Virus et trojan

Résolu
mibylag -  
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   -
Bonsoir,
J'ai pas mal regardé vos réponses en ce qui concerne les problémes de virus et j'ai suivi vos conseils.
1. j'ai lancé CCleaner puis supprimé tous les fichiers après analyse
2. j'ai installé AVG qui m'a détecté 116 infections et 12 spywares :o(
3. j'ai cherché un antivirus online mais comme j'ai mozilla firefox j'ai trouvé panda. Seulement mon scan n'est pas terminé et il a déjà trouvé 64 fichiers infectés...

Je vous envoie donc mon scan HijackThis dans l'espoir que vous puissiez m'aider
Merci d'avance
Mibylag

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:06:06, on 27/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://fr.rd.yahoo.com/customize/ie/defaults/sb/ymsgr6/fr/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe
O2 - BHO: (no name) - {15729091-B62F-4F6D-8A35-13F382B60A72} - C:\WINDOWS\system32\jkklLBrQ.dll (file missing)
O2 - BHO: (no name) - {313E714C-4DED-44B3-8533-3DEC5E7A1E6e} - C:\WINDOWS\system32\uitqwflo.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6B63D8B2-8B87-462A-AF33-43ECBF5E3AA0} - C:\WINDOWS\system32\khfeefec.dll (file missing)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {97303810-7860-7929-47E7-049678F337EB} - (no file)
O2 - BHO: offersfortoday - {97d5017d-065e-85c3-2210-a889a7ffddca} - C:\WINDOWS\system32\nsv31.dll (file missing)
O2 - BHO: AVG Security Toolbar - {a057a204-bacc-4d26-9990-79a187e2698e} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {B2494493-B5E8-4382-B498-A7A98A72D7DB} - C:\WINDOWS\system32\byXNeFvt.dll (file missing)
O2 - BHO: (no name) - {E3A70EC8-9644-45E5-9447-CC9D8B9C8B12} - C:\WINDOWS\system32\uitqwflo.dll (file missing)
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - (no file)
O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [fiupgplria] REM c:\windows\system32\fiupgplria.exe fiupgplria
O4 - HKLM\..\Run: [aqwmmgq] REM c:\windows\system32\aqwmmgq.exe aqwmmgq
O4 - HKLM\..\Run: [wkvarw] REM c:\windows\system32\wkvarw.exe wkvarw
O4 - HKLM\..\Run: [BMd3576966] Rundll32.exe "C:\WINDOWS\system32\kqudtipb.dll",s
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [msctrl.exe] C:\Program Files\Microsoft Security Adviser\msctrl.exe
O4 - HKLM\..\Run: [msavsc.exe] C:\Program Files\Microsoft Security Adviser\msavsc.exe
O4 - HKLM\..\Run: [msscan.exe] C:\Program Files\Microsoft Security Adviser\msscan.exe
O4 - HKLM\..\Run: [msiemon.exe] C:\Program Files\Microsoft Security Adviser\msiemon.exe
O4 - HKLM\..\Run: [msfw.exe] C:\Program Files\Microsoft Security Adviser\msfw.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msctrl.exe] C:\Program Files\Microsoft Security Adviser\msctrl.exe
O4 - HKCU\..\Run: [msavsc.exe] C:\Program Files\Microsoft Security Adviser\msavsc.exe
O4 - HKCU\..\Run: [msscan.exe] C:\Program Files\Microsoft Security Adviser\msscan.exe
O4 - HKCU\..\Run: [msiemon.exe] C:\Program Files\Microsoft Security Adviser\msiemon.exe
O4 - HKCU\..\Run: [msfw.exe] C:\Program Files\Microsoft Security Adviser\msfw.exe
O4 - HKCU\..\Run: [MSFox] C:\DOCUME~1\BE3F5~1.LAG\LOCALS~1\Temp\xxx75.exe
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Search - ?p=ZNfox000
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {86EEF11E-FF16-48CE-B1A2-474B663041A9} - http://kit.carpediem.fr/13493/CD/EntreNanas.exe
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: khfeefec - khfeefec.dll (file missing)
O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - C:\Program Files\Ares\chatServer.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe (file missing)
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: ViGUARD Service (VigService) - Unknown owner - C:\Program Files\ViGUARD\SERVICE.EXE (file missing)
A voir également:

30 réponses

Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Salut,

- Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31) :
http://siri.urz.free.fr/Fix/SmitfraudFix.exe ou http://www.geekstogo.com/forum/files/file/6-smitfraudfix/

- Enregistre-le sur le Bureau.

- Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée.

- Un rapport sera généré, poste-le dans ta prochaine réponse.

[*] process.exe est détecté par certains antivirus comme étant un risktool. Il ne s'agit pas d'un virus mais d'un utilitaire destiné à mettre fin à des processus.[*]

** Ne fais l'étape 2 que si on te le demande, on doit d'abord examiner le premier rapport de SmitfraudFix.
1
mibylag
 
Bonjour Destrio5 et merci pour ta réponse si rapide !

Voici le rapport

SmitFraudFix v2.367

Rapport fait à 9:41:27,76, 28/10/2008
Executé à partir de C:\Documents and Settings\Nom supprimé Modération CCM \Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\system32\wscntfy.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

Fichier hosts corrompu !

127.0.0.1 www.legal-at-spybot.info
127.0.0.1 legal-at-spybot.info

»»»»»»»»»»»»»»»»»»»»»»»» C:\

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\a.exe PRESENT !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Nom supprimé Modération CCM

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Nom supprimé Modération CCM \Application Data

»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\BE3F5~1.LAG\Favoris

»»»»»»»»»»»»»»»»»»»»»»»» Bureau

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"

»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

AntiXPVSTFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="avgrsstx.dll"
"LoadAppInit_DLLs"=dword:00000001

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,userinit.exe"
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» RK

»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Palladia 300/400 Usb Adsl Modem - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.1.1

Description: Palladia 300/400 Usb Adsl Modem - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.1.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{049BDDC0-0B52-4610-8B38-596FCE33D1E6}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B014DDE9-1925-464F-9A82-F0D854344697}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{049BDDC0-0B52-4610-8B38-596FCE33D1E6}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B014DDE9-1925-464F-9A82-F0D854344697}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{049BDDC0-0B52-4610-8B38-596FCE33D1E6}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B014DDE9-1925-464F-9A82-F0D854344697}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

»»»»»»»»»»»»»»»»»»»»»»»» Fin
0
mibylag
 
Re-Bonjour,
Ayant un message "alert danger adwarevirtumonde et privacyremover " j'ai lancé combofix comme il était conseillé dans un autre post.
Je ne sais pas si ça peut aider mais je poste à mon tour le rapport combofix. Merci encore

ComboFix 08-10-27.03 - Nom supprimé Modération CCM 2008-10-28 10:36:15.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.204 [GMT 1:00]
Lancé depuis: C:\Documents and Settings\Nom supprimé Modération CCM \Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Nom supprimé Modération CCM \Application Data\rhcc6dj0e979
C:\Documents and Settings\Nom supprimé Modération CCM \real.txt
C:\Documents and Settings\BRENDAN\Application Data\rhcc6dj0e979
C:\Documents and Settings\BRENDAN\Menu Démarrer\Programmes\PlayMP3z
C:\Documents and Settings\BRENDAN\Menu Démarrer\Programmes\PlayMP3z\Run PlayMP3z.lnk
C:\Documents and Settings\BRENDAN\real.txt
C:\Program Files\FBrowserAdvisor
C:\Program Files\FBrowsingAdvisor
C:\Program Files\FBrowsingAdvisor\IXPCOMEvents.xpt
C:\Program Files\FBrowsingAdvisor\Logo.png
C:\Program Files\FBrowsingAdvisor\main.db
C:\Program Files\FBrowsingAdvisor\Thumbs.db
C:\Program Files\FBrowsingAdvisor\unins000.dat
C:\Program Files\FBrowsingAdvisor\unins000.exe
C:\Program Files\FBrowsingAdvisor\XPCOMEvents.dll
C:\Program Files\Microsoft Security Adviser
C:\Program Files\Microsoft Security Adviser\msctrl.log
C:\Program Files\Microsoft Security Adviser\mssadv.log
C:\Program Files\Microsoft Security Adviser\mssadv_sp.log
C:\Program Files\PlayMP3z
C:\Program Files\PlayMP3z\uninstall.exe
C:\Program Files\rhcc6dj0e979
C:\WINDOWS\BMd3576966.txt
C:\WINDOWS\BMd3576966.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\pack.epk
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\_000005_.tmp.dll
C:\WINDOWS\system32\_000117_.tmp.dll
C:\WINDOWS\system32\4.tmp
C:\WINDOWS\system32\a.exe
C:\WINDOWS\system32\afymfztcjl.dat
C:\WINDOWS\system32\afymfztcjl_nav.dat
C:\WINDOWS\system32\afymfztcjl_navps.dat
C:\WINDOWS\system32\aqwmmgq.dat
C:\WINDOWS\system32\aqwmmgq_nav.dat
C:\WINDOWS\system32\aqwmmgq_navps.dat
C:\WINDOWS\system32\bilctpih.ini
C:\WINDOWS\system32\bnajhroo.ini
C:\WINDOWS\system32\csrihhofh.dat
C:\WINDOWS\system32\csrihhofh_navps.dat
C:\WINDOWS\system32\eksbbi.dat
C:\WINDOWS\system32\eksbbi_nav.dat
C:\WINDOWS\system32\eksbbi_navps.dat
C:\WINDOWS\system32\fiupgplria.dat
C:\WINDOWS\system32\fiupgplria_nav.dat
C:\WINDOWS\system32\fiupgplria_navps.dat
C:\WINDOWS\system32\gmqjbqli.ini
C:\WINDOWS\system32\lhcwihpe.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\Microsoft\backup.ftp
C:\WINDOWS\system32\Microsoft\backup.tftp
C:\WINDOWS\system32\nbxyorgg.ini
C:\WINDOWS\system32\nidcimrb.ini
C:\WINDOWS\system32\oamvqeph.ini
C:\WINDOWS\system32\phc96dj0e979.bmp
C:\WINDOWS\system32\pphc96dj0e979.exe
C:\WINDOWS\system32\QrBLlkkj.ini
C:\WINDOWS\system32\QrBLlkkj.ini2
C:\WINDOWS\system32\rdrfxqxxjv.dat
C:\WINDOWS\system32\rdrfxqxxjv_nav.dat
C:\WINDOWS\system32\rdrfxqxxjv_navps.dat
C:\WINDOWS\system32\real.txt
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\tlfwmmy_navup.dat
C:\WINDOWS\system32\tvFeNXyb.ini
C:\WINDOWS\system32\tvFeNXyb.ini2
C:\WINDOWS\system32\UpMedia
C:\WINDOWS\system32\vueydajr.ini
C:\WINDOWS\system32\wkvarw.dat
C:\WINDOWS\system32\wkvarw_nav.dat
C:\WINDOWS\system32\wkvarw_navps.dat
C:\WINDOWS\system32\xgsnopu.dat
C:\WINDOWS\system32\xgsnopu_nav.dat
C:\WINDOWS\system32\xgsnopu_navps.dat
C:\WINDOWS\system32\xjrucrfg.ini
C:\WINDOWS\system32\zdhorlgib.dat
C:\WINDOWS\system32\zdhorlgib_nav.dat
C:\WINDOWS\system32\zdhorlgib_navps.dat
C:\WINDOWS\system32\zrqgdllop.dat
C:\WINDOWS\system32\zrqgdllop_nav.dat
C:\WINDOWS\system32\zrqgdllop_navps.dat

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BOONTY_GAMES
-------\Legacy_FOPN
-------\Legacy_FWSVC
-------\Legacy_LDRSVC
-------\Legacy_VSPF
-------\Legacy_VSPF_HK
-------\Service_Boonty Games
-------\Service_ldrsvc

((((((((((((((((((((((((((((( Fichiers créés du 2008-09-28 au 2008-10-28 ))))))))))))))))))))))))))))))))))))
.

2008-10-28 09:41 . 2008-09-08 22:38 88,576 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-10-28 09:41 . 2008-10-10 07:58 82,944 --a------ C:\WINDOWS\system32\o4Patch.exe
2008-10-28 09:41 . 2008-10-10 07:58 82,944 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-10-28 09:41 . 2008-10-28 09:41 2,450 --a------ C:\WINDOWS\system32\tmp.reg
2008-10-28 09:37 . 2008-10-01 14:51 87,552 --a------ C:\WINDOWS\system32\VACFix.exe
2008-10-28 09:37 . 2008-05-18 20:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-10-28 09:37 . 2008-08-18 11:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-10-28 09:37 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-10-28 09:36 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-10-28 09:36 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-10-28 09:36 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-10-28 09:36 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-10-27 19:06 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
2008-10-27 19:05 . 2008-10-27 19:05 <REP> d-------- C:\Program Files\Panda Security
2008-10-27 17:24 . 2008-10-27 17:34 <REP> d-------- C:\Program Files\Trend Micro
2008-10-27 16:29 . 2008-10-27 18:43 <REP> d--h----- C:\$AVG8.VAULT$
2008-10-27 16:27 . 2008-10-27 16:27 90,632 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-10-27 16:27 . 2008-10-27 16:27 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-10-27 16:27 . 2008-10-27 16:27 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-10-27 16:26 . 2008-10-28 09:28 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
2008-10-27 16:26 . 2008-10-27 16:36 <REP> d-------- C:\Documents and Settings\Nom supprimé Modération CCM \Application Data\AVGTOOLBAR
2008-10-27 16:26 . 2008-10-27 16:26 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-10-27 16:25 . 2008-10-27 16:25 <REP> d-------- C:\Program Files\AVG
2008-10-27 16:25 . 2008-10-27 16:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-10-24 17:40 . 2008-10-28 10:50 104,670 --a------ C:\WINDOWS\system32\drivers\eef6c0ac.sys
2008-10-22 17:32 . 2008-10-22 17:32 102,172 --a------ C:\WINDOWS\system32\cont_offersfortoday-remove.exe
2008-10-22 17:32 . 2008-10-22 17:32 79,085 --a------ C:\WINDOWS\system32\fyglbdtfjrzxm.exe
2008-10-12 09:29 . 2008-10-12 09:29 <REP> d-------- C:\Documents and Settings\Nom supprimé Modération CCM \Application Data\DWGEditor
2008-09-28 11:12 . 2008-09-28 11:51 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-27 17:20 --------- d-----w C:\Documents and Settings\Nom supprimé Modération CCM \Application Data\VMNTOOLBAR
2008-10-27 16:25 --------- d-----w C:\Program Files\Circle Developement
2008-10-27 08:50 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\Real4new
2008-10-27 08:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\great coal love default
2008-10-22 18:03 --------- d-----w C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar
2008-10-21 21:18 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\uTorrent
2008-10-18 10:21 --------- d-----w C:\Program Files\NoteWorthy Composer
2008-10-12 14:16 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-10-12 10:06 --------- d-----w C:\Program Files\InterActual
2008-10-12 10:06 --------- d-----w C:\Program Files\Google
2008-10-12 09:44 --------- d-----w C:\Program Files\vghd
2008-10-12 09:25 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-12 09:25 --------- d-----w C:\Program Files\QuickTime
2008-10-12 09:25 --------- d-----w C:\Program Files\LimeWire
2008-10-12 09:25 --------- d-----w C:\Program Files\ganjasw
2008-10-12 09:24 --------- d-----w C:\Program Files\Motus
2008-10-12 09:24 --------- d-----w C:\Program Files\DivX
2008-10-12 08:41 --------- d-----w C:\Program Files\SolidWorks
2008-10-12 08:39 --------- d-----w C:\Program Files\Fichiers communs\Bluebeam Software
2008-10-12 08:30 --------- d-----w C:\Program Files\Zylom Games
2008-10-12 08:28 --------- d-----w C:\Program Files\GIMP-2.0
2008-10-12 08:24 --------- d-----w C:\Program Files\Neuf
2008-09-30 21:23 --------- d-----w C:\Documents and Settings\BRENDAN\Application Data\uTorrent
2008-09-30 16:51 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-09-24 18:09 3,532 ----a-w C:\drmHeader.bin
2008-09-22 11:46 --------- d-----w C:\Documents and Settings\BRENDAN\Application Data\AdobeUM
2008-09-14 17:29 --------- d-----w C:\Documents and Settings\Nom supprimé Modération CCM TE\Application Data\dvdcss
2008-09-10 20:20 --------- d-----w C:\Documents and Settings\\Application Data\Viewpoint
2008-09-07 20:06 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-01 17:43 --------- d-----w C:\Documents and Settings\\Application Data\SolidWorks
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2005-08-02 14:20 109,384 -c--a-w C:\Documents and Settings\\Application Data\GDIPFONTCACHEV1.DAT
2003-09-03 12:18 109,712 -c--a-w C:\Program Files\setup.exe
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-10-27 1235736]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

C:\Documents and Settings\All Users\Menu D'marrer\Programmes\D'marrage\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-20 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
"vidc.xvid"= xvid.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\microsoft office\\office11\\EXCEL.EXE"=
"C:\\Program Files\\microsoft office\\office11\\POWERPNT.EXE"=
"C:\\Program Files\\microsoft office\\office11\\WINWORD.EXE"=
"C:\\Program Files\\Outlook Express\\msimn.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"80:TCP"= 80:TCP:@xpsp2res.dll,-22004

R0 avgrkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-10-27 12936]
R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 28544]
R0 sonyhcb;Sony Digital Imaging Base;C:\WINDOWS\system32\DRIVERS\sonyhcb.sys [2001-11-05 6097]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 avgldx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-10-27 97928]
R1 avgtdix;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-10-27 90632]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-27 231704]
R3 mgau;mgau;C:\WINDOWS\system32\DRIVERS\mgaum.sys [2001-08-23 320384]
R3 PALLADIA;Palladia 300/400 Usb Adsl Modem;C:\WINDOWS\system32\DRIVERS\usbiad.sys [2005-06-13 31579]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S2 VigService;ViGUARD Service;C:\Program Files\ViGUARD\SERVICE.EXE [ ]
S3 nenum13E;nenum13E;C:\DOCUME~1\BE3F5~1.LAG\LOCALS~1\Temp\nenum13E.sys [ ]
S3 sonyhcs;Sony Digital Imaging Video;C:\WINDOWS\system32\DRIVERS\sonyhcs.sys [2001-11-05 299923]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f3fee60-23cf-11dc-a860-0016ce2a8bc5}]
\Shell\Auto\command - wscript "esta ig.vbs"
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript "esta ig.vbs"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b54f18ea-f36d-11db-a813-0016ce2a8bc5}]
\Shell\AutoRun\command - RavMon.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb854c26-dbdf-11dc-a980-0016ce2a8bc5}]
\Shell\Auto\command - cmd /C launch.bat
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
.
Contenu du dossier 'Tâches planifiées'

2008-10-28 C:\WINDOWS\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe []
.
- - - - ORPHELINS SUPPRIMES - - - -

BHO-{15729091-B62F-4F6D-8A35-13F382B60A72} - C:\WINDOWS\system32\jkklLBrQ.dll
BHO-{313E714C-4DED-44B3-8533-3DEC5E7A1E6e} - C:\WINDOWS\system32\uitqwflo.dll
BHO-{6B63D8B2-8B87-462A-AF33-43ECBF5E3AA0} - C:\WINDOWS\system32\khfeefec.dll
BHO-{97303810-7860-7929-47E7-049678F337EB} - (no file)
BHO-{97d5017d-065e-85c3-2210-a889a7ffddca} - C:\WINDOWS\system32\nsv31.dll
BHO-{B2494493-B5E8-4382-B498-A7A98A72D7DB} - C:\WINDOWS\system32\byXNeFvt.dll
BHO-{E3A70EC8-9644-45E5-9447-CC9D8B9C8B12} - C:\WINDOWS\system32\uitqwflo.dll
ShellExecuteHooks-{6B63D8B2-8B87-462A-AF33-43ECBF5E3AA0} - C:\WINDOWS\system32\khfeefec.dll
Notify-khfeefec - khfeefec.dll

.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Nom supprimé Modération CCM E\Application Data\Mozilla\Firefox\Profiles\9wm7ol4h.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 10:48:03
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MysqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-nt MysqlInventime"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eef6c0ac]
"ImagePath"="\SystemRoot\System32\drivers\eef6c0ac.sys"
.
------------------------ Autres processus actifs ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Heure de fin: 2008-10-28 11:01:52 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-28 10:01:30

Avant-CF: 9 144 528 896 octets libres
Après-CF: 9,082,003,456 octets libres

288 --- E O F --- 2008-10-24 16:47:41
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Il y a du boulot.

- Redémarre ton ordinateur en mode sans échec :
https://blog.sosordi.net/

- Double-clique sur SmitfraudFix.exe, choisis l'option 2 et Entrée.

- Réponds O (Oui) à ces deux questions si elles te sont posées :

Voulez-vous nettoyer le registre ?
Corriger le fichier infecté ?

- Un rapport sera généré, sauvegarde-le sur le Bureau.

- Redémarre en mode normal.

- Poste le rapport SmitfraudFix.
0
mibylag
 
Bonsoir,
Voici le rapport suite à la manip "mode sans échec"

SmitFraudFix v2.368

Rapport fait à 18:54:18,07, 28/10/2008
Executé à partir de C:\Documents and Settings\B. LAGOUTTE\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode sans echec

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

AntiXPVSTFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» RK


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{049BDDC0-0B52-4610-8B38-596FCE33D1E6}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B014DDE9-1925-464F-9A82-F0D854344697}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{049BDDC0-0B52-4610-8B38-596FCE33D1E6}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B014DDE9-1925-464F-9A82-F0D854344697}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{049BDDC0-0B52-4610-8B38-596FCE33D1E6}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B014DDE9-1925-464F-9A82-F0D854344697}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

Nettoyage terminé.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» Fin
0
mibylag
 
Bonsoir destrio5... Tu es par là ?
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Pardon, j'étais au McDo.

- Télécharge et installe Malwarebytes' Anti-Malware :
http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebyte s anti malware

- Mets-le à jour.

- Redémarre en mode sans échec (Recommandé) :
https://blog.sosordi.net/

- Choisis ta session habituelle.

- Fais un scan complet avec Malwarebytes' Anti-Malware .

- Supprime tout ce que le logiciel trouve, enregistre le rapport.

- Redémarre en mode normal et poste le rapport ici.
0
mibylag
 
pas de problème, t'as quand même le droit de manger !!
je fais tout ça et je te poste le rapport!
0
mibylag
 
Re bonsoir,
Voici enfin le rapport... ça a pris bcp de temps !
Merci pour ton aide et pour le temps que tu m'accordes.

Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1333
Windows 5.1.2600 Service Pack 2

29/10/2008 00:26:02
mbam-log-2008-10-29 (00-26-02).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 161356
Temps écoulé: 2 hour(s), 27 minute(s), 50 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 30
Valeur(s) du Registre infectée(s): 3
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 4
Fichier(s) infecté(s): 47

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\acm.acmfactory (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\acm.acmfactory.1 (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\browsingadvisor.pornpro_bho (Adware.PlayMP3Z-biz) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\browsingadvisor.pornpro_bho.1 (Adware.PlayMP3Z-biz) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\browsingtool.browserwatcher (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\browsingtool.browserwatcher.1 (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\browsingtool.pornpro_bho (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\browsingtool.pornpro_bho.1 (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\browsingtool.precachebrowserhost (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\browsingtool.precachebrowserhost.1 (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{43382522-a846-46f4-ac57-1f71ae6e1086} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{50a1aa3b-80e3-15cf-0f1a-83a98ad98fe9} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{572fb162-c0ba-4edf-8cff-e3846153b9b0} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72a836d1-bc00-43c0-a941-17960e4fb842} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7f68785e-4894-7bb2-5fde-cc3eee2ebc82} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e698e657-649e-5d40-752d-9a3b78ea832a} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0daee015-a728-c212-9b8f-298391b8328e} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{aaf21892-e4d8-e8ed-e36a-3a91e3b2db29} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{fe3af205-54df-b146-1f0e-c9262829ed18} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{df901432-1b9f-4f5b-9e56-301c553f9095} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{84d39d08-a551-a4e5-c8d1-3327573d4640} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{127df9b4-d75d-44a6-af78-8c3a8ceb03db} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\browsingadvisor (Adware.PlayMP3Z-biz) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\browsingtool (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cont_offersfortoday (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\BrowsingTool.DLL (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\fbrowsingadvisor_is1 (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\ACM.DLL (Adware.WhenUSave) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\rhcc6dj0e979 (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Program Files\Save (Adware.WhenUSave) -> Quarantined and deleted successfully.
C:\Program Files\Fichiers communs\Carlson (Dialer) -> Quarantined and deleted successfully.
C:\Program Files\BrowsingAdvisor (Adware.PlayMP3Z-biz) -> Quarantined and deleted successfully.
C:\Program Files\BrowsingTool (Adware.Agent) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\Program Files\Mozilla Firefox\regxpcom.exe (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\FBrowsingAdvisor\XPCOMEvents.dll.vir (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003080.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003107.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003108.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003109.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003110.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003111.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003112.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003113.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003115.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003116.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003118.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003120.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003121.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003123.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003124.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003125.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003126.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003127.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003128.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003129.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003131.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003132.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003134.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003135.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003136.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003137.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003138.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP8\A0003139.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP9\A0004189.dll (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\Save\ffext.mod (Adware.WhenUSave) -> Quarantined and deleted successfully.
C:\Program Files\Save\save.db (Adware.WhenUSave) -> Quarantined and deleted successfully.
C:\Program Files\Save\save.htm (Adware.WhenUSave) -> Quarantined and deleted successfully.
C:\Program Files\Save\store.db (Adware.WhenUSave) -> Quarantined and deleted successfully.
C:\Program Files\BrowsingAdvisor\BrowsingAdvisor.dat (Adware.PlayMP3Z-biz) -> Quarantined and deleted successfully.
C:\Program Files\BrowsingAdvisor\pcre3.dll (Adware.PlayMP3Z-biz) -> Quarantined and deleted successfully.
C:\Program Files\BrowsingAdvisor\uninstall.exe (Adware.PlayMP3Z-biz) -> Quarantined and deleted successfully.
C:\Program Files\BrowsingTool\BrowsingTool.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\BrowsingTool\pcre3.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\BrowsingTool\uninstall.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\components\nsoffersfortoday.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cont_offersfortoday-remove.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Documents and Settings\E\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiMalware2009.lnk (Rogue.AntiMalware2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menu Démarrer\carlton (Dialer) -> Quarantined and deleted successfully.
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
---> Relance MBAM, va dans Quarantaine et supprime tout.

- Télécharge Navilog1 (de IL-MAFIOSO) et enregistre-le sur le bureau :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

- Double-clique sur Navilog1.exe afin de lancer l'installation

- Si le fix ne lance pas automatiquement après son installation, double-clique sur Navilog1 présent sur le bureau

- Appuie sur F ou f puis valide par Entrée

- Appuie sur une touche de ton clavier à chaque fois que cela est demandé, tu arriveras au menu des options

- Choisis l'option 1 et appuie sur la touche Entrée pour valider ton choix

- Patiente jusqu'au message : *** Analyse terminée le ..... ***

- Le scan fini, le bloc-notes contenant le rapport sera affiché, poste le contenu de ce rapport dans ta prochaine réponse

- Si le résultat du scan ne s'affiche pas, tu le trouveras dans C:\fixnavi.txt

N'utilise pas l'option 2, 3 et 4 sans notre accord, des fichiers légitimes peuvent être inclus dans ce scan.
0
mibylag
 
Bonjour
Voici le rapport navilog

Search Navipromo version 3.6.7 commencé le 29/10/2008 à 9:17:18,81

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "B. LAGOUTTE"

Mise à jour le 22.10.2008 à 20h00 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.11
Système de fichiers : NTFS

Recherche executé en mode normal

*** Recherche Programmes installés ***


*** Recherche dossiers dans "C:\WINDOWS" ***


*** Recherche dossiers dans "C:\Program Files" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\B. LAGOUTTE\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\BRENDAN\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\B. LAGOUTTE\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\BRENDAN\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\B. LAGOUTTE\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\BRENDAN\menudm~1\progra~1" ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans "C:\WINDOWS\system32" *

* Recherche dans "C:\Documents and Settings\B. LAGOUTTE\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\BRENDAN\locals~1\applic~1" *



*** Recherche fichiers ***



*** Recherche clés spécifiques dans le Registre ***


*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :


2)Recherche Heuristique :

* Dans "C:\WINDOWS\system32" :


* Dans "C:\Documents and Settings\B. LAGOUTTE\locals~1\applic~1" :


* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :


* Dans "C:\DOCUME~1\BRENDAN\locals~1\applic~1" :


3)Recherche Certificats :

Certificat Egroup absent !
Certificat Electronic-Group trouvé !
Certificat Montorgueil absent !
Certificat OOO-Favorit trouvé !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche fichiers connus :



*** Analyse terminée le 29/10/2008 à 9:29:10,82 ***
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
---> Relance Navilog1, fais l'option 2 et poste le rapport.
0
mibylag
 
Bonsoir,
Voila le rapport....

Clean Navipromo version 3.6.7 commencé le 29/10/2008 à 16:37:52,15

Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "B. LAGOUTTE"

Mise à jour le 22.10.2008 à 20h00 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.11
Système de fichiers : NTFS

Mode suppression automatique
avec prise en charge résultats Catchme et GNS


Nettoyage exécuté au redémarrage de l'ordinateur


*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)


*** Suppression avec sauvegardes résultats GenericNaviSearch ***

* Suppression dans "C:\WINDOWS\System32" *


* Suppression dans "C:\Documents and Settings\B. LAGOUTTE\locals~1\applic~1" *


* Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

* Suppression dans "C:\DOCUME~1\BRENDAN\locals~1\applic~1" *


*** Suppression dossiers dans "C:\WINDOWS" ***


*** Suppression dossiers dans "C:\Program Files" ***


*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


*** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\B. LAGOUTTE\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\BRENDAN\applic~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\B. LAGOUTTE\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\BRENDAN\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\B. LAGOUTTE\menudm~1\progra~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\BRENDAN\menudm~1\progra~1" ***



*** Suppression fichiers ***


*** Suppression fichiers temporaires ***

Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\B. LAGOUTTE\locals~1\Temp effectué !

*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

2)Recherche, création sauvegardes et suppression Heuristique :


* Dans "C:\WINDOWS\system32" *


* Dans "C:\Documents and Settings\B. LAGOUTTE\locals~1\applic~1" *


* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *


* Dans "C:\DOCUME~1\BRENDAN\locals~1\applic~1" *


*** Sauvegarde du Registre vers dossier Safebackup ***

sauvegarde du Registre réalisée avec succès !

*** Nettoyage Registre ***

Nettoyage Registre Ok


*** Certificats ***

Certificat Egroup absent !
Certificat Electronic-Group supprimé !
Certificat Montorgueil absent !
Certificat OOO-Favorit supprimé !
Certificat Sunny-Day-Design-Ltdt absent !

*** Nettoyage terminé le 29/10/2008 à 17:04:07,85 ***
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
---> Désinstalle Navilog1.

--> Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
http://www.mediafire.com/download.php?nmieja4c4gm

--> Lance l'installation avec les paramètres par défaut.

--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.

--> Double-clique sur le raccourci UsbFix sur ton Bureau.

--> Le PC va redémarrer.

--> Après redémarrage, poste le rapport UsbFix.txt

Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.

(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)
0
mibylag
 
re !

Voici le rapport usbfix




-------------- UsbFix V2.395 ---------------

* User : B. LAGOUTTE - BLAGOUTTE
* Outils mis a jours le 27/10/2008 par Chiquitine29 et Chimay8
* Recherche effectuée à 20:42:48 le 29/10/2008
* Windows Xp - Internet Explorer 7.0.5730.11


--------------- [ Processus actifs ] ----------------


C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\DOCUME~1\BE3F5~1.LAG\LOCALS~1\Temp\1.tmp\b2e.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup

--------------- [ Informations lecteurs ] ----------------

C: - Lecteur fixe

E: - Lecteur amovible

H: - Lecteur amovible

J: - Lecteur amovible

K: - Lecteur amovible


--------------- [ Registre / Startup ] ----------------


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
AVG8_TRAY REG_SZ C:\PROGRA~1\AVG\AVG8\avgtray.exe

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\optionalcomponents

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

--------------- [ Registre / Mountpoint2 ] ----------------

Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5f3fee60-23cf-11dc-a860-0016ce2a8bc5}\Shell\AutoRun\command
Supprimé ! - HKEY_USERS\S-1-5-21-3118666475-222590133-1001321657-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5f3fee60-23cf-11dc-a860-0016ce2a8bc5}\Shell\AutoRun\command
Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b54f18ea-f36d-11db-a813-0016ce2a8bc5}\Shell\AutoRun\command
Supprimé ! - HKEY_USERS\S-1-5-21-3118666475-222590133-1001321657-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b54f18ea-f36d-11db-a813-0016ce2a8bc5}\Shell\AutoRun\command
Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eb854c26-dbdf-11dc-a980-0016ce2a8bc5}\Shell\AutoRun\command
Supprimé ! - HKEY_USERS\S-1-5-21-3118666475-222590133-1001321657-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eb854c26-dbdf-11dc-a980-0016ce2a8bc5}\Shell\AutoRun\command

--------------- [ Nettoyage des disques ] ----------------


--------------- ! Fin du rapport ! ----------------
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
---> Désinstalle UsbFix.

---> Télécharge Lop S&D sur ton Bureau.
---> Double-clique dessus pour lancer l'installation.
---> Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
---> Séléctionne la langue souhaitée, puis choisis l'option 1 (Recherche).
---> Patiente jusqu'à la fin du scan.
---> Poste le rapport généré (C:\lopR.txt).
0
mibylag
 
désolé destrio5 je sais que tu ne t'occupes pas que de moi mais tu es dans les parages ?
0
mibylag
 
re !
Voici le rapport Lop S&D

--------------------\\ Lop S&D 4.2.4-8 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : B. LAGOUTTE ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081029-0] 4.8.1229 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:105 Go (Free:9 Go)
D:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)

"C:\Lop SD" ( MAJ : 27-10-2008|09:15 )
Option : [1] ( 29/10/2008|22:41 )

--------------------\\ Listing des dossiers dans APPLIC~1

[17/03/2005|08:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
[16/08/2004|18:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[16/08/2004|17:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[17/03/2005|07:53] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
[17/03/2005|07:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[17/03/2005|07:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
[17/03/2005|07:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver

[20/01/2007|10:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[03/01/2008|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[10/06/2006|16:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[14/10/2006|16:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[28/10/2008|13:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg8
[01/04/2006|11:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[16/08/2005|12:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[23/06/2006|16:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\enc jugs great user
[26/11/2005|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Global Software Publishing
[10/02/2008|22:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[20/04/2008|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[27/10/2008|09:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
[12/12/2006|20:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[10/06/2006|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak
[21/04/2006|14:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[29/12/2006|13:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MakeMusic
[28/10/2008|21:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[28/03/2006|15:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[05/01/2008|18:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Micro Application
[17/09/2008|06:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[22/04/2007|17:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NCH Swift Sound
[28/12/2007|23:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[22/04/2006|12:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[16/08/2004|18:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[06/11/2005|11:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBT
[21/06/2006|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[16/03/2008|02:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[06/11/2005|14:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[02/07/2005|19:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[17/12/2007|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[17/04/2006|15:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ViGUARD
[06/11/2005|14:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[13/10/2007|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[06/07/2007|15:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[30/06/2008|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[18/01/2007|16:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
[27/12/2007|20:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[24/06/2006|16:51] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Adobe
[20/08/2008|12:57] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\AdobeUM
[19/11/2006|11:38] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Ahead
[17/03/2005|08:00] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\AOL
[07/06/2006|09:54] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Apple Computer
[29/10/2008|08:34] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\AVGTOOLBAR
[13/05/2008|20:17] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Creative
[31/03/2005|19:07] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\CyberLink
[21/10/2006|21:28] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\DivX
[14/09/2008|18:29] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\dvdcss
[12/10/2008|09:29] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\DWGEditor
[27/12/2007|11:29] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Google
[19/11/2005|17:25] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Help
[22/02/2008|13:21] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Identities
[14/04/2005|13:24] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Leadertech
[03/04/2005|09:39] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Macromedia
[28/10/2008|21:43] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Malwarebytes
[16/10/2008|15:36] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Microsoft
[06/11/2005|10:53] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Microsoft Web Folders
[05/05/2007|13:51] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Mozilla
[15/02/2008|17:46] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\MPMAN
[22/04/2007|17:30] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\NCH Swift Sound
[28/12/2007|23:13] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\PlayFirst
[05/05/2005|08:21] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Real
[27/10/2008|09:50] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Real4new
[17/12/2006|09:41] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Skype
[01/09/2008|18:43] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\SolidWorks
[14/04/2005|13:24] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Sonic
[17/03/2005|07:39] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Sun
[17/03/2005|07:48] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Symantec
[05/05/2007|13:52] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Talkback
[05/05/2007|13:51] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Thunderbird
[28/10/2008|11:29] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\uTorrent
[10/09/2008|21:20] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Viewpoint
[12/01/2008|13:28] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\vlc
[29/10/2008|19:13] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\VMNTOOLBAR
[24/04/2006|15:09] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Yahoo!
[17/03/2005|07:45] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\You've Got Pictures Screensaver
[28/12/2007|23:13] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Zylom

[17/09/2006|12:05] C:\DOCUME~1\BRENDAN\APPLIC~1\.gaim
[08/09/2008|11:14] C:\DOCUME~1\BRENDAN\APPLIC~1\Adobe
[22/09/2008|12:46] C:\DOCUME~1\BRENDAN\APPLIC~1\AdobeUM
[20/01/2008|17:59] C:\DOCUME~1\BRENDAN\APPLIC~1\Ahead
[17/03/2005|08:00] C:\DOCUME~1\BRENDAN\APPLIC~1\AOL
[22/05/2006|18:36] C:\DOCUME~1\BRENDAN\APPLIC~1\Apple Computer
[20/04/2007|18:04] C:\DOCUME~1\BRENDAN\APPLIC~1\AquaNox
[24/08/2006|14:06] C:\DOCUME~1\BRENDAN\APPLIC~1\BSplayer
[29/12/2006|21:47] C:\DOCUME~1\BRENDAN\APPLIC~1\Creative
[21/06/2005|15:39] C:\DOCUME~1\BRENDAN\APPLIC~1\CyberLink
[17/10/2006|17:58] C:\DOCUME~1\BRENDAN\APPLIC~1\DivX
[10/08/2008|10:13] C:\DOCUME~1\BRENDAN\APPLIC~1\dvdcss
[04/03/2008|13:08] C:\DOCUME~1\BRENDAN\APPLIC~1\DWGEditor
[08/09/2007|19:38] C:\DOCUME~1\BRENDAN\APPLIC~1\Ecran de veille
[18/12/2005|14:13] C:\DOCUME~1\BRENDAN\APPLIC~1\Google
[30/08/2006|11:55] C:\DOCUME~1\BRENDAN\APPLIC~1\Help
[16/08/2004|18:19] C:\DOCUME~1\BRENDAN\APPLIC~1\Identities
[25/04/2005|17:44] C:\DOCUME~1\BRENDAN\APPLIC~1\InstallShield Installation Information
[24/06/2006|08:59] C:\DOCUME~1\BRENDAN\APPLIC~1\Lavasoft
[16/04/2005|18:31] C:\DOCUME~1\BRENDAN\APPLIC~1\Leadertech
[22/06/2008|19:46] C:\DOCUME~1\BRENDAN\APPLIC~1\LimeWire
[27/01/2007|16:26] C:\DOCUME~1\BRENDAN\APPLIC~1\Macromedia
[25/03/2008|12:45] C:\DOCUME~1\BRENDAN\APPLIC~1\Microsoft
[17/09/2006|12:08] C:\DOCUME~1\BRENDAN\APPLIC~1\Mozilla
[17/06/2008|12:31] C:\DOCUME~1\BRENDAN\APPLIC~1\MPMAN
[25/03/2007|11:33] C:\DOCUME~1\BRENDAN\APPLIC~1\Nero
[20/05/2005|08:32] C:\DOCUME~1\BRENDAN\APPLIC~1\Real
[16/07/2008|22:19] C:\DOCUME~1\BRENDAN\APPLIC~1\Real4new
[26/12/2007|10:52] C:\DOCUME~1\BRENDAN\APPLIC~1\Skype
[17/08/2008|22:06] C:\DOCUME~1\BRENDAN\APPLIC~1\SolidWorks
[16/04/2005|18:31] C:\DOCUME~1\BRENDAN\APPLIC~1\Sonic
[17/03/2005|07:39] C:\DOCUME~1\BRENDAN\APPLIC~1\Sun
[17/03/2005|07:48] C:\DOCUME~1\BRENDAN\APPLIC~1\Symantec
[17/09/2006|12:08] C:\DOCUME~1\BRENDAN\APPLIC~1\Talkback
[17/09/2006|12:08] C:\DOCUME~1\BRENDAN\APPLIC~1\Thunderbird
[21/05/2006|11:42] C:\DOCUME~1\BRENDAN\APPLIC~1\U3
[30/09/2008|22:23] C:\DOCUME~1\BRENDAN\APPLIC~1\uTorrent
[17/12/2007|18:20] C:\DOCUME~1\BRENDAN\APPLIC~1\Viewpoint
[09/12/2007|12:04] C:\DOCUME~1\BRENDAN\APPLIC~1\vlc
[22/10/2008|19:03] C:\DOCUME~1\BRENDAN\APPLIC~1\vmntoolbar
[17/04/2006|18:52] C:\DOCUME~1\BRENDAN\APPLIC~1\Webroot
[13/07/2006|15:31] C:\DOCUME~1\BRENDAN\APPLIC~1\Yahoo!
[17/03/2005|07:45] C:\DOCUME~1\BRENDAN\APPLIC~1\You've Got Pictures Screensaver

[17/03/2005|08:00] C:\DOCUME~1\DEFAUL~1\APPLIC~1\AOL
[16/08/2004|18:19] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[16/08/2004|17:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[17/03/2005|07:53] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[17/03/2005|07:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun
[17/03/2005|07:48] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec
[17/03/2005|07:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver

[28/10/2008|13:18] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[17/04/2006|15:17] C:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot

[28/10/2008|13:18] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[03/04/2005|10:04] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[29/10/2008 22:38][--a------] C:\WINDOWS\tasks\Symantec NetDetect.job
[29/10/2008 20:42][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ MsgPlus SPONSOR INSTALLED !

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MsgPlus! Plugin]
"DisplayName"="Messenger Plus! 3 & Sponsor"
"SponsorInstalled"=dword:00000000

--------------------\\ Listing des dossiers dans C:\Program Files

[24/06/2006|16:48] C:\Program Files\7-Zip
[24/06/2006|16:45] C:\Program Files\Adobe
[19/09/2006|19:37] C:\Program Files\Advanced Messenger Plus
[23/06/2006|17:06] C:\Program Files\Adverts
[10/06/2006|17:32] C:\Program Files\Alwil Software
[17/04/2005|17:51] C:\Program Files\Analog Devices
[27/10/2008|16:25] C:\Program Files\AVG
[12/05/2008|09:47] C:\Program Files\CCleaner
[27/10/2008|17:25] C:\Program Files\Circle Developement
[08/04/2006|12:10] C:\Program Files\Common Files
[16/08/2004|18:05] C:\Program Files\ComPlus Applications
[09/11/2006|20:05] C:\Program Files\Creative
[17/03/2005|07:52] C:\Program Files\CyberLink
[24/04/2006|20:47] C:\Program Files\Dekovir
[24/10/2005|18:30] C:\Program Files\directx
[25/11/2006|19:09] C:\Program Files\Disc2Phone
[12/10/2008|10:24] C:\Program Files\DivX
[24/04/2005|18:11] C:\Program Files\DVD Audio Extractor
[10/06/2006|11:32] C:\Program Files\EA SPORTS
[25/12/2007|11:45] C:\Program Files\eMule
[03/04/2005|13:35] C:\Program Files\EVEREST Home Edition
[28/10/2008|10:40] C:\Program Files\Fichiers communs
[20/04/2008|18:15] C:\Program Files\Finale 2005b
[29/12/2006|13:27] C:\Program Files\Finale Performance Assessment
[25/12/2007|12:05] C:\Program Files\foobar2000
[25/12/2007|12:04] C:\Program Files\Gaim
[12/10/2008|10:25] C:\Program Files\ganjasw
[12/10/2008|09:28] C:\Program Files\GIMP-2.0
[12/10/2008|11:06] C:\Program Files\Google
[17/04/2006|15:07] C:\Program Files\Grisoft
[29/12/2005|14:52] C:\Program Files\Illustrate
[31/10/2005|13:56] C:\Program Files\IncrediMail
[05/01/2008|18:39] C:\Program Files\InstallShield Installation Information
[12/10/2008|11:06] C:\Program Files\InterActual
[15/10/2008|22:35] C:\Program Files\Internet Explorer
[03/05/2007|19:05] C:\Program Files\Java
[22/11/2007|19:17] C:\Program Files\jeux
[10/06/2006|11:42] C:\Program Files\Kodak
[17/03/2005|07:45] C:\Program Files\Learn2.com
[20/02/2006|10:12] C:\Program Files\LEGO Media
[12/10/2008|10:25] C:\Program Files\LimeWire
[13/04/2007|20:55] C:\Program Files\Loop12 V2
[17/07/2006|21:07] C:\Program Files\Macrogaming
[28/10/2008|21:43] C:\Program Files\Malwarebytes' Anti-Malware
[03/12/2005|11:21] C:\Program Files\Maxis
[26/05/2006|22:18] C:\Program Files\Mes Jeux Téléchargés
[12/10/2008|10:25] C:\Program Files\Messenger
[07/09/2008|21:06] C:\Program Files\Messenger Plus! Live
[17/03/2008|22:04] C:\Program Files\MessengerPlus! 3
[05/01/2008|18:17] C:\Program Files\Micro Application
[07/07/2007|13:30] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[06/11/2005|11:01] C:\Program Files\microsoft frontpage
[19/09/2005|12:15] C:\Program Files\Microsoft Games
[17/10/2007|13:19] C:\Program Files\Microsoft Office
[14/09/2005|16:43] C:\Program Files\Microsoft Référence
[13/11/2007|19:19] C:\Program Files\Microsoft SQL Server Compact Edition
[06/11/2005|10:56] C:\Program Files\Microsoft Visual Studio
[24/04/2005|17:09] C:\Program Files\Microsoft Works
[17/03/2005|07:58] C:\Program Files\Microsoft.NET
[12/10/2008|10:24] C:\Program Files\Motus
[16/08/2004|18:06] C:\Program Files\Movie Maker
[29/10/2008|21:40] C:\Program Files\Mozilla Firefox
[12/10/2008|15:16] C:\Program Files\Mozilla Thunderbird
[22/05/2007|21:34] C:\Program Files\MP3 Player Utilities 3.57
[07/04/2005|17:29] C:\Program Files\MSN
[25/04/2006|11:35] C:\Program Files\MSN Games
[16/08/2004|18:03] C:\Program Files\MSN Gaming Zone
[06/07/2007|15:09] C:\Program Files\MSN Messenger
[21/06/2007|18:51] C:\Program Files\MSNTweaker
[18/11/2006|15:23] C:\Program Files\MSXML 4.0
[24/04/2006|20:51] C:\Program Files\Musique
[29/10/2008|19:22] C:\Program Files\Navilog1
[22/04/2007|17:34] C:\Program Files\NCH Swift Sound
[28/10/2006|11:06] C:\Program Files\Nero
[22/02/2007|22:22] C:\Program Files\NetMeeting
[12/10/2008|09:24] C:\Program Files\Neuf
[18/10/2008|11:21] C:\Program Files\NoteWorthy Composer
[16/08/2004|18:03] C:\Program Files\Online Services
[13/04/2008|17:18] C:\Program Files\Outlook Express
[17/09/2006|12:03] C:\Program Files\Pack Securite
[27/10/2008|19:05] C:\Program Files\Panda Security
[09/04/2008|14:12] C:\Program Files\Picasa2
[17/04/2005|22:02] C:\Program Files\QuickEuro 2002
[12/10/2008|10:25] C:\Program Files\QuickTime
[17/03/2005|07:45] C:\Program Files\Real
[21/06/2008|14:05] C:\Program Files\Real4new
[25/04/2005|17:44] C:\Program Files\Rockstar Games
[17/03/2005|07:38] C:\Program Files\S3Inc
[31/03/2005|10:12] C:\Program Files\SAGEM
[12/09/2006|10:03] C:\Program Files\Samsung
[18/04/2005|14:35] C:\Program Files\Services en ligne
[25/03/2007|17:08] C:\Program Files\Setup
[22/10/2006|21:12] C:\Program Files\Sibelius Software
[24/06/2006|17:47] C:\Program Files\Skype
[20/02/2006|14:19] C:\Program Files\SmartMusic
[06/11/2005|11:03] C:\Program Files\Snapshot Viewer
[12/10/2008|09:41] C:\Program Files\SolidWorks
[17/03/2005|08:00] C:\Program Files\Sonic
[23/12/2007|17:44] C:\Program Files\Spybot
[15/03/2008|12:28] C:\Program Files\Spybot - Search & Destroy
[06/11/2005|15:01] C:\Program Files\Symantec
[04/02/2006|23:18] C:\Program Files\THQ
[27/10/2008|17:34] C:\Program Files\Trend Micro
[16/08/2004|18:19] C:\Program Files\Uninstall Information
[29/10/2008|22:37] C:\Program Files\UsbFix
[11/08/2008|20:24] C:\Program Files\uTorrent
[12/10/2008|10:44] C:\Program Files\vghd
[19/11/2006|20:08] C:\Program Files\VIA
[09/12/2007|11:58] C:\Program Files\VideoLAN
[17/03/2005|07:45] C:\Program Files\Viewpoint
[17/04/2006|15:19] C:\Program Files\ViGUARD
[13/04/2007|20:34] C:\Program Files\Virtual Creatures
[19/11/2006|12:03] C:\Program Files\VirtualDubMod_1_5_10_2_All_inclusive
[25/12/2007|12:04] C:\Program Files\Visicom Media
[17/10/2007|22:18] C:\Program Files\vmntoolbar
[01/11/2005|13:20] C:\Program Files\Webteh
[24/01/2008|16:35] C:\Program Files\WinamaxPoker
[22/05/2007|21:23] C:\Program Files\WinAVI Video Converter
[27/02/2008|23:04] C:\Program Files\Windows Live
[30/09/2008|17:51] C:\Program Files\Windows Live Safety Center
[10/02/2008|22:24] C:\Program Files\Windows Live Toolbar
[24/11/2006|18:00] C:\Program Files\Windows Media Components
[12/10/2008|10:25] C:\Program Files\Windows Media Connect 2
[13/04/2008|17:18] C:\Program Files\Windows Media Player
[16/08/2004|18:03] C:\Program Files\Windows NT
[16/08/2004|18:07] C:\Program Files\WindowsUpdate
[30/04/2005|17:45] C:\Program Files\WinRAR
[16/08/2004|18:11] C:\Program Files\xerox
[10/02/2008|22:23] C:\Program Files\Yahoo!
[24/04/2006|20:48] C:\Program Files\Yahoo! Games
[12/09/2007|14:21] C:\Program Files\YesMessenger
[12/10/2008|09:30] C:\Program Files\Zylom Games

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[24/06/2006|16:44] C:\Program Files\Fichiers communs\Adobe
[28/10/2006|11:06] C:\Program Files\Fichiers communs\Ahead
[10/06/2006|16:36] C:\Program Files\Fichiers communs\AOL
[10/06/2006|16:36] C:\Program Files\Fichiers communs\aolshare
[12/10/2008|09:39] C:\Program Files\Fichiers communs\Bluebeam Software
[01/04/2006|11:47] C:\Program Files\Fichiers communs\BOONTY Shared
[12/10/2008|09:39] C:\Program Files\Fichiers communs\DESIGNER
[24/10/2005|19:01] C:\Program Files\Fichiers communs\DirectX
[04/03/2008|13:09] C:\Program Files\Fichiers communs\eDrawings2005
[17/09/2006|11:57] C:\Program Files\Fichiers communs\GTK
[21/05/2006|11:42] C:\Program Files\Fichiers communs\InstallShield
[17/03/2005|07:38] C:\Program Files\Fichiers communs\Java
[27/10/2008|16:23] C:\Program Files\Fichiers communs\Microsoft Shared
[16/08/2004|18:06] C:\Program Files\Fichiers communs\MSSoap
[17/03/2005|07:45] C:\Program Files\Fichiers communs\Nullsoft
[10/07/2005|14:11] C:\Program Files\Fichiers communs\Oberon Media
[16/08/2004|17:57] C:\Program Files\Fichiers communs\ODBC
[01/12/2005|10:37] C:\Program Files\Fichiers communs\Real
[16/08/2004|18:06] C:\Program Files\Fichiers communs\Services
[04/03/2008|13:01] C:\Program Files\Fichiers communs\Solidworks Data
[17/03/2005|08:00] C:\Program Files\Fichiers communs\Sonic Shared
[16/08/2004|17:56] C:\Program Files\Fichiers communs\SpeechEngines
[07/05/2005|09:38] C:\Program Files\Fichiers communs\SureThing Shared
[06/11/2005|15:34] C:\Program Files\Fichiers communs\Symantec Shared
[13/06/2007|12:16] C:\Program Files\Fichiers communs\System
[13/11/2007|18:55] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[29/12/2006|13:36] C:\Program Files\Fichiers communs\Wise Installation Wizard
[17/03/2005|07:53] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 35 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
C:\Program Files\Adverts
C:\Program Files\Circle Developement

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-29 22:42:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 613

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\BE3F5~1.LAG\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\crack.au-143c79f9-3758f902.au
C:\DOCUME~1\BE3F5~1.LAG\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\crack.au-143c79f9-3758f902.idx

[F:7][D:2]-> C:\DOCUME~1\BE3F5~1.LAG\LOCALS~1\Temp
[F:16][D:0]-> C:\DOCUME~1\BE3F5~1.LAG\Cookies
[F:169][D:5]-> C:\DOCUME~1\BE3F5~1.LAG\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 29/10/2008|22:45 - Option : [1]

--------------------\\ Fin du rapport a 22:45:33
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
---> Relance Lop S&D.
---> Choisis cette fois-ci l'option 2 (Suppression).
---> Ne ferme pas la fenêtre lors de la suppression !
---> Poste le rapport généré (C:\lopR.txt).
0
mibylag
 
le voici... tu crois qu'on est en bonne voie ?


--------------------\\ Lop S&D 4.2.4-8 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : B. LAGOUTTE ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081029-0] 4.8.1229 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:105 Go (Free:9 Go)
D:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)

"C:\Lop SD" ( MAJ : 27-10-2008|09:15 )
Option : [2] ( 29/10/2008|23:32 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
Supprime! - C:\Program Files\Adverts
Supprime! - C:\Program Files\Circle Developement

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Supprime! - C:\Program Files\Viewpoint
Supprime! - C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Viewpoint
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans APPLIC~1

[17/03/2005|08:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
[16/08/2004|18:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[16/08/2004|17:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[17/03/2005|07:53] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
[17/03/2005|07:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[17/03/2005|07:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
[17/03/2005|07:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver

[20/01/2007|10:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[03/01/2008|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[10/06/2006|16:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[14/10/2006|16:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[28/10/2008|13:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg8
[01/04/2006|11:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[16/08/2005|12:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[23/06/2006|16:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\enc jugs great user
[26/11/2005|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Global Software Publishing
[10/02/2008|22:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[20/04/2008|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[12/12/2006|20:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[10/06/2006|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak
[21/04/2006|14:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[29/12/2006|13:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MakeMusic
[28/10/2008|21:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[28/03/2006|15:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[05/01/2008|18:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Micro Application
[17/09/2008|06:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[22/04/2007|17:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NCH Swift Sound
[28/12/2007|23:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[22/04/2006|12:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[16/08/2004|18:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[06/11/2005|11:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBT
[21/06/2006|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[16/03/2008|02:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[06/11/2005|14:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[02/07/2005|19:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[17/04/2006|15:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ViGUARD
[06/11/2005|14:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[13/10/2007|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[06/07/2007|15:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[30/06/2008|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[18/01/2007|16:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
[27/12/2007|20:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[24/06/2006|16:51] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Adobe
[20/08/2008|12:57] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\AdobeUM
[19/11/2006|11:38] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Ahead
[17/03/2005|08:00] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\AOL
[07/06/2006|09:54] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Apple Computer
[29/10/2008|08:34] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\AVGTOOLBAR
[13/05/2008|20:17] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Creative
[31/03/2005|19:07] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\CyberLink
[21/10/2006|21:28] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\DivX
[14/09/2008|18:29] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\dvdcss
[12/10/2008|09:29] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\DWGEditor
[27/12/2007|11:29] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Google
[19/11/2005|17:25] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Help
[22/02/2008|13:21] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Identities
[14/04/2005|13:24] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Leadertech
[03/04/2005|09:39] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Macromedia
[28/10/2008|21:43] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Malwarebytes
[16/10/2008|15:36] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Microsoft
[06/11/2005|10:53] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Microsoft Web Folders
[05/05/2007|13:51] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Mozilla
[15/02/2008|17:46] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\MPMAN
[22/04/2007|17:30] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\NCH Swift Sound
[28/12/2007|23:13] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\PlayFirst
[05/05/2005|08:21] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Real
[27/10/2008|09:50] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Real4new
[17/12/2006|09:41] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Skype
[01/09/2008|18:43] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\SolidWorks
[14/04/2005|13:24] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Sonic
[17/03/2005|07:39] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Sun
[17/03/2005|07:48] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Symantec
[05/05/2007|13:52] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Talkback
[05/05/2007|13:51] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Thunderbird
[28/10/2008|11:29] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\uTorrent
[12/01/2008|13:28] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\vlc
[29/10/2008|19:13] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\VMNTOOLBAR
[24/04/2006|15:09] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Yahoo!
[17/03/2005|07:45] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\You've Got Pictures Screensaver
[28/12/2007|23:13] C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\Zylom

[17/09/2006|12:05] C:\DOCUME~1\BRENDAN\APPLIC~1\.gaim
[08/09/2008|11:14] C:\DOCUME~1\BRENDAN\APPLIC~1\Adobe
[22/09/2008|12:46] C:\DOCUME~1\BRENDAN\APPLIC~1\AdobeUM
[20/01/2008|17:59] C:\DOCUME~1\BRENDAN\APPLIC~1\Ahead
[17/03/2005|08:00] C:\DOCUME~1\BRENDAN\APPLIC~1\AOL
[22/05/2006|18:36] C:\DOCUME~1\BRENDAN\APPLIC~1\Apple Computer
[20/04/2007|18:04] C:\DOCUME~1\BRENDAN\APPLIC~1\AquaNox
[24/08/2006|14:06] C:\DOCUME~1\BRENDAN\APPLIC~1\BSplayer
[29/12/2006|21:47] C:\DOCUME~1\BRENDAN\APPLIC~1\Creative
[21/06/2005|15:39] C:\DOCUME~1\BRENDAN\APPLIC~1\CyberLink
[17/10/2006|17:58] C:\DOCUME~1\BRENDAN\APPLIC~1\DivX
[10/08/2008|10:13] C:\DOCUME~1\BRENDAN\APPLIC~1\dvdcss
[04/03/2008|13:08] C:\DOCUME~1\BRENDAN\APPLIC~1\DWGEditor
[08/09/2007|19:38] C:\DOCUME~1\BRENDAN\APPLIC~1\Ecran de veille
[18/12/2005|14:13] C:\DOCUME~1\BRENDAN\APPLIC~1\Google
[30/08/2006|11:55] C:\DOCUME~1\BRENDAN\APPLIC~1\Help
[16/08/2004|18:19] C:\DOCUME~1\BRENDAN\APPLIC~1\Identities
[25/04/2005|17:44] C:\DOCUME~1\BRENDAN\APPLIC~1\InstallShield Installation Information
[24/06/2006|08:59] C:\DOCUME~1\BRENDAN\APPLIC~1\Lavasoft
[16/04/2005|18:31] C:\DOCUME~1\BRENDAN\APPLIC~1\Leadertech
[22/06/2008|19:46] C:\DOCUME~1\BRENDAN\APPLIC~1\LimeWire
[27/01/2007|16:26] C:\DOCUME~1\BRENDAN\APPLIC~1\Macromedia
[25/03/2008|12:45] C:\DOCUME~1\BRENDAN\APPLIC~1\Microsoft
[17/09/2006|12:08] C:\DOCUME~1\BRENDAN\APPLIC~1\Mozilla
[17/06/2008|12:31] C:\DOCUME~1\BRENDAN\APPLIC~1\MPMAN
[25/03/2007|11:33] C:\DOCUME~1\BRENDAN\APPLIC~1\Nero
[20/05/2005|08:32] C:\DOCUME~1\BRENDAN\APPLIC~1\Real
[16/07/2008|22:19] C:\DOCUME~1\BRENDAN\APPLIC~1\Real4new
[26/12/2007|10:52] C:\DOCUME~1\BRENDAN\APPLIC~1\Skype
[17/08/2008|22:06] C:\DOCUME~1\BRENDAN\APPLIC~1\SolidWorks
[16/04/2005|18:31] C:\DOCUME~1\BRENDAN\APPLIC~1\Sonic
[17/03/2005|07:39] C:\DOCUME~1\BRENDAN\APPLIC~1\Sun
[17/03/2005|07:48] C:\DOCUME~1\BRENDAN\APPLIC~1\Symantec
[17/09/2006|12:08] C:\DOCUME~1\BRENDAN\APPLIC~1\Talkback
[17/09/2006|12:08] C:\DOCUME~1\BRENDAN\APPLIC~1\Thunderbird
[21/05/2006|11:42] C:\DOCUME~1\BRENDAN\APPLIC~1\U3
[30/09/2008|22:23] C:\DOCUME~1\BRENDAN\APPLIC~1\uTorrent
[17/12/2007|18:20] C:\DOCUME~1\BRENDAN\APPLIC~1\Viewpoint
[09/12/2007|12:04] C:\DOCUME~1\BRENDAN\APPLIC~1\vlc
[22/10/2008|19:03] C:\DOCUME~1\BRENDAN\APPLIC~1\vmntoolbar
[17/04/2006|18:52] C:\DOCUME~1\BRENDAN\APPLIC~1\Webroot
[13/07/2006|15:31] C:\DOCUME~1\BRENDAN\APPLIC~1\Yahoo!
[17/03/2005|07:45] C:\DOCUME~1\BRENDAN\APPLIC~1\You've Got Pictures Screensaver

[17/03/2005|08:00] C:\DOCUME~1\DEFAUL~1\APPLIC~1\AOL
[16/08/2004|18:19] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[16/08/2004|17:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[17/03/2005|07:53] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[17/03/2005|07:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun
[17/03/2005|07:48] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec
[17/03/2005|07:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver

[28/10/2008|13:18] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[17/04/2006|15:17] C:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot

[28/10/2008|13:18] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[03/04/2005|10:04] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[29/10/2008 23:28][--a------] C:\WINDOWS\tasks\Symantec NetDetect.job
[29/10/2008 20:42][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ MsgPlus SPONSOR INSTALLED !

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MsgPlus! Plugin]
"SponsorInstalled"=dword:00000000


--------------------\\ Listing des dossiers dans C:\Program Files

[24/06/2006|16:48] C:\Program Files\7-Zip
[24/06/2006|16:45] C:\Program Files\Adobe
[19/09/2006|19:37] C:\Program Files\Advanced Messenger Plus
[10/06/2006|17:32] C:\Program Files\Alwil Software
[17/04/2005|17:51] C:\Program Files\Analog Devices
[27/10/2008|16:25] C:\Program Files\AVG
[12/05/2008|09:47] C:\Program Files\CCleaner
[08/04/2006|12:10] C:\Program Files\Common Files
[16/08/2004|18:05] C:\Program Files\ComPlus Applications
[09/11/2006|20:05] C:\Program Files\Creative
[17/03/2005|07:52] C:\Program Files\CyberLink
[24/04/2006|20:47] C:\Program Files\Dekovir
[24/10/2005|18:30] C:\Program Files\directx
[25/11/2006|19:09] C:\Program Files\Disc2Phone
[12/10/2008|10:24] C:\Program Files\DivX
[24/04/2005|18:11] C:\Program Files\DVD Audio Extractor
[10/06/2006|11:32] C:\Program Files\EA SPORTS
[25/12/2007|11:45] C:\Program Files\eMule
[03/04/2005|13:35] C:\Program Files\EVEREST Home Edition
[28/10/2008|10:40] C:\Program Files\Fichiers communs
[20/04/2008|18:15] C:\Program Files\Finale 2005b
[29/12/2006|13:27] C:\Program Files\Finale Performance Assessment
[25/12/2007|12:05] C:\Program Files\foobar2000
[25/12/2007|12:04] C:\Program Files\Gaim
[12/10/2008|10:25] C:\Program Files\ganjasw
[12/10/2008|09:28] C:\Program Files\GIMP-2.0
[12/10/2008|11:06] C:\Program Files\Google
[17/04/2006|15:07] C:\Program Files\Grisoft
[29/12/2005|14:52] C:\Program Files\Illustrate
[31/10/2005|13:56] C:\Program Files\IncrediMail
[05/01/2008|18:39] C:\Program Files\InstallShield Installation Information
[12/10/2008|11:06] C:\Program Files\InterActual
[15/10/2008|22:35] C:\Program Files\Internet Explorer
[03/05/2007|19:05] C:\Program Files\Java
[22/11/2007|19:17] C:\Program Files\jeux
[10/06/2006|11:42] C:\Program Files\Kodak
[17/03/2005|07:45] C:\Program Files\Learn2.com
[20/02/2006|10:12] C:\Program Files\LEGO Media
[12/10/2008|10:25] C:\Program Files\LimeWire
[13/04/2007|20:55] C:\Program Files\Loop12 V2
[17/07/2006|21:07] C:\Program Files\Macrogaming
[28/10/2008|21:43] C:\Program Files\Malwarebytes' Anti-Malware
[03/12/2005|11:21] C:\Program Files\Maxis
[26/05/2006|22:18] C:\Program Files\Mes Jeux Téléchargés
[12/10/2008|10:25] C:\Program Files\Messenger
[07/09/2008|21:06] C:\Program Files\Messenger Plus! Live
[17/03/2008|22:04] C:\Program Files\MessengerPlus! 3
[05/01/2008|18:17] C:\Program Files\Micro Application
[07/07/2007|13:30] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[06/11/2005|11:01] C:\Program Files\microsoft frontpage
[19/09/2005|12:15] C:\Program Files\Microsoft Games
[17/10/2007|13:19] C:\Program Files\Microsoft Office
[14/09/2005|16:43] C:\Program Files\Microsoft Référence
[13/11/2007|19:19] C:\Program Files\Microsoft SQL Server Compact Edition
[06/11/2005|10:56] C:\Program Files\Microsoft Visual Studio
[24/04/2005|17:09] C:\Program Files\Microsoft Works
[17/03/2005|07:58] C:\Program Files\Microsoft.NET
[12/10/2008|10:24] C:\Program Files\Motus
[16/08/2004|18:06] C:\Program Files\Movie Maker
[29/10/2008|22:48] C:\Program Files\Mozilla Firefox
[12/10/2008|15:16] C:\Program Files\Mozilla Thunderbird
[22/05/2007|21:34] C:\Program Files\MP3 Player Utilities 3.57
[07/04/2005|17:29] C:\Program Files\MSN
[25/04/2006|11:35] C:\Program Files\MSN Games
[16/08/2004|18:03] C:\Program Files\MSN Gaming Zone
[06/07/2007|15:09] C:\Program Files\MSN Messenger
[21/06/2007|18:51] C:\Program Files\MSNTweaker
[18/11/2006|15:23] C:\Program Files\MSXML 4.0
[24/04/2006|20:51] C:\Program Files\Musique
[29/10/2008|19:22] C:\Program Files\Navilog1
[22/04/2007|17:34] C:\Program Files\NCH Swift Sound
[28/10/2006|11:06] C:\Program Files\Nero
[22/02/2007|22:22] C:\Program Files\NetMeeting
[12/10/2008|09:24] C:\Program Files\Neuf
[18/10/2008|11:21] C:\Program Files\NoteWorthy Composer
[16/08/2004|18:03] C:\Program Files\Online Services
[13/04/2008|17:18] C:\Program Files\Outlook Express
[17/09/2006|12:03] C:\Program Files\Pack Securite
[27/10/2008|19:05] C:\Program Files\Panda Security
[09/04/2008|14:12] C:\Program Files\Picasa2
[17/04/2005|22:02] C:\Program Files\QuickEuro 2002
[12/10/2008|10:25] C:\Program Files\QuickTime
[17/03/2005|07:45] C:\Program Files\Real
[21/06/2008|14:05] C:\Program Files\Real4new
[25/04/2005|17:44] C:\Program Files\Rockstar Games
[17/03/2005|07:38] C:\Program Files\S3Inc
[31/03/2005|10:12] C:\Program Files\SAGEM
[12/09/2006|10:03] C:\Program Files\Samsung
[18/04/2005|14:35] C:\Program Files\Services en ligne
[25/03/2007|17:08] C:\Program Files\Setup
[22/10/2006|21:12] C:\Program Files\Sibelius Software
[24/06/2006|17:47] C:\Program Files\Skype
[20/02/2006|14:19] C:\Program Files\SmartMusic
[06/11/2005|11:03] C:\Program Files\Snapshot Viewer
[12/10/2008|09:41] C:\Program Files\SolidWorks
[17/03/2005|08:00] C:\Program Files\Sonic
[23/12/2007|17:44] C:\Program Files\Spybot
[15/03/2008|12:28] C:\Program Files\Spybot - Search & Destroy
[06/11/2005|15:01] C:\Program Files\Symantec
[04/02/2006|23:18] C:\Program Files\THQ
[27/10/2008|17:34] C:\Program Files\Trend Micro
[16/08/2004|18:19] C:\Program Files\Uninstall Information
[29/10/2008|22:37] C:\Program Files\UsbFix
[11/08/2008|20:24] C:\Program Files\uTorrent
[12/10/2008|10:44] C:\Program Files\vghd
[19/11/2006|20:08] C:\Program Files\VIA
[09/12/2007|11:58] C:\Program Files\VideoLAN
[17/04/2006|15:19] C:\Program Files\ViGUARD
[13/04/2007|20:34] C:\Program Files\Virtual Creatures
[19/11/2006|12:03] C:\Program Files\VirtualDubMod_1_5_10_2_All_inclusive
[25/12/2007|12:04] C:\Program Files\Visicom Media
[17/10/2007|22:18] C:\Program Files\vmntoolbar
[01/11/2005|13:20] C:\Program Files\Webteh
[24/01/2008|16:35] C:\Program Files\WinamaxPoker
[22/05/2007|21:23] C:\Program Files\WinAVI Video Converter
[27/02/2008|23:04] C:\Program Files\Windows Live
[30/09/2008|17:51] C:\Program Files\Windows Live Safety Center
[10/02/2008|22:24] C:\Program Files\Windows Live Toolbar
[24/11/2006|18:00] C:\Program Files\Windows Media Components
[12/10/2008|10:25] C:\Program Files\Windows Media Connect 2
[13/04/2008|17:18] C:\Program Files\Windows Media Player
[16/08/2004|18:03] C:\Program Files\Windows NT
[16/08/2004|18:07] C:\Program Files\WindowsUpdate
[30/04/2005|17:45] C:\Program Files\WinRAR
[16/08/2004|18:11] C:\Program Files\xerox
[10/02/2008|22:23] C:\Program Files\Yahoo!
[24/04/2006|20:48] C:\Program Files\Yahoo! Games
[12/09/2007|14:21] C:\Program Files\YesMessenger
[12/10/2008|09:30] C:\Program Files\Zylom Games

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[24/06/2006|16:44] C:\Program Files\Fichiers communs\Adobe
[28/10/2006|11:06] C:\Program Files\Fichiers communs\Ahead
[10/06/2006|16:36] C:\Program Files\Fichiers communs\AOL
[10/06/2006|16:36] C:\Program Files\Fichiers communs\aolshare
[12/10/2008|09:39] C:\Program Files\Fichiers communs\Bluebeam Software
[01/04/2006|11:47] C:\Program Files\Fichiers communs\BOONTY Shared
[12/10/2008|09:39] C:\Program Files\Fichiers communs\DESIGNER
[24/10/2005|19:01] C:\Program Files\Fichiers communs\DirectX
[04/03/2008|13:09] C:\Program Files\Fichiers communs\eDrawings2005
[17/09/2006|11:57] C:\Program Files\Fichiers communs\GTK
[21/05/2006|11:42] C:\Program Files\Fichiers communs\InstallShield
[17/03/2005|07:38] C:\Program Files\Fichiers communs\Java
[27/10/2008|16:23] C:\Program Files\Fichiers communs\Microsoft Shared
[16/08/2004|18:06] C:\Program Files\Fichiers communs\MSSoap
[17/03/2005|07:45] C:\Program Files\Fichiers communs\Nullsoft
[10/07/2005|14:11] C:\Program Files\Fichiers communs\Oberon Media
[16/08/2004|17:57] C:\Program Files\Fichiers communs\ODBC
[01/12/2005|10:37] C:\Program Files\Fichiers communs\Real
[16/08/2004|18:06] C:\Program Files\Fichiers communs\Services
[04/03/2008|13:01] C:\Program Files\Fichiers communs\Solidworks Data
[17/03/2005|08:00] C:\Program Files\Fichiers communs\Sonic Shared
[16/08/2004|17:56] C:\Program Files\Fichiers communs\SpeechEngines
[07/05/2005|09:38] C:\Program Files\Fichiers communs\SureThing Shared
[06/11/2005|15:34] C:\Program Files\Fichiers communs\Symantec Shared
[13/06/2007|12:16] C:\Program Files\Fichiers communs\System
[13/11/2007|18:55] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[29/12/2006|13:36] C:\Program Files\Fichiers communs\Wise Installation Wizard
[17/03/2005|07:53] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 33 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-29 23:34:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 613

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\BE3F5~1.LAG\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\crack.au-143c79f9-3758f902.au
C:\DOCUME~1\BE3F5~1.LAG\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\crack.au-143c79f9-3758f902.idx


[F:7][D:2]-> C:\DOCUME~1\BE3F5~1.LAG\LOCALS~1\Temp
[F:16][D:0]-> C:\DOCUME~1\BE3F5~1.LAG\Cookies
[F:169][D:5]-> C:\DOCUME~1\BE3F5~1.LAG\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 29/10/2008|22:45 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 29/10/2008|23:36 - Option : [2]

--------------------\\ Fin du rapport a 23:36:32
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
"le voici... tu crois qu'on est en bonne voie ?"
---> Oui, c'est sûr.

Je te réponds plus tard dans la nuit.
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
/!\ Seul mibylag peut suivre cette procédure /!\

1/

---> Clique sur Démarrer, Exécuter, tape notepad clique sur OK.

---> Copie le texte ci-dessous par sélection puis Ctrl+C :

KillAll::

File::
C:\WINDOWS\system32\AntiXPVSTFix.exe
C:\WINDOWS\system32\o4Patch.exe
C:\WINDOWS\system32\IEDFix.C.exe
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\VACFix.exe
C:\WINDOWS\system32\IEDFix.exe
C:\WINDOWS\system32\404Fix.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\system32\VCCLSID.exe
C:\WINDOWS\system32\SrchSTS.exe
C:\WINDOWS\system32\Process.exe
C:\WINDOWS\system32\dumphive.exe
C:\WINDOWS\system32\drivers\eef6c0ac.sys
C:\WINDOWS\system32\cont_offersfortoday-remove.exe
C:\WINDOWS\system32\fyglbdtfjrzxm.exe

Folder::
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR
C:\Program Files\Circle Developement
C:\Documents and Settings\All Users\Application Data\great coal love default
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar
C:\DOCUME~1\ALLUSE~1\APPLIC~1\enc jugs great user

Driver::
VigService
nenum13E

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eef6c0ac]

---> Colle la sélection dans le bloc-notes

---> Enregistre ce fichier sur le bureau (Impératif)

---> Nom du fichier : CFScript
---> Type du fichier : tous les fichiers
---> Clique sur Enregistrer
---> Quitte le bloc-notes

2/

---> Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :
http://www.searchengines.pl/phpbb203/pliki/picasso/virus/programs/combofix/combofix_cfscript.gif

[*] Une fenêtre bleue va apparaître : au message qui apparaît, tu acceptes.

[*] Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal !
Ne touche à rien tant que le scan n'est pas terminé.

[*] Une fois le scan achevé, un rapport va s'afficher : poste-le

[*] Si le fichier ne s'ouvre pas, il se trouve ici C:\ComboFix.txt
0
mibylag
 
Bonjour Destrio5,
Voici le rapport suite aux modifs sur combofix

ComboFix 08-10-30.04 - B. LAGOUTTE 2008-10-30 8:54:08.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.113 [GMT 1:00]
Lancé depuis: C:\Documents and Settings\B. LAGOUTTE\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.

((((((((((((((((((((((((((((( Fichiers créés du 2008-09-28 au 2008-10-30 ))))))))))))))))))))))))))))))))))))
.

2008-10-29 22:40 . 2008-10-30 08:43 <REP> d-------- C:\Lop SD
2008-10-29 20:36 . 2008-10-29 22:37 <REP> d-------- C:\Program Files\UsbFix
2008-10-29 09:16 . 2008-10-29 19:22 <REP> d-------- C:\Program Files\Navilog1
2008-10-28 21:43 . 2008-10-28 21:43 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-28 21:43 . 2008-10-28 21:43 <REP> d-------- C:\Documents and Settings\B. LAGOUTTE\Application Data\Malwarebytes
2008-10-28 21:43 . 2008-10-28 21:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-28 21:43 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-28 21:43 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-28 18:50 . 2005-03-17 07:34 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2008-10-28 18:50 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-10-28 18:50 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-10-28 18:50 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-10-28 18:50 . 2005-04-03 13:19 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-10-28 18:50 . 2005-03-17 07:46 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2008-10-28 18:50 . 2005-04-03 13:19 <REP> dr------- C:\Documents and Settings\Administrateur\Bureau
2008-10-28 18:50 . 2005-03-17 07:45 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\You've Got Pictures Screensaver
2008-10-28 18:50 . 2005-03-17 07:48 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2008-10-28 18:50 . 2005-03-17 08:00 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\AOL
2008-10-28 18:50 . 2008-10-28 18:50 <REP> d-------- C:\Documents and Settings\Administrateur
2008-10-28 13:20 . 2008-10-29 20:48 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
2008-10-28 13:20 . 2008-10-29 08:34 <REP> d-------- C:\Documents and Settings\B. LAGOUTTE\Application Data\AVGTOOLBAR
2008-10-28 13:20 . 2008-10-29 20:45 98,440 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-10-28 13:20 . 2008-10-28 13:20 90,632 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-10-28 13:20 . 2008-10-28 13:20 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-10-28 13:20 . 2008-10-28 13:20 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-10-28 09:41 . 2008-09-08 22:38 88,576 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-10-28 09:41 . 2008-10-10 07:58 82,944 --a------ C:\WINDOWS\system32\o4Patch.exe
2008-10-28 09:41 . 2008-10-10 07:58 82,944 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-10-28 09:41 . 2008-10-28 18:54 1,196 --a------ C:\WINDOWS\system32\tmp.reg
2008-10-28 09:37 . 2008-10-01 14:51 87,552 --a------ C:\WINDOWS\system32\VACFix.exe
2008-10-28 09:37 . 2008-05-18 20:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-10-28 09:37 . 2008-08-18 11:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-10-28 09:37 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-10-28 09:36 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-10-28 09:36 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-10-28 09:36 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-10-27 19:06 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
2008-10-27 19:05 . 2008-10-27 19:05 <REP> d-------- C:\Program Files\Panda Security
2008-10-27 17:24 . 2008-10-27 17:34 <REP> d-------- C:\Program Files\Trend Micro
2008-10-27 16:29 . 2008-10-29 11:49 <REP> d--h----- C:\$AVG8.VAULT$
2008-10-27 16:25 . 2008-10-27 16:25 <REP> d-------- C:\Program Files\AVG
2008-10-27 16:25 . 2008-10-28 13:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-10-24 17:40 . 2008-10-30 09:01 104,670 --a------ C:\WINDOWS\system32\drivers\eef6c0ac.sys
2008-10-22 17:32 . 2008-10-22 17:32 79,085 --a------ C:\WINDOWS\system32\fyglbdtfjrzxm.exe
2008-10-12 09:29 . 2008-10-12 09:29 <REP> d-------- C:\Documents and Settings\B. LAGOUTTE\Application Data\DWGEditor
2008-09-28 11:12 . 2008-09-28 11:51 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-29 18:13 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR
2008-10-28 10:29 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\uTorrent
2008-10-27 08:50 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\Real4new
2008-10-22 18:03 --------- d-----w C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar
2008-10-18 10:21 --------- d-----w C:\Program Files\NoteWorthy Composer
2008-10-15 16:59 332,800 ------w C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-12 14:16 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-10-12 10:06 --------- d-----w C:\Program Files\InterActual
2008-10-12 10:06 --------- d-----w C:\Program Files\Google
2008-10-12 09:44 --------- d-----w C:\Program Files\vghd
2008-10-12 09:25 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-12 09:25 --------- d-----w C:\Program Files\QuickTime
2008-10-12 09:25 --------- d-----w C:\Program Files\LimeWire
2008-10-12 09:25 --------- d-----w C:\Program Files\ganjasw
2008-10-12 09:24 --------- d-----w C:\Program Files\Motus
2008-10-12 09:24 --------- d-----w C:\Program Files\DivX
2008-10-12 08:41 --------- d-----w C:\Program Files\SolidWorks
2008-10-12 08:39 --------- d-----w C:\Program Files\Fichiers communs\Bluebeam Software
2008-10-12 08:30 --------- d-----w C:\Program Files\Zylom Games
2008-10-12 08:28 --------- d-----w C:\Program Files\GIMP-2.0
2008-10-12 08:24 --------- d-----w C:\Program Files\Neuf
2008-10-03 17:12 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2008-09-30 21:23 --------- d-----w C:\Documents and Settings\BRENDAN\Application Data\uTorrent
2008-09-30 16:51 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-09-24 18:09 3,532 ----a-w C:\drmHeader.bin
2008-09-22 11:46 --------- d-----w C:\Documents and Settings\BRENDAN\Application Data\AdobeUM
2008-09-15 15:39 1,846,144 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-15 15:39 1,846,144 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-09-14 17:29 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\dvdcss
2008-09-07 20:06 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-01 17:43 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\SolidWorks
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-28 10:04 333,056 ------w C:\WINDOWS\system32\dllcache\srv.sys
2008-08-27 09:11 3,593,216 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-08-25 08:39 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-08-25 08:38 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-23 05:56 635,848 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-08-23 05:54 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-08-14 13:44 2,182,400 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:44 2,182,400 ------w C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-08-14 13:44 2,138,112 ------w C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-08-14 13:44 2,059,776 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 13:44 2,059,776 ------w C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-08-14 13:44 2,017,792 ------w C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-08-14 09:51 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2005-08-02 14:20 109,384 -c--a-w C:\Documents and Settings\B. LAGOUTTE\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot@2008-10-28_10.59.57.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-27 15:26:52 26,824 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-10-28 12:20:24 26,824 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-10-30 07:06:25 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_7e4.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-10-28 1235736]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-20 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
"vidc.xvid"= xvid.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\microsoft office\\office11\\EXCEL.EXE"=
"C:\\Program Files\\microsoft office\\office11\\POWERPNT.EXE"=
"C:\\Program Files\\microsoft office\\office11\\WINWORD.EXE"=
"C:\\Program Files\\Outlook Express\\msimn.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"80:TCP"= 80:TCP:@xpsp2res.dll,-22004

.
Contenu du dossier 'Tâches planifiées'

2008-10-30 C:\WINDOWS\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe []
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\B. LAGOUTTE\Application Data\Mozilla\Firefox\Profiles\9wm7ol4h.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 08:59:44
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...


**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MysqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-nt MysqlInventime"

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\eef6c0ac]
"ImagePath"="\SystemRoot\System32\drivers\eef6c0ac.sys"
.
Heure de fin: 2008-10-30 9:05:38
ComboFix-quarantined-files.txt 2008-10-30 08:04:23
ComboFix2.txt 2008-10-28 10:01:56

Avant-CF: 10 061 688 832 octets libres
Après-CF: 10,061,762,560 octets libres

198 --- E O F --- 2008-10-24 16:47:41
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Tu n'as pas suivi la procédure.
0
mibylag
 
Bonsoir Destrio5

Désolé pour la mauvaise manip mais j'avais supprimé combofix après résolution de virtumonde, et quand j'ai fait le glisser déplacer, ça n'a pas du marcher.
Voici donc le bon rapport j'espère

ComboFix 08-10-30.07 - B. LAGOUTTE 2008-10-30 18:24:01.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.121 [GMT 1:00]
Lancé depuis: C:\Documents and Settings\B. LAGOUTTE\Bureau\ComboFix.exe
Commutateurs utilisés :: C:\Documents and Settings\B. LAGOUTTE\Bureau\CFScript.txt
* Un nouveau point de restauration a été créé

FILE ::
C:\WINDOWS\system32\404Fix.exe
C:\WINDOWS\system32\AntiXPVSTFix.exe
C:\WINDOWS\system32\cont_offersfortoday-remove.exe
C:\WINDOWS\system32\drivers\eef6c0ac.sys
C:\WINDOWS\system32\dumphive.exe
C:\WINDOWS\system32\fyglbdtfjrzxm.exe
C:\WINDOWS\system32\IEDFix.C.exe
C:\WINDOWS\system32\IEDFix.exe
C:\WINDOWS\system32\o4Patch.exe
C:\WINDOWS\system32\Process.exe
C:\WINDOWS\system32\SrchSTS.exe
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\VACFix.exe
C:\WINDOWS\system32\VCCLSID.exe
C:\WINDOWS\system32\WS2Fix.exe
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\ALLUSE~1\APPLIC~1\enc jugs great user
C:\DOCUME~1\ALLUSE~1\APPLIC~1\enc jugs great user\Admin 64 proc
C:\DOCUME~1\ALLUSE~1\APPLIC~1\enc jugs great user\itch bone htm
C:\DOCUME~1\ALLUSE~1\APPLIC~1\enc jugs great user\Roaderroractive
C:\DOCUME~1\ALLUSE~1\APPLIC~1\enc jugs great user\sign for bin
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\---Yahoo.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\[u]0/u1net.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\a.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\amazon.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\an.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\arrow_down.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\arrow_up.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\arrowB.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\arrowT.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\autofill.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\avstate.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\b.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\bg_pub.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\bg_ttl.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\bn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\bottom.png
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\bottom_left.png
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\bottom_right.png
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\c.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\canalblog.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\cn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\COMBOSEARCH.acs
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\d.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\dictionary2.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\dn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\downfile\searchdataV3.php1100828
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\downfile\searchdataV3.php1248296
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\downfile\searchdataV3.php1677890
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\downfile\searchdataV3.php1947578
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\downfile\searchdataV3.php27798312
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\downfile\searchdataV3.php2921000
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\downfile\searchdataV3.php29305015
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\downfile\searchdataV3.php3130375
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\downfile\searchdataV3.php636640
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\DownloadCOM.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\dropdown.css
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\ErrorLog.txt
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\ErrorPageTemplate.css
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\f.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_argentine.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_australia.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_brazil.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_canada.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_china.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_france.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_germany.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_greece.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_hongkong.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_india.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_indonesia.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_italy.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_japan.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_korea.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_mexico.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_netherlands.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_spain.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_sweeden.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_taiwan.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_uk.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\flag_usa.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\fn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\g.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\gaming.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\gn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\gograph.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\graphred0.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\graphred0_5.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\graphred1.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\graphred1_5.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\graphred2.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\graphred2_5.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\graphred3.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\graphred3_5.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\graphred4.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\graphred4_5.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\graphred5.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_aquarius.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_aries.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_cancer.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_capricorn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_gemini.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_leo.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_libra.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_pisces.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_sagittarius.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_scorpio.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_taurus.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\h_virgo.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\help.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\hideremove.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\highlight.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\hn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\hororank.xml
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\i.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\IEtab1_7d.zip
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\in.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\ipsearch.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\j.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\jn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\k.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\kn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\l.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\left.png
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\ln.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\loading.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\login.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\logo.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\n.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt1100828
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt11738031
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt1248296
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt15803703
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt1677890
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt1851531
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt1947578
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt21115296
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt27798406
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt2921000
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt29305031
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt4408015
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\New York_NY_weather.txt636640
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\new02.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\news.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\news.html
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\nn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\o.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\on.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\p.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\p_yahoo.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\p_yahoo_fr.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\pestscanimg.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\pixsy.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\pn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\popup_off.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\popup_on.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\popup_ona.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\q.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\qn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\r.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\relatedlinks.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\report.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\right.png
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\rn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\rss.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\rss.xsl
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\rss1.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\rsslib.js
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\rssmenu1_7a.zip
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\s.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\search.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\search_fr.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\security.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt1140171
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt1153937
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt1248062
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt1249812
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt1255546
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt1258656
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt1307171
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt1479828
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt1504140
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt2473625
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt27191156
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt27529796
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt27744484
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt30666031
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt31470375
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt31622843
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt372156
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt4491859
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt5248406
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt5488468
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt623656
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt625468
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt669265
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt6724796
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt767687
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt7813625
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sinfo.txt8875296
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\siteinfo.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\slider.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\sn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\spacer.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\stars-red1.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\stars-red2.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\stars-red3.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\stars-red4.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\stars-red5.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\storage.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\t.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\tab_icon.png
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\tabdataV3.js
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\tablib.js
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\tabwelcome_en.html
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\tabwelcome_fr.html
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\technorati.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\thes_search.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\tn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\tools.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\top.png
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\top_left.png
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\top_right.png
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\translate.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\u.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\un.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\utf8.js
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\v.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\vmlib.js
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\vmntoolbartb0501.cfg
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\vn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\w.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\web_en.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\wikipedia.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\wn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\x.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\xp_close_small.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\Yahoo.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\yahoo_search.gif
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\YouTube.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\z.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\zn.bmp
C:\Documents and Settings\B. LAGOUTTE\Application Data\VMNTOOLBAR\zoom.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\---Yahoo.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\[u]0/u1net.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\1px_dark.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\1px_green.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\1px_white.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\a.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\amazon.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\an.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\arrow_down.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\arrow_red.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\arrow_red2.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\arrow_up.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\arrowB.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\arrowT.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\autofill.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\avstate.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\b.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\background2.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\bg_pub.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\bg_ttl.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\bgmeteo_results.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\bn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\bottom.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\bottom_left.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\bottom_right.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\btn_close.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\btn_minus.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\btn_moreforecast.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\c.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\canalblog.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\cn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\COMBOSEARCH.acs
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\d.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\dictionary2.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\dn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\downfile\searchdataV3.php25279734
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\downfile\searchdataV3.php433921
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\DownloadCOM.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\dropdown.css
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\ErrorLog.txt
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\ErrorPageTemplate.css
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\f.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_argentine.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_australia.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_brazil.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_canada.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_china.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_france.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_germany.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_greece.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_hongkong.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_india.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_indonesia.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_italy.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_japan.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_korea.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_mexico.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_netherlands.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_spain.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_sweeden.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_taiwan.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_uk.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\flag_usa.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\fn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\g.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\gaming.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\gn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\gograph.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\graphred0.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\graphred0_5.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\graphred1.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\graphred1_5.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\graphred2.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\graphred2_5.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\graphred3.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\graphred3_5.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\graphred4.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\graphred4_5.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\graphred5.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_aquarius.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_aries.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_cancer.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_capricorn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_gemini.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_leo.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_libra.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_pisces.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_sagittarius.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_scorpio.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_taurus.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\h_virgo.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\help.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\hideremove.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\highlight.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\hn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\i.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\icotemp_placeholder.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\IEtab1_7c.zip
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\IEtab1_7d.zip
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\in.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\ipsearch.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\j.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\jn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\k.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\kn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\l.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\left.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\ln.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\loading.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\login.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\logo.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\n.bmp
0
mibylag > mibylag
 
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt11160203
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt11160250
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt11160281
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt14170953
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt15044046
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt15899109
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt15899187
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt17328046
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt18184015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt18390015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt18884015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt20684015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt20860015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt21202000
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt23841140
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt2910328
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt30885218
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt3831593
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt433953
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt8378812
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\new02.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\news.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\news.html
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\nn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\o.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\on.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\p.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\p_yahoo.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\p_yahoo_fr.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\pestscanimg.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\pixsy.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\pn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\popup_off.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\popup_on.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\popup_ona.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\q.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\qn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\r.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\relatedlinks.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\report.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\right.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rss.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rss.xsl
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rss1.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rsslib.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rssmenu1_7a.zip
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\s.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\search.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\search_fr.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\security.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt10442828
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt11004687
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt12539468
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt13153312
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt132953
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1486265
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1497515
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt15171609
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1546937
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1555203
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1686625
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt172796
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt17310015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt18106765
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt184062
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt18836484
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1909343
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt19769656
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt19930937
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt21597796
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt22799015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt25160875
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt2643687
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt27214921
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt29814453
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt310000
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt3120703
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt323890
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt341140
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt36856281
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt39784015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt39987796
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt40853531
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt40972796
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt41608140
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt4359140
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt4407390
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt47194125
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt5225843
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt5393656
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt6013437
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt6014000
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt6197953
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt6513156
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt8293984
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt885781
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt9145250
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\siteinfo.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\slider.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\spacer.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\stars-red1.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\stars-red2.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\stars-red3.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\stars-red4.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\stars-red5.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\storage.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\t.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tab_icon.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tabdata.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tabdataV3.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tablib.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tabwelcome_en.html
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tabwelcome_fr.html
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\technorati.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\thes_search.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tools.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\top.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\top_left.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\top_right.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\translate.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\u.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\un.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\utf8.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\v.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\vmlib.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\vmntoolbartb1501.cfg
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\vn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\w.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\web.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\web_fr.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\wikipedia.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\wn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\x.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\xp_close_small.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\yahoo.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\yahoo_search.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\YouTube.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\z.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\zn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\zoom.bmp
C:\WINDOWS\system32\404Fix.exe
C:\WINDOWS\system32\AntiXPVSTFix.exe
C:\WINDOWS\system32\drivers\eef6c0ac.sys
C:\WINDOWS\system32\dumphive.exe
C:\WINDOWS\system32\fyglbdtfjrzxm.exe
C:\WINDOWS\system32\IEDFix.C.exe
C:\WINDOWS\system32\IEDFix.exe
C:\WINDOWS\system32\o4Patch.exe
C:\WINDOWS\system32\SrchSTS.exe
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\VACFix.exe
C:\WINDOWS\system32\VCCLSID.exe
C:\WINDOWS\system32\WS2Fix.exe

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NENUM13E
-------\Legacy_VIGSERVICE
-------\Service_nenum13E
-------\Service_VigService
-------\Service_eef6c0ac


((((((((((((((((((((((((((((( Fichiers créés du 2008-09-28 au 2008-10-30 ))))))))))))))))))))))))))))))))))))
.

2008-10-29 22:40 . 2008-10-30 08:43 <REP> d-------- C:\Lop SD
2008-10-29 20:36 . 2008-10-29 22:37 <REP> d-------- C:\Program Files\UsbFix
2008-10-29 09:16 . 2008-10-29 19:22 <REP> d-------- C:\Program Files\Navilog1
2008-10-28 21:43 . 2008-10-28 21:43 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-28 21:43 . 2008-10-28 21:43 <REP> d-------- C:\Documents and Settings\B. LAGOUTTE\Application Data\Malwarebytes
2008-10-28 21:43 . 2008-10-28 21:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-28 21:43 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-28 21:43 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-28 18:50 . 2005-03-17 07:34 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2008-10-28 18:50 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-10-28 18:50 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-10-28 18:50 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-10-28 18:50 . 2005-04-03 13:19 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-10-28 18:50 . 2005-03-17 07:46 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2008-10-28 18:50 . 2005-04-03 13:19 <REP> dr------- C:\Documents and Settings\Administrateur\Bureau
2008-10-28 18:50 . 2005-03-17 07:45 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\You've Got Pictures Screensaver
2008-10-28 18:50 . 2005-03-17 07:48 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2008-10-28 18:50 . 2005-03-17 08:00 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\AOL
2008-10-28 18:50 . 2008-10-28 18:50 <REP> d-------- C:\Documents and Settings\Administrateur
2008-10-28 13:20 . 2008-10-30 18:36 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
2008-10-28 13:20 . 2008-10-29 08:34 <REP> d-------- C:\Documents and Settings\B. LAGOUTTE\Application Data\AVGTOOLBAR
2008-10-28 13:20 . 2008-10-29 20:45 98,440 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-10-28 13:20 . 2008-10-28 13:20 90,632 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-10-28 13:20 . 2008-10-28 13:20 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-10-28 13:20 . 2008-10-28 13:20 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-10-27 19:06 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
2008-10-27 19:05 . 2008-10-27 19:05 <REP> d-------- C:\Program Files\Panda Security
2008-10-27 17:24 . 2008-10-27 17:34 <REP> d-------- C:\Program Files\Trend Micro
2008-10-27 16:29 . 2008-10-30 11:11 <REP> d--h----- C:\$AVG8.VAULT$
2008-10-27 16:25 . 2008-10-27 16:25 <REP> d-------- C:\Program Files\AVG
2008-10-27 16:25 . 2008-10-28 13:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-10-12 09:29 . 2008-10-12 09:29 <REP> d-------- C:\Documents and Settings\B. LAGOUTTE\Application Data\DWGEditor
2008-09-28 11:12 . 2008-09-28 11:51 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 10:29 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\uTorrent
2008-10-27 08:50 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\Real4new
2008-10-18 10:21 --------- d-----w C:\Program Files\NoteWorthy Composer
2008-10-12 14:16 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-10-12 10:06 --------- d-----w C:\Program Files\InterActual
2008-10-12 10:06 --------- d-----w C:\Program Files\Google
2008-10-12 09:44 --------- d-----w C:\Program Files\vghd
2008-10-12 09:25 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-12 09:25 --------- d-----w C:\Program Files\QuickTime
2008-10-12 09:25 --------- d-----w C:\Program Files\LimeWire
2008-10-12 09:25 --------- d-----w C:\Program Files\ganjasw
2008-10-12 09:24 --------- d-----w C:\Program Files\Motus
2008-10-12 09:24 --------- d-----w C:\Program Files\DivX
2008-10-12 08:41 --------- d-----w C:\Program Files\SolidWorks
2008-10-12 08:39 --------- d-----w C:\Program Files\Fichiers communs\Bluebeam Software
2008-10-12 08:30 --------- d-----w C:\Program Files\Zylom Games
2008-10-12 08:28 --------- d-----w C:\Program Files\GIMP-2.0
2008-10-12 08:24 --------- d-----w C:\Program Files\Neuf
2008-09-30 21:23 --------- d-----w C:\Documents and Settings\BRENDAN\Application Data\uTorrent
2008-09-30 16:51 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-09-24 18:09 3,532 ----a-w C:\drmHeader.bin
2008-09-22 11:46 --------- d-----w C:\Documents and Settings\BRENDAN\Application Data\AdobeUM
2008-09-14 17:29 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\dvdcss
2008-09-07 20:06 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-01 17:43 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\SolidWorks
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2005-08-02 14:20 109,384 -c--a-w C:\Documents and Settings\B. LAGOUTTE\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot@2008-10-28_10.59.57.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-27 15:26:52 26,824 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-10-28 12:20:24 26,824 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-10-30 17:33:27 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_73c.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-10-28 1235736]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-20 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
"vidc.xvid"= xvid.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\microsoft office\\office11\\EXCEL.EXE"=
"C:\\Program Files\\microsoft office\\office11\\POWERPNT.EXE"=
"C:\\Program Files\\microsoft office\\office11\\WINWORD.EXE"=
"C:\\Program Files\\Outlook Express\\msimn.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"80:TCP"= 80:TCP:@xpsp2res.dll,-22004

R0 avgrkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-10-28 12936]
R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 28544]
R0 sonyhcb;Sony Digital Imaging Base;C:\WINDOWS\system32\DRIVERS\sonyhcb.sys [2001-11-05 6097]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 avgldx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-10-29 98440]
R1 avgtdix;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-10-28 90632]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-28 231704]
R3 mgau;mgau;C:\WINDOWS\system32\DRIVERS\mgaum.sys [2001-08-23 320384]
R3 PALLADIA;Palladia 300/400 Usb Adsl Modem;C:\WINDOWS\system32\DRIVERS\usbiad.sys [2005-06-13 31579]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 sonyhcs;Sony Digital Imaging Video;C:\WINDOWS\system32\DRIVERS\sonyhcs.sys [2001-11-05 299923]
.
Contenu du dossier 'Tâches planifiées'

2008-10-30 C:\WINDOWS\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe []
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 18:36:23
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MysqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-nt MysqlInventime"
.
------------------------ Autres processus actifs ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Heure de fin: 2008-10-30 18:50:28 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-30 17:50:02
ComboFix2.txt 2008-10-30 08:05:42
ComboFix3.txt 2008-10-28 10:01:56

Avant-CF: 10 019 303 424 octets libres
Après-CF: 10,010,988,544 octets libres

699 --- E O F --- 2008-10-24 16:47:41
0
mibylag > mibylag
 
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt11160203
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt11160250
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt11160281
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt14170953
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt15044046
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt15899109
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt15899187
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt17328046
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt18184015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt18390015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt18884015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt20684015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt20860015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt21202000
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt23841140
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt2910328
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt30885218
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt3831593
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt433953
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\New York_NY_weather.txt8378812
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\new02.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\news.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\news.html
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\nn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\o.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\on.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\p.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\p_yahoo.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\p_yahoo_fr.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\pestscanimg.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\pixsy.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\pn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\popup_off.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\popup_on.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\popup_ona.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\q.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\qn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\r.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\relatedlinks.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\report.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\right.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rss.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rss.xsl
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rss1.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rsslib.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\rssmenu1_7a.zip
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\s.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\search.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\search_fr.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\security.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt10442828
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt11004687
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt12539468
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt13153312
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt132953
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1486265
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1497515
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt15171609
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1546937
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1555203
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1686625
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt172796
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt17310015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt18106765
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt184062
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt18836484
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt1909343
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt19769656
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt19930937
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt21597796
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt22799015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt25160875
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt2643687
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt27214921
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt29814453
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt310000
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt3120703
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt323890
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt341140
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt36856281
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt39784015
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt39987796
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt40853531
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt40972796
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt41608140
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt4359140
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt4407390
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt47194125
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt5225843
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt5393656
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt6013437
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt6014000
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt6197953
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt6513156
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt8293984
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt885781
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sinfo.txt9145250
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\siteinfo.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\slider.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\sn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\spacer.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\stars-red1.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\stars-red2.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\stars-red3.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\stars-red4.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\stars-red5.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\storage.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\t.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tab_icon.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tabdata.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tabdataV3.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tablib.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tabwelcome_en.html
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tabwelcome_fr.html
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\technorati.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\thes_search.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\tools.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\top.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\top_left.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\top_right.png
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\translate.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\u.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\un.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\utf8.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\v.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\vmlib.js
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\vmntoolbartb1501.cfg
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\vn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\w.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\web.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\web_fr.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\wikipedia.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\wn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\x.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\xp_close_small.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\yahoo.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\yahoo_search.gif
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\YouTube.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\z.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\zn.bmp
C:\Documents and Settings\BRENDAN\Application Data\vmntoolbar\zoom.bmp
0
mibylag > mibylag
 
C:\WINDOWS\system32\404Fix.exe
C:\WINDOWS\system32\AntiXPVSTFix.exe
C:\WINDOWS\system32\drivers\eef6c0ac.sys
C:\WINDOWS\system32\dumphive.exe
C:\WINDOWS\system32\fyglbdtfjrzxm.exe
C:\WINDOWS\system32\IEDFix.C.exe
C:\WINDOWS\system32\IEDFix.exe
C:\WINDOWS\system32\o4Patch.exe
C:\WINDOWS\system32\SrchSTS.exe
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\VACFix.exe
C:\WINDOWS\system32\VCCLSID.exe
C:\WINDOWS\system32\WS2Fix.exe

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NENUM13E
-------\Legacy_VIGSERVICE
-------\Service_nenum13E
-------\Service_VigService
-------\Service_eef6c0ac


((((((((((((((((((((((((((((( Fichiers créés du 2008-09-28 au 2008-10-30 ))))))))))))))))))))))))))))))))))))
.

2008-10-29 22:40 . 2008-10-30 08:43 <REP> d-------- C:\Lop SD
2008-10-29 20:36 . 2008-10-29 22:37 <REP> d-------- C:\Program Files\UsbFix
2008-10-29 09:16 . 2008-10-29 19:22 <REP> d-------- C:\Program Files\Navilog1
2008-10-28 21:43 . 2008-10-28 21:43 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-28 21:43 . 2008-10-28 21:43 <REP> d-------- C:\Documents and Settings\B. LAGOUTTE\Application Data\Malwarebytes
2008-10-28 21:43 . 2008-10-28 21:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-28 21:43 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-28 21:43 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-28 18:50 . 2005-03-17 07:34 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2008-10-28 18:50 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-10-28 18:50 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-10-28 18:50 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-10-28 18:50 . 2005-04-03 13:19 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-10-28 18:50 . 2005-03-17 07:46 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2008-10-28 18:50 . 2005-04-03 13:19 <REP> dr------- C:\Documents and Settings\Administrateur\Bureau
2008-10-28 18:50 . 2005-03-17 07:45 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\You've Got Pictures Screensaver
2008-10-28 18:50 . 2005-03-17 07:48 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2008-10-28 18:50 . 2005-03-17 08:00 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\AOL
2008-10-28 18:50 . 2008-10-28 18:50 <REP> d-------- C:\Documents and Settings\Administrateur
2008-10-28 13:20 . 2008-10-30 18:36 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
2008-10-28 13:20 . 2008-10-29 08:34 <REP> d-------- C:\Documents and Settings\B. LAGOUTTE\Application Data\AVGTOOLBAR
2008-10-28 13:20 . 2008-10-29 20:45 98,440 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-10-28 13:20 . 2008-10-28 13:20 90,632 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-10-28 13:20 . 2008-10-28 13:20 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-10-28 13:20 . 2008-10-28 13:20 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-10-27 19:06 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
2008-10-27 19:05 . 2008-10-27 19:05 <REP> d-------- C:\Program Files\Panda Security
2008-10-27 17:24 . 2008-10-27 17:34 <REP> d-------- C:\Program Files\Trend Micro
2008-10-27 16:29 . 2008-10-30 11:11 <REP> d--h----- C:\$AVG8.VAULT$
2008-10-27 16:25 . 2008-10-27 16:25 <REP> d-------- C:\Program Files\AVG
2008-10-27 16:25 . 2008-10-28 13:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-10-12 09:29 . 2008-10-12 09:29 <REP> d-------- C:\Documents and Settings\B. LAGOUTTE\Application Data\DWGEditor
2008-09-28 11:12 . 2008-09-28 11:51 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 10:29 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\uTorrent
2008-10-27 08:50 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\Real4new
2008-10-18 10:21 --------- d-----w C:\Program Files\NoteWorthy Composer
2008-10-12 14:16 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-10-12 10:06 --------- d-----w C:\Program Files\InterActual
2008-10-12 10:06 --------- d-----w C:\Program Files\Google
2008-10-12 09:44 --------- d-----w C:\Program Files\vghd
2008-10-12 09:25 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-12 09:25 --------- d-----w C:\Program Files\QuickTime
2008-10-12 09:25 --------- d-----w C:\Program Files\LimeWire
2008-10-12 09:25 --------- d-----w C:\Program Files\ganjasw
2008-10-12 09:24 --------- d-----w C:\Program Files\Motus
2008-10-12 09:24 --------- d-----w C:\Program Files\DivX
2008-10-12 08:41 --------- d-----w C:\Program Files\SolidWorks
2008-10-12 08:39 --------- d-----w C:\Program Files\Fichiers communs\Bluebeam Software
2008-10-12 08:30 --------- d-----w C:\Program Files\Zylom Games
2008-10-12 08:28 --------- d-----w C:\Program Files\GIMP-2.0
2008-10-12 08:24 --------- d-----w C:\Program Files\Neuf
2008-09-30 21:23 --------- d-----w C:\Documents and Settings\BRENDAN\Application Data\uTorrent
2008-09-30 16:51 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-09-24 18:09 3,532 ----a-w C:\drmHeader.bin
2008-09-22 11:46 --------- d-----w C:\Documents and Settings\BRENDAN\Application Data\AdobeUM
2008-09-14 17:29 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\dvdcss
2008-09-07 20:06 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-01 17:43 --------- d-----w C:\Documents and Settings\B. LAGOUTTE\Application Data\SolidWorks
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2005-08-02 14:20 109,384 -c--a-w C:\Documents and Settings\B. LAGOUTTE\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot@2008-10-28_10.59.57.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-27 15:26:52 26,824 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-10-28 12:20:24 26,824 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-10-30 17:33:27 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_73c.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-10-28 1235736]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-20 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
"vidc.xvid"= xvid.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\microsoft office\\office11\\EXCEL.EXE"=
"C:\\Program Files\\microsoft office\\office11\\POWERPNT.EXE"=
"C:\\Program Files\\microsoft office\\office11\\WINWORD.EXE"=
"C:\\Program Files\\Outlook Express\\msimn.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"80:TCP"= 80:TCP:@xpsp2res.dll,-22004

R0 avgrkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-10-28 12936]
R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 28544]
R0 sonyhcb;Sony Digital Imaging Base;C:\WINDOWS\system32\DRIVERS\sonyhcb.sys [2001-11-05 6097]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 avgldx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-10-29 98440]
R1 avgtdix;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-10-28 90632]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-28 231704]
R3 mgau;mgau;C:\WINDOWS\system32\DRIVERS\mgaum.sys [2001-08-23 320384]
R3 PALLADIA;Palladia 300/400 Usb Adsl Modem;C:\WINDOWS\system32\DRIVERS\usbiad.sys [2005-06-13 31579]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 sonyhcs;Sony Digital Imaging Video;C:\WINDOWS\system32\DRIVERS\sonyhcs.sys [2001-11-05 299923]
.
Contenu du dossier 'Tâches planifiées'

2008-10-30 C:\WINDOWS\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe []
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 18:36:23
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MysqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-nt MysqlInventime"
.
------------------------ Autres processus actifs ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Heure de fin: 2008-10-30 18:50:28 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-30 17:50:02
ComboFix2.txt 2008-10-30 08:05:42
ComboFix3.txt 2008-10-28 10:01:56

Avant-CF: 10 019 303 424 octets libres
Après-CF: 10,010,988,544 octets libres

699 --- E O F --- 2008-10-24 16:47:41
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
---> Télécharge Toolbar S&D (Team IDN) sur ton Bureau.
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
0
mibylag
 
je fais tout ça
désolé pour le post du rapport en 3 fois
0
mibylag
 
re, voici le rapport


-----------\\ ToolBar S&D 1.2.4 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : B. LAGOUTTE ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081030-0] 4.8.1229 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:105 Go (Free:9 Go)
D:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)

"C:\ToolBar SD" ( MAJ : 27-10-2008|09:25 )
Option : [1] ( 30/10/2008|19:42 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\VMNToolbar
C:\Program Files\VMNToolbar
C:\Program Files\VMNToolbar\install.ico
C:\Program Files\VMNToolbar\tbuninstall.exe
C:\Program Files\VMNToolbar\toolbar.ini
C:\Program Files\VMNToolbar\uninstall.exe
C:\Program Files\VMNToolbar\vmntoolbar.dll

-----------\\ Extensions

(BRENDAN) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(BRENDAN) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
(BRENDAN) - {77b819fa-95ad-4f2c-ac7c-486b356188a9} => ietab


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"First Home Page"="https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"


--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\BE3F5~1.LAG\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\crack.au-143c79f9-3758f902.au
C:\DOCUME~1\BE3F5~1.LAG\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\crack.au-143c79f9-3758f902.idx



1 - "C:\ToolBar SD\TB_1.txt" - 30/10/2008|19:45 - Option : [1]

-----------\\ Fin du rapport a 19:45:01,81
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Va dans Ajout/Suppression des programmes et désinstalle VMNToolbar.
0
mibylag
 
re,
dans "panneau de config/ajouter ou supprimer des programmes" je trouve pas vmntoollbar. Mais quand j'ai tapé le nom dans "rechercher" j'ai trouvé 6 documents avec ce nom : 2 dans C:\program files (1 dossier qui s'appelle vmntoolbar et 1 autre fichier vmntoolbar.dll --- les 4 autres sont dans C:\qoobox\quarantaine.....

Je fais quoi ?
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
---> Relance ToolBar S&D, fais l'option 2 et poste le rapport.
0
mibylag
 
le voilà


-----------\\ ToolBar S&D 1.2.4 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER :Nom supprimé Modération CCM ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081030-0] 4.8.1229 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:105 Go (Free:9 Go)
D:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)

"C:\ToolBar SD" ( MAJ : 27-10-2008|09:25 )
Option : [2] ( 30/10/2008|21:02 )

-----------\\ SUPPRESSION

Supprime! - C:\Program Files\VMNToolbar\install.ico
Supprime! - C:\Program Files\VMNToolbar\tbuninstall.exe
Supprime! - C:\Program Files\VMNToolbar\toolbar.ini
Supprime! - C:\Program Files\VMNToolbar\uninstall.exe
Supprime! - C:\Program Files\VMNToolbar\vmntoolbar.dll
Supprime! - C:\DOCUME~1\BE3F5~1.LAG\APPLIC~1\VMNToolbar
Supprime! - C:\Program Files\VMNToolbar

-----------\\ Recherche de Fichiers / Dossiers ...


-----------\\ Extensions

(BRENDAN) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(BRENDAN) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
(BRENDAN) - {77b819fa-95ad-4f2c-ac7c-486b356188a9} => ietab


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"First Home Page"="https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"


--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\BE3F5~1.LAG\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\crack.au-143c79f9-3758f902.au
C:\DOCUME~1\BE3F5~1.LAG\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\crack.au-143c79f9-3758f902.idx



1 - "C:\ToolBar SD\TB_1.txt" - 30/10/2008|19:45 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 30/10/2008|21:05 - Option : [2]

-----------\\ Fin du rapport a 21:05:57,07
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
---> Poste un nouveau rapport HijackThis.

Ton PC va mieux ?
0
mibylag
 
voici le rapport HijackThis

Mon ordi va mieux je te remercie vraiment !

Dois-je garder Combofix, Malwarebites', Panda activescan, LopSD, ToolbarSD ?
J'ai donc avast et tu m'as fait installer AVG, que j'aurais pendant 1 mois gratuitement, ensuite je garde Avast seul ou tu me recommandes de lui ajouter un deuxième antivirus ?


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:30:29, on 30/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {a057a204-bacc-4d26-9990-79a187e2698e} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - C:\Program Files\Ares\chatServer.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe (file missing)
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Il ne faut qu'un seul antivirus. Je te conseille AVG ou Antivir. Ils sont gratuits.

---> Mets à jour Java :
https://www.java.com/fr/download/manual.jsp

---> Supprime les traces de Norton avec ceci :
ftp://ftp.symantec.com/public/francais/removal_tools/Norton_Removal_Tool.exe

---> Poste un nouveau rapport HijackThis.
0
mibylag
 
norton remover ok, java installé !
voici le rapport HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:08:24, on 30/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {a057a204-bacc-4d26-9990-79a187e2698e} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - C:\Program Files\Ares\chatServer.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe (file missing)
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
0
mibylag
 
par contre l'ordi rame....
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Oui car tu as deux antivirus et il n'en faut qu'un.

Vire Avast.
0
mibylag
 
ça y est, c'est fait.
As-tu décelé un autre problème ?
Dois-je garder tous les logiciels que tu m'as demandé de télécharger (combifix, lopsd, toolbarSD, malwarebytes', norton remover) ?
En tout cas je te remercie vraiment de tout le temps que tu m'as accordé ; Merci et bravo pour ton travail, c'est agréable d'être aidé dans ces conditions.
0