Demarage impossible

Résolu
Bonjour,
ce matin, mon amie a voulu allumer le pc, le debut du demarrage c'est effectuer normalement, puis une page c'est ouverte avec un defilement incessant de nom de dossiers avec des trojans, dans le doute elle a eteint immediatement le pc. ce soir, j'ai moi meme voulu redemarrer le pc, tout ce passe normalement, la page avec windows et le curseur qui defile s'affiche, et en lieu et place de la page de demarrage avec les differentes cessions possibles, j'ai un ecran noir avec uniquement le curseur de la souris, qui lui fonctionne normalement. j'ai une option possible " console de recuperation ", voila pour le gros du probleme. dois-je reinstaller windows dans l'expectative de perdre les donnes figurants sur le disque dur ou ai-je une autre possiblite. merci a tous de votre aide
Configuration: Windows Vista
Firefox 3.5.1

54 réponses

Résumé de la discussion

Un PC sous Windows Vista affiche au démarrage une page listant des trojans, puis un écran noir avec le curseur et une option de récupération, ce qui soulève la question d'une réinstallation. Des solutions proposées incluent le démarrage en mode sans échec, la console de récupération et l'exécution d'outils de détection comme OTL, GMER ou Malwarebytes pour nettoyer les malwares et éviter une réinstallation précipitée. Plusieurs messages mentionnent des rapports de scans et des conseils d'exécution en mode administrateur, puis l'utilisation d'outils comme Navilog ou des analyses complémentaires pour isoler et supprimer les éléments détectés. Pour mémoire, il est conseillé de vérifier les restes et d'effectuer un nettoyage approfondi tout en sauvegardant les données avant toute réinstallation.

Bobot (l’IA à votre service)
  1. ok attends d'avoir tout fini pour mettre en resolu quand meme :)
    0
    1. merci beaucoup a toi pour ton temps et ta patience, bonne continuation, je te poste le rapport tool cleaner des demain car la vé au dodo demain boulot a 7 h, encore merci pour tout ;-)
      0
      1. c'est bien ce que je pensais , on fait le menage :

        ▶ Télécharge :ATF Cleaner par Atribune

        Double-clique ATF-Cleaner.exe afin de lancer le programme.
        Sous l'onglet Main, choisis : Select All
        Clique sur le bouton Empty Selected
        Si tu utilises le navigateur Firefox :
        Clique Firefox au haut et choisis : Select All
        Clique le bouton Empty Selected a
        NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invité.
        Si tu utilises le navigateur Opera :
        Clique Opera au haut et choisis : Select All
        Clique le bouton Empty Selected
        NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invité.
        Clique Exit, du menu prinicipal, afin de fermer le programme.
        Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.

        __________________________________________________

        ▶ Tu peux garder ATF pour d'eventuels netttoyages un peu plus poussés
        __________________________________________________

        ▶---> Télécharge ToolsCleaner2sur ton Bureau.
        * Double-clique sur ToolsCleaner2.exe pour le lancer.
        * Clique sur Recherche et laisse le scan agir.
        * Clique sur Suppression pour finaliser.
        * Tu peux, si tu le souhaites, te servir des Options Facultatives.
        * Clique sur Quitter pour obtenir le rapport.
        * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
        ________________________________________________

        ▶ Tu peux supprimer ToolCleaner
        _________________________________________________

        ▶ Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :

        * Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
        * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
        * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse
        * Veille a ce que dans les options le reglage soit au demarrage de windows et réglé sur "effacement securisé" 35 passes (guttman)
        __________________________________________________

        Attention : ne pas toucher au PC pendant qu'il travaille !

        ▶ Nettoyage et Défragmentation de tes Disques

        *Nettoyage :

        Clic droit sur "poste de travail"(ordinateur pour vista) ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Général"
        Cliques sur le bouton "nettoyage de disque", OK
        tu le fais pour chacun de tes disques
        ________________________________________________

        *Vérifications des erreurs :

        Clic droit sur "poste de travail"(ordinateur pour vista) ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Outil"
        "Vérifier maintenant", une boîte s'ouvre, cocher les cases :
        -réparer automatiquement les erreurs...
        -rechercher et tenter une récupération...

        --->Démarrer, ok
        Note : s'il te dis de redémarrer ton Pc pour le faire , tu redémarres et tu laisses faire, cela prend un peu de temps c'est normal
        tu le fais pour chacun de tes disques
        ________________________________________________

        ensuite toujours dans le même onglet tu choisis :

        *Défragmentation :
        "défragmenter maintenant", OK
        une boîte s'ouvre, tu sélectionnes le disque à défragmenter, et tu cliques sur "analyser", puis après l'analyse, "défragmenter" . OK
        tu le fais pour chacun de tes disques
        _______________________________________________

        Note : si tu as un utilitaire pour défragmenter , utilises le à la place

        pour ce faire Defraggler est proposé
        _________________________________________________

        ▶ Peux-tu vérifier ta Console Java ? :

        et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).

        voici pour desinstaller :

        JavaRa

        Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
        * Double-clique sur le répertoire JavaRa.
        * Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
        * Choisis Français puis clique sur Select.
        * Clique sur Recherche de mises à jour.
        * Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
        * Autorise le processus à se connecter s'il le demande, clique sur Installer et suis les instructions d'installation qui prennent quelques minutes.
        * L'installation est terminée, reviens à l'écran de JavaRa et clique sur Effacer les anciennes versions.
        * Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
        * Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
        * Ferme l'application.

        Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.

        _________________________________________________

        ▶ Mets à jour Adobe Reader si ce n'est pas le cas (désinstalle avant la version antérieure)
        __________________________________________________

        ▶ Je te conseille si tu n en as pas , afin de mieux securiser ton pc , d'installer un parefeu :

        Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO

        https://www.commentcamarche.net/telecharger/securite/16545-online-armor-personal-firewall/
        https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
        https://forum.pcastuces.com/sujet.asp?f=25&s=35606
        https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
        https://manuelsdaide.com/contact/
        http://www.open-files.com/forum/index.php?showtopic=29277
        https://www.commentcamarche.net/telecharger/securite/24863-zonealarm/
        ___________________________________________________

        ▶ Tu peux aussi vider ta corbeille,quoi que Ccleaner le fasse tout seul
        _____________________________________________________

        ▶ Si nous avons utilisé MalwareByte's Anti-Malware , vide sa quarantaine :

        * Lance le programme puis clique sur <Quarantaine>.
        * Sélectionne tous les éléments puis clique sur <supprimer>.
        * Quitte le programme.
        ______________________________________________________

        ▶ si tu as installé Antivir :

        Configuration
        ________________________________________________________

        ▶ Idem pour ton antivirus : vide sa quarantaine si ce n'est pas déjà fait
        ______________________________________________________

        ▶ Désactive et réactive la restauration de système, pour cela : suis les instructions du lien :

        Lien XP

        Lien Vista

        ▶ Sitôt fait , recrées un point de restoration dit "sain" pour parer à quelques eventuels problêmes dans le futur
        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Quelques conseils et recommandations pour l'avenir :

        ▶ Passe un coup de MalwareByte's Anti-Malware de temps en temps (1 fois par semaine , suivant l'utilisation que tu fais de ton PC.
        ▶ Utilise aussi tes autres logiciels de protection (scannes antivirus, antispywares...). N'oublie pas de faire les mises à jour avant de les utiliser.
        * Pense aussi à faire une défragmentation de tes disques durs de temps en temps (garde suffisamment d'espace sur C:\ (1/3 de libre pour être à l'aise))
        _____________

        ▶ Pour bien protéger ton PC :
        [1 seul Antivirus] + [1 seul Pare feu] + [Un bon Antispyware avec immunisation] + [Mises à Jour récentes Windows et Logiciels de Protection] + [Utilisation de Firefox -ou autres- (Internet Explorer présente des failles de sécurité qui mettent longtemps avant d'être corrigées mais il faut absolument le conserver pour les mises à jour Windows et Windows live Messenger)]

        Je te conseille d'installer cette extension pour Firefox pour securiser ton surf : WOT
        Je te conseille d'installer cette extension pour Internet Explorer pour securiser ton surf : WOT

        PS : En fait la meilleure des protections c'est toi même : ce que tu fais avec ton PC : où tu surfes, télécharges...ect....
        Les virus utilisent les failles de ton PC pour infecter un système

        ▶ dans le souhait de vouloir desinstaller un antivirus au profit d'un autre , voici quelques liens :

        Desinstaller Avast
        Desinstaller BitDefender
        Desinstaller Norton
        Desinstaller Kaspersky
        Desinstaller AVG

        ou tout en un :

        Désinstallation Antivirus , Parefeu , Antispyware
        _____________

        ▶ SpywareBlaster = petit logiciel qui bloque l'installation d'activeX nuisibles au PC.(Fonctionne en arrière plan)

        ____________

        ▶ Si tu as Vista n'oublie pas de réactiver le controle des comptes des utilisateurs(UAC)
        ___________

        ▶ Si tu as Spybot S&D et que nous avons desactive le "Tea-timer" tu peux le réactiver
        ___________

        ▶ si nous avons affiché les fichiers cachés , n'oublies pas de les remettre en attribut "caché"
        ____________

        Voila,

        Bonne lecture, à bientot , une fois tout ceci fait,

        tu peux mettre le topic en resolu

        Bonne continuation et surtout , prudence et bon surf :)

        0
        1. bien tu ne l'as donc plus même apres un certain temps d'utilisation ?
          0
          1. c'est a dire ? pour ma par le principal soucis qui etait cette fenetre d'un pseudo nettoyeur qui s'ouvrait intempestivement a l'allumage du pc et me bloquait toutes fonctions possible, je ne voit rien d'autre
            0
            1. voici le rapport SAS

              SUPERAntiSpyware Scan Log
              https://www.superantispyware.com/

              Generated 08/04/2009 at 09:44 PM

              Application Version : 4.27.1000

              Core Rules Database Version : 4037
              Trace Rules Database Version: 1977

              Scan type : Custom Scan
              Total Scan Time : 00:35:38

              Memory items scanned : 493
              Memory threats detected : 0
              Registry items scanned : 5149
              Registry threats detected : 0
              File items scanned : 27172
              File threats detected : 425

              Adware.Tracking Cookie
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@weborama[2].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@boursoramabanque.solution.weborama[3].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@msnportal.112.2o7[2].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@atdmt[3].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@smartadserver[2].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@doubleclick[2].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@xiti[2].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@revsci[2].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@advertising[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@perf.overture[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@media.adrevolver[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@xiti[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@zedo[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@virginmobile.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@tradedoubler[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@247realmedia[3].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@247realmedia[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@mediaplex[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adtech[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adtech[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@tradedoubler[4].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@tradedoubler[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adviva[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@batiwebgroupe.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adrevolver[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@weborama[3].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@cms.trafficmp[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@himedia.individuad[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@cms.trafficmp[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@sexyavenue[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.googleadservices[10].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@fr.at.atwola[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.googleadservices[11].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@ww251.smartadserver[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@fl01.ct2.comclick[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@track.webgains[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@ad.yieldmanager[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@fr.at.atwola[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@ad.yieldmanager[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@optimost[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@ad.yieldmanager[3].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@d2.advertserve[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@ads.traffic-o-rama[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@ad.yieldmanager[5].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@converse.112.2o7[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@autoscout24.112.2o7[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@track.effiliation[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.googleadservices[5].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.googleadservices[6].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.googleadservices[3].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.googleadservices[4].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.googleadservices[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.googleadservices[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@advertising[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@leviseu.122.2o7[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@track.effiliation[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@tribalfusion[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@blancheporte.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@blancheporte.solution.weborama[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@track.effiliation[3].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@aimfar.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www3.smartadserver[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@boursoramabanque.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@advertising[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@votremagasingalerieslafayette.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.googleadservices[9].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.googleadservices[7].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.googleadservices[8].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@118218.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.sexyavenue[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.smartadserver[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adserver.bleucom[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.smartadserver[3].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adserver.keltravo[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@server.iad.liveperson[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@tracking.veille-referencement[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@advertstream[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@windowslivemessenger.solution.weborama[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@vivelledop.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@cetelem.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@media.photobucket[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@ad.cotecine[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@serving-sys[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@soixante-sexdu66.skyrock[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@lascad.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@directtrack[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@apmebf[3].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@apmebf[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@banquepopulaire.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@mediastay.directtrack[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@2o7[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adserver.aol[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adserving.favorit-network[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adserving.favorit-network[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@nike.112.2o7[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adserver.sevenload[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@data.coremetrics[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adfarm1.adition[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@uk.at.atwola[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@bwincom.122.2o7[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@imrworldwide[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@bluestreak[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@lfstmedia[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@doubleclick[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@msnportal.112.2o7[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@atdmt[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@ww57.smartadserver[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@smartadserver[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@fnacmagasin.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@content.yieldmanager[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@content.yieldmanager[3].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@stat.dealtime[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@myroitracking[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@yourmedia[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@a.websponsors[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@ads.eorezo[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@stats.equinoa[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@specificclick[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@overture[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@bs.serving-sys[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@a.websponsors[3].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@ttbdurex.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@t.bbtrack[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@tracking.publicidees[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@t.bbtrack[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@samsung.solution.weborama[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@fastclick[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@stats.searchtrack[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@fastclick[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@ad.zanox[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@clicksor[2].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@adv.bewebmedia[1].txt
              C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@x-beach-and-sex.skyrock[1].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@msnportal.112.2o7[1].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@118218.solution.weborama[2].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@weborama[1].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@atdmt[1].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@boursoramabanque.solution.weborama[2].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@smartadserver[1].txt
              C:\Documents and Settings\fabiienne\Cookies\fabiienne@xiti[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@sexandtrash[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@lorealpariselseve.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@1800.stats.misstrends[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@tracking.publicidees[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@clickz.lonelycheatingwives[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@atdmt[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.highmetrics[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@doubleclick[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@doubleclick[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@rm.piximedia[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@tracking.publicidees[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@clickintext[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@clickintext[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.pointroll[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@a.websponsors[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@castorama.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.adtrak[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.zetrack[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@adserver.aol[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@virginmobile.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@overture[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@pornhub[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@pornhub[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.canalblog[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.web-mediaplayer[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@socialmedia[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@banner.eurogrand[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ad.yieldmanager[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ad.yieldmanager[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@optimost[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.sorpresor[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@banner.eurogrand[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@1-porno[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck me play rugby@server.lon.liveperson[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@optimost[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@boursoramabanque.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@a.websponsors[4].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@a.websponsors[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@apmebf[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@himedia.individuad[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.widgetbucks[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.porno-gratuit[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@nestlecereals.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@toplist[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@youporn[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@youporn[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@xxx-concour-2008-xxx.skyrock[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.realtechnetwork[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@smartadserver[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@smartadserver[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@pornhub[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.crakmedia[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.videosdesexe[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@pornhub.brazzers[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@multimedia.ftpk[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@web-mediaplayer[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.xxxblackbook[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@stat.hi-pi[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@xxx-luxury-boy-xxx.skyrock[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@adtech[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@mediastay.directtrack[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@mediastay.directtrack[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@cityclub.gamingpromo[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@atwola[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.easy-forex[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@content.yieldmanager[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@stat.blogorama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@xxxmode-lovexxx.skyrock[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@mediatis[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@adviva[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@stats.adbrite[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.boonty[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@mediatis[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@porn-hub[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.domainsuite[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads2.k8l[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@d2.advertserve[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@youporn.videobox[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@3.adbrite[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@d2.advertserve[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@sexinyourcity[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.archiveporno[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@cdiscount[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.archiveporno[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@chitika[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@adfarm1.adition[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@xxxblackbook[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.sexe-au-bois[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.sites-de-sexe[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@weborama[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ushuaia.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@extrait-sexe[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@cdiscount[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@segafredovirginradiotour.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@windowslivemessenger.solution.weborama[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@media.adrevolver[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.sexyavenue[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.googleadservices[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@media6degrees[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@banners.sites-de-sexe[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@enhance[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@secure.archiveporno[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@secure.archiveporno[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.pornhublive[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.googleadservices[6].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@eas.apm.emediate[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@yourmedia[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@adsby.zwoops[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@livecams.youporn[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.googleadservices[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@eas.apm.emediate[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck me play rugby@xiti[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@fl01.ct2.comclick[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.k8l[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.googleadservices[4].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@bluestreak[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@rts.pgmediaserve[4].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@pool2.stolenpornpasswords[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@bluestreak[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@amateur2sexe[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@premiere.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@mediaplex[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@rts.pgmediaserve[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.discountrealitysites[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@bluestreak[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@tracker.affistats[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@tracker.affistats[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@rts.pgmediaserve[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@adserver.adreactor[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck me play rugby@xxx-just-3ll3-xxx.skyrock[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@bluestreak[4].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ad.zanox[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@hypertracker[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ad.zanox[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@dvd.pornhub[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@zedo[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@cetelem.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@banners.searchingbooth[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@adopt.specificclick[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@collective-media[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ad.zanox[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@dynamic.media.adrevolver[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@track.effiliation[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@track.effiliation[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.openx[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@youporngay[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@vivelledop.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@1734.stats.misstrends[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@aem.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@adv.surinter[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@youporngay[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@vivelledop.solution.weborama[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.1-porno[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@partyfriendfinder[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads4.blastro[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.oxistats[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@finder-x[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.ftpk[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@sr2.livemediasrv[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@bs.serving-sys[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@xiti[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@richmedia.yahoo[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.kiaramedia[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@banner.joylandcasino[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.hotbar[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@bs.serving-sys[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@zanox[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.pornhub[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.pornhub[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@track.espaceclient[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.us.e-planning[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@pornhublive[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@sr2.livemediasrv[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.kiaramedia[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck me play rugby@yourmedia[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.counter.orditona[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@banner.cotedazurpalace[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@pornravage[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@kjr72.bestrevenue[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@kjr72.bestrevenue[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@banner.cotedazurpalace[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@banner.32vegas[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@sexual-r0ck.skyrock[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@gamingpromo[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@pubs.sites-de-sexe[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@pornravage[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@banner.32vegas[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@stats.advertmaster[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@msnaccountservices.112.2o7[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@rugbysex.skyrock[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@advertstream[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@stats.searchtrack[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@stats.searchtrack[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@fastclick[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@banner.cdpoker[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@spamblockerutility[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ad.caradisiac[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@zanox.promovacances[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@zanox.promovacances[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@stats.advertmaster[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@nextag[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@banner.cdpoker[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@nextag[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@hotbar[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@mediatraffic[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.mediatis[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@at.atwola[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.adomos[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.mediatis[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ad-self[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@lfstmedia[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.mediatis[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.socialreach[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@serving-sys[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@serving-sys[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@serving-sys[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ad2.doublepimp[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@604.stats.misstrends[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@803.stats.misstrends[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@mediatraffic[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.glispa[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@xxx-ramountcho-xxx.skyrock[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@t.bbtrack[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@virginradio.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@pub.sexyvideos[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@questionmarket[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ad.ieurop[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@notrefamille.112.2o7[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.react2media[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@xxx-et0iile-66-xxx.skyrock[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@sex-rugby-alcol.skyrock[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@xxx-et0iile-66-xxx.skyrock[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@directtrack[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@directtrack[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.sexezoom[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@t.bbtrack[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@msnportal.112.2o7[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@virgin17.solution.weborama[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@247realmedia[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@2o7[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@adrevolver[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads-dev.youporn[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads-dev.youporn[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@ads.react2media[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@advertising[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@aimfar.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@atdmt[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@atdmt[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@azjmp[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@click.cashengines[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@cnam.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@date.ventivmedia[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@discountrealitysites[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@euroclick[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@imrworldwide[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@imrworldwide[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@interhome.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@kitkat.solution.weborama[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@leblogsexe[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@media.photobucket[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@media.sensis.com[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@nestleextreme.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@pornotube[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@samsung.solution.weborama[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@specificclick[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@stats.canalblog[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@topdesexe[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@trackers.1st-affiliation[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@tracking.veille-referencement[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@tradedoubler[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@tradedoubler[3].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@vodka-pomm3-xxx.skyrock[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.ads-click[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.finder-x[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.sexandtrash[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@www.sexyvideos[2].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@xxx-0ver-drive-xxx.skyrock[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@xxx-emotik-girl-xxx.skyrock[1].txt
              C:\Documents and Settings\SUCK ME PLAY RUGBY\Cookies\suck_me_play_rugby@zbox.zanox[1].txt
              C:\Lop SD\Backup-Lop\DOCUME~1\FABIIE~1\Cookies\fabiienne@advertising[1].txt
              C:\Program Files\Ad-remover\QUARANTINE\DOCUME~1\SUCKME~1\Cookies\suck_me_play_rugby@partypoker[1].txt.vir
              C:\Program Files\Ad-remover\QUARANTINE\DOCUME~1\SUCKME~1\Cookies\suck_me_play_rugby@ads.eorezo[1].txt.vir
              C:\Program Files\Ad-remover\QUARANTINE\DOCUME~1\SUCKME~1\Cookies\suck_me_play_rugby@ads.eorezo[3].txt.vir

              Adware.Vundo/Variant-MSFake
              C:\PROGRAM FILES\NAVILOG1\REG.EXE
              0
              1. desinstalle Navilog

                ▶ Télécharge Superantispyware (SAS)

                ▶ Choisis "enregistrer" et enregistre-le sur ton bureau.

                ▶ Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

                ▶ Créé une icône sur le bureau.

                ▶ Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

                ▶- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
                ▶- Sous Configuration and Preferences, clique sur le bouton "Preferences"
                ▶- Clique sur l'onglet "Scanning Control "
                ▶- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

                ▶Close browsers before scanning
                ▶Scan for tracking cookies
                ▶Terminate memory threats before quarantining

                ▶ Laisse les autres lignes décochées.

                ▶ Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

                ▶ Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

                ▶ Dans la colonne de gauche, coche C:\Fixed Drive.

                ▶ Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

                ▶ Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

                ▶ A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

                ▶ Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

                ▶ Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

                Pour recopier les informations sur le forum, fais ceci :

                ▶ - après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
                ▶ - Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
                ▶- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

                ▶ - Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

                ▶ - Copie son contenu dans ta réponse.

                Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
                0
                1. voici le rapport navilog

                  Fix Navipromo version 4.0.1 commencé le 04/08/2009 20:04:03,14

                  !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                  !!! Postez ce rapport sur le forum pour le faire analyser !!!

                  Outil exécuté depuis C:\Program Files\navilog1

                  Mise à jour le 18.07.2009 à 11h00 par IL-MAFIOSO

                  Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                  X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
                  BIOS : Phoenix - Award BIOS v6.00PG
                  USER : fabiienne ( Administrator )
                  BOOT : Normal boot

                  Antivirus : Avira AntiVir PersonalEdition Classic 8.0.1.30 (Activated)

                  C:\ (Local Disk) - NTFS - Total:179 Go (Free:138 Go)
                  D:\ (Local Disk) - FAT32 - Total:6 Go (Free:3 Go)
                  E:\ (CD or DVD)
                  G:\ (USB)
                  H:\ (USB)
                  I:\ (USB)
                  J:\ (USB)

                  Recherche executée en mode normal

                  [b]Aucune Infection Navipromo/Egdaccess trouvé/b

                  *** Scan terminé 04/08/2009 20:13:28,42 ***
                  0
                  1. bon il faut voir s il n y a pas de restes :

                    Télécharge Navilog1 depuis-ce lien

                    ▶ Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                    ▶ Ensuite double clique sur navilog1.exe pour lancer l'installation.

                    Une fois l'installation terminée, le fix s'exécutera automatiquement.

                    ▶ Au menu principal, Fais le choix 1 >> Recherche / suppression automatique

                    Patiente jusqu'au message :
                    *** Analyse Termine le ..... ***

                    >>>>> Le fix peut durer une dizaine de minutes ;)

                    ▶ Appuie sur une touche le bloc note va s'ouvrir.

                    ▶ Copie-colle le rapport ici.

                    0
                    1. dans ce cas comment se fait il que Malwarebytes ait supprimé Navipromo que Combofix et moi meme n'avons pas vu ?
                      0
                      1. Rien n'as ete effectuer sur mon pc pendant la manip, il y a eu seulement des fenetres qui ce sont ouvertes que j' ai du fermer car le scan ne continuait pas sans ca,
                        0
                        1. tu veux bien arrêter de faire n importe quoi avec ton pc pendant la desinfection stp ???
                          0
                          1. Voici le rapport demande

                            Malwarebytes' Anti-Malware 1.40
                            Version de la base de données: 2557
                            Windows 5.1.2600 Service Pack 3

                            04/08/2009 15:21:51
                            mbam-log-2009-08-04 (15-21-51).txt

                            Type de recherche: Examen complet (C:\|D:\|E:\|G:\|H:\|I:\|J:\|)
                            Eléments examinés: 235388
                            Temps écoulé: 1 hour(s), 27 minute(s), 23 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 0
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 1
                            Fichier(s) infecté(s): 26

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            C:\Documents and Settings\Compaq_Propriétaire\Application Data\WinTouch (Adware.WinPop) -> Quarantined and deleted successfully.

                            Fichier(s) infecté(s):
                            C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\kymiq_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\kymiq_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\kymiq.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Application Data\kymiq.exe (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                            C:\Program Files\Ad-remover\QUARANTINE\DOCUME~1\SUCKME~1\APPLIC~1\EoRezo\SoftwareUpdate.exe.vir (Adware.EoRezo) -> Quarantined and deleted successfully.
                            C:\Program Files\Ad-remover\QUARANTINE\DOCUME~1\SUCKME~1\APPLIC~1\EoRezo\SoftwareUpdateHP.exe.vir (Adware.EoRezo) -> Quarantined and deleted successfully.
                            C:\Program Files\Ad-remover\QUARANTINE\PROGRA~1\EoRezo\EoAdv.dll.vir (Adware.EoRezo) -> Quarantined and deleted successfully.
                            C:\Program Files\Ad-remover\QUARANTINE\PROGRA~1\EoRezo\EoEngine.exe.vir (Adware.EoRezo) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP228\A0486918.exe (Adware.EoRezo) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP228\A0486926.dll (Adware.EoRezo) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP245\A0497360.dll (Adware.EoRezo) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP245\A0497367.exe (Adware.EoRezo) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP245\A0497393.exe (Adware.EoRezo) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP245\A0497392.exe (Adware.EoRezo) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP245\A0497420.exe (Rogue.AVCare) -> Quarantined and deleted successfully.
                            C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP245\A0497422.exe (Rogue.AVCare) -> Quarantined and deleted successfully.
                            C:\_OTL\MovedFiles\08042009_002131\Qoobox\Quarantine\C\DOCUME~1\ALLUSE~1\APPLIC~1\16970934\16970934.exe.vir (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
                            C:\_OTL\MovedFiles\08042009_002131\Qoobox\Quarantine\C\WINDOWS\msa.exe.vir (Trojan-Agent) -> Quarantined and deleted successfully.
                            C:\_OTL\MovedFiles\08042009_002131\Qoobox\Quarantine\C\WINDOWS\system32\msxml71.dll.vir (Trojan.Downloader) -> Quarantined and deleted successfully.
                            C:\_OTL\MovedFiles\08042009_002131\Qoobox\Quarantine\C\WINDOWS\system32\UACfacxewqwev.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
                            C:\_OTL\MovedFiles\08042009_002131\Qoobox\Quarantine\C\WINDOWS\system32\UACfpxuequmpd.dll.vir (Rogue.Agent) -> Quarantined and deleted successfully.
                            C:\_OTL\MovedFiles\08042009_002131\Qoobox\Quarantine\C\WINDOWS\system32\UACpymcqftapp.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
                            C:\_OTL\MovedFiles\08042009_002131\Qoobox\Quarantine\C\WINDOWS\system32\UACxvswxjpwip.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
                            C:\_OTL\MovedFiles\08042009_002131\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACxvcchtrpph.sys.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Compaq_Propriétaire\Application Data\WinTouch\wintouch.cfg (Adware.WinPop) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Compaq_Propriétaire\Bureau\System Security 2009.lnk (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
                            0
                            1. ▶ Double clic sur OTL.exe pour le lancer.

                              ▶Copie la liste qui se trouve en gras ci-dessous,

                              ▶ colle-la dans la zone sous Customs Scans/Fixes :

                              :processes
                              explorer.exe
                              iexplore.exe
                              firefox.exe
                              msnmsgr.exe
                              TeaTimer.exe

                              :OTL
                              O2 - BHO: (no name) - {64F56FC1-1272-44CD-BA6E-39723696E350} - No CLSID value found.
                              O2 - BHO: (no name) - {C7B76B90-3455-4AE6-A752-EAC4D19689E5} - No CLSID value found.
                              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Reg Error: Key error.)
                              O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Reg Error: Key error.)

                              :commands
                              [emptytemp]
                              [start explorer]
                              [reboot]

                              ▶ Clique sur RunFix pour lancer la suppression.

                              ▶ Poste le rapport

                              ensuite :

                              Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                              ▶ Télécharges :

                              Malwarebytes

                              ou :

                              Malwarebytes

                              ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                              (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                              ▶ Potasses le Tuto pour te familiariser avec le prg :

                              ( cela dit, il est très simple d'utilisation ).

                              relance malwarebytes en suivant scrupuleusement ces consignes :

                              ! Déconnecte toi et ferme toutes applications en cours !

                              ▶ Lance Malwarebyte's .

                              Fais un examen dit "Complet" .

                              ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                              ▶ à la fin tu cliques sur "résultat" .
                              ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                              ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                              ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                              0
                              1. http://www.cijoint.fr/cjlink.php?file=cj200908/cijDDlp0Ap.txt
                                0
                                1. ok refais le scan d'OTL stp comme indiqué plus haut par cijoint.fr
                                  0
                                  1. j ai 2 rapport de genere, les voici

                                    Files\Folders moved on Reboot...
                                    File\Folder C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk not found!
                                    C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\desktop.ini moved successfully.
                                    C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\FHV3KUKQ\desktop.ini moved successfully.
                                    C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\EY2V9AVC\desktop.ini moved successfully.
                                    C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\B1978PHD\desktop.ini moved successfully.
                                    C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\55KYG4S1\desktop.ini moved successfully.
                                    C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\desktop.ini moved successfully.
                                    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\XF17AFSA\desktop.ini moved successfully.
                                    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KEYMV7GC\desktop.ini moved successfully.
                                    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\JW8WCYVZ\desktop.ini moved successfully.
                                    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DVA2DMGG\desktop.ini moved successfully.
                                    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini moved successfully.
                                    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\desktop.ini moved successfully.
                                    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\W3AZNAQT\desktop.ini moved successfully.
                                    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\A0D6BDCR\desktop.ini moved successfully.
                                    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\7UFOVJTZ\desktop.ini moved successfully.
                                    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\151TLXQM\desktop.ini moved successfully.
                                    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini moved successfully.
                                    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\desktop.ini moved successfully.
                                    C:\WINDOWS\002889_.tmp moved successfully.
                                    C:\WINDOWS\msdownld.tmp moved successfully.
                                    C:\WINDOWS\System32\CONFIG.TMP moved successfully.
                                    C:\WINDOWS\System32\SET72.tmp moved successfully.
                                    C:\WINDOWS\System32\SET74.tmp moved successfully.
                                    C:\WINDOWS\System32\SET79.tmp moved successfully.
                                    C:\WINDOWS\System32\SET80.tmp moved successfully.
                                    File\Folder C:\WINDOWS\temp\logishrd\LVPrcInj01.dll not found!
                                    C:\WINDOWS\temp\LVCOMSX.LOG moved successfully.

                                    Registry entries deleted on Reboot...

                                    et le second

                                    All processes killed
                                    ========== PROCESSES ==========
                                    Process explorer.exe killed successfully!
                                    No active process named iexplore.exe was found!
                                    No active process named firefox.exe was found!
                                    No active process named msnmsgr.exe was found!
                                    No active process named TeaTimer.exe was found!
                                    ========== OTL ==========
                                    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{090058F0-4A54-401C-BFD2-C4D3644B87C7}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{090058F0-4A54-401C-BFD2-C4D3644B87C7}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2148CE21-EB54-4369-8E8F-C1B9CD0C6322}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2148CE21-EB54-4369-8E8F-C1B9CD0C6322}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A08F9C7-4FAF-424A-BB9F-1ADDEB92BF48}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A08F9C7-4FAF-424A-BB9F-1ADDEB92BF48}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3834C4C7-7107-5888-0016-5900CAB4819F}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3834C4C7-7107-5888-0016-5900CAB4819F}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E34C4B5-7107-5BFA-0013-5A00BFC08199}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E34C4B5-7107-5BFA-0013-5A00BFC08199}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
                                    File move failed. C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk scheduled to be moved on reboot.
                                    File C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe not found.
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ not found.
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ not found.
                                    File C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll not found.
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ipp\ not found.
                                    File Protocol\Handler\ipp - No CLSID value found not found.
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ not found.
                                    File Protocol\Handler\msdaipp - No CLSID value found not found.
                                    ========== REGISTRY ==========
                                    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz not found.
                                    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task not found.
                                    Registry key HKEY_USERS\S-1-5-21-2771654111-942230600-1761531002-1010..\Software\Microsoft\Windows\CurrentVersion\Run not found.
                                    Registry key HKEY_USERS\S-1-5-21-2771654111-942230600-1761531002-1010..\Software\Microsoft\Windows\CurrentVersion\Run not found.
                                    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA4228 not found.
                                    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC5353 not found.
                                    ========== FILES ==========
                                    File\Folder C:\WINDOWS\PEV.exe not found.
                                    File\Folder C:\Qoobox not found.
                                    File\Folder C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job not found.
                                    File\Folder C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job not found.
                                    File\Folder C:\WINDOWS\System32\67422E-02 not found.
                                    File\Folder C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} not found.
                                    ========== COMMANDS ==========

                                    [EMPTYTEMP]

                                    User: Administrateur
                                    ->Temp folder emptied: 0 bytes
                                    ->Temporary Internet Files folder emptied: 33170 bytes

                                    User: All Users

                                    User: Compaq_Propriétaire
                                    File delete failed. C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\IEC5.tmp scheduled to be deleted on reboot.
                                    File delete failed. C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\IECC.tmp scheduled to be deleted on reboot.
                                    ->Temp folder emptied: 747430 bytes
                                    ->Temporary Internet Files folder emptied: 12000236 bytes

                                    User: Default User
                                    ->Temp folder emptied: 0 bytes
                                    ->Temporary Internet Files folder emptied: 0 bytes

                                    User: fabiienne
                                    ->Temp folder emptied: 0 bytes
                                    ->Temporary Internet Files folder emptied: 2431299 bytes
                                    ->Java cache emptied: 0 bytes
                                    ->Apple Safari cache emptied: 0 bytes

                                    User: LocalService
                                    ->Temp folder emptied: 65536 bytes
                                    ->Temporary Internet Files folder emptied: 32768 bytes

                                    User: NetworkService
                                    ->Temp folder emptied: 0 bytes
                                    ->Temporary Internet Files folder emptied: 32768 bytes

                                    User: SUCK ME PLAY RUGBY
                                    ->Temp folder emptied: 1035606905 bytes
                                    ->Temporary Internet Files folder emptied: 373795 bytes
                                    ->Java cache emptied: 231690 bytes
                                    ->Apple Safari cache emptied: 37274587 bytes

                                    %systemdrive% .tmp files removed: 0 bytes
                                    %systemroot% .tmp files removed: 0 bytes
                                    %systemroot%\System32 .tmp files removed: 0 bytes
                                    Windows Temp folder emptied: 0 bytes
                                    RecycleBin emptied: 3172420 bytes

                                    Total Files Cleaned = 1041,41 mb

                                    OTL by OldTimer - Version 3.0.10.4 log created on 08042009_124708
                                    0
                                    • 1
                                    • 2
                                    • 3