Cid pop up

Fermé
louhna - 28 oct. 2008 à 11:15
geoffrey5 Messages postés 13732 Date d'inscription dimanche 20 mai 2007 Statut Contributeur sécurité Dernière intervention 21 mai 2010 - 28 oct. 2008 à 11:59
Bonjour, ce n'est pas la première fois que cela m'arrive mais la il persiste, depuis hier j'ai des fenêtres CID qui s'ouvrent mais le problème c'est que j'ai déjà enlevé le sponsor d'msn donc ça ne vient pas de ça donc j'aimerais avoir de l'aide svp merci
A voir également:

7 réponses

geoffrey5 Messages postés 13732 Date d'inscription dimanche 20 mai 2007 Statut Contributeur sécurité Dernière intervention 21 mai 2010 10
28 oct. 2008 à 11:16
Salut !!

▶ Télécharger et enregistrer lopSD sur le Bureau

(C est le numéro 4 en bas de la page)

▶ Double-clic Lop S&D

▶ Faire l'installation

▶ Fermer toutes les applications

▶ Le lancer par un double-clic sur le raccourci qui est sur le bureau
Avec VISTA => clic-droit et => Exécuter en tant qu'administrateur

▶ Taper F pour français , puis presser entrée

▶ Taper 1

▶ Presser Entrée

▶ Le PC va redémarrer
Note= si l'antivirus annonce une infection dans TEMP , l'ignorer

▶ Attendre l'apparition du rapport
▶ Copier le rapport et le coller dans la réponse
le rapport se trouve aussi à C:\lopR
0
oups dsl j'ai eu un bug
0
tiotjordan Messages postés 545 Date d'inscription lundi 1 septembre 2008 Statut Membre Dernière intervention 17 août 2013 230
28 oct. 2008 à 11:18
dans la google tollbar tu doit avoir a peut près au milieu de l'ecran " autoriser/bloquer les fenetres pop-up" ou (un nombre) bloqués"

si c'est ecrit "autoriser/bloquer ...", tu clique dessus

si c'est ecrit "(un nombre) bloqués, tu fait rien est dans ce cas la je c'est pas comment tu peut faire!!!
0
--------------------\\ Lop S&D 4.2.4-8 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Xp Pro Sp2 ( Administrator )
BOOT : Normal boot
Antivirus : Trend Micro PC-cillin Internet Security 2007 15.30.1234 (Not Activated)
Firewall : Trend Micro PC-cillin Internet Security 15 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:38 Go)
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 27-10-2008|09:15 )
Option : [1] ( 28/10/2008|11:21 )

--------------------\\ Listing des dossiers dans APPLIC~1

[06/08/2007|18:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[06/08/2007|18:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[20/07/2008|08:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Astar Games
[25/03/2008|14:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Awem
[11/07/2008|15:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFish
[28/10/2008|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
[20/01/2007|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[11/10/2008|06:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Christmasville
[21/01/2007|00:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[02/04/2008|10:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EscapeTheMuseum
[30/05/2008|19:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[09/11/2007|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[24/08/2008|15:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GameFiesta
[16/06/2008|18:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GameHouse
[25/09/2008|07:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii
[08/06/2008|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii Games
[29/11/2007|18:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[19/04/2008|16:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
[06/04/2008|13:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin Games
[01/03/2008|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[09/04/2007|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[24/07/2007|13:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Meridian93
[19/03/2007|11:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[19/04/2008|04:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[13/10/2008|16:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[29/02/2008|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\My Games
[14/09/2008|05:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MysteryChronicles
[02/04/2007|14:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\n7-89-o9-3r-4t-r9
[25/01/2008|05:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NeptunesAdve
[16/11/2007|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Media
[18/04/2008|09:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[22/10/2008|08:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[30/03/2008|06:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Realv1005
[21/08/2008|09:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Reflexivev1005
[03/06/2007|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[05/09/2007|16:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecretsOfOlympus
[11/08/2008|10:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Slapdash Games
[05/06/2008|17:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SpinTop Games
[28/04/2008|18:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SugarGames
[28/10/2008|10:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[04/04/2007|13:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TERMINAL Studio
[24/08/2008|06:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TheRace_dev
[08/05/2007|09:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
[11/02/2007|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[12/02/2007|22:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[20/01/2007|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[03/03/2008|06:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[02/04/2007|13:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[19/01/2007|18:18] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[19/01/2007|18:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[19/01/2007|18:22] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[06/03/2008|11:24] C:\DOCUME~1\XPPROS~1\APPLIC~1\Abra Academy2
[17/02/2008|05:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\Adobe
[05/09/2007|14:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\AlwaysNeat
[19/08/2007|16:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\Apple Computer
[27/08/2007|13:01] C:\DOCUME~1\XPPROS~1\APPLIC~1\Beep Industries
[24/01/2008|11:16] C:\DOCUME~1\XPPROS~1\APPLIC~1\Big Fish Games
[11/07/2008|15:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\BigFish
[28/01/2008|08:10] C:\DOCUME~1\XPPROS~1\APPLIC~1\BloodTies
[20/07/2008|07:56] C:\DOCUME~1\XPPROS~1\APPLIC~1\cerasus.media
[21/01/2007|00:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\CyberLink
[25/08/2008|20:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\DAEMON Tools
[22/05/2007|18:04] C:\DOCUME~1\XPPROS~1\APPLIC~1\EPSON
[22/01/2008|09:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\Flood Light Games
[09/11/2007|20:21] C:\DOCUME~1\XPPROS~1\APPLIC~1\FloodLightGames
[01/03/2008|19:07] C:\DOCUME~1\XPPROS~1\APPLIC~1\ForgottenRiddles
[29/07/2008|16:22] C:\DOCUME~1\XPPROS~1\APPLIC~1\ForgottenRiddles2
[27/03/2008|09:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\Friday's games
[09/05/2008|07:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Gaijin Ent
[24/08/2008|15:14] C:\DOCUME~1\XPPROS~1\APPLIC~1\GameFiesta
[25/10/2008|18:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\GameHouse
[08/06/2008|18:39] C:\DOCUME~1\XPPROS~1\APPLIC~1\Gogii Games
[14/08/2007|18:34] C:\DOCUME~1\XPPROS~1\APPLIC~1\Google
[15/02/2007|15:11] C:\DOCUME~1\XPPROS~1\APPLIC~1\Help
[07/07/2008|16:28] C:\DOCUME~1\XPPROS~1\APPLIC~1\Icone
[23/10/2008|06:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Identities
[19/01/2007|18:31] C:\DOCUME~1\XPPROS~1\APPLIC~1\InterTrust
[12/08/2008|08:03] C:\DOCUME~1\XPPROS~1\APPLIC~1\iWin
[06/04/2008|13:36] C:\DOCUME~1\XPPROS~1\APPLIC~1\iWinArcade
[07/10/2008|04:59] C:\DOCUME~1\XPPROS~1\APPLIC~1\JoyBits
[04/02/2008|10:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\Legends of pirates
[19/01/2008|17:05] C:\DOCUME~1\XPPROS~1\APPLIC~1\Macromedia
[18/09/2007|16:53] C:\DOCUME~1\XPPROS~1\APPLIC~1\Magic Academy
[24/07/2007|13:37] C:\DOCUME~1\XPPROS~1\APPLIC~1\Meridian93
[15/09/2008|09:55] C:\DOCUME~1\XPPROS~1\APPLIC~1\Microsoft
[21/07/2007|08:09] C:\DOCUME~1\XPPROS~1\APPLIC~1\MSNInstaller
[28/01/2008|14:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\My Games
[26/08/2008|07:16] C:\DOCUME~1\XPPROS~1\APPLIC~1\MysteryStudio
[15/01/2008|17:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\Mysteryville2
[28/01/2008|17:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\Pirateville
[18/04/2008|09:26] C:\DOCUME~1\XPPROS~1\APPLIC~1\PlayFirst
[21/09/2008|16:44] C:\DOCUME~1\XPPROS~1\APPLIC~1\Realv1005
[25/10/2008|18:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Righteous Kill
[18/03/2007|05:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\Screenshot Sender
[20/01/2007|18:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\SecuROM
[08/08/2007|09:48] C:\DOCUME~1\XPPROS~1\APPLIC~1\SpinTop
[18/09/2008|16:41] C:\DOCUME~1\XPPROS~1\APPLIC~1\SpinTop Games
[06/07/2008|15:52] C:\DOCUME~1\XPPROS~1\APPLIC~1\SprillBermudeEng
[18/02/2007|09:44] C:\DOCUME~1\XPPROS~1\APPLIC~1\Sun
[30/07/2008|14:41] C:\DOCUME~1\XPPROS~1\APPLIC~1\TheScruffs
[21/08/2008|09:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\TMInc
[14/11/2007|19:09] C:\DOCUME~1\XPPROS~1\APPLIC~1\URUSoft
[06/08/2007|18:28] C:\DOCUME~1\XPPROS~1\APPLIC~1\vlc
[23/10/2008|06:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Zylom

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[27/10/2008 21:00][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[28/10/2008 06:48][--ah-----] C:\WINDOWS\tasks\SA.DAT
[07/09/2002 01:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[19/01/2007|18:31] C:\Program Files\Adobe
[19/01/2007|18:30] C:\Program Files\Ahead
[26/08/2008|07:47] C:\Program Files\Alawar
[03/03/2007|06:51] C:\Program Files\Ancient Mosaic
[06/08/2007|18:17] C:\Program Files\Apple Software Update
[30/03/2007|09:38] C:\Program Files\BFG
[14/09/2008|04:44] C:\Program Files\bfgclient
[26/07/2008|10:01] C:\Program Files\Bookworm Adventures Deluxe
[28/08/2007|06:30] C:\Program Files\Boonty
[28/09/2008|11:07] C:\Program Files\BoontyGames
[19/01/2007|18:15] C:\Program Files\ComPlus Applications
[13/04/2007|09:44] C:\Program Files\Cradle Of Rome
[19/01/2007|18:29] C:\Program Files\CyberLink
[19/01/2007|18:29] C:\Program Files\CyberLink DVD Solution
[25/08/2008|20:44] C:\Program Files\DAEMON Tools Toolbar
[28/10/2008|06:51] C:\Program Files\eMule
[12/02/2007|22:11] C:\Program Files\epson
[22/08/2008|16:41] C:\Program Files\Fenomen Games Downloader
[14/11/2007|19:07] C:\Program Files\ffdshow
[29/03/2008|15:09] C:\Program Files\Fichiers communs
[09/08/2007|12:14] C:\Program Files\Fresco Wizard
[07/10/2008|19:56] C:\Program Files\GameFiesta
[26/10/2008|14:13] C:\Program Files\GameHouse
[08/10/2008|06:57] C:\Program Files\Gamenext
[05/09/2007|16:06] C:\Program Files\Games
[20/09/2008|10:48] C:\Program Files\GamesBar
[27/10/2008|21:07] C:\Program Files\Google
[12/06/2008|10:10] C:\Program Files\Hide and Secret 2 - Cliffhanger Castle
[11/08/2007|14:52] C:\Program Files\HipSoft
[04/09/2007|05:29] C:\Program Files\Holiday Express
[07/07/2008|16:30] C:\Program Files\Icone
[17/10/2008|18:36] C:\Program Files\InstallShield Installation Information
[15/10/2008|21:38] C:\Program Files\Internet Explorer
[06/04/2008|13:35] C:\Program Files\iWin Games
[01/09/2008|09:29] C:\Program Files\iWin.com
[17/07/2008|16:58] C:\Program Files\Java
[05/09/2007|16:19] C:\Program Files\Jewel Miner
[01/08/2007|13:40] C:\Program Files\Jewel Quest 2
[07/07/2008|16:30] C:\Program Files\LETMIN
[10/06/2008|10:45] C:\Program Files\M6 Jeux
[16/10/2007|17:56] C:\Program Files\Macrogaming
[06/07/2008|15:39] C:\Program Files\Magic Academy
[07/09/2007|07:09] C:\Program Files\MagicInlay_at
[14/08/2008|20:17] C:\Program Files\Messenger
[19/04/2008|16:52] C:\Program Files\Messenger Plus! Live
[19/01/2007|18:18] C:\Program Files\microsoft frontpage
[31/01/2007|20:35] C:\Program Files\Microsoft Office
[19/01/2007|18:35] C:\Program Files\Microsoft Visual Studio
[06/09/2008|09:31] C:\Program Files\Microsoft Works
[19/01/2007|18:36] C:\Program Files\Microsoft.NET
[08/09/2007|15:31] C:\Program Files\MirrorMagic_at
[19/01/2007|18:16] C:\Program Files\Movie Maker
[31/01/2007|20:35] C:\Program Files\MSECache
[21/07/2007|08:09] C:\Program Files\MSN
[19/01/2007|18:14] C:\Program Files\MSN Gaming Zone
[20/04/2007|18:47] C:\Program Files\Mysteries Of Horus
[24/10/2008|18:12] C:\Program Files\Mystery Case Files Madame Fate
[14/09/2008|04:58] C:\Program Files\Mystery Chronicles - Murder Among Friends
[02/12/2007|16:52] C:\Program Files\Mysteryville
[19/01/2007|18:16] C:\Program Files\NetMeeting
[26/10/2008|08:12] C:\Program Files\Oberon Media
[19/01/2007|18:15] C:\Program Files\Online Services
[19/10/2007|05:35] C:\Program Files\orange
[13/06/2007|20:44] C:\Program Files\Outlook Express
[25/11/2007|08:16] C:\Program Files\Puzzle Express
[25/11/2007|08:13] C:\Program Files\PuzzleInlay_at
[06/08/2007|18:18] C:\Program Files\QuickTime
[10/09/2007|08:05] C:\Program Files\RainbowWeb_at
[21/01/2007|14:56] C:\Program Files\Real
[17/02/2007|05:45] C:\Program Files\ReflexiveArcade
[17/10/2008|18:36] C:\Program Files\Rockstar Games
[24/03/2007|22:42] C:\Program Files\SAGEM
[19/01/2007|18:17] C:\Program Files\Services en ligne
[24/08/2007|06:45] C:\Program Files\Shockwave.com
[17/11/2007|07:43] C:\Program Files\Stone Of Destiny
[17/07/2008|16:58] C:\Program Files\Sun
[08/05/2007|09:19] C:\Program Files\Trend Micro
[22/08/2007|16:56] C:\Program Files\TryMedia
[19/01/2007|18:26] C:\Program Files\Uninstall Information
[14/11/2007|19:09] C:\Program Files\URUSoft
[25/10/2008|12:50] C:\Program Files\Valve
[14/04/2007|14:12] C:\Program Files\VIA
[14/04/2007|14:13] C:\Program Files\VIAudioi
[06/08/2007|18:27] C:\Program Files\VideoLAN
[03/03/2008|06:46] C:\Program Files\Windows Live
[18/12/2007|14:08] C:\Program Files\Windows Media Connect 2
[06/09/2008|17:26] C:\Program Files\Windows Media Player
[19/01/2007|18:14] C:\Program Files\Windows NT
[19/01/2007|18:17] C:\Program Files\WindowsUpdate
[06/09/2008|16:12] C:\Program Files\WinRAR
[19/01/2007|18:18] C:\Program Files\xerox
[22/08/2007|16:55] C:\Program Files\Yahoo! Games
[23/10/2008|07:54] C:\Program Files\Zylom Games

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[21/01/2007|06:27] C:\Program Files\Fichiers communs\Adobe
[19/01/2007|18:30] C:\Program Files\Fichiers communs\Ahead
[20/01/2007|18:30] C:\Program Files\Fichiers communs\BOONTY Shared
[19/01/2007|18:35] C:\Program Files\Fichiers communs\DESIGNER
[12/02/2007|22:13] C:\Program Files\Fichiers communs\InstallShield
[18/02/2007|09:42] C:\Program Files\Fichiers communs\Java
[13/06/2008|02:04] C:\Program Files\Fichiers communs\Microsoft Shared
[19/01/2007|18:16] C:\Program Files\Fichiers communs\MSSoap
[21/10/2008|09:23] C:\Program Files\Fichiers communs\Oberon Media
[19/01/2007|19:07] C:\Program Files\Fichiers communs\ODBC
[20/01/2007|19:20] C:\Program Files\Fichiers communs\Real
[19/01/2007|18:16] C:\Program Files\Fichiers communs\Services
[19/01/2007|19:07] C:\Program Files\Fichiers communs\SpeechEngines
[13/06/2007|20:44] C:\Program Files\Fichiers communs\System
[21/01/2007|16:03] C:\Program Files\Fichiers communs\Vivicam3695
[03/03/2008|06:47] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 45 Processes )

iexplore.exe ~ [PID:2536]
iexplore.exe ~ [PID:2492]

--------------------\\ Recherche avec S_Lop

C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\bis3B.exe

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default\Tons logo.exe
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsb2C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsc28.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsc3F.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsd51.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nse45.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nse4A.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsf3.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsg16.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsh99.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsi3D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsisdt.dll
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsj3C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsk25.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsk7.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsn1F.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsn91.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsq1C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nst4D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsv24.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsw3D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsy5E.tmp
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adultfriendfinder[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@advertising[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adin.bigpoint[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.seafight.bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.thepimps.bigpoint[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@banner.casinoking[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@casinoking[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adopt.euroclick[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@partygaming.122.2o7[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@partypoker[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.seafight.bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@888[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@888[2].txt

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Love default global mess"="C:\\Documents and Settings\\All Users\\Application Data\\great coal love default\\Tons logo.exe"

--------------------\\ Verification du fichier Hosts

Fichier Hosts MODIFIE

127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD

-> 72 [ 70 ## added by CiD ]

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 11:24:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 7

--------------------\\ Recherche d'autres infections

C:\WINDOWS\system32\nnVxayxx.ini
C:\WINDOWS\system32\nnVxayxx.ini2
C:\WINDOWS\system32\xxyaxVnn.dll
[b]==> VUNDO <==/b

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\XPPROS~1\Local Settings\Temp\110079234\ghost_hunter\data\audio\efx\lightning_crack.ogg
C:\DOCUME~1\XPPROS~1\Local Settings\Temp\110456968\ghost_hunter\data\audio\efx\lightning_crack.ogg
C:\DOCUME~1\XPPROS~1\Local Settings\Temporary Internet Files\Content.IE5\PDIFTQME\keyGen[1].htm
C:\DOCUME~1\XPPROS~1\Local Settings\Temporary Internet Files\Content.IE5\R62U4EFG\keyGen[1].htm
C:\DOCUME~1\XPPROS~1\Recent\Keygen counter strike source (cle cd)Steam counter strike source.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 + Internet Explorer 7 + Crack.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Fr Crack‚ (2).lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Fr Crack‚.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Francais pour Windows version Crack‚.lnk
C:\DOCUME~1\XPPROS~1\Recent\Wmp11 Fr Crack Windows Media Player 11 Windows Xp.lnk
C:\DOCUME~1\XPPROS~1\Recent\[PC GAME MULTI] - Gran Theft Auto San Andreas + Crack NoCD - (Perfect DVD Version) - (Eng-Ita-Deu-Fra-Esp) - (By GTA Squall89).lnk


[F:26037][D:642]-> C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp
[F:156][D:0]-> C:\DOCUME~1\XPPROS~1\Cookies
[F:3404][D:8]-> C:\DOCUME~1\XPPROS~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 28/10/2008|11:29 - Option : [1]

--------------------\\ Fin du rapport a 11:29:17
0
--------------------\\ Lop S&D 4.2.4-8 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Xp Pro Sp2 ( Administrator )
BOOT : Normal boot
Antivirus : Trend Micro PC-cillin Internet Security 2007 15.30.1234 (Not Activated)
Firewall : Trend Micro PC-cillin Internet Security 15 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:38 Go)
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 27-10-2008|09:15 )
Option : [1] ( 28/10/2008|11:21 )

--------------------\\ Listing des dossiers dans APPLIC~1

[06/08/2007|18:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[06/08/2007|18:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[20/07/2008|08:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Astar Games
[25/03/2008|14:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Awem
[11/07/2008|15:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFish
[28/10/2008|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
[20/01/2007|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[11/10/2008|06:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Christmasville
[21/01/2007|00:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[02/04/2008|10:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EscapeTheMuseum
[30/05/2008|19:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[09/11/2007|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[24/08/2008|15:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GameFiesta
[16/06/2008|18:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GameHouse
[25/09/2008|07:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii
[08/06/2008|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii Games
[29/11/2007|18:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[19/04/2008|16:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
[06/04/2008|13:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin Games
[01/03/2008|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[09/04/2007|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[24/07/2007|13:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Meridian93
[19/03/2007|11:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[19/04/2008|04:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[13/10/2008|16:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[29/02/2008|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\My Games
[14/09/2008|05:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MysteryChronicles
[02/04/2007|14:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\n7-89-o9-3r-4t-r9
[25/01/2008|05:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NeptunesAdve
[16/11/2007|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Media
[18/04/2008|09:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[22/10/2008|08:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[30/03/2008|06:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Realv1005
[21/08/2008|09:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Reflexivev1005
[03/06/2007|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[05/09/2007|16:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecretsOfOlympus
[11/08/2008|10:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Slapdash Games
[05/06/2008|17:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SpinTop Games
[28/04/2008|18:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SugarGames
[28/10/2008|10:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[04/04/2007|13:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TERMINAL Studio
[24/08/2008|06:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TheRace_dev
[08/05/2007|09:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
[11/02/2007|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[12/02/2007|22:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[20/01/2007|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[03/03/2008|06:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[02/04/2007|13:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[19/01/2007|18:18] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[19/01/2007|18:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[19/01/2007|18:22] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[06/03/2008|11:24] C:\DOCUME~1\XPPROS~1\APPLIC~1\Abra Academy2
[17/02/2008|05:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\Adobe
[05/09/2007|14:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\AlwaysNeat
[19/08/2007|16:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\Apple Computer
[27/08/2007|13:01] C:\DOCUME~1\XPPROS~1\APPLIC~1\Beep Industries
[24/01/2008|11:16] C:\DOCUME~1\XPPROS~1\APPLIC~1\Big Fish Games
[11/07/2008|15:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\BigFish
[28/01/2008|08:10] C:\DOCUME~1\XPPROS~1\APPLIC~1\BloodTies
[20/07/2008|07:56] C:\DOCUME~1\XPPROS~1\APPLIC~1\cerasus.media
[21/01/2007|00:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\CyberLink
[25/08/2008|20:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\DAEMON Tools
[22/05/2007|18:04] C:\DOCUME~1\XPPROS~1\APPLIC~1\EPSON
[22/01/2008|09:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\Flood Light Games
[09/11/2007|20:21] C:\DOCUME~1\XPPROS~1\APPLIC~1\FloodLightGames
[01/03/2008|19:07] C:\DOCUME~1\XPPROS~1\APPLIC~1\ForgottenRiddles
[29/07/2008|16:22] C:\DOCUME~1\XPPROS~1\APPLIC~1\ForgottenRiddles2
[27/03/2008|09:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\Friday's games
[09/05/2008|07:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Gaijin Ent
[24/08/2008|15:14] C:\DOCUME~1\XPPROS~1\APPLIC~1\GameFiesta
[25/10/2008|18:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\GameHouse
[08/06/2008|18:39] C:\DOCUME~1\XPPROS~1\APPLIC~1\Gogii Games
[14/08/2007|18:34] C:\DOCUME~1\XPPROS~1\APPLIC~1\Google
[15/02/2007|15:11] C:\DOCUME~1\XPPROS~1\APPLIC~1\Help
[07/07/2008|16:28] C:\DOCUME~1\XPPROS~1\APPLIC~1\Icone
[23/10/2008|06:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Identities
[19/01/2007|18:31] C:\DOCUME~1\XPPROS~1\APPLIC~1\InterTrust
[12/08/2008|08:03] C:\DOCUME~1\XPPROS~1\APPLIC~1\iWin
[06/04/2008|13:36] C:\DOCUME~1\XPPROS~1\APPLIC~1\iWinArcade
[07/10/2008|04:59] C:\DOCUME~1\XPPROS~1\APPLIC~1\JoyBits
[04/02/2008|10:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\Legends of pirates
[19/01/2008|17:05] C:\DOCUME~1\XPPROS~1\APPLIC~1\Macromedia
[18/09/2007|16:53] C:\DOCUME~1\XPPROS~1\APPLIC~1\Magic Academy
[24/07/2007|13:37] C:\DOCUME~1\XPPROS~1\APPLIC~1\Meridian93
[15/09/2008|09:55] C:\DOCUME~1\XPPROS~1\APPLIC~1\Microsoft
[21/07/2007|08:09] C:\DOCUME~1\XPPROS~1\APPLIC~1\MSNInstaller
[28/01/2008|14:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\My Games
[26/08/2008|07:16] C:\DOCUME~1\XPPROS~1\APPLIC~1\MysteryStudio
[15/01/2008|17:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\Mysteryville2
[28/01/2008|17:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\Pirateville
[18/04/2008|09:26] C:\DOCUME~1\XPPROS~1\APPLIC~1\PlayFirst
[21/09/2008|16:44] C:\DOCUME~1\XPPROS~1\APPLIC~1\Realv1005
[25/10/2008|18:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Righteous Kill
[18/03/2007|05:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\Screenshot Sender
[20/01/2007|18:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\SecuROM
[08/08/2007|09:48] C:\DOCUME~1\XPPROS~1\APPLIC~1\SpinTop
[18/09/2008|16:41] C:\DOCUME~1\XPPROS~1\APPLIC~1\SpinTop Games
[06/07/2008|15:52] C:\DOCUME~1\XPPROS~1\APPLIC~1\SprillBermudeEng
[18/02/2007|09:44] C:\DOCUME~1\XPPROS~1\APPLIC~1\Sun
[30/07/2008|14:41] C:\DOCUME~1\XPPROS~1\APPLIC~1\TheScruffs
[21/08/2008|09:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\TMInc
[14/11/2007|19:09] C:\DOCUME~1\XPPROS~1\APPLIC~1\URUSoft
[06/08/2007|18:28] C:\DOCUME~1\XPPROS~1\APPLIC~1\vlc
[23/10/2008|06:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Zylom

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[27/10/2008 21:00][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[28/10/2008 06:48][--ah-----] C:\WINDOWS\tasks\SA.DAT
[07/09/2002 01:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[19/01/2007|18:31] C:\Program Files\Adobe
[19/01/2007|18:30] C:\Program Files\Ahead
[26/08/2008|07:47] C:\Program Files\Alawar
[03/03/2007|06:51] C:\Program Files\Ancient Mosaic
[06/08/2007|18:17] C:\Program Files\Apple Software Update
[30/03/2007|09:38] C:\Program Files\BFG
[14/09/2008|04:44] C:\Program Files\bfgclient
[26/07/2008|10:01] C:\Program Files\Bookworm Adventures Deluxe
[28/08/2007|06:30] C:\Program Files\Boonty
[28/09/2008|11:07] C:\Program Files\BoontyGames
[19/01/2007|18:15] C:\Program Files\ComPlus Applications
[13/04/2007|09:44] C:\Program Files\Cradle Of Rome
[19/01/2007|18:29] C:\Program Files\CyberLink
[19/01/2007|18:29] C:\Program Files\CyberLink DVD Solution
[25/08/2008|20:44] C:\Program Files\DAEMON Tools Toolbar
[28/10/2008|06:51] C:\Program Files\eMule
[12/02/2007|22:11] C:\Program Files\epson
[22/08/2008|16:41] C:\Program Files\Fenomen Games Downloader
[14/11/2007|19:07] C:\Program Files\ffdshow
[29/03/2008|15:09] C:\Program Files\Fichiers communs
[09/08/2007|12:14] C:\Program Files\Fresco Wizard
[07/10/2008|19:56] C:\Program Files\GameFiesta
[26/10/2008|14:13] C:\Program Files\GameHouse
[08/10/2008|06:57] C:\Program Files\Gamenext
[05/09/2007|16:06] C:\Program Files\Games
[20/09/2008|10:48] C:\Program Files\GamesBar
[27/10/2008|21:07] C:\Program Files\Google
[12/06/2008|10:10] C:\Program Files\Hide and Secret 2 - Cliffhanger Castle
[11/08/2007|14:52] C:\Program Files\HipSoft
[04/09/2007|05:29] C:\Program Files\Holiday Express
[07/07/2008|16:30] C:\Program Files\Icone
[17/10/2008|18:36] C:\Program Files\InstallShield Installation Information
[15/10/2008|21:38] C:\Program Files\Internet Explorer
[06/04/2008|13:35] C:\Program Files\iWin Games
[01/09/2008|09:29] C:\Program Files\iWin.com
[17/07/2008|16:58] C:\Program Files\Java
[05/09/2007|16:19] C:\Program Files\Jewel Miner
[01/08/2007|13:40] C:\Program Files\Jewel Quest 2
[07/07/2008|16:30] C:\Program Files\LETMIN
[10/06/2008|10:45] C:\Program Files\M6 Jeux
[16/10/2007|17:56] C:\Program Files\Macrogaming
[06/07/2008|15:39] C:\Program Files\Magic Academy
[07/09/2007|07:09] C:\Program Files\MagicInlay_at
[14/08/2008|20:17] C:\Program Files\Messenger
[19/04/2008|16:52] C:\Program Files\Messenger Plus! Live
[19/01/2007|18:18] C:\Program Files\microsoft frontpage
[31/01/2007|20:35] C:\Program Files\Microsoft Office
[19/01/2007|18:35] C:\Program Files\Microsoft Visual Studio
[06/09/2008|09:31] C:\Program Files\Microsoft Works
[19/01/2007|18:36] C:\Program Files\Microsoft.NET
[08/09/2007|15:31] C:\Program Files\MirrorMagic_at
[19/01/2007|18:16] C:\Program Files\Movie Maker
[31/01/2007|20:35] C:\Program Files\MSECache
[21/07/2007|08:09] C:\Program Files\MSN
[19/01/2007|18:14] C:\Program Files\MSN Gaming Zone
[20/04/2007|18:47] C:\Program Files\Mysteries Of Horus
[24/10/2008|18:12] C:\Program Files\Mystery Case Files Madame Fate
[14/09/2008|04:58] C:\Program Files\Mystery Chronicles - Murder Among Friends
[02/12/2007|16:52] C:\Program Files\Mysteryville
[19/01/2007|18:16] C:\Program Files\NetMeeting
[26/10/2008|08:12] C:\Program Files\Oberon Media
[19/01/2007|18:15] C:\Program Files\Online Services
[19/10/2007|05:35] C:\Program Files\orange
[13/06/2007|20:44] C:\Program Files\Outlook Express
[25/11/2007|08:16] C:\Program Files\Puzzle Express
[25/11/2007|08:13] C:\Program Files\PuzzleInlay_at
[06/08/2007|18:18] C:\Program Files\QuickTime
[10/09/2007|08:05] C:\Program Files\RainbowWeb_at
[21/01/2007|14:56] C:\Program Files\Real
[17/02/2007|05:45] C:\Program Files\ReflexiveArcade
[17/10/2008|18:36] C:\Program Files\Rockstar Games
[24/03/2007|22:42] C:\Program Files\SAGEM
[19/01/2007|18:17] C:\Program Files\Services en ligne
[24/08/2007|06:45] C:\Program Files\Shockwave.com
[17/11/2007|07:43] C:\Program Files\Stone Of Destiny
[17/07/2008|16:58] C:\Program Files\Sun
[08/05/2007|09:19] C:\Program Files\Trend Micro
[22/08/2007|16:56] C:\Program Files\TryMedia
[19/01/2007|18:26] C:\Program Files\Uninstall Information
[14/11/2007|19:09] C:\Program Files\URUSoft
[25/10/2008|12:50] C:\Program Files\Valve
[14/04/2007|14:12] C:\Program Files\VIA
[14/04/2007|14:13] C:\Program Files\VIAudioi
[06/08/2007|18:27] C:\Program Files\VideoLAN
[03/03/2008|06:46] C:\Program Files\Windows Live
[18/12/2007|14:08] C:\Program Files\Windows Media Connect 2
[06/09/2008|17:26] C:\Program Files\Windows Media Player
[19/01/2007|18:14] C:\Program Files\Windows NT
[19/01/2007|18:17] C:\Program Files\WindowsUpdate
[06/09/2008|16:12] C:\Program Files\WinRAR
[19/01/2007|18:18] C:\Program Files\xerox
[22/08/2007|16:55] C:\Program Files\Yahoo! Games
[23/10/2008|07:54] C:\Program Files\Zylom Games

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[21/01/2007|06:27] C:\Program Files\Fichiers communs\Adobe
[19/01/2007|18:30] C:\Program Files\Fichiers communs\Ahead
[20/01/2007|18:30] C:\Program Files\Fichiers communs\BOONTY Shared
[19/01/2007|18:35] C:\Program Files\Fichiers communs\DESIGNER
[12/02/2007|22:13] C:\Program Files\Fichiers communs\InstallShield
[18/02/2007|09:42] C:\Program Files\Fichiers communs\Java
[13/06/2008|02:04] C:\Program Files\Fichiers communs\Microsoft Shared
[19/01/2007|18:16] C:\Program Files\Fichiers communs\MSSoap
[21/10/2008|09:23] C:\Program Files\Fichiers communs\Oberon Media
[19/01/2007|19:07] C:\Program Files\Fichiers communs\ODBC
[20/01/2007|19:20] C:\Program Files\Fichiers communs\Real
[19/01/2007|18:16] C:\Program Files\Fichiers communs\Services
[19/01/2007|19:07] C:\Program Files\Fichiers communs\SpeechEngines
[13/06/2007|20:44] C:\Program Files\Fichiers communs\System
[21/01/2007|16:03] C:\Program Files\Fichiers communs\Vivicam3695
[03/03/2008|06:47] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 45 Processes )

iexplore.exe ~ [PID:2536]
iexplore.exe ~ [PID:2492]

--------------------\\ Recherche avec S_Lop

C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\bis3B.exe

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default\Tons logo.exe
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsb2C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsc28.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsc3F.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsd51.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nse45.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nse4A.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsf3.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsg16.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsh99.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsi3D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsisdt.dll
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsj3C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsk25.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsk7.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsn1F.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsn91.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsq1C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nst4D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsv24.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsw3D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsy5E.tmp
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adultfriendfinder[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@advertising[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adin.bigpoint[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.seafight.bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.thepimps.bigpoint[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@banner.casinoking[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@casinoking[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adopt.euroclick[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@partygaming.122.2o7[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@partypoker[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.seafight.bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@888[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@888[2].txt

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Love default global mess"="C:\\Documents and Settings\\All Users\\Application Data\\great coal love default\\Tons logo.exe"

--------------------\\ Verification du fichier Hosts

Fichier Hosts MODIFIE

127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD

-> 72 [ 70 ## added by CiD ]

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 11:24:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 7

--------------------\\ Recherche d'autres infections

C:\WINDOWS\system32\nnVxayxx.ini
C:\WINDOWS\system32\nnVxayxx.ini2
C:\WINDOWS\system32\xxyaxVnn.dll
[b]==> VUNDO <==/b

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\XPPROS~1\Local Settings\Temp\110079234\ghost_hunter\data\audio\efx\lightning_crack.ogg
C:\DOCUME~1\XPPROS~1\Local Settings\Temp\110456968\ghost_hunter\data\audio\efx\lightning_crack.ogg
C:\DOCUME~1\XPPROS~1\Local Settings\Temporary Internet Files\Content.IE5\PDIFTQME\keyGen[1].htm
C:\DOCUME~1\XPPROS~1\Local Settings\Temporary Internet Files\Content.IE5\R62U4EFG\keyGen[1].htm
C:\DOCUME~1\XPPROS~1\Recent\Keygen counter strike source (cle cd)Steam counter strike source.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 + Internet Explorer 7 + Crack.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Fr Crack‚ (2).lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Fr Crack‚.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Francais pour Windows version Crack‚.lnk
C:\DOCUME~1\XPPROS~1\Recent\Wmp11 Fr Crack Windows Media Player 11 Windows Xp.lnk
C:\DOCUME~1\XPPROS~1\Recent\[PC GAME MULTI] - Gran Theft Auto San Andreas + Crack NoCD - (Perfect DVD Version) - (Eng-Ita-Deu-Fra-Esp) - (By GTA Squall89).lnk


[F:26037][D:642]-> C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp
[F:156][D:0]-> C:\DOCUME~1\XPPROS~1\Cookies
[F:3404][D:8]-> C:\DOCUME~1\XPPROS~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 28/10/2008|11:29 - Option : [1]

--------------------\\ Fin du rapport a 11:29:17
0
--------------------\\ Lop S&D 4.2.4-8 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Xp Pro Sp2 ( Administrator )
BOOT : Normal boot
Antivirus : Trend Micro PC-cillin Internet Security 2007 15.30.1234 (Not Activated)
Firewall : Trend Micro PC-cillin Internet Security 15 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:38 Go)
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 27-10-2008|09:15 )
Option : [1] ( 28/10/2008|11:21 )

--------------------\\ Listing des dossiers dans APPLIC~1

[06/08/2007|18:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[06/08/2007|18:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[20/07/2008|08:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Astar Games
[25/03/2008|14:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Awem
[11/07/2008|15:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFish
[28/10/2008|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
[20/01/2007|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[11/10/2008|06:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Christmasville
[21/01/2007|00:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[02/04/2008|10:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EscapeTheMuseum
[30/05/2008|19:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[09/11/2007|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[24/08/2008|15:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GameFiesta
[16/06/2008|18:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GameHouse
[25/09/2008|07:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii
[08/06/2008|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii Games
[29/11/2007|18:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[19/04/2008|16:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
[06/04/2008|13:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin Games
[01/03/2008|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[09/04/2007|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[24/07/2007|13:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Meridian93
[19/03/2007|11:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[19/04/2008|04:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[13/10/2008|16:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[29/02/2008|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\My Games
[14/09/2008|05:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MysteryChronicles
[02/04/2007|14:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\n7-89-o9-3r-4t-r9
[25/01/2008|05:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NeptunesAdve
[16/11/2007|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Media
[18/04/2008|09:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[22/10/2008|08:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[30/03/2008|06:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Realv1005
[21/08/2008|09:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Reflexivev1005
[03/06/2007|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[05/09/2007|16:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecretsOfOlympus
[11/08/2008|10:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Slapdash Games
[05/06/2008|17:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SpinTop Games
[28/04/2008|18:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SugarGames
[28/10/2008|10:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[04/04/2007|13:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TERMINAL Studio
[24/08/2008|06:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TheRace_dev
[08/05/2007|09:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
[11/02/2007|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[12/02/2007|22:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[20/01/2007|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[03/03/2008|06:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[02/04/2007|13:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[19/01/2007|18:18] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[19/01/2007|18:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[19/01/2007|18:22] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[06/03/2008|11:24] C:\DOCUME~1\XPPROS~1\APPLIC~1\Abra Academy2
[17/02/2008|05:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\Adobe
[05/09/2007|14:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\AlwaysNeat
[19/08/2007|16:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\Apple Computer
[27/08/2007|13:01] C:\DOCUME~1\XPPROS~1\APPLIC~1\Beep Industries
[24/01/2008|11:16] C:\DOCUME~1\XPPROS~1\APPLIC~1\Big Fish Games
[11/07/2008|15:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\BigFish
[28/01/2008|08:10] C:\DOCUME~1\XPPROS~1\APPLIC~1\BloodTies
[20/07/2008|07:56] C:\DOCUME~1\XPPROS~1\APPLIC~1\cerasus.media
[21/01/2007|00:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\CyberLink
[25/08/2008|20:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\DAEMON Tools
[22/05/2007|18:04] C:\DOCUME~1\XPPROS~1\APPLIC~1\EPSON
[22/01/2008|09:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\Flood Light Games
[09/11/2007|20:21] C:\DOCUME~1\XPPROS~1\APPLIC~1\FloodLightGames
[01/03/2008|19:07] C:\DOCUME~1\XPPROS~1\APPLIC~1\ForgottenRiddles
[29/07/2008|16:22] C:\DOCUME~1\XPPROS~1\APPLIC~1\ForgottenRiddles2
[27/03/2008|09:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\Friday's games
[09/05/2008|07:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Gaijin Ent
[24/08/2008|15:14] C:\DOCUME~1\XPPROS~1\APPLIC~1\GameFiesta
[25/10/2008|18:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\GameHouse
[08/06/2008|18:39] C:\DOCUME~1\XPPROS~1\APPLIC~1\Gogii Games
[14/08/2007|18:34] C:\DOCUME~1\XPPROS~1\APPLIC~1\Google
[15/02/2007|15:11] C:\DOCUME~1\XPPROS~1\APPLIC~1\Help
[07/07/2008|16:28] C:\DOCUME~1\XPPROS~1\APPLIC~1\Icone
[23/10/2008|06:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Identities
[19/01/2007|18:31] C:\DOCUME~1\XPPROS~1\APPLIC~1\InterTrust
[12/08/2008|08:03] C:\DOCUME~1\XPPROS~1\APPLIC~1\iWin
[06/04/2008|13:36] C:\DOCUME~1\XPPROS~1\APPLIC~1\iWinArcade
[07/10/2008|04:59] C:\DOCUME~1\XPPROS~1\APPLIC~1\JoyBits
[04/02/2008|10:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\Legends of pirates
[19/01/2008|17:05] C:\DOCUME~1\XPPROS~1\APPLIC~1\Macromedia
[18/09/2007|16:53] C:\DOCUME~1\XPPROS~1\APPLIC~1\Magic Academy
[24/07/2007|13:37] C:\DOCUME~1\XPPROS~1\APPLIC~1\Meridian93
[15/09/2008|09:55] C:\DOCUME~1\XPPROS~1\APPLIC~1\Microsoft
[21/07/2007|08:09] C:\DOCUME~1\XPPROS~1\APPLIC~1\MSNInstaller
[28/01/2008|14:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\My Games
[26/08/2008|07:16] C:\DOCUME~1\XPPROS~1\APPLIC~1\MysteryStudio
[15/01/2008|17:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\Mysteryville2
[28/01/2008|17:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\Pirateville
[18/04/2008|09:26] C:\DOCUME~1\XPPROS~1\APPLIC~1\PlayFirst
[21/09/2008|16:44] C:\DOCUME~1\XPPROS~1\APPLIC~1\Realv1005
[25/10/2008|18:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Righteous Kill
[18/03/2007|05:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\Screenshot Sender
[20/01/2007|18:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\SecuROM
[08/08/2007|09:48] C:\DOCUME~1\XPPROS~1\APPLIC~1\SpinTop
[18/09/2008|16:41] C:\DOCUME~1\XPPROS~1\APPLIC~1\SpinTop Games
[06/07/2008|15:52] C:\DOCUME~1\XPPROS~1\APPLIC~1\SprillBermudeEng
[18/02/2007|09:44] C:\DOCUME~1\XPPROS~1\APPLIC~1\Sun
[30/07/2008|14:41] C:\DOCUME~1\XPPROS~1\APPLIC~1\TheScruffs
[21/08/2008|09:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\TMInc
[14/11/2007|19:09] C:\DOCUME~1\XPPROS~1\APPLIC~1\URUSoft
[06/08/2007|18:28] C:\DOCUME~1\XPPROS~1\APPLIC~1\vlc
[23/10/2008|06:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Zylom

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[27/10/2008 21:00][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[28/10/2008 06:48][--ah-----] C:\WINDOWS\tasks\SA.DAT
[07/09/2002 01:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[19/01/2007|18:31] C:\Program Files\Adobe
[19/01/2007|18:30] C:\Program Files\Ahead
[26/08/2008|07:47] C:\Program Files\Alawar
[03/03/2007|06:51] C:\Program Files\Ancient Mosaic
[06/08/2007|18:17] C:\Program Files\Apple Software Update
[30/03/2007|09:38] C:\Program Files\BFG
[14/09/2008|04:44] C:\Program Files\bfgclient
[26/07/2008|10:01] C:\Program Files\Bookworm Adventures Deluxe
[28/08/2007|06:30] C:\Program Files\Boonty
[28/09/2008|11:07] C:\Program Files\BoontyGames
[19/01/2007|18:15] C:\Program Files\ComPlus Applications
[13/04/2007|09:44] C:\Program Files\Cradle Of Rome
[19/01/2007|18:29] C:\Program Files\CyberLink
[19/01/2007|18:29] C:\Program Files\CyberLink DVD Solution
[25/08/2008|20:44] C:\Program Files\DAEMON Tools Toolbar
[28/10/2008|06:51] C:\Program Files\eMule
[12/02/2007|22:11] C:\Program Files\epson
[22/08/2008|16:41] C:\Program Files\Fenomen Games Downloader
[14/11/2007|19:07] C:\Program Files\ffdshow
[29/03/2008|15:09] C:\Program Files\Fichiers communs
[09/08/2007|12:14] C:\Program Files\Fresco Wizard
[07/10/2008|19:56] C:\Program Files\GameFiesta
[26/10/2008|14:13] C:\Program Files\GameHouse
[08/10/2008|06:57] C:\Program Files\Gamenext
[05/09/2007|16:06] C:\Program Files\Games
[20/09/2008|10:48] C:\Program Files\GamesBar
[27/10/2008|21:07] C:\Program Files\Google
[12/06/2008|10:10] C:\Program Files\Hide and Secret 2 - Cliffhanger Castle
[11/08/2007|14:52] C:\Program Files\HipSoft
[04/09/2007|05:29] C:\Program Files\Holiday Express
[07/07/2008|16:30] C:\Program Files\Icone
[17/10/2008|18:36] C:\Program Files\InstallShield Installation Information
[15/10/2008|21:38] C:\Program Files\Internet Explorer
[06/04/2008|13:35] C:\Program Files\iWin Games
[01/09/2008|09:29] C:\Program Files\iWin.com
[17/07/2008|16:58] C:\Program Files\Java
[05/09/2007|16:19] C:\Program Files\Jewel Miner
[01/08/2007|13:40] C:\Program Files\Jewel Quest 2
[07/07/2008|16:30] C:\Program Files\LETMIN
[10/06/2008|10:45] C:\Program Files\M6 Jeux
[16/10/2007|17:56] C:\Program Files\Macrogaming
[06/07/2008|15:39] C:\Program Files\Magic Academy
[07/09/2007|07:09] C:\Program Files\MagicInlay_at
[14/08/2008|20:17] C:\Program Files\Messenger
[19/04/2008|16:52] C:\Program Files\Messenger Plus! Live
[19/01/2007|18:18] C:\Program Files\microsoft frontpage
[31/01/2007|20:35] C:\Program Files\Microsoft Office
[19/01/2007|18:35] C:\Program Files\Microsoft Visual Studio
[06/09/2008|09:31] C:\Program Files\Microsoft Works
[19/01/2007|18:36] C:\Program Files\Microsoft.NET
[08/09/2007|15:31] C:\Program Files\MirrorMagic_at
[19/01/2007|18:16] C:\Program Files\Movie Maker
[31/01/2007|20:35] C:\Program Files\MSECache
[21/07/2007|08:09] C:\Program Files\MSN
[19/01/2007|18:14] C:\Program Files\MSN Gaming Zone
[20/04/2007|18:47] C:\Program Files\Mysteries Of Horus
[24/10/2008|18:12] C:\Program Files\Mystery Case Files Madame Fate
[14/09/2008|04:58] C:\Program Files\Mystery Chronicles - Murder Among Friends
[02/12/2007|16:52] C:\Program Files\Mysteryville
[19/01/2007|18:16] C:\Program Files\NetMeeting
[26/10/2008|08:12] C:\Program Files\Oberon Media
[19/01/2007|18:15] C:\Program Files\Online Services
[19/10/2007|05:35] C:\Program Files\orange
[13/06/2007|20:44] C:\Program Files\Outlook Express
[25/11/2007|08:16] C:\Program Files\Puzzle Express
[25/11/2007|08:13] C:\Program Files\PuzzleInlay_at
[06/08/2007|18:18] C:\Program Files\QuickTime
[10/09/2007|08:05] C:\Program Files\RainbowWeb_at
[21/01/2007|14:56] C:\Program Files\Real
[17/02/2007|05:45] C:\Program Files\ReflexiveArcade
[17/10/2008|18:36] C:\Program Files\Rockstar Games
[24/03/2007|22:42] C:\Program Files\SAGEM
[19/01/2007|18:17] C:\Program Files\Services en ligne
[24/08/2007|06:45] C:\Program Files\Shockwave.com
[17/11/2007|07:43] C:\Program Files\Stone Of Destiny
[17/07/2008|16:58] C:\Program Files\Sun
[08/05/2007|09:19] C:\Program Files\Trend Micro
[22/08/2007|16:56] C:\Program Files\TryMedia
[19/01/2007|18:26] C:\Program Files\Uninstall Information
[14/11/2007|19:09] C:\Program Files\URUSoft
[25/10/2008|12:50] C:\Program Files\Valve
[14/04/2007|14:12] C:\Program Files\VIA
[14/04/2007|14:13] C:\Program Files\VIAudioi
[06/08/2007|18:27] C:\Program Files\VideoLAN
[03/03/2008|06:46] C:\Program Files\Windows Live
[18/12/2007|14:08] C:\Program Files\Windows Media Connect 2
[06/09/2008|17:26] C:\Program Files\Windows Media Player
[19/01/2007|18:14] C:\Program Files\Windows NT
[19/01/2007|18:17] C:\Program Files\WindowsUpdate
[06/09/2008|16:12] C:\Program Files\WinRAR
[19/01/2007|18:18] C:\Program Files\xerox
[22/08/2007|16:55] C:\Program Files\Yahoo! Games
[23/10/2008|07:54] C:\Program Files\Zylom Games

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[21/01/2007|06:27] C:\Program Files\Fichiers communs\Adobe
[19/01/2007|18:30] C:\Program Files\Fichiers communs\Ahead
[20/01/2007|18:30] C:\Program Files\Fichiers communs\BOONTY Shared
[19/01/2007|18:35] C:\Program Files\Fichiers communs\DESIGNER
[12/02/2007|22:13] C:\Program Files\Fichiers communs\InstallShield
[18/02/2007|09:42] C:\Program Files\Fichiers communs\Java
[13/06/2008|02:04] C:\Program Files\Fichiers communs\Microsoft Shared
[19/01/2007|18:16] C:\Program Files\Fichiers communs\MSSoap
[21/10/2008|09:23] C:\Program Files\Fichiers communs\Oberon Media
[19/01/2007|19:07] C:\Program Files\Fichiers communs\ODBC
[20/01/2007|19:20] C:\Program Files\Fichiers communs\Real
[19/01/2007|18:16] C:\Program Files\Fichiers communs\Services
[19/01/2007|19:07] C:\Program Files\Fichiers communs\SpeechEngines
[13/06/2007|20:44] C:\Program Files\Fichiers communs\System
[21/01/2007|16:03] C:\Program Files\Fichiers communs\Vivicam3695
[03/03/2008|06:47] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 45 Processes )

iexplore.exe ~ [PID:2536]
iexplore.exe ~ [PID:2492]

--------------------\\ Recherche avec S_Lop

C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\bis3B.exe

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default\Tons logo.exe
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsb2C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsc28.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsc3F.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsd51.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nse45.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nse4A.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsf3.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsg16.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsh99.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsi3D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsisdt.dll
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsj3C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsk25.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsk7.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsn1F.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsn91.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsq1C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nst4D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsv24.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsw3D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsy5E.tmp
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adultfriendfinder[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@advertising[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adin.bigpoint[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.seafight.bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.thepimps.bigpoint[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@banner.casinoking[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@casinoking[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adopt.euroclick[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@partygaming.122.2o7[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@partypoker[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.seafight.bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@888[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@888[2].txt

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Love default global mess"="C:\\Documents and Settings\\All Users\\Application Data\\great coal love default\\Tons logo.exe"

--------------------\\ Verification du fichier Hosts

Fichier Hosts MODIFIE

127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD

-> 72 [ 70 ## added by CiD ]

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 11:24:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 7

--------------------\\ Recherche d'autres infections

C:\WINDOWS\system32\nnVxayxx.ini
C:\WINDOWS\system32\nnVxayxx.ini2
C:\WINDOWS\system32\xxyaxVnn.dll
[b]==> VUNDO <==/b

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\XPPROS~1\Local Settings\Temp\110079234\ghost_hunter\data\audio\efx\lightning_crack.ogg
C:\DOCUME~1\XPPROS~1\Local Settings\Temp\110456968\ghost_hunter\data\audio\efx\lightning_crack.ogg
C:\DOCUME~1\XPPROS~1\Local Settings\Temporary Internet Files\Content.IE5\PDIFTQME\keyGen[1].htm
C:\DOCUME~1\XPPROS~1\Local Settings\Temporary Internet Files\Content.IE5\R62U4EFG\keyGen[1].htm
C:\DOCUME~1\XPPROS~1\Recent\Keygen counter strike source (cle cd)Steam counter strike source.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 + Internet Explorer 7 + Crack.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Fr Crack‚ (2).lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Fr Crack‚.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Francais pour Windows version Crack‚.lnk
C:\DOCUME~1\XPPROS~1\Recent\Wmp11 Fr Crack Windows Media Player 11 Windows Xp.lnk
C:\DOCUME~1\XPPROS~1\Recent\[PC GAME MULTI] - Gran Theft Auto San Andreas + Crack NoCD - (Perfect DVD Version) - (Eng-Ita-Deu-Fra-Esp) - (By GTA Squall89).lnk


[F:26037][D:642]-> C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp
[F:156][D:0]-> C:\DOCUME~1\XPPROS~1\Cookies
[F:3404][D:8]-> C:\DOCUME~1\XPPROS~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 28/10/2008|11:29 - Option : [1]

--------------------\\ Fin du rapport a 11:29:17
0
geoffrey5 Messages postés 13732 Date d'inscription dimanche 20 mai 2007 Statut Contributeur sécurité Dernière intervention 21 mai 2010 10
28 oct. 2008 à 11:35
ok maintenant fais ceci stp :

▶ Relance Lop S&D

▶ Choisis cette fois-ci l'option 2 (Suppression)

▶ Ne ferme pas la fenêtre lors de la suppression !

▶ Poste le rapport généré (C:\lopR.txt)

* (Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)


ensuite :


Fais un rapport hijackthis pour que je puisse vérifier les infections de ton pc stp

▶ Télécharge hijackthis à cette adresse, tout est expliqué pour bien l installer et pour savoir s'en servir :

https://www.androidworld.fr/


Comment copier/coller le rapport :


Quand tu as le rapport à l écran, tu fais ctrl A pour "sélectionner tout" puis ctrl C pour "copier".

ensuite tu viens sur le forum pour me répondre et tu fais ctrl V pour "coller" le rapport.

Une explication des raccourcis clavier sont illustrés sur mon site web à cette adresse :

https://www.androidworld.fr/
0
--------------------\\ Lop S&D 4.2.4-8 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Xp Pro Sp2 ( Administrator )
BOOT : Normal boot
Antivirus : Trend Micro PC-cillin Internet Security 2007 15.30.1234 (Not Activated)
Firewall : Trend Micro PC-cillin Internet Security 15 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:38 Go)
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 27-10-2008|09:15 )
Option : [1] ( 28/10/2008|11:21 )

--------------------\\ Listing des dossiers dans APPLIC~1

[06/08/2007|18:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[06/08/2007|18:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[20/07/2008|08:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Astar Games
[25/03/2008|14:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Awem
[11/07/2008|15:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFish
[28/10/2008|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
[20/01/2007|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[11/10/2008|06:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Christmasville
[21/01/2007|00:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[02/04/2008|10:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EscapeTheMuseum
[30/05/2008|19:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[09/11/2007|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[24/08/2008|15:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GameFiesta
[16/06/2008|18:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GameHouse
[25/09/2008|07:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii
[08/06/2008|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii Games
[29/11/2007|18:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[19/04/2008|16:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
[06/04/2008|13:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin Games
[01/03/2008|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[09/04/2007|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[24/07/2007|13:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Meridian93
[19/03/2007|11:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[19/04/2008|04:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[13/10/2008|16:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[29/02/2008|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\My Games
[14/09/2008|05:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MysteryChronicles
[02/04/2007|14:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\n7-89-o9-3r-4t-r9
[25/01/2008|05:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NeptunesAdve
[16/11/2007|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Media
[18/04/2008|09:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[22/10/2008|08:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[30/03/2008|06:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Realv1005
[21/08/2008|09:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Reflexivev1005
[03/06/2007|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[05/09/2007|16:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecretsOfOlympus
[11/08/2008|10:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Slapdash Games
[05/06/2008|17:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SpinTop Games
[28/04/2008|18:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SugarGames
[28/10/2008|10:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[04/04/2007|13:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TERMINAL Studio
[24/08/2008|06:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TheRace_dev
[08/05/2007|09:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
[11/02/2007|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[12/02/2007|22:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[20/01/2007|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[03/03/2008|06:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[02/04/2007|13:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[19/01/2007|18:18] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[19/01/2007|18:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[19/01/2007|18:22] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[06/03/2008|11:24] C:\DOCUME~1\XPPROS~1\APPLIC~1\Abra Academy2
[17/02/2008|05:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\Adobe
[05/09/2007|14:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\AlwaysNeat
[19/08/2007|16:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\Apple Computer
[27/08/2007|13:01] C:\DOCUME~1\XPPROS~1\APPLIC~1\Beep Industries
[24/01/2008|11:16] C:\DOCUME~1\XPPROS~1\APPLIC~1\Big Fish Games
[11/07/2008|15:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\BigFish
[28/01/2008|08:10] C:\DOCUME~1\XPPROS~1\APPLIC~1\BloodTies
[20/07/2008|07:56] C:\DOCUME~1\XPPROS~1\APPLIC~1\cerasus.media
[21/01/2007|00:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\CyberLink
[25/08/2008|20:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\DAEMON Tools
[22/05/2007|18:04] C:\DOCUME~1\XPPROS~1\APPLIC~1\EPSON
[22/01/2008|09:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\Flood Light Games
[09/11/2007|20:21] C:\DOCUME~1\XPPROS~1\APPLIC~1\FloodLightGames
[01/03/2008|19:07] C:\DOCUME~1\XPPROS~1\APPLIC~1\ForgottenRiddles
[29/07/2008|16:22] C:\DOCUME~1\XPPROS~1\APPLIC~1\ForgottenRiddles2
[27/03/2008|09:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\Friday's games
[09/05/2008|07:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Gaijin Ent
[24/08/2008|15:14] C:\DOCUME~1\XPPROS~1\APPLIC~1\GameFiesta
[25/10/2008|18:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\GameHouse
[08/06/2008|18:39] C:\DOCUME~1\XPPROS~1\APPLIC~1\Gogii Games
[14/08/2007|18:34] C:\DOCUME~1\XPPROS~1\APPLIC~1\Google
[15/02/2007|15:11] C:\DOCUME~1\XPPROS~1\APPLIC~1\Help
[07/07/2008|16:28] C:\DOCUME~1\XPPROS~1\APPLIC~1\Icone
[23/10/2008|06:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Identities
[19/01/2007|18:31] C:\DOCUME~1\XPPROS~1\APPLIC~1\InterTrust
[12/08/2008|08:03] C:\DOCUME~1\XPPROS~1\APPLIC~1\iWin
[06/04/2008|13:36] C:\DOCUME~1\XPPROS~1\APPLIC~1\iWinArcade
[07/10/2008|04:59] C:\DOCUME~1\XPPROS~1\APPLIC~1\JoyBits
[04/02/2008|10:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\Legends of pirates
[19/01/2008|17:05] C:\DOCUME~1\XPPROS~1\APPLIC~1\Macromedia
[18/09/2007|16:53] C:\DOCUME~1\XPPROS~1\APPLIC~1\Magic Academy
[24/07/2007|13:37] C:\DOCUME~1\XPPROS~1\APPLIC~1\Meridian93
[15/09/2008|09:55] C:\DOCUME~1\XPPROS~1\APPLIC~1\Microsoft
[21/07/2007|08:09] C:\DOCUME~1\XPPROS~1\APPLIC~1\MSNInstaller
[28/01/2008|14:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\My Games
[26/08/2008|07:16] C:\DOCUME~1\XPPROS~1\APPLIC~1\MysteryStudio
[15/01/2008|17:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\Mysteryville2
[28/01/2008|17:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\Pirateville
[18/04/2008|09:26] C:\DOCUME~1\XPPROS~1\APPLIC~1\PlayFirst
[21/09/2008|16:44] C:\DOCUME~1\XPPROS~1\APPLIC~1\Realv1005
[25/10/2008|18:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Righteous Kill
[18/03/2007|05:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\Screenshot Sender
[20/01/2007|18:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\SecuROM
[08/08/2007|09:48] C:\DOCUME~1\XPPROS~1\APPLIC~1\SpinTop
[18/09/2008|16:41] C:\DOCUME~1\XPPROS~1\APPLIC~1\SpinTop Games
[06/07/2008|15:52] C:\DOCUME~1\XPPROS~1\APPLIC~1\SprillBermudeEng
[18/02/2007|09:44] C:\DOCUME~1\XPPROS~1\APPLIC~1\Sun
[30/07/2008|14:41] C:\DOCUME~1\XPPROS~1\APPLIC~1\TheScruffs
[21/08/2008|09:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\TMInc
[14/11/2007|19:09] C:\DOCUME~1\XPPROS~1\APPLIC~1\URUSoft
[06/08/2007|18:28] C:\DOCUME~1\XPPROS~1\APPLIC~1\vlc
[23/10/2008|06:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Zylom

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[27/10/2008 21:00][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[28/10/2008 06:48][--ah-----] C:\WINDOWS\tasks\SA.DAT
[07/09/2002 01:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[19/01/2007|18:31] C:\Program Files\Adobe
[19/01/2007|18:30] C:\Program Files\Ahead
[26/08/2008|07:47] C:\Program Files\Alawar
[03/03/2007|06:51] C:\Program Files\Ancient Mosaic
[06/08/2007|18:17] C:\Program Files\Apple Software Update
[30/03/2007|09:38] C:\Program Files\BFG
[14/09/2008|04:44] C:\Program Files\bfgclient
[26/07/2008|10:01] C:\Program Files\Bookworm Adventures Deluxe
[28/08/2007|06:30] C:\Program Files\Boonty
[28/09/2008|11:07] C:\Program Files\BoontyGames
[19/01/2007|18:15] C:\Program Files\ComPlus Applications
[13/04/2007|09:44] C:\Program Files\Cradle Of Rome
[19/01/2007|18:29] C:\Program Files\CyberLink
[19/01/2007|18:29] C:\Program Files\CyberLink DVD Solution
[25/08/2008|20:44] C:\Program Files\DAEMON Tools Toolbar
[28/10/2008|06:51] C:\Program Files\eMule
[12/02/2007|22:11] C:\Program Files\epson
[22/08/2008|16:41] C:\Program Files\Fenomen Games Downloader
[14/11/2007|19:07] C:\Program Files\ffdshow
[29/03/2008|15:09] C:\Program Files\Fichiers communs
[09/08/2007|12:14] C:\Program Files\Fresco Wizard
[07/10/2008|19:56] C:\Program Files\GameFiesta
[26/10/2008|14:13] C:\Program Files\GameHouse
[08/10/2008|06:57] C:\Program Files\Gamenext
[05/09/2007|16:06] C:\Program Files\Games
[20/09/2008|10:48] C:\Program Files\GamesBar
[27/10/2008|21:07] C:\Program Files\Google
[12/06/2008|10:10] C:\Program Files\Hide and Secret 2 - Cliffhanger Castle
[11/08/2007|14:52] C:\Program Files\HipSoft
[04/09/2007|05:29] C:\Program Files\Holiday Express
[07/07/2008|16:30] C:\Program Files\Icone
[17/10/2008|18:36] C:\Program Files\InstallShield Installation Information
[15/10/2008|21:38] C:\Program Files\Internet Explorer
[06/04/2008|13:35] C:\Program Files\iWin Games
[01/09/2008|09:29] C:\Program Files\iWin.com
[17/07/2008|16:58] C:\Program Files\Java
[05/09/2007|16:19] C:\Program Files\Jewel Miner
[01/08/2007|13:40] C:\Program Files\Jewel Quest 2
[07/07/2008|16:30] C:\Program Files\LETMIN
[10/06/2008|10:45] C:\Program Files\M6 Jeux
[16/10/2007|17:56] C:\Program Files\Macrogaming
[06/07/2008|15:39] C:\Program Files\Magic Academy
[07/09/2007|07:09] C:\Program Files\MagicInlay_at
[14/08/2008|20:17] C:\Program Files\Messenger
[19/04/2008|16:52] C:\Program Files\Messenger Plus! Live
[19/01/2007|18:18] C:\Program Files\microsoft frontpage
[31/01/2007|20:35] C:\Program Files\Microsoft Office
[19/01/2007|18:35] C:\Program Files\Microsoft Visual Studio
[06/09/2008|09:31] C:\Program Files\Microsoft Works
[19/01/2007|18:36] C:\Program Files\Microsoft.NET
[08/09/2007|15:31] C:\Program Files\MirrorMagic_at
[19/01/2007|18:16] C:\Program Files\Movie Maker
[31/01/2007|20:35] C:\Program Files\MSECache
[21/07/2007|08:09] C:\Program Files\MSN
[19/01/2007|18:14] C:\Program Files\MSN Gaming Zone
[20/04/2007|18:47] C:\Program Files\Mysteries Of Horus
[24/10/2008|18:12] C:\Program Files\Mystery Case Files Madame Fate
[14/09/2008|04:58] C:\Program Files\Mystery Chronicles - Murder Among Friends
[02/12/2007|16:52] C:\Program Files\Mysteryville
[19/01/2007|18:16] C:\Program Files\NetMeeting
[26/10/2008|08:12] C:\Program Files\Oberon Media
[19/01/2007|18:15] C:\Program Files\Online Services
[19/10/2007|05:35] C:\Program Files\orange
[13/06/2007|20:44] C:\Program Files\Outlook Express
[25/11/2007|08:16] C:\Program Files\Puzzle Express
[25/11/2007|08:13] C:\Program Files\PuzzleInlay_at
[06/08/2007|18:18] C:\Program Files\QuickTime
[10/09/2007|08:05] C:\Program Files\RainbowWeb_at
[21/01/2007|14:56] C:\Program Files\Real
[17/02/2007|05:45] C:\Program Files\ReflexiveArcade
[17/10/2008|18:36] C:\Program Files\Rockstar Games
[24/03/2007|22:42] C:\Program Files\SAGEM
[19/01/2007|18:17] C:\Program Files\Services en ligne
[24/08/2007|06:45] C:\Program Files\Shockwave.com
[17/11/2007|07:43] C:\Program Files\Stone Of Destiny
[17/07/2008|16:58] C:\Program Files\Sun
[08/05/2007|09:19] C:\Program Files\Trend Micro
[22/08/2007|16:56] C:\Program Files\TryMedia
[19/01/2007|18:26] C:\Program Files\Uninstall Information
[14/11/2007|19:09] C:\Program Files\URUSoft
[25/10/2008|12:50] C:\Program Files\Valve
[14/04/2007|14:12] C:\Program Files\VIA
[14/04/2007|14:13] C:\Program Files\VIAudioi
[06/08/2007|18:27] C:\Program Files\VideoLAN
[03/03/2008|06:46] C:\Program Files\Windows Live
[18/12/2007|14:08] C:\Program Files\Windows Media Connect 2
[06/09/2008|17:26] C:\Program Files\Windows Media Player
[19/01/2007|18:14] C:\Program Files\Windows NT
[19/01/2007|18:17] C:\Program Files\WindowsUpdate
[06/09/2008|16:12] C:\Program Files\WinRAR
[19/01/2007|18:18] C:\Program Files\xerox
[22/08/2007|16:55] C:\Program Files\Yahoo! Games
[23/10/2008|07:54] C:\Program Files\Zylom Games

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[21/01/2007|06:27] C:\Program Files\Fichiers communs\Adobe
[19/01/2007|18:30] C:\Program Files\Fichiers communs\Ahead
[20/01/2007|18:30] C:\Program Files\Fichiers communs\BOONTY Shared
[19/01/2007|18:35] C:\Program Files\Fichiers communs\DESIGNER
[12/02/2007|22:13] C:\Program Files\Fichiers communs\InstallShield
[18/02/2007|09:42] C:\Program Files\Fichiers communs\Java
[13/06/2008|02:04] C:\Program Files\Fichiers communs\Microsoft Shared
[19/01/2007|18:16] C:\Program Files\Fichiers communs\MSSoap
[21/10/2008|09:23] C:\Program Files\Fichiers communs\Oberon Media
[19/01/2007|19:07] C:\Program Files\Fichiers communs\ODBC
[20/01/2007|19:20] C:\Program Files\Fichiers communs\Real
[19/01/2007|18:16] C:\Program Files\Fichiers communs\Services
[19/01/2007|19:07] C:\Program Files\Fichiers communs\SpeechEngines
[13/06/2007|20:44] C:\Program Files\Fichiers communs\System
[21/01/2007|16:03] C:\Program Files\Fichiers communs\Vivicam3695
[03/03/2008|06:47] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 45 Processes )

iexplore.exe ~ [PID:2536]
iexplore.exe ~ [PID:2492]

--------------------\\ Recherche avec S_Lop

C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\bis3B.exe

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default\Tons logo.exe
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsb2C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsc28.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsc3F.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsd51.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nse45.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nse4A.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsf3.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsg16.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsh99.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsi3D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsisdt.dll
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsj3C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsk25.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsk7.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsn1F.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsn91.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsq1C.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nst4D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsv24.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsw3D.tmp
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsy5E.tmp
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adultfriendfinder[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@advertising[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adin.bigpoint[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.seafight.bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.thepimps.bigpoint[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@banner.casinoking[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@casinoking[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adopt.euroclick[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@partygaming.122.2o7[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@partypoker[2].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.seafight.bigpoint[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@888[1].txt
C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@888[2].txt

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Love default global mess"="C:\\Documents and Settings\\All Users\\Application Data\\great coal love default\\Tons logo.exe"

--------------------\\ Verification du fichier Hosts

Fichier Hosts MODIFIE

127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD

-> 72 [ 70 ## added by CiD ]

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 11:24:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 7

--------------------\\ Recherche d'autres infections

C:\WINDOWS\system32\nnVxayxx.ini
C:\WINDOWS\system32\nnVxayxx.ini2
C:\WINDOWS\system32\xxyaxVnn.dll
[b]==> VUNDO <==/b

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\XPPROS~1\Local Settings\Temp\110079234\ghost_hunter\data\audio\efx\lightning_crack.ogg
C:\DOCUME~1\XPPROS~1\Local Settings\Temp\110456968\ghost_hunter\data\audio\efx\lightning_crack.ogg
C:\DOCUME~1\XPPROS~1\Local Settings\Temporary Internet Files\Content.IE5\PDIFTQME\keyGen[1].htm
C:\DOCUME~1\XPPROS~1\Local Settings\Temporary Internet Files\Content.IE5\R62U4EFG\keyGen[1].htm
C:\DOCUME~1\XPPROS~1\Recent\Keygen counter strike source (cle cd)Steam counter strike source.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 + Internet Explorer 7 + Crack.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Fr Crack‚ (2).lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Fr Crack‚.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Francais pour Windows version Crack‚.lnk
C:\DOCUME~1\XPPROS~1\Recent\Wmp11 Fr Crack Windows Media Player 11 Windows Xp.lnk
C:\DOCUME~1\XPPROS~1\Recent\[PC GAME MULTI] - Gran Theft Auto San Andreas + Crack NoCD - (Perfect DVD Version) - (Eng-Ita-Deu-Fra-Esp) - (By GTA Squall89).lnk


[F:26037][D:642]-> C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp
[F:156][D:0]-> C:\DOCUME~1\XPPROS~1\Cookies
[F:3404][D:8]-> C:\DOCUME~1\XPPROS~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 28/10/2008|11:29 - Option : [1]

--------------------\\ Fin du rapport a 11:29:17
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
--------------------\\ Lop S&D 4.2.4-8 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Xp Pro Sp2 ( Administrator )
BOOT : Normal boot
Antivirus : Trend Micro PC-cillin Internet Security 2007 15.30.1234 (Not Activated)
Firewall : Trend Micro PC-cillin Internet Security 15 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:38 Go)
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 27-10-2008|09:15 )
Option : [2] ( 28/10/2008|11:42 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default\Tons logo.exe
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsb2C.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsc28.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsc3F.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsd51.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nse45.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nse4A.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsf3.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsg16.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsh99.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsi3D.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsisdt.dll
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsj3C.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsk25.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsk7.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsn1F.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsn91.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsq1C.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nst4D.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsv24.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsw3D.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\nsy5E.tmp
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adultfriendfinder[1].txt
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adin.bigpoint[2].txt
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@bigpoint[1].txt
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.seafight.bigpoint[1].txt
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@fr.thepimps.bigpoint[2].txt
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@banner.casinoking[2].txt
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@casinoking[1].txt
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@adopt.euroclick[1].txt
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@partygaming.122.2o7[1].txt
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@partypoker[2].txt
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@888[1].txt
Supprime! - C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@888[2].txt
Supprime! - C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\bis3B.exe
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\great coal love default
-
[ Fichier Hosts ] .. Restaure!

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans APPLIC~1

[06/08/2007|18:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[06/08/2007|18:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[20/07/2008|08:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Astar Games
[25/03/2008|14:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Awem
[11/07/2008|15:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFish
[28/10/2008|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
[20/01/2007|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[11/10/2008|06:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Christmasville
[21/01/2007|00:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[02/04/2008|10:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EscapeTheMuseum
[30/05/2008|19:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[09/11/2007|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[24/08/2008|15:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GameFiesta
[16/06/2008|18:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GameHouse
[25/09/2008|07:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii
[08/06/2008|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii Games
[27/10/2008|21:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[06/04/2008|13:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin Games
[01/03/2008|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[09/04/2007|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[24/07/2007|13:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Meridian93
[19/03/2007|11:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[19/04/2008|04:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[13/10/2008|16:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[29/02/2008|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\My Games
[14/09/2008|05:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MysteryChronicles
[02/04/2007|14:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\n7-89-o9-3r-4t-r9
[25/01/2008|05:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NeptunesAdve
[16/11/2007|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Media
[18/04/2008|09:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[22/10/2008|08:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[30/03/2008|06:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Realv1005
[21/08/2008|09:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Reflexivev1005
[03/06/2007|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[05/09/2007|16:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecretsOfOlympus
[11/08/2008|10:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Slapdash Games
[05/06/2008|17:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SpinTop Games
[28/04/2008|18:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SugarGames
[28/10/2008|10:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[04/04/2007|13:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TERMINAL Studio
[24/08/2008|06:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TheRace_dev
[08/05/2007|09:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
[11/02/2007|20:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[12/02/2007|22:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[20/01/2007|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[03/03/2008|06:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[02/04/2007|13:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[19/01/2007|18:18] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[19/01/2007|18:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[19/01/2007|18:22] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[06/03/2008|11:24] C:\DOCUME~1\XPPROS~1\APPLIC~1\Abra Academy2
[17/02/2008|05:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\Adobe
[05/09/2007|14:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\AlwaysNeat
[19/08/2007|16:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\Apple Computer
[27/08/2007|13:01] C:\DOCUME~1\XPPROS~1\APPLIC~1\Beep Industries
[24/01/2008|11:16] C:\DOCUME~1\XPPROS~1\APPLIC~1\Big Fish Games
[11/07/2008|15:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\BigFish
[28/01/2008|08:10] C:\DOCUME~1\XPPROS~1\APPLIC~1\BloodTies
[20/07/2008|07:56] C:\DOCUME~1\XPPROS~1\APPLIC~1\cerasus.media
[21/01/2007|00:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\CyberLink
[25/08/2008|20:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\DAEMON Tools
[22/05/2007|18:04] C:\DOCUME~1\XPPROS~1\APPLIC~1\EPSON
[22/01/2008|09:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\Flood Light Games
[09/11/2007|20:21] C:\DOCUME~1\XPPROS~1\APPLIC~1\FloodLightGames
[01/03/2008|19:07] C:\DOCUME~1\XPPROS~1\APPLIC~1\ForgottenRiddles
[29/07/2008|16:22] C:\DOCUME~1\XPPROS~1\APPLIC~1\ForgottenRiddles2
[27/03/2008|09:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\Friday's games
[09/05/2008|07:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Gaijin Ent
[24/08/2008|15:14] C:\DOCUME~1\XPPROS~1\APPLIC~1\GameFiesta
[25/10/2008|18:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\GameHouse
[08/06/2008|18:39] C:\DOCUME~1\XPPROS~1\APPLIC~1\Gogii Games
[14/08/2007|18:34] C:\DOCUME~1\XPPROS~1\APPLIC~1\Google
[15/02/2007|15:11] C:\DOCUME~1\XPPROS~1\APPLIC~1\Help
[07/07/2008|16:28] C:\DOCUME~1\XPPROS~1\APPLIC~1\Icone
[23/10/2008|06:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Identities
[19/01/2007|18:31] C:\DOCUME~1\XPPROS~1\APPLIC~1\InterTrust
[12/08/2008|08:03] C:\DOCUME~1\XPPROS~1\APPLIC~1\iWin
[06/04/2008|13:36] C:\DOCUME~1\XPPROS~1\APPLIC~1\iWinArcade
[07/10/2008|04:59] C:\DOCUME~1\XPPROS~1\APPLIC~1\JoyBits
[04/02/2008|10:18] C:\DOCUME~1\XPPROS~1\APPLIC~1\Legends of pirates
[19/01/2008|17:05] C:\DOCUME~1\XPPROS~1\APPLIC~1\Macromedia
[18/09/2007|16:53] C:\DOCUME~1\XPPROS~1\APPLIC~1\Magic Academy
[24/07/2007|13:37] C:\DOCUME~1\XPPROS~1\APPLIC~1\Meridian93
[15/09/2008|09:55] C:\DOCUME~1\XPPROS~1\APPLIC~1\Microsoft
[21/07/2007|08:09] C:\DOCUME~1\XPPROS~1\APPLIC~1\MSNInstaller
[28/01/2008|14:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\My Games
[26/08/2008|07:16] C:\DOCUME~1\XPPROS~1\APPLIC~1\MysteryStudio
[15/01/2008|17:38] C:\DOCUME~1\XPPROS~1\APPLIC~1\Mysteryville2
[28/01/2008|17:06] C:\DOCUME~1\XPPROS~1\APPLIC~1\Pirateville
[18/04/2008|09:26] C:\DOCUME~1\XPPROS~1\APPLIC~1\PlayFirst
[21/09/2008|16:44] C:\DOCUME~1\XPPROS~1\APPLIC~1\Realv1005
[25/10/2008|18:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Righteous Kill
[18/03/2007|05:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\Screenshot Sender
[20/01/2007|18:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\SecuROM
[08/08/2007|09:48] C:\DOCUME~1\XPPROS~1\APPLIC~1\SpinTop
[18/09/2008|16:41] C:\DOCUME~1\XPPROS~1\APPLIC~1\SpinTop Games
[06/07/2008|15:52] C:\DOCUME~1\XPPROS~1\APPLIC~1\SprillBermudeEng
[18/02/2007|09:44] C:\DOCUME~1\XPPROS~1\APPLIC~1\Sun
[30/07/2008|14:41] C:\DOCUME~1\XPPROS~1\APPLIC~1\TheScruffs
[21/08/2008|09:42] C:\DOCUME~1\XPPROS~1\APPLIC~1\TMInc
[14/11/2007|19:09] C:\DOCUME~1\XPPROS~1\APPLIC~1\URUSoft
[06/08/2007|18:28] C:\DOCUME~1\XPPROS~1\APPLIC~1\vlc
[23/10/2008|06:35] C:\DOCUME~1\XPPROS~1\APPLIC~1\Zylom

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[27/10/2008 21:00][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[28/10/2008 06:48][--ah-----] C:\WINDOWS\tasks\SA.DAT
[07/09/2002 01:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[19/01/2007|18:31] C:\Program Files\Adobe
[19/01/2007|18:30] C:\Program Files\Ahead
[26/08/2008|07:47] C:\Program Files\Alawar
[03/03/2007|06:51] C:\Program Files\Ancient Mosaic
[06/08/2007|18:17] C:\Program Files\Apple Software Update
[30/03/2007|09:38] C:\Program Files\BFG
[14/09/2008|04:44] C:\Program Files\bfgclient
[26/07/2008|10:01] C:\Program Files\Bookworm Adventures Deluxe
[28/08/2007|06:30] C:\Program Files\Boonty
[28/09/2008|11:07] C:\Program Files\BoontyGames
[19/01/2007|18:15] C:\Program Files\ComPlus Applications
[13/04/2007|09:44] C:\Program Files\Cradle Of Rome
[19/01/2007|18:29] C:\Program Files\CyberLink
[19/01/2007|18:29] C:\Program Files\CyberLink DVD Solution
[25/08/2008|20:44] C:\Program Files\DAEMON Tools Toolbar
[28/10/2008|06:51] C:\Program Files\eMule
[12/02/2007|22:11] C:\Program Files\epson
[22/08/2008|16:41] C:\Program Files\Fenomen Games Downloader
[14/11/2007|19:07] C:\Program Files\ffdshow
[29/03/2008|15:09] C:\Program Files\Fichiers communs
[09/08/2007|12:14] C:\Program Files\Fresco Wizard
[07/10/2008|19:56] C:\Program Files\GameFiesta
[26/10/2008|14:13] C:\Program Files\GameHouse
[08/10/2008|06:57] C:\Program Files\Gamenext
[05/09/2007|16:06] C:\Program Files\Games
[20/09/2008|10:48] C:\Program Files\GamesBar
[27/10/2008|21:07] C:\Program Files\Google
[12/06/2008|10:10] C:\Program Files\Hide and Secret 2 - Cliffhanger Castle
[11/08/2007|14:52] C:\Program Files\HipSoft
[04/09/2007|05:29] C:\Program Files\Holiday Express
[07/07/2008|16:30] C:\Program Files\Icone
[17/10/2008|18:36] C:\Program Files\InstallShield Installation Information
[15/10/2008|21:38] C:\Program Files\Internet Explorer
[06/04/2008|13:35] C:\Program Files\iWin Games
[01/09/2008|09:29] C:\Program Files\iWin.com
[17/07/2008|16:58] C:\Program Files\Java
[05/09/2007|16:19] C:\Program Files\Jewel Miner
[01/08/2007|13:40] C:\Program Files\Jewel Quest 2
[07/07/2008|16:30] C:\Program Files\LETMIN
[10/06/2008|10:45] C:\Program Files\M6 Jeux
[16/10/2007|17:56] C:\Program Files\Macrogaming
[06/07/2008|15:39] C:\Program Files\Magic Academy
[07/09/2007|07:09] C:\Program Files\MagicInlay_at
[14/08/2008|20:17] C:\Program Files\Messenger
[19/04/2008|16:52] C:\Program Files\Messenger Plus! Live
[19/01/2007|18:18] C:\Program Files\microsoft frontpage
[31/01/2007|20:35] C:\Program Files\Microsoft Office
[19/01/2007|18:35] C:\Program Files\Microsoft Visual Studio
[06/09/2008|09:31] C:\Program Files\Microsoft Works
[19/01/2007|18:36] C:\Program Files\Microsoft.NET
[08/09/2007|15:31] C:\Program Files\MirrorMagic_at
[19/01/2007|18:16] C:\Program Files\Movie Maker
[31/01/2007|20:35] C:\Program Files\MSECache
[21/07/2007|08:09] C:\Program Files\MSN
[19/01/2007|18:14] C:\Program Files\MSN Gaming Zone
[20/04/2007|18:47] C:\Program Files\Mysteries Of Horus
[24/10/2008|18:12] C:\Program Files\Mystery Case Files Madame Fate
[14/09/2008|04:58] C:\Program Files\Mystery Chronicles - Murder Among Friends
[02/12/2007|16:52] C:\Program Files\Mysteryville
[19/01/2007|18:16] C:\Program Files\NetMeeting
[26/10/2008|08:12] C:\Program Files\Oberon Media
[19/01/2007|18:15] C:\Program Files\Online Services
[19/10/2007|05:35] C:\Program Files\orange
[13/06/2007|20:44] C:\Program Files\Outlook Express
[25/11/2007|08:16] C:\Program Files\Puzzle Express
[25/11/2007|08:13] C:\Program Files\PuzzleInlay_at
[06/08/2007|18:18] C:\Program Files\QuickTime
[10/09/2007|08:05] C:\Program Files\RainbowWeb_at
[21/01/2007|14:56] C:\Program Files\Real
[17/02/2007|05:45] C:\Program Files\ReflexiveArcade
[17/10/2008|18:36] C:\Program Files\Rockstar Games
[24/03/2007|22:42] C:\Program Files\SAGEM
[19/01/2007|18:17] C:\Program Files\Services en ligne
[24/08/2007|06:45] C:\Program Files\Shockwave.com
[17/11/2007|07:43] C:\Program Files\Stone Of Destiny
[17/07/2008|16:58] C:\Program Files\Sun
[08/05/2007|09:19] C:\Program Files\Trend Micro
[22/08/2007|16:56] C:\Program Files\TryMedia
[19/01/2007|18:26] C:\Program Files\Uninstall Information
[14/11/2007|19:09] C:\Program Files\URUSoft
[25/10/2008|12:50] C:\Program Files\Valve
[14/04/2007|14:12] C:\Program Files\VIA
[14/04/2007|14:13] C:\Program Files\VIAudioi
[06/08/2007|18:27] C:\Program Files\VideoLAN
[03/03/2008|06:46] C:\Program Files\Windows Live
[18/12/2007|14:08] C:\Program Files\Windows Media Connect 2
[06/09/2008|17:26] C:\Program Files\Windows Media Player
[19/01/2007|18:14] C:\Program Files\Windows NT
[19/01/2007|18:17] C:\Program Files\WindowsUpdate
[06/09/2008|16:12] C:\Program Files\WinRAR
[19/01/2007|18:18] C:\Program Files\xerox
[22/08/2007|16:55] C:\Program Files\Yahoo! Games
[23/10/2008|07:54] C:\Program Files\Zylom Games

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[21/01/2007|06:27] C:\Program Files\Fichiers communs\Adobe
[19/01/2007|18:30] C:\Program Files\Fichiers communs\Ahead
[20/01/2007|18:30] C:\Program Files\Fichiers communs\BOONTY Shared
[19/01/2007|18:35] C:\Program Files\Fichiers communs\DESIGNER
[12/02/2007|22:13] C:\Program Files\Fichiers communs\InstallShield
[18/02/2007|09:42] C:\Program Files\Fichiers communs\Java
[13/06/2008|02:04] C:\Program Files\Fichiers communs\Microsoft Shared
[19/01/2007|18:16] C:\Program Files\Fichiers communs\MSSoap
[21/10/2008|09:23] C:\Program Files\Fichiers communs\Oberon Media
[19/01/2007|19:07] C:\Program Files\Fichiers communs\ODBC
[20/01/2007|19:20] C:\Program Files\Fichiers communs\Real
[19/01/2007|18:16] C:\Program Files\Fichiers communs\Services
[19/01/2007|19:07] C:\Program Files\Fichiers communs\SpeechEngines
[13/06/2007|20:44] C:\Program Files\Fichiers communs\System
[21/01/2007|16:03] C:\Program Files\Fichiers communs\Vivicam3695
[03/03/2008|06:47] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 43 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\XPPROS~1\Cookies\xp pro sp2@advertising[1].txt

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 11:44:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 7

--------------------\\ Recherche d'autres infections

C:\WINDOWS\system32\nnVxayxx.ini
C:\WINDOWS\system32\nnVxayxx.ini2
C:\WINDOWS\system32\xxyaxVnn.dll
[b]==> VUNDO <==/b

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\XPPROS~1\Local Settings\Temp\110079234\ghost_hunter\data\audio\efx\lightning_crack.ogg
C:\DOCUME~1\XPPROS~1\Local Settings\Temp\110456968\ghost_hunter\data\audio\efx\lightning_crack.ogg
C:\DOCUME~1\XPPROS~1\Local Settings\Temporary Internet Files\Content.IE5\PDIFTQME\keyGen[1].htm
C:\DOCUME~1\XPPROS~1\Local Settings\Temporary Internet Files\Content.IE5\R62U4EFG\keyGen[1].htm
C:\DOCUME~1\XPPROS~1\Recent\Keygen counter strike source (cle cd)Steam counter strike source.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 + Internet Explorer 7 + Crack.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Fr Crack‚ (2).lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Fr Crack‚.lnk
C:\DOCUME~1\XPPROS~1\Recent\Windows Media Player 11 Francais pour Windows version Crack‚.lnk
C:\DOCUME~1\XPPROS~1\Recent\Wmp11 Fr Crack Windows Media Player 11 Windows Xp.lnk
C:\DOCUME~1\XPPROS~1\Recent\[PC GAME MULTI] - Gran Theft Auto San Andreas + Crack NoCD - (Perfect DVD Version) - (Eng-Ita-Deu-Fra-Esp) - (By GTA Squall89).lnk


[F:25953][D:624]-> C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp
[F:149][D:0]-> C:\DOCUME~1\XPPROS~1\Cookies
[F:3626][D:12]-> C:\DOCUME~1\XPPROS~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 28/10/2008|11:29 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 28/10/2008|11:47 - Option : [2]

--------------------\\ Fin du rapport a 11:47:43
0
geoffrey5 Messages postés 13732 Date d'inscription dimanche 20 mai 2007 Statut Contributeur sécurité Dernière intervention 21 mai 2010 10
28 oct. 2008 à 11:51
tu m as renvoyé le meme rapport que tout à l heure... Il faut envoyer le rapport de la suppression
0
oui dsl mais mon pc rame et ça me fait faire des conneries donc je t'ai posté le 2eme rapport et voici celui de hijackthis



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:51:38, on 28/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\CAPRPCSN.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PccGuide.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\eMule\emule.exe
C:\WINDOWS\system32\spool\drivers\w32x86\2\CAPPSWN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\2\CAPPSWN.EXE
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\XPPROS~1\LOCALS~1\Temp\Rar$EX10.328\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus DX4200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /O6 "USB001" /M "Stylus DX4200"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [Way Nurb Frag Book] C:\Documents and Settings\All Users\Application Data\InsideHopeWayNurb\For Pile.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CAPON] C:\WINDOWS\system32\Spool\Drivers\w32x86\2\CAPONN.EXE
O4 - HKLM\..\Run: [30e33147] rundll32.exe "C:\WINDOWS\system32\pbdrbkju.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\\Steam.exe -silent
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: BoontyBox 01net.lnk = C:\Program Files\Boonty\BoontyBox\BoontyBox.exe
O4 - Startup: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
O4 - Global Startup: Fenêtre d'état Canon LBP-800.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\2\CAPPSWN.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Rainbow Web\Images\stg_drm.ocx
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Mahjong Quest 2\Images\armhelper.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{8E6AA9BF-82AB-489B-AF14-7F0284DA3D26}: NameServer = 80.10.246.2,80.10.246.129
O20 - AppInit_DLLs: jxqixu.dll
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Protection Trend Micro contre les programmes espions (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O24 - Desktop Component 0: (no name) - http://photos.cityvox.com/photos_400/83/56/211027.jpg
0
geoffrey5 Messages postés 13732 Date d'inscription dimanche 20 mai 2007 Statut Contributeur sécurité Dernière intervention 21 mai 2010 10
28 oct. 2008 à 11:59
ok on continue...

▶ Télécharger SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

(c est le numéro 8 en bas de la page)


▶ Double cliquer sur SDFix.exe et choisir Install pour l'extraire dans un dossier dédié sur ton disque C:.

/!\ Démarre en mode sans échec : après le bip et avant le logo windows tapoter sur la touche F8 (ou F5): menu M.S.E..

▶ Choisir son compte, pas celui de l'Administrateur ou autre.

Dérouler la liste des instructions ci-dessous :

• Ouvrir le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
• Appuyer sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuyer sur une touche pour redémarrer le PC.
• Le système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuyer sur une touche pour finir l'exécution du script et charger les icônes du Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
• Enfin, copier/coller le contenu du fichier Report.txt dans la prochaine réponse sur le forum
0