[résolu] Trojan récalcitrant
Forum Sécurité - Virus : [résolu] Trojan récalcitrant
Bonjour,
Je rencontre des problèmes depuis quelques temps avec trojan dropper qui sont apparus au travers de mns, en envoyant des liens à tous mes contacts, j'ai essayé msn fix qui ne détecte rien.
En revanche a-squared détecte plusieurs trojan qui restent malgré l'élimination.
Pourriez-vous m'aider?
Merci
Message édité par keymiloup le 21-06-2009 à 17:38:21
Bonjour,
- Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
- Double-clique sur RSIT.exe afin de lancer le programme.
(Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)
- Clique sur Continue à l'écran Disclaimer.
- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
Note : les rapports sont sauvegardés dans le dossier C:\rsit.
Bonjour,
voici les rapports:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Celine at 2009-06-20 15:34:13
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 281 GB (92%) free of 305 GB
Total RAM: 2046 MB (38% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:34:21, on 20/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\UMStor\Res.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\a-squared Free\a2free.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\SphinxV5\Sphinx.exe
C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE
C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCview.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Celine\Bureau\RSIT.exe
C:\Program Files\trend micro\Celine.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O2 - BHO: PDF-XChange Viewer IE-Plugin - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [USB Storage Toolbox] C:\WINDOWS\UMStor\Res.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [RegistryBooster 2 d’Uniblue ] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Ekiga.lnk = C:\Program Files\Ekiga\ekiga.exe
O4 - Startup: ex-fumeurs.lnk = C:\Program Files\ex-fumeurs\ex-fumeurs.exe
O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: OpenOffice.org 3.0.lnk.disabled
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Docteur Club Internet.lnk.disabled
O4 - Global Startup: WinZip Quick Pick.lnk.disabled
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.04\AMVConverter\grab.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/micros [...] 9021722828
O17 - HKLM\System\CCS\Services\Tcpip\..\{24AB0520-3295-4062-90D6-60FBF4F747A7}: NameServer = 86.64.145.140,84.103.237.140
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 13282 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\A3310BBC91B2BEDC.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-06-02 1082880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]
PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-06-10 2094616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-05-07 259696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-05-07 668656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F}]
PDF-XChange Viewer IE-Plugin - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll [2009-03-30 1092888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-05-07 470512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-11-12 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll [2009-01-30 1114112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-06-10 2094616]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-05-07 259696]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-05-10 16342528]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-02 86016]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-02 13529088]
"NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"BJCFD"=C:\Program Files\BroadJump\Client Foundation\CFD.exe [2003-01-27 376912]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2007-10-10 36352]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-04-10 148888]
"USB Storage Toolbox"=C:\WINDOWS\UMStor\Res.EXE [2005-09-14 65536]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"Family Tree Builder Update"=C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2009-01-14 113680]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe [2009-01-30 992256]
"TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2009-02-06 185872]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-05-30 292136]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe [2008-08-21 443968]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-12-15 68856]
"RegistryBooster 2 d’Uniblue "=C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S []
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]
"Uniblue RegistryBooster 2009"=C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S []
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
Docteur Club Internet.lnk.disabled - C:\Program Files\Club-Internet\Dr Club Internet\bin\matcli.exe
WinZip Quick Pick.lnk.disabled - C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\Celine\Menu Démarrer\Programmes\Démarrage
Démarrage d'Office.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE
Ekiga.lnk - C:\Program Files\Ekiga\ekiga.exe
ex-fumeurs.lnk - C:\Program Files\ex-fumeurs\ex-fumeurs.exe
Microsoft Recherche accélérée.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
OpenOffice.org 3.0.lnk.disabled - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=4294967295
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\NeroExpress\Installation\Setupx.exe"="D:\NeroExpress\Installation\Setupx.exe:*:Enabled:Nero ProductSetup"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\SecondLife\SLVoice.exe"="C:\Program Files\SecondLife\SLVoice.exe:*
isabled:SLVoice"
"C:\Program Files\BitDownload\BitDownload.exe"="C:\Program Files\BitDownload\BitDownload.exe:*:Enabled:BitDownload"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\Program Files\Free Download Manager\fdm.exe"="C:\Program Files\Free Download Manager\fdm.exe:*:Enabled:Free Download Manager"
"DEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~ӟ"="DEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~ӟ:*:Enabled:Nod32 Service"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\SecondLife\SecondLife.exe"="C:\Program Files\SecondLife\SecondLife.exe:*:Enabled:Second Life"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Ekiga\ekiga.exe"="C:\Program Files\Ekiga\ekiga.exe:*
isabled:ekiga"
"C:\Python23\pythonw.exe"="C:\Python23\pythonw.exe:*:Enabled
ythonw"
"C:\Documents and Settings\Celine\Local Settings\Temp\Rar$EX02.468\eMule0.49c\emule.exe"="C:\Documents and Settings\Celine\Local Settings\Temp\Rar$EX02.468\eMule0.49c\emule.exe:*:Enabled:eMule"
"C:\Program Files\Fichiers communs\Ahead\Nero Web\SetupX.exe"="C:\Program Files\Fichiers communs\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
"C:\Documents and Settings\Celine\Local Settings\Temp\Nero Web\SetupXu.exe"="C:\Documents and Settings\Celine\Local Settings\Temp\Nero Web\SetupXu.exe:*:Enabled:Nero ProductSetup"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
======List of files/folders created in the last 1 months======
2009-06-18 09:52:27 ----A---- C:\WINDOWS\msnfix.txt
2009-06-16 08:22:10 ----D---- C:\Documents and Settings\Celine\Application Data\vlc
2009-06-16 08:21:52 ----D---- C:\Documents and Settings\Celine\Application Data\dvdcss
2009-06-16 08:20:21 ----SHD---- C:\Config.Msi
2009-06-16 08:14:46 ----A---- C:\Documents and Settings\All Users\Application Data\vlc-0.9.9-win32.exe
2009-06-14 12:54:22 ----D---- C:\Program Files\Hotspot_Shield
2009-06-14 08:45:30 ----D---- C:\Program Files\Fichiers communs\Skype
2009-06-14 08:45:27 ----RD---- C:\Program Files\Skype
2009-06-11 09:17:43 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-06-11 09:17:37 ----HDC---- C:\WINDOWS\$NtUninstallKB969897$
2009-06-11 09:17:33 ----HDC---- C:\WINDOWS\$NtUninstallKB969898$
2009-06-11 09:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-06-11 09:15:41 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-06-06 23:27:40 ----D---- C:\Documents and Settings\Celine\Application Data\Help
2009-06-05 09:45:14 ----D---- C:\Program Files\iPod
2009-06-05 09:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-05 09:43:33 ----D---- C:\Program Files\QuickTime
2009-06-05 09:39:07 ----D---- C:\Program Files\Safari
2009-05-22 08:28:26 ----D---- C:\Documents and Settings\Celine\Application Data\GetRightToGo
======List of files/folders modified in the last 1 months======
2009-06-20 15:34:14 ----D---- C:\Program Files\trend micro
2009-06-20 15:32:48 ----D---- C:\WINDOWS\Prefetch
2009-06-20 14:26:06 ----AH---- C:\WINDOWS\system32\FFASTLOG.TXT
2009-06-20 12:10:47 ----D---- C:\Program Files\Mozilla Firefox
2009-06-20 10:53:59 ----D---- C:\Program Files\a-squared Free
2009-06-20 10:51:13 ----D---- C:\WINDOWS\Temp
2009-06-20 09:08:34 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-20 09:08:21 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-06-20 08:31:19 ----D---- C:\WINDOWS\Debug
2009-06-20 08:19:04 ----D---- C:\WINDOWS\system32\CatRoot2
2009-06-20 00:14:27 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-06-20 00:11:03 ----D---- C:\Documents and Settings\Celine\Application Data\Skype
2009-06-19 23:49:32 ----D---- C:\WINDOWS\system32
2009-06-19 23:18:38 ----A---- C:\WINDOWS\NeroDigital.ini
2009-06-19 22:24:34 ----RD---- C:\Program Files
2009-06-19 22:24:34 ----D---- C:\Program Files\Navilog1
2009-06-19 17:24:41 ----D---- C:\Documents and Settings\Celine\Application Data\skypePM
2009-06-19 07:41:16 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-06-18 15:55:34 ----D---- C:\WINDOWS
2009-06-18 09:51:33 ----D---- C:\unzipped
2009-06-18 08:57:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-18 08:57:31 ----D---- C:\WINDOWS\system32\drivers
2009-06-18 08:46:16 ----D---- C:\WINDOWS\Minidump
2009-06-16 08:21:17 ----SHD---- C:\WINDOWS\Installer
2009-06-16 08:20:49 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-06-16 08:19:24 ----D---- C:\Python23
2009-06-15 18:03:41 ----D---- C:\Program Files\eMule
2009-06-15 10:53:43 ----SHD---- C:\System Volume Information
2009-06-15 10:49:54 ----D---- C:\WINDOWS\repair
2009-06-15 10:49:49 ----D---- C:\WINDOWS\Registration
2009-06-14 12:54:15 ----HD---- C:\WINDOWS\inf
2009-06-14 08:45:30 ----D---- C:\Program Files\Fichiers communs
2009-06-14 08:45:30 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2009-06-12 07:21:25 ----D---- C:\Program Files\Bonjour
2009-06-12 07:20:59 ----D---- C:\Program Files\Winamp
2009-06-11 09:18:14 ----A---- C:\WINDOWS\win.ini
2009-06-11 09:17:45 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-06-11 09:17:33 ----HD---- C:\WINDOWS\$hf_mig$
2009-06-10 09:53:45 ----D---- C:\Program Files\PHPNukeFR
2009-06-08 10:35:03 ----D---- C:\Program Files\WinZip
2009-06-05 09:45:30 ----D---- C:\Program Files\iTunes
2009-06-05 09:45:13 ----D---- C:\Program Files\Fichiers communs\Apple
2009-06-05 09:37:46 ----D---- C:\Program Files\Windows Media Player
2009-06-01 09:51:14 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;Pilote de processeur AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 43520]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-02-13 28376]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-03-24 55640]
R2 CVPNDRVA;Cisco Systems IPsec Driver; \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys []
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2008-12-08 55136]
R3 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2007-01-24 127376]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-05-10 4419584]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12288]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-02 6554496]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-12-14 85120]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 catchme;catchme; \??\C:\DOCUME~1\Celine\LOCALS~1\Temp\catchme.sys []
S3 CVirtA;Cisco Systems VPN Adapter; C:\WINDOWS\system32\DRIVERS\CVirtA.sys [2007-01-18 5275]
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 ICDSX;Sony IC Recorder (SX); C:\WINDOWS\System32\Drivers\ICDSX.sys [2003-10-01 31744]
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 tapvpn;TAP VPN Adapter; C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2006-10-26 27136]
S3 vsdatant;vsdatant; \??\C:\WINDOWS\system32\vsdatant.sys []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2009-06-12 718880]
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2009-01-02 611664]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-03-02 185089]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-05-29 144712]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2007-07-16 1524512]
R2 fsssvc;Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-04-10 152984]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [2008-01-24 73728]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-02 159812]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-05-30 541992]
S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-01-30 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-07 182768]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-11-28 800040]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Service de partage de ports Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
-----------------EOF-----------------
Et le rapport info ?
oups pardon, le voilà
info.txt logfile of random's system information tool 1.06 2009-03-30 19:09:33
======Uninstall list======
-->C:\PROGRA~1\CLUB-I~1\DRCLUB~1\Uninstall.exe TONLFR
-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe AIR-->c:\Program Files\Fichiers communs\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Anchor Service CS3-->MsiExec.exe /I{A4464AC3-D85E-4649-8748-706191063DF6}
Adobe Asset Services CS3-->MsiExec.exe /I{7302810D-7ACF-4339-B27B-57016CAADDCD}
Adobe Bridge CS3-->MsiExec.exe /I{FABA59CC-347B-478B-B2A7-37BF0885CACB}
Adobe Bridge Start Meeting-->MsiExec.exe /I{CE52110A-7773-444F-9E5D-4A45E4792DB6}
Adobe Camera Raw 4.0-->MsiExec.exe /I{AED353B9-E6D7-406F-B007-2C55C5265EB3}
Adobe CMaps-->MsiExec.exe /I{D8FC8E35-D397-4C16-87AE-141A625221E4}
Adobe Default Language CS3-->MsiExec.exe /I{D446BA40-1F5F-44EB-A794-0AC14F809C79}
Adobe Device Central CS3-->MsiExec.exe /I{265FCC3B-4814-4B2B-89D6-217DFB8AD886}
Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{F36CFE58-47C0-4D75-995B-E0172563FA83}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Fonts All-->MsiExec.exe /I{162DDD86-C087-4E59-B7A8-0C1D8F884A9A}
Adobe Help Viewer 1.1-->MsiExec.exe /I{F3697BA5-C8D8-4925-ACCA-F486C76BAD33}
Adobe Linguistics CS3-->MsiExec.exe /I{E5C28906-EC86-404E-BB4F-6AB2590451FF}
Adobe PDF Library Files-->MsiExec.exe /I{91D829E6-F1D1-433F-861F-0552DFED0EAD}
Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\8d0dc9390f2c596455e1446b5918a40\Setup.exe
Adobe Photoshop CS3-->MsiExec.exe /I{F32F1F7C-322D-46B9-B69A-5C3EDC88B74C}
Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
Adobe Setup-->MsiExec.exe /I{CBF7A9A4-C0D4-4BA0-8991-C9B7D90A5298}
Adobe Stock Photos CS3-->MsiExec.exe /I{73B79E83-490B-460D-B0D6-2C7B73980325}
Adobe Type Support-->MsiExec.exe /I{A78A65E4-1D88-477A-83B4-3EC540F6A55A}
Adobe Version Cue CS3 Client-->MsiExec.exe /I{BF18C55F-791F-4C17-AB75-E397EE01C14B}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{51DC4D9C-F729-48A7-9CE0-BC77529ECCA2}
Adobe XMP Panels CS3-->MsiExec.exe /I{F0CF6455-EDD8-41C6-A96A-223874E660CC}
Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
AppSnap 1.3.0-->C:\Program Files\AppSnap\uninst.exe
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
a-squared Free 4.0-->"C:\Program Files\a-squared Free\unins000.exe"
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
BroadJump Client Foundation-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\BroadJump\Client Foundation\Uninst.isu" -c"C:\Program Files\BroadJump\Client Foundation\RmvBJCFD.dll" -b"CFD" -h"CFD" -a
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Configurateur Modem-->"C:\Program Files\Club-Internet\Assistance\uninstall.exe"
Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Docteur Club Internet-->C:\WINDOWS\Motive\TONLFR\MCCUninst.exe
DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
Earthsim-->"C:\Documents and Settings\All Users\Application Data\Earthsim\Channel\esuninst.exe"
eMule-->"C:\Program Files\eMule\Uninstall.exe"
eMusic - 50 Free MP3 offer-->"C:\Program Files\Winamp\eMusic\Uninst-eMusic-promotion.exe"
ex-fumeurs (désinstallation)-->"C:\Program Files\ex-fumeurs\uninst-ex-fumeurs.exe"
Favorit-->"c:\documents and settings\celine\local settings\application data\ikiwq.exe" -uninstall
ffdshow [rev 2033] [2008-07-05]-->"C:\Program Files\ffdshow\unins000.exe"
Finance 2003 version 10.03-->"C:\Program Files\SoftChris\Finance 2003\unins000.exe"
Flary Address-->MsiExec.exe /X{F618BFCB-BCD8-4698-BEE8-B0C5FD75DA23}
Free Download Manager 2.5 build 758-->C:\Program Files\Free Download Manager\uninst.exe
Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
Gimp 2.6.1-->"C:\Program Files\Gimp-2.0\setup\unins000.exe"
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
HijackThis 2.0.2-->"C:\Documents and Settings\Celine\Bureau\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
ID3 Lyrics Editor-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MP3\ID3EDIT\Uninst.isu"
Inkscape 0.46-->C:\Program Files\Inkscape\Uninstall.exe
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
Le Sphinx-->C:\SphinxV5\licence\UNWISE.EXE C:\SphinxV5\licence\install.log
Lecteur CANAL-->MsiExec.exe /X{04DA096D-6236-4A5D-8FB6-3081E67009BA}
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
LightScribe System Software 1.12.29.2-->MsiExec.exe /X{CF8C077A-B467-4C43-8DB5-3A9B94FF9681}
MadOnion.com/3DMark2001 SE-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{91B323B5-A79C-4D23-BD6D-046C565F9BCF}\Setup.exe" -l0x9 uninstall -uninst
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Media Player Classic fr-->"C:\Program Files\Media Player Classic\uninstall.exe"
Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2003 Web Components-->MsiExec.exe /I{90A4040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office 97 Professional-->C:\Program Files\Microsoft Office\Office\Install\Acme.exe /w Off97Pro.STF
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0120-040C-0000-0000000FF1CE}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office XP Web Components-->MsiExec.exe /I{9026040C-6000-11D3-8CFE-0150048383C9}
Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MozyHome Remote Backup-->MsiExec.exe /X{D2058971-12C7-46E2-9DDB-933C8A6D2051}
MP3 Player Utilities 4.00-->MsiExec.exe /I{7784A172-61F1-445E-8368-601607E0DD22}
MP3 Player Utilities 4.04-->MsiExec.exe /I{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Navilog1 3.7.6-->"C:\Program Files\Navilog1\unins000.exe"
Nero 7 Essentials-->MsiExec.exe /X{7BAA9BA8-0761-42EF-842A-23FAA5321036}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
OpenOffice.org 3.0-->MsiExec.exe /I{1572F66F-F9AD-4D45-B0D2-0F45A0D5A0F6}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Package de pilotes Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)-->C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\amdk8_C7A451815AD6A55564D6F47B5A12C61D8B4DCFD1\amdk8.inf
Paint.NET v3.36-->MsiExec.exe /X{43602F34-1AA3-44FB-AEB2-D08C2C73743F}
PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
PHPNukeFR Toolbar-->C:\PROGRA~1\PHPNUK~1\UNWISE.EXE /U C:\PROGRA~1\PHPNUK~1\INSTALL.LOG
Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe"
QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
REALTEK GbE & FE Ethernet PCI NIC Driver-->C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\SETUP.EXE -runfromtemp -l0x040c -removeonly
REALTEK GbE & FE Ethernet PCI-E NIC Driver-->C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x040c -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.EXE" -l0x40c -removeonly
SecondLife (remove only)-->"C:\Program Files\SecondLife\uninst.exe" /P="SecondLife"
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
The_Pirate_Bay Toolbar-->C:\PROGRA~1\THE_PI~1\UNWISE.EXE /U C:\PROGRA~1\THE_PI~1\INSTALL.LOG
USB Disk Win98 Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BF5EE349-90CD-4422-A43B-661778180173}\Setup.exe"
VLC media player 0.9.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
VPN Client-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5624C000-B109-11D4-9DB4-00E0290FCAC5}\Setup.exe" -l0x9 VpnUninstall
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
ZebHelpProcess 2.33-->"C:\Program Files\ZebHelpProcess 2\unins000.exe"
======Hosts File======
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
======Security center information======
AV: Avira AntiVir PersonalEdition Classic
======System event log======
Computer Name: PEREA-A88DA7661
Event Code: 51
Message: Une erreur a été détectée sur le périphérique \Device\Harddisk6\D au cours d'une opération de pagination.
Record Number: 7427
Source Name: Disk
Time Written: 20090301171757.000000+060
Event Type: Avertissement
User:
Computer Name: PEREA-A88DA7661
Event Code: 51
Message: Une erreur a été détectée sur le périphérique \Device\Harddisk6\D au cours d'une opération de pagination.
Record Number: 7426
Source Name: Disk
Time Written: 20090301171746.000000+060
Event Type: Avertissement
User:
Computer Name: PEREA-A88DA7661
Event Code: 51
Message: Une erreur a été détectée sur le périphérique \Device\Harddisk6\D au cours d'une opération de pagination.
Record Number: 7425
Source Name: Disk
Time Written: 20090301171735.000000+060
Event Type: Avertissement
User:
Computer Name: PEREA-A88DA7661
Event Code: 51
Message: Une erreur a été détectée sur le périphérique \Device\Harddisk6\D au cours d'une opération de pagination.
Record Number: 7424
Source Name: Disk
Time Written: 20090301171734.000000+060
Event Type: Avertissement
User:
Computer Name: PEREA-A88DA7661
Event Code: 51
Message: Une erreur a été détectée sur le périphérique \Device\Harddisk6\D au cours d'une opération de pagination.
Record Number: 7423
Source Name: Disk
Time Written: 20090301171723.000000+060
Event Type: Avertissement
User:
=====Application event log=====
Computer Name: PEREA-A88DA7661
Event Code: 4096
Message: Le service AntiVir a bien démarré!
Record Number: 1294
Source Name: Avira AntiVir
Time Written: 20090201094343.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: PEREA-A88DA7661
Event Code: 1800
Message: Le service Centre de sécurité Windows a démarré.
Record Number: 1293
Source Name: SecurityCenter
Time Written: 20090201094342.000000+060
Event Type: Informations
User:
Computer Name: PEREA-A88DA7661
Event Code: 0
Message:
Record Number: 1292
Source Name: SeaPort
Time Written: 20090201094342.000000+060
Event Type: Informations
User:
Computer Name: PEREA-A88DA7661
Event Code: 4
Message: The LightScribe Service started successfully.
Record Number: 1291
Source Name: LightScribeService
Time Written: 20090201094339.000000+060
Event Type: Informations
User:
Computer Name: PEREA-A88DA7661
Event Code: 1
Message:
Record Number: 1290
Source Name: Bonjour Service
Time Written: 20090201094339.000000+060
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=6b02
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
-----------------EOF-----------------
- Désinstalle Navilog1.
Peux-tu me poster le rapport du dernier scan que tu as fait avec MBAM ?
Je mets MBAM, j'aurais bien mis celui de a-squared que je viens de faire mais je ne le trouve pas.
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2302
Windows 5.1.2600 Service Pack 3
18/06/2009 09:47:54
mbam-log-2009-06-18 (09-47-54).txt
Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|)
Eléments examinés: 185159
Temps écoulé: 46 minute(s), 15 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
------------------------------------------------------------------------------------------------------
Change ton mot de passe MSN et ta question secrète.
As-tu fait un scan avec AntiVir ?
voilà j'ai changé le passe.
J'ai scané avec antivir hier mais rien trouvé, il n'y a que a-squared qui trouve le trojan dropper et un autre.
Tu peux me donner l'emplacement et le nom du fichier infecté ?
Je refais un scan et poste le résultat
et bien comme de par hasard il ne détecte rien, alors que 3 fois de suite il relevait les trojan..enfin dois je penser que c'est réglé?
- Désinstalle pdfforge Toolbar et Java 6 Update 7.
- Mets à jour Java.
- Mets à jour Adobe Reader.
- Mets à jour Internet Explorer.
voilà mission accomplie...merci beaucoup pour tous ces conseils avisés...tout roule maintenant?
Non, je viens de remarquer un truc dans le rapport log de RSIT.
- Télécharge Lop S&D sur ton Bureau.
- Double-clique dessus pour lancer l'installation.
- Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
- Sélectionne la langue souhaitée, puis choisis l'option 1 (Recherche) .
- Patiente jusqu'à la fin du scan.
- Poste le rapport généré (C:\lopR.txt).
je me disais aussi..héé catchme??...le rapport:
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 5200+ )
BIOS : Award Modular BIOS v6.00PG
USER : Celine ( Administrator )
BOOT : Normal boot
Antivirus : AntiVir Desktop 9.0.1.26 (Activated)
C:\ (Local Disk) - NTFS - Total:298 Go (Free:274 Go)
D:\ (CD or DVD)
E:\ (USB)
F:\ (USB)
G:\ (USB)
H:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 21/06/2009| 1:52 )
--------------------\\ Listing des dossiers dans APPLIC~1
[05/06/2009|09:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[24/03/2009|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[14/11/2008|16:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[15/12/2008|21:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[15/12/2008|21:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[15/05/2009|17:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[21/12/2008|10:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
[09/12/2008|18:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[11/12/2008|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Earthsim
[08/02/2009|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
[26/01/2009|20:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[11/12/2008|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[11/12/2008|18:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files
[02/01/2009|07:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[11/12/2008|19:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\LightScribe
[26/12/2008|16:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[21/02/2009|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[09/12/2008|16:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive
[03/04/2009|08:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MyHeritage
[14/11/2008|16:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[23/03/2009|07:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[25/12/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SITEguard
[14/06/2009|08:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[21/06/2009|01:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[05/05/2009|07:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Steek
[25/12/2008|10:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\STOPzilla!
[03/02/2009|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[14/11/2008|17:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[09/12/2008|18:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[18/04/2009|10:52] C:\DOCUME~1\Celine\APPLIC~1\Adobe
[11/12/2008|22:23] C:\DOCUME~1\Celine\APPLIC~1\Ahead
[21/12/2008|10:43] C:\DOCUME~1\Celine\APPLIC~1\Apple Computer
[11/12/2008|18:54] C:\DOCUME~1\Celine\APPLIC~1\Axialis
[21/12/2008|11:07] C:\DOCUME~1\Celine\APPLIC~1\Azureus
[11/04/2009|22:51] C:\DOCUME~1\Celine\APPLIC~1\BitSpirit
[19/06/2009|22:35] C:\DOCUME~1\Celine\APPLIC~1\dvdcss
[10/04/2009|16:31] C:\DOCUME~1\Celine\APPLIC~1\Free Download Manager
[22/05/2009|08:29] C:\DOCUME~1\Celine\APPLIC~1\GetRightToGo
[11/12/2008|19:18] C:\DOCUME~1\Celine\APPLIC~1\Google
[13/05/2009|09:30] C:\DOCUME~1\Celine\APPLIC~1\gtk-2.0
[06/06/2009|23:27] C:\DOCUME~1\Celine\APPLIC~1\Help
[14/11/2008|15:49] C:\DOCUME~1\Celine\APPLIC~1\Identities
[09/12/2008|18:07] C:\DOCUME~1\Celine\APPLIC~1\Inkscape
[14/11/2008|15:54] C:\DOCUME~1\Celine\APPLIC~1\InstallShield
[02/01/2009|07:17] C:\DOCUME~1\Celine\APPLIC~1\Lavasoft
[18/12/2008|21:19] C:\DOCUME~1\Celine\APPLIC~1\LimeWire
[15/11/2008|10:42] C:\DOCUME~1\Celine\APPLIC~1\Macromedia
[26/12/2008|16:03] C:\DOCUME~1\Celine\APPLIC~1\Malwarebytes
[25/12/2008|03:29] C:\DOCUME~1\Celine\APPLIC~1\Media Player Classic
[11/04/2009|16:46] C:\DOCUME~1\Celine\APPLIC~1\Microsoft
[06/02/2009|09:22] C:\DOCUME~1\Celine\APPLIC~1\Mozilla
[03/04/2009|08:33] C:\DOCUME~1\Celine\APPLIC~1\MyHeritage
[14/12/2008|15:26] C:\DOCUME~1\Celine\APPLIC~1\OpenOffice.org
[06/02/2009|10:16] C:\DOCUME~1\Celine\APPLIC~1\Real
[11/12/2008|18:28] C:\DOCUME~1\Celine\APPLIC~1\SecondLife
[20/06/2009|00:11] C:\DOCUME~1\Celine\APPLIC~1\Skype
[19/06/2009|17:24] C:\DOCUME~1\Celine\APPLIC~1\skypePM
[11/12/2008|19:37] C:\DOCUME~1\Celine\APPLIC~1\Sphinx
[09/12/2008|18:10] C:\DOCUME~1\Celine\APPLIC~1\Sun
[03/04/2009|08:31] C:\DOCUME~1\Celine\APPLIC~1\The Complete Genealogy Reporter - FTB
[06/02/2009|09:22] C:\DOCUME~1\Celine\APPLIC~1\Thunderbird
[11/12/2008|23:37] C:\DOCUME~1\Celine\APPLIC~1\Uniblue
[16/06/2009|08:22] C:\DOCUME~1\Celine\APPLIC~1\vlc
[09/12/2008|18:09] C:\DOCUME~1\Celine\APPLIC~1\Winamp
[14/12/2008|15:25] C:\DOCUME~1\Celine\APPLIC~1\WinRAR
[14/02/2009|13:28] C:\DOCUME~1\Celine\APPLIC~1\Yahoo!
[14/11/2008|15:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Adobe
[31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Grisoft
[31/12/2008|06:42] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Macromedia
[31/12/2008|06:44] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[31/12/2008|06:55] C:\DOCUME~1\INVIT~1\APPLIC~1\Mozilla
[04/01/2009|07:24] C:\DOCUME~1\INVIT~1\APPLIC~1\Winamp
[04/01/2009|03:21] C:\DOCUME~1\INVIT~1\APPLIC~1\WinRAR
[09/12/2008|18:04] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[24/12/2008|11:39] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[20/06/2009 21:00][--ah-----] C:\WINDOWS\tasks\A3310BBC91B2BEDC.job
[16/06/2009 09:31][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[21/06/2009 01:23][--ah-----] C:\WINDOWS\tasks\SA.DAT
[14/04/2008 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
( A3310BBC91B2BEDC.job )=( c:\docume~1\celine\applic~1\mealtr~1\1601jugs.exe )
--------------------\\ Listing des dossiers dans C:\Program Files
[30/01/2009|18:23] C:\Program Files\Adobe
[15/12/2008|21:43] C:\Program Files\Apple Software Update
[09/12/2008|18:11] C:\Program Files\AppSnap
[21/12/2008|10:48] C:\Program Files\AskSearch
[20/06/2009|16:21] C:\Program Files\a-squared Free
[09/12/2008|18:00] C:\Program Files\Audacity
[15/05/2009|17:15] C:\Program Files\Avira
[11/12/2008|19:01] C:\Program Files\Axialis
[19/04/2009|19:16] C:\Program Files\BitSpirit
[12/06/2009|07:21] C:\Program Files\Bonjour
[09/12/2008|16:45] C:\Program Files\BroadJump
[21/03/2009|18:12] C:\Program Files\Canal
[14/02/2009|13:28] C:\Program Files\CCleaner
[11/12/2008|20:19] C:\Program Files\Cisco Systems
[09/12/2008|16:47] C:\Program Files\Club-Internet
[09/12/2008|16:47] C:\Program Files\Common Files
[14/11/2008|15:43] C:\Program Files\ComPlus Applications
[25/01/2009|11:51] C:\Program Files\Conduit
[14/11/2008|15:52] C:\Program Files\DIFX
[09/12/2008|18:02] C:\Program Files\DVD Shrink
[15/06/2009|18:03] C:\Program Files\eMule
[14/03/2009|19:09] C:\Program Files\ex-fumeurs
[09/12/2008|18:04] C:\Program Files\ffdshow
[21/06/2009|01:31] C:\Program Files\Fichiers communs
[27/03/2009|16:36] C:\Program Files\Flary Address
[30/01/2009|18:02] C:\Program Files\Free Download Manager
[09/12/2008|18:04] C:\Program Files\Gimp-2.0
[26/01/2009|23:23] C:\Program Files\Google
[11/12/2008|19:49] C:\Program Files\Grisoft
[14/06/2009|12:54] C:\Program Files\Hotspot_Shield
[09/12/2008|18:06] C:\Program Files\Inkscape
[03/03/2009|18:17] C:\Program Files\InstallShield Installation Information
[21/06/2009|01:41] C:\Program Files\Internet Explorer
[05/06/2009|09:45] C:\Program Files\iPod
[05/06/2009|09:45] C:\Program Files\iTunes
[21/06/2009|01:33] C:\Program Files\Java
[02/01/2009|07:17] C:\Program Files\Lavasoft
[09/12/2008|18:17] C:\Program Files\MadOnion.com
[18/06/2009|08:57] C:\Program Files\Malwarebytes' Anti-Malware
[21/12/2008|10:43] C:\Program Files\Meal trust real
[09/12/2008|18:03] C:\Program Files\Media Player Classic
[14/11/2008|17:36] C:\Program Files\Messenger
[17/12/2008|08:01] C:\Program Files\Microsoft
[14/11/2008|15:45] C:\Program Files\microsoft frontpage
[14/12/2008|15:34] C:\Program Files\Microsoft Office
[11/02/2009|10:30] C:\Program Files\Microsoft Office Outlook Connector
[26/02/2009|07:27] C:\Program Files\Microsoft Silverlight
[17/12/2008|07:57] C:\Program Files\Microsoft SQL Server Compact Edition
[17/12/2008|07:59] C:\Program Files\Microsoft Sync Framework
[11/12/2008|19:05] C:\Program Files\Microsoft.NET
[09/12/2008|16:47] C:\Program Files\Motive
[14/11/2008|15:44] C:\Program Files\Movie Maker
[21/06/2009|01:30] C:\Program Files\Mozilla Firefox
[11/02/2009|10:33] C:\Program Files\Mozilla Thunderbird
[27/03/2009|16:36] C:\Program Files\MP3
[27/03/2009|16:32] C:\Program Files\MP3 Player Utilities 4.00
[27/03/2009|16:31] C:\Program Files\MP3 Player Utilities 4.04
[27/01/2009|09:35] C:\Program Files\MSBuild
[11/02/2009|10:29] C:\Program Files\MSECache
[14/11/2008|15:42] C:\Program Files\MSN
[14/11/2008|15:43] C:\Program Files\MSN Gaming Zone
[14/11/2008|17:36] C:\Program Files\MSXML 4.0
[03/04/2009|08:35] C:\Program Files\MyHeritage
[20/06/2009|15:53] C:\Program Files\Navilog1
[14/11/2008|16:03] C:\Program Files\Nero
[14/11/2008|15:44] C:\Program Files\NetMeeting
[23/03/2009|07:06] C:\Program Files\NOS
[09/12/2008|18:01] C:\Program Files\OpenOffice.org 3
[14/11/2008|15:44] C:\Program Files\Outlook Express
[27/01/2009|09:45] C:\Program Files\Paint.NET
[11/04/2009|16:47] C:\Program Files\PDFCreator
[09/12/2008|18:06] C:\Program Files\PhotoFiltre
[10/06/2009|09:53] C:\Program Files\PHPNukeFR
[09/12/2008|18:06] C:\Program Files\Picasa2
[05/06/2009|09:43] C:\Program Files\QuickTime
[06/02/2009|10:14] C:\Program Files\Real
[11/12/2008|16:47] C:\Program Files\Realtek
[27/01/2009|09:35] C:\Program Files\Reference Assemblies
[05/06/2009|09:39] C:\Program Files\Safari
[24/12/2008|11:14] C:\Program Files\Safer Networking
[30/12/2008|16:33] C:\Program Files\SecondLife
[14/11/2008|15:44] C:\Program Files\Services en ligne
[14/06/2009|08:45] C:\Program Files\Skype
[09/12/2008|18:02] C:\Program Files\SoftChris
[20/06/2009|09:08] C:\Program Files\Spybot - Search & Destroy
[03/02/2009|14:54] C:\Program Files\SpywareBlaster
[07/05/2009|09:36] C:\Program Files\Steek
[31/03/2009|13:31] C:\Program Files\Text2PDF v1.5
[03/04/2009|08:10] C:\Program Files\Tracker Software
[20/06/2009|15:39] C:\Program Files\trend micro
[14/11/2008|15:49] C:\Program Files\Uninstall Information
[03/03/2009|18:17] C:\Program Files\USB Disk Win98 Driver
[09/12/2008|18:03] C:\Program Files\VideoLAN
[24/12/2008|19:20] C:\Program Files\Vuze
[12/06/2009|07:20] C:\Program Files\Winamp
[21/02/2009|09:23] C:\Program Files\Windows Live
[17/12/2008|07:55] C:\Program Files\Windows Live SkyDrive
[17/12/2008|09:22] C:\Program Files\Windows Live Toolbar
[14/11/2008|17:32] C:\Program Files\Windows Media Connect 2
[05/06/2009|09:37] C:\Program Files\Windows Media Player
[14/12/2008|15:33] C:\Program Files\Windows Messaging
[23/12/2008|11:44] C:\Program Files\Windows NT
[14/11/2008|15:44] C:\Program Files\WindowsUpdate
[14/12/2008|15:25] C:\Program Files\WinRAR
[08/06/2009|10:35] C:\Program Files\WinZip
[14/11/2008|15:45] C:\Program Files\xerox
[11/04/2009|20:24] C:\Program Files\Yahoo!
[05/02/2009|07:48] C:\Program Files\ZebHelpProcess 2
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[20/04/2009|19:42] C:\Program Files\Fichiers communs\Adobe
[21/03/2009|18:11] C:\Program Files\Fichiers communs\Adobe AIR
[14/11/2008|16:05] C:\Program Files\Fichiers communs\Ahead
[05/06/2009|09:45] C:\Program Files\Fichiers communs\Apple
[05/02/2009|07:48] C:\Program Files\Fichiers communs\Borland Shared
[14/12/2008|15:41] C:\Program Files\Fichiers communs\DESIGNER
[11/12/2008|20:19] C:\Program Files\Fichiers communs\Deterministic Networks
[09/12/2008|18:16] C:\Program Files\Fichiers communs\InstallShield
[24/12/2008|19:09] C:\Program Files\Fichiers communs\iS3
[14/11/2008|16:06] C:\Program Files\Fichiers communs\LightScribe
[30/01/2009|18:17] C:\Program Files\Fichiers communs\Macrovision Shared
[15/05/2009|17:14] C:\Program Files\Fichiers communs\Microsoft Shared
[09/12/2008|16:47] C:\Program Files\Fichiers communs\Motive
[14/11/2008|15:44] C:\Program Files\Fichiers communs\MSSoap
[14/11/2008|16:38] C:\Program Files\Fichiers communs\ODBC
[06/02/2009|10:14] C:\Program Files\Fichiers communs\Real
[14/11/2008|15:44] C:\Program Files\Fichiers communs\Services
[14/06/2009|08:45] C:\Program Files\Fichiers communs\Skype
[14/11/2008|16:38] C:\Program Files\Fichiers communs\SpeechEngines
[17/12/2008|08:01] C:\Program Files\Fichiers communs\System
[17/12/2008|07:49] C:\Program Files\Fichiers communs\Windows Live
[02/01/2009|07:16] C:\Program Files\Fichiers communs\Wise Installation Wizard
[06/02/2009|10:14] C:\Program Files\Fichiers communs\xing shared
--------------------\\ Process
( 52 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\Program Files\mealtr~1
C:\WINDOWS\Tasks\A3310BBC91B2BEDC.job
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-21 01:53:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:68][D:13]-> C:\DOCUME~1\Celine\LOCALS~1\Temp
[F:15][D:0]-> C:\DOCUME~1\Celine\Cookies
[F:6][D:4]-> C:\DOCUME~1\Celine\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 31/03/2009| 7:21 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 21/06/2009| 1:55 - Option : [1]
--------------------\\ Fin du rapport a 1:55:07
J'ai bien fait de vérifier, je vois une infection Lop.
- Relance Lop S&D.
- Choisis cette fois-ci l'option 2 (Suppression).
- Ne ferme pas la fenêtre lors de la suppression !
- Poste le rapport généré (C:\lopR.txt).
(Si le Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
c'est koi?
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 5200+ )
BIOS : Award Modular BIOS v6.00PG
USER : Celine ( Administrator )
BOOT : Normal boot
Antivirus : AntiVir Desktop 9.0.1.26 (Activated)
C:\ (Local Disk) - NTFS - Total:298 Go (Free:274 Go)
D:\ (CD or DVD)
E:\ (USB)
F:\ (USB)
G:\ (USB)
H:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 21/06/2009| 2:06 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\WINDOWS\Tasks\A3310BBC91B2BEDC.job
Supprime! - C:\Program Files\mealtr~1
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[05/06/2009|09:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[24/03/2009|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[14/11/2008|16:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[15/12/2008|21:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[15/12/2008|21:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[15/05/2009|17:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[21/12/2008|10:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
[09/12/2008|18:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[11/12/2008|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Earthsim
[08/02/2009|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
[26/01/2009|20:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[11/12/2008|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[11/12/2008|18:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files
[02/01/2009|07:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[11/12/2008|19:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\LightScribe
[26/12/2008|16:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[21/02/2009|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[09/12/2008|16:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive
[03/04/2009|08:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MyHeritage
[14/11/2008|16:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[21/06/2009|02:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[25/12/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SITEguard
[14/06/2009|08:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[21/06/2009|01:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[05/05/2009|07:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Steek
[25/12/2008|10:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\STOPzilla!
[03/02/2009|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[14/11/2008|17:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[09/12/2008|18:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[18/04/2009|10:52] C:\DOCUME~1\Celine\APPLIC~1\Adobe
[11/12/2008|22:23] C:\DOCUME~1\Celine\APPLIC~1\Ahead
[21/12/2008|10:43] C:\DOCUME~1\Celine\APPLIC~1\Apple Computer
[11/12/2008|18:54] C:\DOCUME~1\Celine\APPLIC~1\Axialis
[21/12/2008|11:07] C:\DOCUME~1\Celine\APPLIC~1\Azureus
[11/04/2009|22:51] C:\DOCUME~1\Celine\APPLIC~1\BitSpirit
[19/06/2009|22:35] C:\DOCUME~1\Celine\APPLIC~1\dvdcss
[10/04/2009|16:31] C:\DOCUME~1\Celine\APPLIC~1\Free Download Manager
[22/05/2009|08:29] C:\DOCUME~1\Celine\APPLIC~1\GetRightToGo
[11/12/2008|19:18] C:\DOCUME~1\Celine\APPLIC~1\Google
[13/05/2009|09:30] C:\DOCUME~1\Celine\APPLIC~1\gtk-2.0
[06/06/2009|23:27] C:\DOCUME~1\Celine\APPLIC~1\Help
[14/11/2008|15:49] C:\DOCUME~1\Celine\APPLIC~1\Identities
[09/12/2008|18:07] C:\DOCUME~1\Celine\APPLIC~1\Inkscape
[14/11/2008|15:54] C:\DOCUME~1\Celine\APPLIC~1\InstallShield
[02/01/2009|07:17] C:\DOCUME~1\Celine\APPLIC~1\Lavasoft
[18/12/2008|21:19] C:\DOCUME~1\Celine\APPLIC~1\LimeWire
[15/11/2008|10:42] C:\DOCUME~1\Celine\APPLIC~1\Macromedia
[26/12/2008|16:03] C:\DOCUME~1\Celine\APPLIC~1\Malwarebytes
[25/12/2008|03:29] C:\DOCUME~1\Celine\APPLIC~1\Media Player Classic
[11/04/2009|16:46] C:\DOCUME~1\Celine\APPLIC~1\Microsoft
[06/02/2009|09:22] C:\DOCUME~1\Celine\APPLIC~1\Mozilla
[03/04/2009|08:33] C:\DOCUME~1\Celine\APPLIC~1\MyHeritage
[14/12/2008|15:26] C:\DOCUME~1\Celine\APPLIC~1\OpenOffice.org
[06/02/2009|10:16] C:\DOCUME~1\Celine\APPLIC~1\Real
[11/12/2008|18:28] C:\DOCUME~1\Celine\APPLIC~1\SecondLife
[20/06/2009|00:11] C:\DOCUME~1\Celine\APPLIC~1\Skype
[19/06/2009|17:24] C:\DOCUME~1\Celine\APPLIC~1\skypePM
[11/12/2008|19:37] C:\DOCUME~1\Celine\APPLIC~1\Sphinx
[09/12/2008|18:10] C:\DOCUME~1\Celine\APPLIC~1\Sun
[03/04/2009|08:31] C:\DOCUME~1\Celine\APPLIC~1\The Complete Genealogy Reporter - FTB
[06/02/2009|09:22] C:\DOCUME~1\Celine\APPLIC~1\Thunderbird
[11/12/2008|23:37] C:\DOCUME~1\Celine\APPLIC~1\Uniblue
[16/06/2009|08:22] C:\DOCUME~1\Celine\APPLIC~1\vlc
[09/12/2008|18:09] C:\DOCUME~1\Celine\APPLIC~1\Winamp
[14/12/2008|15:25] C:\DOCUME~1\Celine\APPLIC~1\WinRAR
[14/02/2009|13:28] C:\DOCUME~1\Celine\APPLIC~1\Yahoo!
[14/11/2008|15:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Adobe
[31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Grisoft
[31/12/2008|06:42] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Macromedia
[31/12/2008|06:44] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[31/12/2008|06:55] C:\DOCUME~1\INVIT~1\APPLIC~1\Mozilla
[04/01/2009|07:24] C:\DOCUME~1\INVIT~1\APPLIC~1\Winamp
[04/01/2009|03:21] C:\DOCUME~1\INVIT~1\APPLIC~1\WinRAR
[09/12/2008|18:04] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[24/12/2008|11:39] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[16/06/2009 09:31][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[21/06/2009 02:04][--ah-----] C:\WINDOWS\tasks\SA.DAT
[14/04/2008 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[30/01/2009|18:23] C:\Program Files\Adobe
[15/12/2008|21:43] C:\Program Files\Apple Software Update
[09/12/2008|18:11] C:\Program Files\AppSnap
[21/12/2008|10:48] C:\Program Files\AskSearch
[20/06/2009|16:21] C:\Program Files\a-squared Free
[09/12/2008|18:00] C:\Program Files\Audacity
[15/05/2009|17:15] C:\Program Files\Avira
[11/12/2008|19:01] C:\Program Files\Axialis
[19/04/2009|19:16] C:\Program Files\BitSpirit
[12/06/2009|07:21] C:\Program Files\Bonjour
[09/12/2008|16:45] C:\Program Files\BroadJump
[21/03/2009|18:12] C:\Program Files\Canal
[14/02/2009|13:28] C:\Program Files\CCleaner
[11/12/2008|20:19] C:\Program Files\Cisco Systems
[09/12/2008|16:47] C:\Program Files\Club-Internet
[09/12/2008|16:47] C:\Program Files\Common Files
[14/11/2008|15:43] C:\Program Files\ComPlus Applications
[25/01/2009|11:51] C:\Program Files\Conduit
[14/11/2008|15:52] C:\Program Files\DIFX
[09/12/2008|18:02] C:\Program Files\DVD Shrink
[15/06/2009|18:03] C:\Program Files\eMule
[14/03/2009|19:09] C:\Program Files\ex-fumeurs
[09/12/2008|18:04] C:\Program Files\ffdshow
[21/06/2009|01:31] C:\Program Files\Fichiers communs
[27/03/2009|16:36] C:\Program Files\Flary Address
[30/01/2009|18:02] C:\Program Files\Free Download Manager
[09/12/2008|18:04] C:\Program Files\Gimp-2.0
[26/01/2009|23:23] C:\Program Files\Google
[11/12/2008|19:49] C:\Program Files\Grisoft
[14/06/2009|12:54] C:\Program Files\Hotspot_Shield
[09/12/2008|18:06] C:\Program Files\Inkscape
[03/03/2009|18:17] C:\Program Files\InstallShield Installation Information
[21/06/2009|02:04] C:\Program Files\Internet Explorer
[05/06/2009|09:45] C:\Program Files\iPod
[05/06/2009|09:45] C:\Program Files\iTunes
[21/06/2009|01:33] C:\Program Files\Java
[02/01/2009|07:17] C:\Program Files\Lavasoft
[09/12/2008|18:17] C:\Program Files\MadOnion.com
[18/06/2009|08:57] C:\Program Files\Malwarebytes' Anti-Malware
[09/12/2008|18:03] C:\Program Files\Media Player Classic
[14/11/2008|17:36] C:\Program Files\Messenger
[17/12/2008|08:01] C:\Program Files\Microsoft
[14/11/2008|15:45] C:\Program Files\microsoft frontpage
[14/12/2008|15:34] C:\Program Files\Microsoft Office
[11/02/2009|10:30] C:\Program Files\Microsoft Office Outlook Connector
[26/02/2009|07:27] C:\Program Files\Microsoft Silverlight
[17/12/2008|07:57] C:\Program Files\Microsoft SQL Server Compact Edition
[17/12/2008|07:59] C:\Program Files\Microsoft Sync Framework
[11/12/2008|19:05] C:\Program Files\Microsoft.NET
[09/12/2008|16:47] C:\Program Files\Motive
[14/11/2008|15:44] C:\Program Files\Movie Maker
[21/06/2009|02:05] C:\Program Files\Mozilla Firefox
[11/02/2009|10:33] C:\Program Files\Mozilla Thunderbird
[27/03/2009|16:36] C:\Program Files\MP3
[27/03/2009|16:32] C:\Program Files\MP3 Player Utilities 4.00
[27/03/2009|16:31] C:\Program Files\MP3 Player Utilities 4.04
[27/01/2009|09:35] C:\Program Files\MSBuild
[11/02/2009|10:29] C:\Program Files\MSECache
[14/11/2008|15:42] C:\Program Files\MSN
[14/11/2008|15:43] C:\Program Files\MSN Gaming Zone
[14/11/2008|17:36] C:\Program Files\MSXML 4.0
[03/04/2009|08:35] C:\Program Files\MyHeritage
[20/06/2009|15:53] C:\Program Files\Navilog1
[14/11/2008|16:03] C:\Program Files\Nero
[14/11/2008|15:44] C:\Program Files\NetMeeting
[21/06/2009|02:05] C:\Program Files\NOS
[09/12/2008|18:01] C:\Program Files\OpenOffice.org 3
[14/11/2008|15:44] C:\Program Files\Outlook Express
[27/01/2009|09:45] C:\Program Files\Paint.NET
[11/04/2009|16:47] C:\Program Files\PDFCreator
[09/12/2008|18:06] C:\Program Files\PhotoFiltre
[10/06/2009|09:53] C:\Program Files\PHPNukeFR
[09/12/2008|18:06] C:\Program Files\Picasa2
[05/06/2009|09:43] C:\Program Files\QuickTime
[06/02/2009|10:14] C:\Program Files\Real
[11/12/2008|16:47] C:\Program Files\Realtek
[27/01/2009|09:35] C:\Program Files\Reference Assemblies
[05/06/2009|09:39] C:\Program Files\Safari
[24/12/2008|11:14] C:\Program Files\Safer Networking
[30/12/2008|16:33] C:\Program Files\SecondLife
[14/11/2008|15:44] C:\Program Files\Services en ligne
[14/06/2009|08:45] C:\Program Files\Skype
[09/12/2008|18:02] C:\Program Files\SoftChris
[20/06/2009|09:08] C:\Program Files\Spybot - Search & Destroy
[03/02/2009|14:54] C:\Program Files\SpywareBlaster
[07/05/2009|09:36] C:\Program Files\Steek
[31/03/2009|13:31] C:\Program Files\Text2PDF v1.5
[03/04/2009|08:10] C:\Program Files\Tracker Software
[20/06/2009|15:39] C:\Program Files\trend micro
[14/11/2008|15:49] C:\Program Files\Uninstall Information
[03/03/2009|18:17] C:\Program Files\USB Disk Win98 Driver
[09/12/2008|18:03] C:\Program Files\VideoLAN
[24/12/2008|19:20] C:\Program Files\Vuze
[12/06/2009|07:20] C:\Program Files\Winamp
[21/02/2009|09:23] C:\Program Files\Windows Live
[17/12/2008|07:55] C:\Program Files\Windows Live SkyDrive
[17/12/2008|09:22] C:\Program Files\Windows Live Toolbar
[14/11/2008|17:32] C:\Program Files\Windows Media Connect 2
[05/06/2009|09:37] C:\Program Files\Windows Media Player
[14/12/2008|15:33] C:\Program Files\Windows Messaging
[23/12/2008|11:44] C:\Program Files\Windows NT
[14/11/2008|15:44] C:\Program Files\WindowsUpdate
[14/12/2008|15:25] C:\Program Files\WinRAR
[08/06/2009|10:35] C:\Program Files\WinZip
[14/11/2008|15:45] C:\Program Files\xerox
[11/04/2009|20:24] C:\Program Files\Yahoo!
[05/02/2009|07:48] C:\Program Files\ZebHelpProcess 2
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[20/04/2009|19:42] C:\Program Files\Fichiers communs\Adobe
[21/03/2009|18:11] C:\Program Files\Fichiers communs\Adobe AIR
[14/11/2008|16:05] C:\Program Files\Fichiers communs\Ahead
[05/06/2009|09:45] C:\Program Files\Fichiers communs\Apple
[05/02/2009|07:48] C:\Program Files\Fichiers communs\Borland Shared
[14/12/2008|15:41] C:\Program Files\Fichiers communs\DESIGNER
[11/12/2008|20:19] C:\Program Files\Fichiers communs\Deterministic Networks
[09/12/2008|18:16] C:\Program Files\Fichiers communs\InstallShield
[24/12/2008|19:09] C:\Program Files\Fichiers communs\iS3
[14/11/2008|16:06] C:\Program Files\Fichiers communs\LightScribe
[30/01/2009|18:17] C:\Program Files\Fichiers communs\Macrovision Shared
[15/05/2009|17:14] C:\Program Files\Fichiers communs\Microsoft Shared
[09/12/2008|16:47] C:\Program Files\Fichiers communs\Motive
[14/11/2008|15:44] C:\Program Files\Fichiers communs\MSSoap
[14/11/2008|16:38] C:\Program Files\Fichiers communs\ODBC
[06/02/2009|10:14] C:\Program Files\Fichiers communs\Real
[14/11/2008|15:44] C:\Program Files\Fichiers communs\Services
[14/06/2009|08:45] C:\Program Files\Fichiers communs\Skype
[14/11/2008|16:38] C:\Program Files\Fichiers communs\SpeechEngines
[17/12/2008|08:01] C:\Program Files\Fichiers communs\System
[17/12/2008|07:49] C:\Program Files\Fichiers communs\Windows Live
[02/01/2009|07:16] C:\Program Files\Fichiers communs\Wise Installation Wizard
[06/02/2009|10:14] C:\Program Files\Fichiers communs\xing shared
--------------------\\ Process
( 56 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-21 02:07:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:69][D:13]-> C:\DOCUME~1\Celine\LOCALS~1\Temp
[F:15][D:0]-> C:\DOCUME~1\Celine\Cookies
[F:10][D:4]-> C:\DOCUME~1\Celine\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 31/03/2009| 7:21 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 21/06/2009| 1:55 - Option : [1]
3 - "C:\Lop SD\LopR_3.txt" - 21/06/2009| 2:07 - Option : [2]
--------------------\\ Fin du rapport a 2:07:37
Infection Lop supprimée, ça vient du programme BitDownload.
- Télécharge Ad-Remover (de Cyrildu17 / C_XX) sur ton Bureau.
/!\ Déconnecte-toi et ferme toutes applications en cours /!\
- Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
- Double-clique sur le raccourci d'Ad-Remover situé sur ton Bureau pour le lancer.
(Sous Vista, il faut cliquer droit sur le raccourci d'Ad-Remover et choisir Exécuter en tant qu'administrateur)
- Choisis la langue F pour français.
- Au menu principal, choisis l'option S.
/!\ Laisse travailler l'outil /!\
- Poste le rapport qui apparaît à la fin (C:\Ad-Report-SCAN.log).
(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
Note : "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
Bonjour, le rapport comme prévu
.
======= RAPPORT D'AD-REMOVER 1.1.4.5_L | UNIQUEMENT XP/VISTA/SEVEN =======
.
Mit à jour par C_XX le 20/06/2009 à 3:20 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 8:36:27, 21/06/2009 | Mode Normal | Option: SCAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: PEREA-A88DA7661 | Utilisateur actuel: Celine
.
Administrateur: Administrateur
N'est pas administrateur: ASPNET
Administrateur: Celine
N'est pas administrateur: HelpAssistant *Desactive*
N'est pas administrateur: Invité
N'est pas administrateur: SUPPORT_388945a0 *Desactive*
.
============== ÉLÉMENT(S) TROUVÉ(S) ==============
.
.
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
.
C:\Program Files\AskSearch
C:\DOCUME~1\Celine\APPLIC~1\Mozilla\Firefox\Profiles\fuj5rmd8.default\searchplugins\ask.xml
.
============== Scan additionnel ==============
.
* Mozilla FireFox Version 3.0.11 *
Nom du profil: fuj5rmd8.default (Celine)
.
(Prefs.js) user_pref("browser.search.defaultenginename", "Live Search" );
(Prefs.js) user_pref("browser.search.selectedEngine", "Yahoo" );
(Prefs.js) user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2098232&SearchSource=3&q={searchTerms}" );
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.google.fr/ig?hl=fr" );
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.11" );
.
.
* Internet Explorer Version 8.0.6001.18702 *
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Default_Search_URL: hxxp://www.google.com/ie
Search bar: hxxp://www.google.com/ie
Search Page: hxxp://www.google.com
Start Page: hxxp://search.myheritage.com
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
============== Suspect (Cracks, Serials ... ) ==============
.
.
===================================
.
2365 Octet(s) - C:\Ad-Report-SCAN.log
.
67 Fichier(s) - C:\DOCUME~1\Celine\LOCALS~1\Temp
1 Fichier(s) - C:\WINDOWS\Temp
.
1 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
0 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
.
Fin à: 8:49:27 | 21/06/2009
.
============== E.O.F ==============
.
/!\ Déconnecte-toi et ferme toutes applications en cours /!\
- Double-clique sur le raccourci d'Ad-Remover pour le lancer.
(Sous Vista, il faut cliquer droit sur le raccourci d'Ad-Remover et choisir Exécuter en tant qu'administrateur)
- Choisis la langue F pour français.
- Au menu principal, choisis l'option L et tape sur [Entrée] pour valider.
/!\ Laisse travailler l'outil et ne touche à rien /!\
- Poste le rapport qui apparaît à la fin (C:\Ad-Report-CLEAN.log)
(CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller)
Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
voilà:
.
======= RAPPORT D'AD-REMOVER 1.1.4.5_L | UNIQUEMENT XP/VISTA/SEVEN =======
.
Mit à jour par C_XX le 20/06/2009 à 3:20 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 16:10:28, 21/06/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: PEREA-A88DA7661 | Utilisateur actuel: Celine
.
Administrateur: Administrateur
N'est pas administrateur: ASPNET
Administrateur: Celine
N'est pas administrateur: HelpAssistant *Desactive*
N'est pas administrateur: Invité
N'est pas administrateur: SUPPORT_388945a0 *Desactive*
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
.
C:\Program Files\AskSearch\bin
C:\Program Files\AskSearch\bin\DefaultSearch.dll
C:\Program Files\AskSearch
C:\DOCUME~1\Celine\APPLIC~1\Mozilla\Firefox\Profiles\fuj5rmd8.default\searchplugins\ask.xml
(!) -- Fichiers temporaires supprimés.
.
============== Scan additionnel ==============
.
* Mozilla FireFox Version 3.0.11 *
Nom du profil: fuj5rmd8.default (Celine)
.
(Prefs.js) user_pref("browser.search.defaultenginename", "Live Search" );
(Prefs.js) user_pref("browser.search.selectedEngine", "Yahoo" );
(Prefs.js) user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2098232&SearchSource=3&q={searchTerms}" );
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.google.fr/ig?hl=fr" );
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.11" );
.
.
* Internet Explorer Version 8.0.6001.18702 *
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://www.google.com
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
============== Suspect (Cracks, Serials ... ) ==============
.
.
===================================
.
2746 Octet(s) - C:\Ad-Report-CLEAN.log
2677 Octet(s) - C:\Ad-Report-SCAN.log
.
30 Fichier(s) - C:\DOCUME~1\Celine\LOCALS~1\Temp
1 Fichier(s) - C:\WINDOWS\Temp
.
21 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
2 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
.
Fin à: 16:23:10 | 21/06/2009
.
============== E.O.F ==============
.
- Désinstalle Ad-Remover.
- Refais un scan RSIT et poste le rapport log.
mon rapport chef, héé
Logfile of random's system information tool 1.06 (written by random/random)
Run by Celine at 2009-06-21 16:46:22
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 282 GB (93%) free of 305 GB
Total RAM: 2046 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:46:29, on 21/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\UMStor\Res.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Celine\Bureau\RSIT.exe
C:\Program Files\trend micro\Celine.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: PDF-XChange Viewer IE-Plugin - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [USB Storage Toolbox] C:\WINDOWS\UMStor\Res.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [RegistryBooster 2 d’Uniblue ] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Ekiga.lnk = C:\Program Files\Ekiga\ekiga.exe
O4 - Startup: ex-fumeurs.lnk = C:\Program Files\ex-fumeurs\ex-fumeurs.exe
O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: OpenOffice.org 3.0.lnk.disabled
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Docteur Club Internet.lnk.disabled
O4 - Global Startup: WinZip Quick Pick.lnk.disabled
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.04\AMVConverter\grab.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/micros [...] 9021722828
O17 - HKLM\System\CCS\Services\Tcpip\..\{24AB0520-3295-4062-90D6-60FBF4F747A7}: NameServer = 86.64.145.140,84.103.237.140
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 12781 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-06-02 1082880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]
PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-06-10 2094616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-05-07 259696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-05-07 668656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F}]
PDF-XChange Viewer IE-Plugin - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll [2009-03-30 1092888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-05-07 470512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-11-12 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-06-21 41368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-06-21 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-06-10 2094616]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-05-07 259696]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-05-10 16342528]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-02 86016]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-02 13529088]
"NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"BJCFD"=C:\Program Files\BroadJump\Client Foundation\CFD.exe [2003-01-27 376912]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2007-10-10 36352]
"USB Storage Toolbox"=C:\WINDOWS\UMStor\Res.EXE [2005-09-14 65536]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"Family Tree Builder Update"=C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2009-01-14 113680]
"TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2009-02-06 185872]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-05-30 292136]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-06-21 148888]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe [2008-08-21 443968]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-12-15 68856]
"RegistryBooster 2 d’Uniblue "=C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S []
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]
"Uniblue RegistryBooster 2009"=C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S []
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
Docteur Club Internet.lnk.disabled - C:\Program Files\Club-Internet\Dr Club Internet\bin\matcli.exe
WinZip Quick Pick.lnk.disabled - C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\Celine\Menu Démarrer\Programmes\Démarrage
Démarrage d'Office.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE
Ekiga.lnk - C:\Program Files\Ekiga\ekiga.exe
ex-fumeurs.lnk - C:\Program Files\ex-fumeurs\ex-fumeurs.exe
Microsoft Recherche accélérée.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
OpenOffice.org 3.0.lnk.disabled - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=4294967295
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\NeroExpress\Installation\Setupx.exe"="D:\NeroExpress\Installation\Setupx.exe:*:Enabled:Nero ProductSetup"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\SecondLife\SLVoice.exe"="C:\Program Files\SecondLife\SLVoice.exe:*
isabled:SLVoice"
"C:\Program Files\BitDownload\BitDownload.exe"="C:\Program Files\BitDownload\BitDownload.exe:*:Enabled:BitDownload"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\Program Files\Free Download Manager\fdm.exe"="C:\Program Files\Free Download Manager\fdm.exe:*:Enabled:Free Download Manager"
"DEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~ӟ"="DEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~ӟ:*:Enabled:Nod32 Service"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\SecondLife\SecondLife.exe"="C:\Program Files\SecondLife\SecondLife.exe:*:Enabled:Second Life"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Ekiga\ekiga.exe"="C:\Program Files\Ekiga\ekiga.exe:*
isabled:ekiga"
"C:\Python23\pythonw.exe"="C:\Python23\pythonw.exe:*:Enabled
ythonw"
"C:\Documents and Settings\Celine\Local Settings\Temp\Rar$EX02.468\eMule0.49c\emule.exe"="C:\Documents and Settings\Celine\Local Settings\Temp\Rar$EX02.468\eMule0.49c\emule.exe:*:Enabled:eMule"
"C:\Program Files\Fichiers communs\Ahead\Nero Web\SetupX.exe"="C:\Program Files\Fichiers communs\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
"C:\Documents and Settings\Celine\Local Settings\Temp\Nero Web\SetupXu.exe"="C:\Documents and Settings\Celine\Local Settings\Temp\Nero Web\SetupXu.exe:*:Enabled:Nero ProductSetup"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
======List of files/folders created in the last 1 months======
2009-06-21 02:15:49 ----D---- C:\Program Files\Ad-remover
2009-06-21 01:40:57 ----D---- C:\WINDOWS\ie8updates
2009-06-21 01:40:35 ----A---- C:\WINDOWS\imsins.BAK
2009-06-21 01:39:31 ----HDC---- C:\WINDOWS\ie8
2009-06-21 01:37:32 ----A---- C:\WINDOWS\system32\javaws.exe
2009-06-21 01:37:32 ----A---- C:\WINDOWS\system32\javaw.exe
2009-06-21 01:37:32 ----A---- C:\WINDOWS\system32\java.exe
2009-06-18 09:52:27 ----A---- C:\WINDOWS\msnfix.txt
2009-06-16 08:22:10 ----D---- C:\Documents and Settings\Celine\Application Data\vlc
2009-06-16 08:21:52 ----D---- C:\Documents and Settings\Celine\Application Data\dvdcss
2009-06-16 08:14:46 ----A---- C:\Documents and Settings\All Users\Application Data\vlc-0.9.9-win32.exe
2009-06-14 12:54:22 ----D---- C:\Program Files\Hotspot_Shield
2009-06-14 08:45:30 ----D---- C:\Program Files\Fichiers communs\Skype
2009-06-14 08:45:27 ----RD---- C:\Program Files\Skype
2009-06-11 09:17:43 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-06-11 09:17:37 ----HDC---- C:\WINDOWS\$NtUninstallKB969897$
2009-06-11 09:17:33 ----HDC---- C:\WINDOWS\$NtUninstallKB969898$
2009-06-11 09:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-06-11 09:15:41 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-06-06 23:27:40 ----D---- C:\Documents and Settings\Celine\Application Data\Help
2009-06-05 09:45:14 ----D---- C:\Program Files\iPod
2009-06-05 09:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-05 09:43:33 ----D---- C:\Program Files\QuickTime
2009-06-05 09:39:07 ----D---- C:\Program Files\Safari
2009-05-22 08:28:26 ----D---- C:\Documents and Settings\Celine\Application Data\GetRightToGo
======List of files/folders modified in the last 1 months======
2009-06-21 16:46:25 ----D---- C:\WINDOWS\Prefetch
2009-06-21 16:46:23 ----D---- C:\Program Files\trend micro
2009-06-21 16:45:12 ----D---- C:\WINDOWS\Temp
2009-06-21 16:27:12 ----AH---- C:\WINDOWS\system32\FFASTLOG.TXT
2009-06-21 16:23:55 ----D---- C:\Program Files\Mozilla Firefox
2009-06-21 16:22:08 ----RD---- C:\Program Files
2009-06-21 14:24:55 ----D---- C:\WINDOWS\system32\CatRoot2
2009-06-21 14:23:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-06-21 12:57:58 ----D---- C:\Program Files\eMule
2009-06-21 12:37:43 ----D---- C:\WINDOWS\system32
2009-06-21 08:45:35 ----A---- C:\WINDOWS\NeroDigital.ini
2009-06-21 02:13:13 ----D---- C:\Downloads
2009-06-21 02:12:15 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-06-21 02:07:37 ----D---- C:\Lop SD
2009-06-21 02:07:37 ----A---- C:\lopR.txt
2009-06-21 02:06:25 ----SD---- C:\WINDOWS\Tasks
2009-06-21 02:05:10 ----D---- C:\Program Files\NOS
2009-06-21 02:04:44 ----D---- C:\WINDOWS
2009-06-21 02:04:20 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-06-21 02:04:20 ----D---- C:\WINDOWS\system32\fr-fr
2009-06-21 02:04:20 ----D---- C:\WINDOWS\Help
2009-06-21 02:04:20 ----D---- C:\Program Files\Internet Explorer
2009-06-21 01:54:52 ----HD---- C:\WINDOWS\inf
2009-06-21 01:54:50 ----D---- C:\WINDOWS\system32\CatRoot
2009-06-21 01:41:00 ----HD---- C:\WINDOWS\$hf_mig$
2009-06-21 01:40:27 ----D---- C:\WINDOWS\WBEM
2009-06-21 01:40:22 ----D---- C:\WINDOWS\Media
2009-06-21 01:37:43 ----SHD---- C:\WINDOWS\Installer
2009-06-21 01:37:18 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-06-21 01:33:03 ----D---- C:\Program Files\Java
2009-06-21 01:31:30 ----D---- C:\Program Files\Fichiers communs
2009-06-21 01:29:45 ----D---- C:\WINDOWS\WinSxS
2009-06-21 01:24:07 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-20 16:21:47 ----D---- C:\Program Files\a-squared Free
2009-06-20 15:53:11 ----D---- C:\Program Files\Navilog1
2009-06-20 09:08:21 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-06-20 08:31:19 ----D---- C:\WINDOWS\Debug
2009-06-20 00:11:03 ----D---- C:\Documents and Settings\Celine\Application Data\Skype
2009-06-19 17:24:41 ----D---- C:\Documents and Settings\Celine\Application Data\skypePM
2009-06-19 07:41:16 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-06-18 09:51:33 ----D---- C:\unzipped
2009-06-18 08:57:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-18 08:57:31 ----D---- C:\WINDOWS\system32\drivers
2009-06-18 08:46:16 ----D---- C:\WINDOWS\Minidump
2009-06-16 08:20:49 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-06-16 08:19:24 ----D---- C:\Python23
2009-06-15 10:53:43 ----SHD---- C:\System Volume Information
2009-06-15 10:49:54 ----D---- C:\WINDOWS\repair
2009-06-15 10:49:49 ----D---- C:\WINDOWS\Registration
2009-06-14 08:45:30 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2009-06-12 07:21:25 ----D---- C:\Program Files\Bonjour
2009-06-12 07:20:59 ----D---- C:\Program Files\Winamp
2009-06-11 09:18:14 ----A---- C:\WINDOWS\win.ini
2009-06-10 09:53:45 ----D---- C:\Program Files\PHPNukeFR
2009-06-08 10:35:03 ----D---- C:\Program Files\WinZip
2009-06-05 09:45:30 ----D---- C:\Program Files\iTunes
2009-06-05 09:45:13 ----D---- C:\Program Files\Fichiers communs\Apple
2009-06-05 09:37:46 ----D---- C:\Program Files\Windows Media Player
2009-06-01 09:51:14 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;Pilote de processeur AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 43520]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-02-13 28376]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-03-24 55640]
R2 CVPNDRVA;Cisco Systems IPsec Driver; \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys []
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2008-12-08 55136]
R3 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2007-01-24 127376]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-05-10 4419584]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12288]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-02 6554496]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-12-14 85120]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 catchme;catchme; \??\C:\DOCUME~1\Celine\LOCALS~1\Temp\catchme.sys []
S3 CVirtA;Cisco Systems VPN Adapter; C:\WINDOWS\system32\DRIVERS\CVirtA.sys [2007-01-18 5275]
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 ICDSX;Sony IC Recorder (SX); C:\WINDOWS\System32\Drivers\ICDSX.sys [2003-10-01 31744]
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 tapvpn;TAP VPN Adapter; C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2006-10-26 27136]
S3 vsdatant;vsdatant; \??\C:\WINDOWS\system32\vsdatant.sys []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2009-06-12 718880]
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2009-01-02 611664]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-03-02 185089]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-05-29 144712]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2007-07-16 1524512]
R2 fsssvc;Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-06-21 152984]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [2008-01-24 73728]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-02 159812]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-05-30 541992]
S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-01-30 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2009-06-04 66048]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-07 182768]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-11-28 800040]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Service de partage de ports Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
-----------------EOF-----------------
- Télécharge OTM (OldTimer) sur ton Bureau.
- Double-clique sur OTM.exe afin de le lancer.
- Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
|
- Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
- Clique maintenant sur le bouton MoveIt! puis ferme OTM.
---> Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
- Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
---> Le nom du rapport correspond au moment de sa création : date_heure.log
y voilà:
========== PROCESSES ==========
Process explorer.exe killed successfully.
Process TeaTimer.exe killed successfully.
========== FILES ==========
File/Folder C:\Program Files\BitDownload not found.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Program Files\BitDownload\BitDownload.exe deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\VBE\MSForms.exd scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\VBE\RefEdit.exd scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\etilqs_SyqaGezjGQgo4CAxD8bs scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF1585.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF1F77.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF20E3.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF2DC.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF42E4.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF4E07.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF4FA2.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF516D.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7155.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7BDB.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7BFF.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF8AE1.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF92A4.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF9807.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF9AAE.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFC848.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFC86D.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD1D8.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD304.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD5B6.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD839.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFE168.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF3FA.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF659.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF91A.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.Word\~WRF0001.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.Word\~WRS0000.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\277F1FCC.emf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\53613F37.emf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\756E1BBB.emf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\7AD0348E.emf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\8AE6EA80.emf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\90B93C73.emf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\AA43A1F9.emf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\B12B3BA.emf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\C30BE55D.emf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\EB8E3D8.emf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\F5A8E881.emf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_378.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
OTM by OldTimer - Version 2.1.0.1 log created on 06212009_165821
Files moved on Reboot...
C:\DOCUME~1\Celine\LOCALS~1\Temp\VBE\MSForms.exd moved successfully.
C:\DOCUME~1\Celine\LOCALS~1\Temp\VBE\RefEdit.exd moved successfully.
File C:\DOCUME~1\Celine\LOCALS~1\Temp\etilqs_SyqaGezjGQgo4CAxD8bs not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF1585.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF1F77.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF20E3.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF2DC.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF42E4.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF4E07.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF4FA2.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF516D.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7155.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7BDB.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7BFF.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF8AE1.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF92A4.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF9807.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF9AAE.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFC848.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFC86D.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD1D8.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD304.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD5B6.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD839.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFE168.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF3FA.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF659.tmp not found!
File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF91A.tmp not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.Word\~WRF0001.tmp not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.Word\~WRS0000.tmp not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\277F1FCC.emf not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\53613F37.emf not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\756E1BBB.emf not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\7AD0348E.emf not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\8AE6EA80.emf not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\90B93C73.emf not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\AA43A1F9.emf not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\B12B3BA.emf not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\C30BE55D.emf not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\EB8E3D8.emf not found!
File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\F5A8E881.emf not found!
File C:\WINDOWS\temp\Perflib_Perfdata_378.dat not found!
C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\XUL.mfl moved successfully.
Registry entries deleted on Reboot...
Pas de souci ?
et bien je dirai que tout va bien..
Merci beaucoup pour la mobilisation de tes compétences impressionnantes en la matière.
1/
- Désinstalle HijackThis.
- Télécharge ToolsCleaner2 sur ton Bureau.
- Double-clique sur ToolsCleaner2.exe pour le lancer.
- Clique sur Recherche et laisse le scan agir.
- Clique sur Suppression pour finaliser.
- Tu peux, si tu le souhaites, te servir des Options Facultatives.
- Clique sur Quitter pour obtenir le rapport.
- Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
2/
- Télécharge et installe CCleaner Slim.
- Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
- Va dans Nettoyeur, choisis Analyser. Une fois terminé, lance le nettoyage.
3/
- Il est nécessaire de désactiver puis réactiver la restauration système pour la purger.
==Prévention==
Supprimer les popups d'Antivir : Lien
Conserve MBAM. Il te servira à scanner les fichiers douteux en complément de l'antivirus et scanne le disque dur régulièrement.
Par rapport au P2P : Lien
Voici un dossier complet (A lire avec Adobe Reader ou Foxit Reader) : Lien
==Problème résolu ?==
Si tu estimes que ton problème est résolu :
---> Ajoute maintenant [Résolu] au titre. Pour cela :
- Clique, dans ton premier message, sur le bouton Editer
.
- Rajoute la mention [Résolu] devant le titre.
- Clique ensuite sur Valider votre message.
Sois plus vigilant(e) sur Internet
Comment s'est arrivé?
[ Rapport ToolsCleaner version 2.3.6 (par A.Rothstein & dj QUIOU) ]
--> Recherche:
C:\fixnavi.txt: trouvé !
C:\cleannavi.txt: trouvé !
C:\lopR.txt: trouvé !
C:\TB.txt: trouvé !
C:\Lop SD: trouvé !
C:\!Killbox: trouvé !
C:\_OTM: trouvé !
C:\Toolbar SD: trouvé !
C:\Rsit: trouvé !
C:\Documents and Settings\Celine\Bureau\LopSD.exe: trouvé !
C:\Documents and Settings\Celine\Bureau\OTM.exe: trouvé !
C:\Documents and Settings\Celine\Bureau\Rsit.exe: trouvé !
C:\Documents and Settings\Celine\Recent\MSNFix.lnk: trouvé !
C:\Program Files\Navilog1: trouvé !
C:\Program Files\Ad-remover: trouvé !
C:\Program Files\Ad-remover\BACKUP\Ad-R.exe: trouvé !
C:\Program Files\trend micro\HijackThis.exe: trouvé !
C:\Program Files\trend micro\hijackthis.log: trouvé !
C:\unzipped\MsnFix: trouvé !
C:\unzipped\MSNFix\MsnFix: trouvé !
C:\WINDOWS\msnfix.txt: trouvé !
---------------------------------
--> Suppression:
C:\Documents and Settings\Celine\Bureau\LopSD.exe: supprimé !
C:\Documents and Settings\Celine\Bureau\OTM.exe: supprimé !
C:\Documents and Settings\Celine\Recent\MSNFix.lnk: supprimé !
C:\Program Files\Ad-remover\BACKUP\Ad-R.exe: supprimé !
C:\Program Files\trend micro\HijackThis.exe: supprimé !
C:\fixnavi.txt: supprimé !
C:\cleannavi.txt: supprimé !
C:\lopR.txt: supprimé !
C:\TB.txt: supprimé !
C:\Documents and Settings\Celine\Bureau\Rsit.exe: supprimé !
C:\Program Files\trend micro\hijackthis.log: supprimé !
C:\WINDOWS\msnfix.txt: supprimé !
C:\Lop SD: supprimé !
C:\!Killbox: supprimé !
C:\_OTM: supprimé !
C:\Toolbar SD: supprimé !
C:\Rsit: supprimé !
C:\Program Files\Navilog1: supprimé !
C:\Program Files\Ad-remover: supprimé !
C:\unzipped\MsnFix: supprimé !
Tu peux supprimer ToolsCleaner.
oki merci encore
tchussy
Bonne fin de journée
Il y a 415 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.
