:47] C:\DOCUME~1\Trebz\APPLIC~1\InterTrust
[04/09/2007|20:04] C:\DOCUME~1\Trebz\APPLIC~1\Jasc Software Inc
[17/09/2006|18:34] C:\DOCUME~1\Trebz\APPLIC~1\Leadertech
[12/07/2008|17:51] C:\DOCUME~1\Trebz\APPLIC~1\Line 6
[04/11/2005|23:21] C:\DOCUME~1\Trebz\APPLIC~1\Macromedia
[15/08/2006|12:42] C:\DOCUME~1\Trebz\APPLIC~1\Media Player Classic
[14/06/2007|20:26] C:\DOCUME~1\Trebz\APPLIC~1\Microsoft
[23/09/2006|19:47] C:\DOCUME~1\Trebz\APPLIC~1\Mobile Master
[14/02/2006|20:58] C:\DOCUME~1\Trebz\APPLIC~1\MSN6
[19/02/2006|20:28] C:\DOCUME~1\Trebz\APPLIC~1\Real
[10/11/2007|19:48] C:\DOCUME~1\Trebz\APPLIC~1\Skype
[10/06/2008|18:45] C:\DOCUME~1\Trebz\APPLIC~1\Steinberg
[29/05/2007|22:10] C:\DOCUME~1\Trebz\APPLIC~1\Sun
[30/10/2005|19:04] C:\DOCUME~1\Trebz\APPLIC~1\Symantec
[17/09/2006|18:28] C:\DOCUME~1\Trebz\APPLIC~1\Teleca
[02/06/2008|21:48] C:\DOCUME~1\Trebz\APPLIC~1\vlc
[09/06/2008|19:01] C:\DOCUME~1\Trebz\APPLIC~1\Waves Audio
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/09/2008 15:33][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[04/10/2008 09:27][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[23/06/2008|17:40] C:\Program Files\Ableton
[04/10/2008|11:02] C:\Program Files\Adobe
[21/09/2008|17:37] C:\Program Files\adslTV
[13/11/2006|22:43] C:\Program Files\Ahead
[20/05/2008|20:05] C:\Program Files\Alwil Software
[26/04/2008|15:12] C:\Program Files\Antares
[26/01/2008|18:26] C:\Program Files\Apple Software Update
[24/09/2006|11:44] C:\Program Files\AviSynth 2.5
[30/09/2008|19:37] C:\Program Files\BitDefender
[26/05/2008|20:22] C:\Program Files\BitLord
[10/03/2008|23:23] C:\Program Files\Bonjour
[10/04/2008|18:14] C:\Program Files\brainspawn
[13/11/2006|20:08] C:\Program Files\CCleaner
[05/07/2008|16:08] C:\Program Files\Common Files
[30/12/2007|12:03] C:\Program Files\CyberLink
[01/05/2008|13:27] C:\Program Files\directx
[24/06/2008|19:37] C:\Program Files\DivX
[25/04/2008|16:18] C:\Program Files\DSPFX
[30/10/2005|22:16] C:\Program Files\D-Tools
[12/11/2005|11:55] C:\Program Files\DVD Decrypter
[30/10/2005|23:18] C:\Program Files\DVD Shrink
[03/06/2007|17:56] C:\Program Files\EarMaster
[24/09/2006|14:57] C:\Program Files\eRightSoft
[30/09/2008|19:36] C:\Program Files\Fichiers communs
[27/01/2008|19:22] C:\Program Files\Free iPod Video Converter
[03/11/2005|17:58] C:\Program Files\Guitar Pro 4
[03/10/2008|20:26] C:\Program Files\Hercules
[07/11/2005|20:04] C:\Program Files\Hewlett-Packard
[17/08/2007|17:28] C:\Program Files\Hofmann
[11/06/2007|19:45] C:\Program Files\HP
[06/08/2008|19:33] C:\Program Files\IncrediMail
[03/10/2008|20:26] C:\Program Files\InstallShield Installation Information
[15/09/2007|20:49] C:\Program Files\InterLok
[15/08/2008|19:11] C:\Program Files\Internet Explorer
[26/01/2008|18:33] C:\Program Files\iPod
[26/01/2008|18:33] C:\Program Files\iTunes
[04/09/2007|20:04] C:\Program Files\Jasc Software Inc
[19/10/2007|19:14] C:\Program Files\Java
[24/08/2008|12:05] C:\Program Files\Jibege Freq
[07/11/2006|21:36] C:\Program Files\Lavasoft
[12/07/2008|17:48] C:\Program Files\Line6
[22/06/2008|22:09] C:\Program Files\Logitech
[25/06/2008|22:20] C:\Program Files\ma-config.com
[30/10/2005|18:23] C:\Program Files\Marvell
[02/11/2005|21:07] C:\Program Files\Matroska Playback Pack
[25/06/2008|20:22] C:\Program Files\M-Audio
[15/02/2007|22:06] C:\Program Files\Media Player Classic
[26/08/2008|20:58] C:\Program Files\Messenger
[30/10/2005|18:13] C:\Program Files\microsoft frontpage
[22/04/2007|11:50] C:\Program Files\Microsoft Office
[08/09/2008|23:50] C:\Program Files\Microsoft Picture It! PhotoPub
[23/11/2005|22:11] C:\Program Files\Microsoft Works
[23/11/2005|22:08] C:\Program Files\Microsoft Works Suite 2001
[16/02/2007|18:00] C:\Program Files\Mio Technology
[26/08/2008|20:54] C:\Program Files\Movie Maker
[30/10/2005|21:28] C:\Program Files\MSN
[30/10/2005|18:10] C:\Program Files\MSN Gaming Zone
[11/11/2005|13:05] C:\Program Files\MSN Messenger
[17/11/2006|18:57] C:\Program Files\MSXML 4.0
[12/09/2008|13:17] C:\Program Files\Native Instruments
[04/10/2008|11:15] C:\Program Files\Navilog1
[26/08/2008|20:54] C:\Program Files\NetMeeting
[03/10/2008|21:34] C:\Program Files\Neuf
[27/01/2008|15:44] C:\Program Files\nutri
[19/11/2005|19:27] C:\Program Files\NVIDIA Corporation
[26/08/2008|20:54] C:\Program Files\Outlook Express
[12/09/2008|20:04] C:\Program Files\Pianoteq 2.2
[09/11/2005|21:08] C:\Program Files\Pinnacle
[09/11/2005|23:27] C:\Program Files\PowerQuest
[01/05/2008|13:29] C:\Program Files\QuickTime
[15/02/2007|22:06] C:\Program Files\Real Alternative
[24/06/2008|21:18] C:\Program Files\Realtek AC97
[24/09/2006|16:07] C:\Program Files\Ripp-it_AM
[15/08/2006|12:23] C:\Program Files\Satsuki Decoder Pack
[30/10/2005|18:12] C:\Program Files\Services en ligne
[26/09/2007|19:18] C:\Program Files\Sierra On-Line
[04/12/2005|19:27] C:\Program Files\Skype
[17/09/2006|18:20] C:\Program Files\Sony Ericsson
[10/04/2008|18:07] C:\Program Files\SpectralDesign
[14/09/2008|12:06] C:\Program Files\Spybot - Search & Destroy
[17/08/2008|18:55] C:\Program Files\Steinberg
[10/06/2008|18:40] C:\Program Files\Syncrosoft
[26/09/2008|21:20] C:\Program Files\Trend Micro
[01/05/2008|13:44] C:\Program Files\Uninstall Information
[15/08/2008|19:16] C:\Program Files\vst plugins
[25/04/2008|16:38] C:\Program Files\Waves
[13/12/2006|20:36] C:\Program Files\Windows Media Connect 2
[26/08/2008|20:54] C:\Program Files\Windows Media Player
[26/08/2008|20:54] C:\Program Files\Windows NT
[10/11/2005|01:43] C:\Program Files\WindowsUpdate
[29/08/2008|21:49] C:\Program Files\WinRAR
[30/10/2005|18:13] C:\Program Files\xerox
[09/06/2008|18:47] C:\Program Files\XLN Audio
[24/09/2006|11:22] C:\Program Files\XviD
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[17/09/2006|18:51] C:\Program Files\Fichiers communs\Adobe
[13/11/2006|22:43] C:\Program Files\Fichiers communs\Ahead
[26/01/2008|18:25] C:\Program Files\Fichiers communs\Apple
[30/09/2008|19:37] C:\Program Files\Fichiers communs\BitDefender
[22/04/2007|11:50] C:\Program Files\Fichiers communs\Designer
[07/11/2005|20:05] C:\Program Files\Fichiers communs\Hewlett-Packard
[28/06/2008|13:04] C:\Program Files\Fichiers communs\InstallShield
[29/05/2007|22:08] C:\Program Files\Fichiers communs\Java
[22/06/2008|22:11] C:\Program Files\Fichiers communs\Logitech
[01/05/2008|13:44] C:\Program Files\Fichiers communs\Microsoft Shared
[30/10/2005|18:11] C:\Program Files\Fichiers communs\MSSoap
[19/11/2005|19:27] C:\Program Files\Fichiers communs\NVIDIA Shared
[30/10/2005|18:05] C:\Program Files\Fichiers communs\ODBC
[09/11/2005|20:43] C:\Program Files\Fichiers communs\Services
[30/09/2008|19:32] C:\Program Files\Fichiers communs\Softwin
[30/10/2005|18:05] C:\Program Files\Fichiers communs\SpeechEngines
[06/11/2006|22:17] C:\Program Files\Fichiers communs\Symantec Shared
[26/08/2008|20:54] C:\Program Files\Fichiers communs\System
[17/09/2006|18:21] C:\Program Files\Fichiers communs\Teleca Shared
--------------------\\ Process
( 37 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 12:24:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
C:\WINDOWS\system32\CMnmmUtv.ini
C:\WINDOWS\system32\CMnmmUtv.ini2
[b]==> VUNDO <==/b
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Trebz\Local Settings\Application Data\ApplicationHistory\serial bit defender v10 key keygen.exe.1a8ae99b.ini
C:\DOCUME~1\Trebz\Mes documents\Ableton\Library\Presets\Vinyl Distortion\Crack.adv
C:\DOCUME~1\Trebz\Recent\Addictive Drums Crack Install.lnk
C:\DOCUME~1\Trebz\Recent\Addictive Drums XLN Audio Keygen.lnk
C:\DOCUME~1\Trebz\Recent\BitDefender.Total.Security.2008.V11.0.15.+Keygen+.patch.by-Siegfried.lnk
C:\DOCUME~1\Trebz\Recent\Copy.of.crack.pianoteq.lnk
C:\DOCUME~1\Trebz\Recent\Native Instruments B4 II + KeyGen.lnk
C:\DOCUME~1\Trebz\Recent\Native Instruments b4 v2.0.0.7 Incl Keygen-h2O.lnk
C:\DOCUME~1\Trebz\Recent\total_crack.lnk
[F:136][D:566]-> C:\DOCUME~1\Trebz\LOCALS~1\Temp
[F:544][D:0]-> C:\DOCUME~1\Trebz\Cookies
[F:18213][D:38]-> C:\DOCUME~1\Trebz\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 04/10/2008|11:44 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 04/10/2008|12:26 - Option : [3]
--------------------\\ Fin du rapport a 12:26:21
--------------------\\ Lop S&D 4.2.4-5 XP/Vista
( : )
USER : Trebz ( Administrator )
Antivirus : Bitdefender Antivirus 8.0 (Activated)
Firewall : Bitdefender Firewall 8.0 (Activated)
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [3] ( 04/10/2008|12:21 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@advertstream[2].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@adultfriendfinder[2].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@advertising[2].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@adin.bigpoint[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@bigpoint[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@fr.seafight.bigpoint[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@fr1.darkorbit.bigpoint[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@banner.cotedazurpalace[2].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@cotedazurpalace[2].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@www.cotedazurpalace[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@adopt.euroclick[1].txt
Supprime! - C:\DOCUME~1\Trebz\Cookies\trebz@partypoker[2].txt
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[22/06/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ableton
[15/08/2008|13:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[26/01/2008|18:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/01/2008|18:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[30/09/2008|19:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[30/12/2007|12:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[29/12/2007|18:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[06/08/2008|19:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[06/08/2008|19:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[28/06/2008|13:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[12/07/2008|17:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Line 6
[25/06/2008|22:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[22/04/2007|11:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[30/10/2005|21:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[22/06/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[09/11/2005|21:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[09/11/2005|20:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle Studio
[15/02/2007|22:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[04/12/2005|19:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[17/09/2006|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[14/09/2008|12:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[06/11/2006|22:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[17/09/2006|18:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Teleca
[13/09/2008|14:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/12/2006|21:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[30/10/2005|18:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[13/12/2006|20:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[30/10/2005|18:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[22/06/2008|22:32] C:\DOCUME~1\Trebz\APPLIC~1\Ableton
[15/06/2008|21:38] C:\DOCUME~1\Trebz\APPLIC~1\Adobe
[17/09/2006|18:51] C:\DOCUME~1\Trebz\APPLIC~1\AdobeUM
[27/01/2008|21:21] C:\DOCUME~1\Trebz\APPLIC~1\Apple Computer
[30/09/2008|19:38] C:\DOCUME~1\Trebz\APPLIC~1\Bitdefender
[30/12/2007|12:08] C:\DOCUME~1\Trebz\APPLIC~1\CyberLink
[15/04/2007|11:23] C:\DOCUME~1\Trebz\APPLIC~1\DivX
[07/11/2005|20:05] C:\DOCUME~1\Trebz\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[07/11/2005|20:06] C:\DOCUME~1\Trebz\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[06/08/2008|21:13] C:\DOCUME~1\Trebz\APPLIC~1\Help
[30/10/2005|18:16] C:\DOCUME~1\Trebz\APPLIC~1\Identities
[25/06/2008|20:18] C:\DOCUME~1\Trebz\APPLIC~1\InstallShield
[30/10/2005|18:47] C:\DOCUME~1\Trebz\APPLIC~1\InterTrust
[04/09/2007|20:04] C:\DOCUME~1\Trebz\APPLIC~1\Jasc Software Inc
[17/09/2006|18:34] C:\DOCUME~1\Trebz\APPLIC~1\Leadertech
[12/07/2008|17:51] C:\DOCUME~1\Trebz\APPLIC~1\Line 6
[04/11/2005|23:21] C:\DOCUME~1\Trebz\APPLIC~1\Macromedia
[15/08/2006|12:42] C:\DOCUME~1\Trebz\APPLIC~1\Media Player Classic
[14/06/2007|20:26] C:\DOCUME~1\Trebz\APPLIC~1\Microsoft
[23/09/2006|19:47] C:\DOCUME~1\Trebz\APPLIC~1\Mobile Master
[14/02/2006|20:58] C:\DOCUME~1\Trebz\APPLIC~1\MSN6
[19/02/2006|20:28] C:\DOCUME~1\Trebz\APPLIC~1\Real
[10/11/2007|19:48] C:\DOCUME~1\Trebz\APPLIC~1\Skype
[10/06/2008|18:45] C:\DOCUME~1\Trebz\APPLIC~1\Steinberg
[29/05/2007|22:10] C:\DOCUME~1\Trebz\APPLIC~1\Sun
[30/10/2005|19:04] C:\DOCUME~1\Trebz\APPLIC~1\Symantec
[17/09/2006|18:28] C:\DOCUME~1\Trebz\APPLIC~1\Teleca
[02/06/2008|21:48] C:\DOCUME~1\Trebz\APPLIC~1\vlc
[09/06/2008|19:01] C:\DOCUME~1\Trebz\APPLIC~1\Waves Audio
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/09/2008 15:33][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[04/10/2008 09:27][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[23/06/2008|17:40] C:\Program Files\Ableton
[04/10/2008|11:02] C:\Program Files\Adobe
[21/09/2008|17:37] C:\Program Files\adslTV
[13/11/2006|22:43] C:\Program Files\Ahead
[20/05/2008|20:05] C:\Program Files\Alwil Software
[26/04/2008|15:12] C:\Program Files\Antares
[26/01/2008|18:26] C:\Program Files\Apple Software Update
[24/09/2006|11:44] C:\Program Files\AviSynth 2.5
[30/09/2008|19:37] C:\Program Files\BitDefender
[26/05/2008|20:22] C:\Program Files\BitLord
[10/03/2008|23:23] C:\Program Files\Bonjour
[10/04/2008|18:14] C:\Program Files\brainspawn
[13/11/2006|20:08] C:\Program Files\CCleaner
[05/07/2008|16:08] C:\Program Files\Common Files
[30/12/2007|12:03] C:\Program Files\CyberLink
[01/05/2008|13:27] C:\Program Files\directx
[24/06/2008|19:37] C:\Program Files\DivX
[25/04/2008|16:18] C:\Program Files\DSPFX
[30/10/2005|22:16] C:\Program Files\D-Tools
[12/11/2005|11:55] C:\Program Files\DVD Decrypter
[30/10/2005|23:18] C:\Program Files\DVD Shrink
[03/06/2007|17:56] C:\Program Files\EarMaster
[24/09/2006|14:57] C:\Program Files\eRightSoft
[30/09/2008|19:36] C:\Program Files\Fichiers communs
[27/01/2008|19:22] C:\Program Files\Free iPod Video Converter
[03/11/2005|17:58] C:\Program Files\Guitar Pro 4
[03/10/2008|20:26] C:\Program Files\Hercules
[07/11/2005|20:04] C:\Program Files\Hewlett-Packard
[17/08/2007|17:28] C:\Program Files\Hofmann
[11/06/2007|19:45] C:\Program Files\HP
[06/08/2008|19:33] C:\Program Files\IncrediMail
[03/10/2008|20:26] C:\Program Files\InstallShield Installation Information
[15/09/2007|20:49] C:\Program Files\InterLok
[15/08/2008|19:11] C:\Program Files\Internet Explorer
[26/01/2008|18:33] C:\Program Files\iPod
[26/01/2008|18:33] C:\Program Files\iTunes
[04/09/2007|20:04] C:\Program Files\Jasc Software Inc
[19/10/2007|19:14] C:\Program Files\Java
[24/08/2008|12:05] C:\Program Files\Jibege Freq
[07/11/2006|21:36] C:\Program Files\Lavasoft
[12/07/2008|17:48] C:\Program Files\Line6
[22/06/2008|22:09] C:\Program Files\Logitech
[25/06/2008|22:20] C:\Program Files\ma-config.com
[30/10/2005|18:23] C:\Program Files\Marvell
[02/11/2005|21:07] C:\Program Files\Matroska Playback Pack
[25/06/2008|20:22] C:\Program Files\M-Audio
[15/02/2007|22:06] C:\Program Files\Media Player Classic
[26/08/2008|20:58] C:\Program Files\Messenger
[30/10/2005|18:13] C:\Program Files\microsoft frontpage
[22/04/2007|11:50] C:\Program Files\Microsoft Office
[08/09/2008|23:50] C:\Program Files\Microsoft Picture It! PhotoPub
[23/11/2005|22:11] C:\Program Files\Microsoft Works
[23/11/2005|22:08] C:\Program Files\Microsoft Works Suite 2001
[16/02/2007|18:00] C:\Program Files\Mio Technology
[26/08/2008|20:54] C:\Program Files\Movie Maker
[30/10/2005|21:28] C:\Program Files\MSN
[30/10/2005|18:10] C:\Program Files\MSN Gaming Zone
[11/11/2005|13:05] C:\Program Files\MSN Messenger
[17/11/2006|18:57] C:\Program Files\MSXML 4.0
[12/09/2008|13:17] C:\Program Files\Native Instruments
[04/10/2008|11:15] C:\Program Files\Navilog1
[26/08/2008|20:54] C:\Program Files\NetMeeting
[03/10/2008|21:34] C:\Program Files\Neuf
[27/01/2008|15:44] C:\Program Files\nutri
[19/11/2005|19:27] C:\Program Files\NVIDIA Corporation
[26/08/2008|20:54] C:\Program Files\Outlook Express
[12/09/2008|20:04] C:\Program Files\Pianoteq 2.2
[09/11/2005|21:08] C:\Program Files\Pinnacle
[09/11/2005|23:27] C:\Program Files\PowerQuest
[01/05/2008|13:29] C:\Program Files\QuickTime
[15/02/2007|22:06] C:\Program Files\Real Alternative
[24/06/2008|21:18] C:\Program Files\Realtek AC97
[24/09/2006|16:07] C:\Program Files\Ripp-it_AM
[15/08/2006|12:23] C:\Program Files\Satsuki Decoder Pack
[30/10/2005|18:12] C:\Program Files\Services en ligne
[26/09/2007|19:18] C:\Program Files\Sierra On-Line
[04/12/2005|19:27] C:\Program Files\Skype
[17/09/2006|18:20] C:\Program Files\Sony Ericsson
[10/04/2008|18:07] C:\Program Files\SpectralDesign
[14/09/2008|12:06] C:\Program Files\Spybot - Search & Destroy
[17/08/2008|18:55] C:\Program Files\Steinberg
[10/06/2008|18:40] C:\Program Files\Syncrosoft
[26/09/2008|21:20] C:\Program Files\Trend Micro
[01/05/2008|13:44] C:\Program Files\Uninstall Information
[15/08/2008|19:16] C:\Program Files\vst plugins
[25/04/2008|16:38] C:\Program Files\Waves
[13/12/2006|20:36] C:\Program Files\Windows Media Connect 2
[26/08/2008|20:54] C:\Program Files\Windows Media Player
[26/08/2008|20:54] C:\Program Files\Windows NT
[10/11/2005|01:43] C:\Program Files\WindowsUpdate
[29/08/2008|21:49] C:\Program Files\WinRAR
[30/10/2005|18:13] C:\Program Files\xerox
[09/06/2008|18:47] C:\Program Files\XLN Audio
[24/09/2006|11:22] C:\Program Files\XviD
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[17/09/2006|18:51] C:\Program Files\Fichiers communs\Adobe
[13/11/2006|22:43] C:\Program Files\Fichiers communs\Ahead
[26/01/2008|18:25] C:\Program Files\Fichiers communs\Apple
[30/09/2008|19:37] C:\Program Files\Fichiers communs\BitDefender
[22/04/2007|11:50] C:\Program Files\Fichiers communs\Designer
[07/11/2005|20:05] C:\Program Files\Fichiers communs\Hewlett-Packard
[28/06/2008|13:04] C:\Program Files\Fichiers communs\InstallShield
[29/05/2007|22:08] C:\Program Files\Fichiers communs\Java
[22/06/2008|22:11] C:\Program Files\Fichiers communs\Logitech
[01/05/2008|13:44] C:\Program Files\Fichiers communs\Microsoft Shared
[30/10/2005|18:11] C:\Program Files\Fichiers communs\MSSoap
[19/11/2005|19:27] C:\Program Files\Fichiers communs\NVIDIA Shared
[30/10/2005|18:05] C:\Program Files\Fichiers communs\ODBC
[09/11/2005|20:43] C:\Program Files\Fichiers communs\Services
[30/09/2008|19:32] C:\Program Files\Fichiers communs\Softwin
[30/10/2005|18:05] C:\Program Files\Fichiers communs\SpeechEngines
[06/11/2006|22:17] C:\Program Files\Fichiers communs\Symantec Shared
[26/08/2008|20:54] C:\Program Files\Fichiers communs\System
[17/09/2006|18:21] C:\Program Files\Fichiers communs\Teleca Shared
--------------------\\ Process
( 37 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 12:24:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
C:\WINDOWS\system32\CMnmmUtv.ini
C:\WINDOWS\system32\CMnmmUtv.ini2
[b]==> VUNDO <==/b
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Trebz\Local Settings\Application Data\ApplicationHistory\serial bit defender v10 key keygen.exe.1a8ae99b.ini
C:\DOCUME~1\Trebz\Mes documents\Ableton\Library\Presets\Vinyl Distortion\Crack.adv
C:\DOCUME~1\Trebz\Recent\Addictive Drums Crack Install.lnk
C:\DOCUME~1\Trebz\Recent\Addictive Drums XLN Audio Keygen.lnk
C:\DOCUME~1\Trebz\Recent\BitDefender.Total.Security.2008.V11.0.15.+Keygen+.patch.by-Siegfried.lnk
C:\DOCUME~1\Trebz\Recent\Copy.of.crack.pianoteq.lnk
C:\DOCUME~1\Trebz\Recent\Native Instruments B4 II + KeyGen.lnk
C:\DOCUME~1\Trebz\Recent\Native Instruments b4 v2.0.0.7 Incl Keygen-h2O.lnk
C:\DOCUME~1\Trebz\Recent\total_crack.lnk
[F:136][D:566]-> C:\DOCUME~1\Trebz\LOCALS~1\Temp
[F:544][D:0]-> C:\DOCUME~1\Trebz\Cookies
[F:18213][D:38]-> C:\DOCUME~1\Trebz\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 04/10/2008|11:44 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 04/10/2008|12:26 - Option : [3]
--------------------\\ Fin du rapport a 12:26:21
benurrr
Messages postés
9638
Date d'inscription
samedi 24 mai 2008
Statut
Contributeur sécurité
Dernière intervention
11 janvier 2012
107
>
trebz30
Messages postés
15
Date d'inscription
samedi 4 octobre 2008
Statut
Membre
Dernière intervention
26 février 2010
4 oct. 2008 à 12:32
4 oct. 2008 à 12:32
Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
http://www.atribune.org/ccount/click.php?id=4
Double-clique VundoFix.exe afin de le lancer.
Coche Run VundoFix as a task.
Un message t'avertira que l'outil va se fermer et s'ouvrir à nouveau : clique Ok
Clique sur le bouton Scan for Vundo.
Lorsque le scan est complété, clique sur le bouton Remove Vundo.
Une invite te demandera si tu veux supprimer les fichiers, clique YES
Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
Démarre ton PC à nouveau.
s'il ne trouve rien refait le scan on mode sans echec
http://www.atribune.org/ccount/click.php?id=4
Double-clique VundoFix.exe afin de le lancer.
Coche Run VundoFix as a task.
Un message t'avertira que l'outil va se fermer et s'ouvrir à nouveau : clique Ok
Clique sur le bouton Scan for Vundo.
Lorsque le scan est complété, clique sur le bouton Remove Vundo.
Une invite te demandera si tu veux supprimer les fichiers, clique YES
Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
Démarre ton PC à nouveau.
s'il ne trouve rien refait le scan on mode sans echec
trebz30
Messages postés
15
Date d'inscription
samedi 4 octobre 2008
Statut
Membre
Dernière intervention
26 février 2010
>
benurrr
Messages postés
9638
Date d'inscription
samedi 24 mai 2008
Statut
Contributeur sécurité
Dernière intervention
11 janvier 2012
4 oct. 2008 à 14:05
4 oct. 2008 à 14:05
J'ai lancé vundofix en mode normal et en mode sans echec; et il ne ma pas trouvé d'infection (et j'ai toujours mes fenetres publicitaires)
trebz30
Messages postés
15
Date d'inscription
samedi 4 octobre 2008
Statut
Membre
Dernière intervention
26 février 2010
4 oct. 2008 à 16:32
4 oct. 2008 à 16:32
up
benurrr
Messages postés
9638
Date d'inscription
samedi 24 mai 2008
Statut
Contributeur sécurité
Dernière intervention
11 janvier 2012
107
4 oct. 2008 à 19:00
4 oct. 2008 à 19:00
Téléchargez VirtumundoBeGone sur votre bureau.
http://secured2k.home.comcast.net/~secured2k/tools/VirtumundoBeGone.exe
Double-cliquez ensuite sur VirtumundoBeGone.exe et suivez les instructions qui s'affichent à l'écran.
Une fois terminé, redémarrez votre PC.
PS : Ne vous inquiétez pas si vous voyez un écran bleu "Erreur fatale", c'est normal.
Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
mais C.. de penser que tu es libre...merci a australe13
http://secured2k.home.comcast.net/~secured2k/tools/VirtumundoBeGone.exe
Double-cliquez ensuite sur VirtumundoBeGone.exe et suivez les instructions qui s'affichent à l'écran.
Une fois terminé, redémarrez votre PC.
PS : Ne vous inquiétez pas si vous voyez un écran bleu "Erreur fatale", c'est normal.
Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
mais C.. de penser que tu es libre...merci a australe13
trebz30
Messages postés
15
Date d'inscription
samedi 4 octobre 2008
Statut
Membre
Dernière intervention
26 février 2010
>
benurrr
Messages postés
9638
Date d'inscription
samedi 24 mai 2008
Statut
Contributeur sécurité
Dernière intervention
11 janvier 2012
4 oct. 2008 à 19:38
4 oct. 2008 à 19:38
J'ai lancé VirtumundoBeGone et visiblement il n'a rien trouvé.
Voici le rapport :
[10/04/2008, 19:30:30] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Trebz\Bureau\VirtumundoBeGone.exe" )
[10/04/2008, 19:30:39] - Detected System Information:
[10/04/2008, 19:30:39] - Windows Version: 5.1.2600, Service Pack 2
[10/04/2008, 19:30:39] - Current Username: Trebz (Admin)
[10/04/2008, 19:30:39] - Windows is in NORMAL mode.
[10/04/2008, 19:30:39] - Searching for Browser Helper Objects:
[10/04/2008, 19:30:39] - BHO 1: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/04/2008, 19:30:39] - BHO 2: {9700b61c-eb97-4606-9950-d230c97b0fce} ()
[10/04/2008, 19:30:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/04/2008, 19:30:39] - Checking for HKLM\...\Winlogon\Notify\gpwrsu
[10/04/2008, 19:30:39] - Key not found: HKLM\...\Winlogon\Notify\gpwrsu, continuing.
[10/04/2008, 19:30:39] - BHO 3: {EA820942-2FBE-470D-9BCE-006A7E416651} ()
[10/04/2008, 19:30:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/04/2008, 19:30:39] - Checking for HKLM\...\Winlogon\Notify\vtUmmnMC
[10/04/2008, 19:30:39] - Key not found: HKLM\...\Winlogon\Notify\vtUmmnMC, continuing.
[10/04/2008, 19:30:40] - Finished Searching Browser Helper Objects
[10/04/2008, 19:30:40] - Finishing up...
[10/04/2008, 19:30:40] - Nothing found! Exiting...
[10/04/2008, 19:31:02] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Trebz\Bureau\VirtumundoBeGone.exe" )
[10/04/2008, 19:31:04] - Detected System Information:
[10/04/2008, 19:31:04] - Windows Version: 5.1.2600, Service Pack 2
[10/04/2008, 19:31:04] - Current Username: Trebz (Admin)
[10/04/2008, 19:31:04] - Windows is in NORMAL mode.
[10/04/2008, 19:31:04] - Searching for Browser Helper Objects:
[10/04/2008, 19:31:04] - BHO 1: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/04/2008, 19:31:04] - BHO 2: {9700b61c-eb97-4606-9950-d230c97b0fce} ()
[10/04/2008, 19:31:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/04/2008, 19:31:04] - Checking for HKLM\...\Winlogon\Notify\gpwrsu
[10/04/2008, 19:31:04] - Key not found: HKLM\...\Winlogon\Notify\gpwrsu, continuing.
[10/04/2008, 19:31:04] - BHO 3: {EA820942-2FBE-470D-9BCE-006A7E416651} ()
[10/04/2008, 19:31:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/04/2008, 19:31:04] - Checking for HKLM\...\Winlogon\Notify\vtUmmnMC
[10/04/2008, 19:31:04] - Key not found: HKLM\...\Winlogon\Notify\vtUmmnMC, continuing.
[10/04/2008, 19:31:04] - Finished Searching Browser Helper Objects
[10/04/2008, 19:31:04] - Finishing up...
[10/04/2008, 19:31:04] - Nothing found! Exiting...
Voici le rapport :
[10/04/2008, 19:30:30] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Trebz\Bureau\VirtumundoBeGone.exe" )
[10/04/2008, 19:30:39] - Detected System Information:
[10/04/2008, 19:30:39] - Windows Version: 5.1.2600, Service Pack 2
[10/04/2008, 19:30:39] - Current Username: Trebz (Admin)
[10/04/2008, 19:30:39] - Windows is in NORMAL mode.
[10/04/2008, 19:30:39] - Searching for Browser Helper Objects:
[10/04/2008, 19:30:39] - BHO 1: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/04/2008, 19:30:39] - BHO 2: {9700b61c-eb97-4606-9950-d230c97b0fce} ()
[10/04/2008, 19:30:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/04/2008, 19:30:39] - Checking for HKLM\...\Winlogon\Notify\gpwrsu
[10/04/2008, 19:30:39] - Key not found: HKLM\...\Winlogon\Notify\gpwrsu, continuing.
[10/04/2008, 19:30:39] - BHO 3: {EA820942-2FBE-470D-9BCE-006A7E416651} ()
[10/04/2008, 19:30:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/04/2008, 19:30:39] - Checking for HKLM\...\Winlogon\Notify\vtUmmnMC
[10/04/2008, 19:30:39] - Key not found: HKLM\...\Winlogon\Notify\vtUmmnMC, continuing.
[10/04/2008, 19:30:40] - Finished Searching Browser Helper Objects
[10/04/2008, 19:30:40] - Finishing up...
[10/04/2008, 19:30:40] - Nothing found! Exiting...
[10/04/2008, 19:31:02] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Trebz\Bureau\VirtumundoBeGone.exe" )
[10/04/2008, 19:31:04] - Detected System Information:
[10/04/2008, 19:31:04] - Windows Version: 5.1.2600, Service Pack 2
[10/04/2008, 19:31:04] - Current Username: Trebz (Admin)
[10/04/2008, 19:31:04] - Windows is in NORMAL mode.
[10/04/2008, 19:31:04] - Searching for Browser Helper Objects:
[10/04/2008, 19:31:04] - BHO 1: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/04/2008, 19:31:04] - BHO 2: {9700b61c-eb97-4606-9950-d230c97b0fce} ()
[10/04/2008, 19:31:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/04/2008, 19:31:04] - Checking for HKLM\...\Winlogon\Notify\gpwrsu
[10/04/2008, 19:31:04] - Key not found: HKLM\...\Winlogon\Notify\gpwrsu, continuing.
[10/04/2008, 19:31:04] - BHO 3: {EA820942-2FBE-470D-9BCE-006A7E416651} ()
[10/04/2008, 19:31:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/04/2008, 19:31:04] - Checking for HKLM\...\Winlogon\Notify\vtUmmnMC
[10/04/2008, 19:31:04] - Key not found: HKLM\...\Winlogon\Notify\vtUmmnMC, continuing.
[10/04/2008, 19:31:04] - Finished Searching Browser Helper Objects
[10/04/2008, 19:31:04] - Finishing up...
[10/04/2008, 19:31:04] - Nothing found! Exiting...
benurrr
Messages postés
9638
Date d'inscription
samedi 24 mai 2008
Statut
Contributeur sécurité
Dernière intervention
11 janvier 2012
107
>
trebz30
Messages postés
15
Date d'inscription
samedi 4 octobre 2008
Statut
Membre
Dernière intervention
26 février 2010
4 oct. 2008 à 19:44
4 oct. 2008 à 19:44
télécharge malwarbyte http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebyte s anti malware
a l'installation vérifie que mise a jour et lancer programme et scan complet sont bien cocher
Une fois a jour, le programme va se lancer; clic sur l´onglet paramètre, et coche la case : "Arrêter internet explorer pendant la suppression".
A la fin du scan clique sur Afficher les résultats
Suppression des éléments détectés >>>> clique sur Supprimer la sélection ou supprimer tout
S'il t'es demandé de redémarrer >>> clique sur "Yes"
Et tu poste le rapport générer
et on attendant une réponse tu peut refaire un scan malwarbyte mais on mode sans échec car beaucoup plus efficace
comment démarrer on mode sans échec ici tuto http://www.infos-du-net.com/forum/272325-11-tuto-demarrer-mode-echec
tu enregistre le rapport générer de façon a le retrouver et tu poste le nouveau rapport rapport
a l'installation vérifie que mise a jour et lancer programme et scan complet sont bien cocher
Une fois a jour, le programme va se lancer; clic sur l´onglet paramètre, et coche la case : "Arrêter internet explorer pendant la suppression".
A la fin du scan clique sur Afficher les résultats
Suppression des éléments détectés >>>> clique sur Supprimer la sélection ou supprimer tout
S'il t'es demandé de redémarrer >>> clique sur "Yes"
Et tu poste le rapport générer
et on attendant une réponse tu peut refaire un scan malwarbyte mais on mode sans échec car beaucoup plus efficace
comment démarrer on mode sans échec ici tuto http://www.infos-du-net.com/forum/272325-11-tuto-demarrer-mode-echec
tu enregistre le rapport générer de façon a le retrouver et tu poste le nouveau rapport rapport
trebz30
Messages postés
15
Date d'inscription
samedi 4 octobre 2008
Statut
Membre
Dernière intervention
26 février 2010
>
benurrr
Messages postés
9638
Date d'inscription
samedi 24 mai 2008
Statut
Contributeur sécurité
Dernière intervention
11 janvier 2012
4 oct. 2008 à 21:25
4 oct. 2008 à 21:25
Merci beaucoup pour ton aide benurrr, visiblement, je n'ai plus de publicité.
merci encore pour ton aide.
voici le rapport:
Malwarebytes' Anti-Malware 1.28
Version de la base de données: 1227
Windows 5.1.2600 Service Pack 2
04/10/2008 21:14:17
mbam-log-2008-10-04 (21-14-17).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 130047
Temps écoulé: 1 hour(s), 13 minute(s), 19 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 9
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 8
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\gpwrsu.dll (Trojan.Vundo) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9700b61c-eb97-4606-9950-d230c97b0fce} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9700b61c-eb97-4606-9950-d230c97b0fce} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmf75abf8b (Trojan.Agent) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\gpwrsu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\maryroun.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\skqldeag.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hotflo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\~.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\BMf75abf8b.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BMf75abf8b.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
merci encore pour ton aide.
voici le rapport:
Malwarebytes' Anti-Malware 1.28
Version de la base de données: 1227
Windows 5.1.2600 Service Pack 2
04/10/2008 21:14:17
mbam-log-2008-10-04 (21-14-17).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 130047
Temps écoulé: 1 hour(s), 13 minute(s), 19 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 9
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 8
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\gpwrsu.dll (Trojan.Vundo) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9700b61c-eb97-4606-9950-d230c97b0fce} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9700b61c-eb97-4606-9950-d230c97b0fce} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmf75abf8b (Trojan.Agent) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\gpwrsu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\maryroun.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\skqldeag.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hotflo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\~.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\BMf75abf8b.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BMf75abf8b.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
benurrr
Messages postés
9638
Date d'inscription
samedi 24 mai 2008
Statut
Contributeur sécurité
Dernière intervention
11 janvier 2012
107
>
trebz30
Messages postés
15
Date d'inscription
samedi 4 octobre 2008
Statut
Membre
Dernière intervention
26 février 2010
4 oct. 2008 à 22:46
4 oct. 2008 à 22:46
on va nettoyer les fix qui nous ont servit
Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
Double clique sur ToolsCleaner2.exe >
puis Recherche
et sur Suppression
Note : ton bureau va disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :
CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"
Tape explorer.exe et valide. Cela fera re-apparaître le Bureau
et poste le rapport generer stp
Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
Double clique sur ToolsCleaner2.exe >
puis Recherche
et sur Suppression
Note : ton bureau va disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :
CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"
Tape explorer.exe et valide. Cela fera re-apparaître le Bureau
et poste le rapport generer stp
4 oct. 2008 à 12:04
Juste une petite question, que veux tu dire par "on constate deja du vundo". Qu'est ce qu"un vundo? dois je le supprimer?
voici le fichier d'analyse LOP S&D
--------------------\\ Lop S&D 4.2.4-5 XP/Vista
( : )
USER : Trebz ( Administrator )
Antivirus : Bitdefender Antivirus 8.0 (Activated)
Firewall : Bitdefender Firewall 8.0 (Activated)
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 04/10/2008|11:39 )
--------------------\\ Listing des dossiers dans APPLIC~1
[22/06/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ableton
[15/08/2008|13:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[26/01/2008|18:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/01/2008|18:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[30/09/2008|19:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[30/12/2007|12:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[29/12/2007|18:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[06/08/2008|19:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[06/08/2008|19:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[28/06/2008|13:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[12/07/2008|17:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Line 6
[25/06/2008|22:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[22/04/2007|11:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[30/10/2005|21:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[22/06/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[09/11/2005|21:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[09/11/2005|20:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle Studio
[15/02/2007|22:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[04/12/2005|19:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[17/09/2006|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[14/09/2008|12:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[06/11/2006|22:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[17/09/2006|18:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Teleca
[13/09/2008|14:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/12/2006|21:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[30/10/2005|18:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[13/12/2006|20:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[30/10/2005|18:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[22/06/2008|22:32] C:\DOCUME~1\Trebz\APPLIC~1\Ableton
[15/06/2008|21:38] C:\DOCUME~1\Trebz\APPLIC~1\Adobe
[17/09/2006|18:51] C:\DOCUME~1\Trebz\APPLIC~1\AdobeUM
[27/01/2008|21:21] C:\DOCUME~1\Trebz\APPLIC~1\Apple Computer
[30/09/2008|19:38] C:\DOCUME~1\Trebz\APPLIC~1\Bitdefender
[30/12/2007|12:08] C:\DOCUME~1\Trebz\APPLIC~1\CyberLink
[15/04/2007|11:23] C:\DOCUME~1\Trebz\APPLIC~1\DivX
[07/11/2005|20:05] C:\DOCUME~1\Trebz\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[07/11/2005|20:06] C:\DOCUME~1\Trebz\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[06/08/2008|21:13] C:\DOCUME~1\Trebz\APPLIC~1\Help
[30/10/2005|18:16] C:\DOCUME~1\Trebz\APPLIC~1\Identities
[25/06/2008|20:18] C:\DOCUME~1\Trebz\APPLIC~1\InstallShield
[30/10/2005|18:47] C:\DOCUME~1\Trebz\APPLIC~1\InterTrust
[04/09/2007|20:04] C:\DOCUME~1\Trebz\APPLIC~1\Jasc Software Inc
[17/09/2006|18:34] C:\DOCUME~1\Trebz\APPLIC~1\Leadertech
[12/07/2008|17:51] C:\DOCUME~1\Trebz\APPLIC~1\Line 6
[04/11/2005|23:21] C:\DOCUME~1\Trebz\APPLIC~1\Macromedia
[15/08/2006|12:42] C:\DOCUME~1\Trebz\APPLIC~1\Media Player Classic
[14/06/2007|20:26] C:\DOCUME~1\Trebz\APPLIC~1\Microsoft
[23/09/2006|19:47] C:\DOCUME~1\Trebz\APPLIC~1\Mobile Master
[14/02/2006|20:58] C:\DOCUME~1\Trebz\APPLIC~1\MSN6
[19/02/2006|20:28] C:\DOCUME~1\Trebz\APPLIC~1\Real
[10/11/2007|19:48] C:\DOCUME~1\Trebz\APPLIC~1\Skype
[10/06/2008|18:45] C:\DOCUME~1\Trebz\APPLIC~1\Steinberg
[29/05/2007|22:10] C:\DOCUME~1\Trebz\APPLIC~1\Sun
[30/10/2005|19:04] C:\DOCUME~1\Trebz\APPLIC~1\Symantec
[17/09/2006|18:28] C:\DOCUME~1\Trebz\APPLIC~1\Teleca
[02/06/2008|21:48] C:\DOCUME~1\Trebz\APPLIC~1\vlc
[09/06/2008|19:01] C:\DOCUME~1\Trebz\APPLIC~1\Waves Audio
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/09/2008 15:33][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[04/10/2008 09:27][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[23/06/2008|17:40] C:\Program Files\Ableton
[04/10/2008|11:02] C:\Program Files\Adobe
[21/09/2008|17:37] C:\Program Files\adslTV
[13/11/2006|22:43] C:\Program Files\Ahead
[20/05/2008|20:05] C:\Program Files\Alwil Software
[26/04/2008|15:12] C:\Program Files\Antares
[26/01/2008|18:26] C:\Program Files\Apple Software Update
[24/09/2006|11:44] C:\Program Files\AviSynth 2.5
[30/09/2008|19:37] C:\Program Files\BitDefender
[26/05/2008|20:22] C:\Program Files\BitLord
[10/03/2008|23:23] C:\Program Files\Bonjour
[10/04/2008|18:14] C:\Program Files\brainspawn
[13/11/2006|20:08] C:\Program Files\CCleaner
[05/07/2008|16:08] C:\Program Files\Common Files
[30/12/2007|12:03] C:\Program Files\CyberLink
[01/05/2008|13:27] C:\Program Files\directx
[24/06/2008|19:37] C:\Program Files\DivX
[25/04/2008|16:18] C:\Program Files\DSPFX
[30/10/2005|22:16] C:\Program Files\D-Tools
[12/11/2005|11:55] C:\Program Files\DVD Decrypter
[30/10/2005|23:18] C:\Program Files\DVD Shrink
[03/06/2007|17:56] C:\Program Files\EarMaster
[24/09/2006|14:57] C:\Program Files\eRightSoft
[30/09/2008|19:36] C:\Program Files\Fichiers communs
[27/01/2008|19:22] C:\Program Files\Free iPod Video Converter
[03/11/2005|17:58] C:\Program Files\Guitar Pro 4
[03/10/2008|20:26] C:\Program Files\Hercules
[07/11/2005|20:04] C:\Program Files\Hewlett-Packard
[17/08/2007|17:28] C:\Program Files\Hofmann
[11/06/2007|19:45] C:\Program Files\HP
[06/08/2008|19:33] C:\Program Files\IncrediMail
[03/10/2008|20:26] C:\Program Files\InstallShield Installation Information
[15/09/2007|20:49] C:\Program Files\InterLok
[15/08/2008|19:11] C:\Program Files\Internet Explorer
[26/01/2008|18:33] C:\Program Files\iPod
[26/01/2008|18:33] C:\Program Files\iTunes
[04/09/2007|20:04] C:\Program Files\Jasc Software Inc
[19/10/2007|19:14] C:\Program Files\Java
[24/08/2008|12:05] C:\Program Files\Jibege Freq
[07/11/2006|21:36] C:\Program Files\Lavasoft
[12/07/2008|17:48] C:\Program Files\Line6
[22/06/2008|22:09] C:\Program Files\Logitech
[25/06/2008|22:20] C:\Program Files\ma-config.com
[30/10/2005|18:23] C:\Program Files\Marvell
[02/11/2005|21:07] C:\Program Files\Matroska Playback Pack
[25/06/2008|20:22] C:\Program Files\M-Audio
[15/02/2007|22:06] C:\Program Files\Media Player Classic
[26/08/2008|20:58] C:\Program Files\Messenger
[30/10/2005|18:13] C:\Program Files\microsoft frontpage
[22/04/2007|11:50] C:\Program Files\Microsoft Office
[08/09/2008|23:50] C:\Program Files\Microsoft Picture It! PhotoPub
[23/11/2005|22:11] C:\Program Files\Microsoft Works
[23/11/2005|22:08] C:\Program Files\Microsoft Works Suite 2001
[16/02/2007|18:00] C:\Program Files\Mio Technology
[26/08/2008|20:54] C:\Program Files\Movie Maker
[30/10/2005|21:28] C:\Program Files\MSN
[30/10/2005|18:10] C:\Program Files\MSN Gaming Zone
[11/11/2005|13:05] C:\Program Files\MSN Messenger
[17/11/2006|18:57] C:\Program Files\MSXML 4.0
[12/09/2008|13:17] C:\Program Files\Native Instruments
[04/10/2008|11:15] C:\Program Files\Navilog1
[26/08/2008|20:54] C:\Program Files\NetMeeting
[03/10/2008|21:34] C:\Program Files\Neuf
[27/01/2008|15:44] C:\Program Files\nutri
[19/11/2005|19:27] C:\Program Files\NVIDIA Corporation
[26/08/2008|20:54] C:\Program Files\Outlook Express
[12/09/2008|20:04] C:\Program Files\Pianoteq 2.2
[09/11/2005|21:08] C:\Program Files\Pinnacle
[09/11/2005|23:27] C:\Program Files\PowerQuest
[01/05/2008|13:29] C:\Program Files\QuickTime
[15/02/2007|22:06] C:\Program Files\Real Alternative
[24/06/2008|21:18] C:\Program Files\Realtek AC97
[24/09/2006|16:07] C:\Program Files\Ripp-it_AM
[15/08/2006|12:23] C:\Program Files\Satsuki Decoder Pack
[30/10/2005|18:12] C:\Program Files\Services en ligne
[26/09/2007|19:18] C:\Program Files\Sierra On-Line
[04/12/2005|19:27] C:\Program Files\Skype
[17/09/2006|18:20] C:\Program Files\Sony Ericsson
[10/04/2008|18:07] C:\Program Files\SpectralDesign
[14/09/2008|12:06] C:\Program Files\Spybot - Search & Destroy
[17/08/2008|18:55] C:\Program Files\Steinberg
[10/06/2008|18:40] C:\Program Files\Syncrosoft
[26/09/2008|21:20] C:\Program Files\Trend Micro
[01/05/2008|13:44] C:\Program Files\Uninstall Information
[15/08/2008|19:16] C:\Program Files\vst plugins
[25/04/2008|16:38] C:\Program Files\Waves
[13/12/2006|20:36] C:\Program Files\Windows Media Connect 2
[26/08/2008|20:54] C:\Program Files\Windows Media Player
[26/08/2008|20:54] C:\Program Files\Windows NT
[10/11/2005|01:43] C:\Program Files\WindowsUpdate
[29/08/2008|21:49] C:\Program Files\WinRAR
[30/10/2005|18:13] C:\Program Files\xerox
[09/06/2008|18:47] C:\Program Files\XLN Audio
[24/09/2006|11:22] C:\Program Files\XviD
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[17/09/2006|18:51] C:\Program Files\Fichiers communs\Adobe
[13/11/2006|22:43] C:\Program Files\Fichiers communs\Ahead
[26/01/2008|18:25] C:\Program Files\Fichiers communs\Apple
[30/09/2008|19:37] C:\Program Files\Fichiers communs\BitDefender
[22/04/2007|11:50] C:\Program Files\Fichiers communs\Designer
[07/11/2005|20:05] C:\Program Files\Fichiers communs\Hewlett-Packard
[28/06/2008|13:04] C:\Program Files\Fichiers communs\InstallShield
[29/05/2007|22:08] C:\Program Files\Fichiers communs\Java
[22/06/2008|22:11] C:\Program Files\Fichiers communs\Logitech
[01/05/2008|13:44] C:\Program Files\Fichiers communs\Microsoft Shared
[30/10/2005|18:11] C:\Program Files\Fichiers communs\MSSoap
[19/11/2005|19:27] C:\Program Files\Fichiers communs\NVIDIA Shared
[30/10/2005|18:05] C:\Program Files\Fichiers communs\ODBC
[09/11/2005|20:43] C:\Program Files\Fichiers communs\Services
[30/09/2008|19:32] C:\Program Files\Fichiers communs\Softwin
[30/10/2005|18:05] C:\Program Files\Fichiers communs\SpeechEngines
[06/11/2006|22:17] C:\Program Files\Fichiers communs\Symantec Shared
[26/08/2008|20:54] C:\Program Files\Fichiers communs\System
[17/09/2006|18:21] C:\Program Files\Fichiers communs\Teleca Shared
--------------------\\ Process
( 39 Processes )
IEXPLORE.EXE ~ [PID:1828]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\Trebz\Cookies\trebz@advertstream[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@adultfriendfinder[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@advertising[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@adin.bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@fr.seafight.bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@fr1.darkorbit.bigpoint[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@banner.cotedazurpalace[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@cotedazurpalace[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@www.cotedazurpalace[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@adopt.euroclick[1].txt
C:\DOCUME~1\Trebz\Cookies\trebz@partypoker[2].txt
C:\DOCUME~1\Trebz\Cookies\trebz@fr.seafight.bigpoint[1].txt
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 11:41:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
C:\WINDOWS\system32\CMnmmUtv.ini
C:\WINDOWS\system32\CMnmmUtv.ini2
[b]==> VUNDO <==/b
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Trebz\Local Settings\Application Data\ApplicationHistory\serial bit defender v10 key keygen.exe.1a8ae99b.ini
C:\DOCUME~1\Trebz\Mes documents\Ableton\Library\Presets\Vinyl Distortion\Crack.adv
C:\DOCUME~1\Trebz\Recent\Addictive Drums Crack Install.lnk
C:\DOCUME~1\Trebz\Recent\Addictive Drums XLN Audio Keygen.lnk
C:\DOCUME~1\Trebz\Recent\BitDefender.Total.Security.2008.V11.0.15.+Keygen+.patch.by-Siegfried.lnk
C:\DOCUME~1\Trebz\Recent\Copy.of.crack.pianoteq.lnk
C:\DOCUME~1\Trebz\Recent\Native Instruments B4 II + KeyGen.lnk
C:\DOCUME~1\Trebz\Recent\Native Instruments b4 v2.0.0.7 Incl Keygen-h2O.lnk
C:\DOCUME~1\Trebz\Recent\total_crack.lnk
[F:136][D:566]-> C:\DOCUME~1\Trebz\LOCALS~1\Temp
[F:551][D:0]-> C:\DOCUME~1\Trebz\Cookies
[F:17745][D:38]-> C:\DOCUME~1\Trebz\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 04/10/2008|11:44 - Option : [1]
--------------------\\ Fin du rapport a 11:44:34