Ecran noir ,Warning

Fermé
sylk62 - 8 mars 2009 à 22:09
 sylk62 - 10 mars 2009 à 22:34
Bonjour,
j'ai ouvert hier un dossier envoyé par 1amie sur MSN messenger,aujourd'hui une autre amie m'a averti que mon pc envoie des messages toutes les 2-3minutes,j'aie donc fait une analyse complète de mon pc et j'aie trouvé 17virus, et 5 spyware.
J'aie mis tout ça en quanrantaine malgré ça il y a 5 fichiers que je ne trouve pas (recherches manuel et recherches auomatique)il était marqué pour ces 5 fichiers qu'ils font parti d'une archive,qu'il faut ouvrir l'archive pour supprimer manuellement.J'aie notée sur papier toutes les données de ces fichiers(fichiers,virus et chemins) mais je ne les trouve pas;de plus a la place de mon fond d'ecran il y a cet ecran noir depuis tt à l'heure avec écrit "Warning,dangerous spyware,many viruses were found on your computer such as:Trojan horse,pass capture,ect...Your personnal information can fall into in the "thirds hands".please check up the computer with a speciale software.thank.
J' y connais pas grand chose en informatique et quand je lis les solutions qui ont été donné a d'autres internaute je m'aperçois que je ne sais mm pas ce qu'est les listes(hyjackthis?) qu'ils vous ont fournis.Pouvez-vous m'aider a ma debarrasser de ce truc?
D'avance Merci.
A voir également:

33 réponses

plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
8 mars 2009 à 22:19
bONSOIR

attention ne suit pas les indications qu'il te donne, si tu telecharge le rogue qu'il te propose sa va etre bien pire

pour l'instant fait ceci :

deconnecte toi d'internet et desactive ton antivirus (fait le durant tout les scan en general)

Option 1 - Recherche :



* Télécharge Smitfraudfix et enregistre le sur le bureau https://www.androidworld.fr/

(c est le numéro 2 en bas de la page) :
* Ensuite double clique sur smitfraudfix puis exécuter
* Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

(attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)
* copier/coller le rapport dans la réponse.


Un tutoriel sonore et animé est à ta disposition sur le site.



(Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
cet utilitaire pourrait arrêter des logiciels de sécurité.)
0
Voilà ce que ça me donne:
SmitFraudFix v2.400

Rapport fait à 22:25:43,25, 08/03/2009
Executé à partir de D:\Documents and Settings\sylk62\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe
C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE
C:\Program Files\SFR\Pack Sécurité\Anti-Virus\FSGK32.EXE
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Apps\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Apps\Softex\OmniPass\OPXPApp.exe
C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fssm32.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Apps\Softex\OmniPass\scureapp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\APPS\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\QuickTime\QTTask.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
C:\Program Files\Hercules\Deluxe Optical Glass\Camservice.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\WINDOWS\fxsteller.exe
C:\APPS\SMP\SmpSys.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Documents and Settings\sylk62\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\inf\rundll33.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
D:\Documents and Settings\sylk62\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\SFR\Pack Sécurité\Common\FSLAUNCH.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» D:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\sylk62


»»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\sylk62\LOCALS~1\Temp


»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\sylk62\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer


»»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\sylk62\Favoris


»»»»»»»»»»»»»»»»»»»»»»»» Bureau


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues


»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"


»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» RK



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.1.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{F171C7F8-1776-49EA-8A33-1678DB13A154}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{F171C7F8-1776-49EA-8A33-1678DB13A154}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{F171C7F8-1776-49EA-8A33-1678DB13A154}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


»»»»»»»»»»»»»»»»»»»»»»»» Fin

Merci de regarder,là je suis complètement paumée.
0
plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
8 mars 2009 à 22:39
ok donc l'infection n'est pas trop etendue apparament rien pour ce rapport parcontre il met en evidence plusieurs processus infectieux dont SWEET IM qui s'ajoute le + souvent en telechargeant des emotions gratuitement sur internet c'est un spyware on commence par sa :

* Télécharge et enregistre le fichier d installation sur ton bureau :

http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

* Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( le bureau )

* Ouvre le dossier Ad-remover présent sur ton bureau, et double clique sur Ad-remover.bat.

* Au menu principal choisi l'option "A"

* Poste le rapport qui apparait à la fin.



( le rapport est sauvegardé aussi sous C:\Ad-report.log )

(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

Note :

Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis
entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels
de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces
antivirus.
0
plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
8 mars 2009 à 22:44
jvé me coucher, je reprends la suite demain

donc pour suivre après option A de ad remover

fait un scan ici et poste le rapport en entier (avec internet explorer)
http://www.bitdefender.fr/scan_fr/scan8/ie.html

puis

* Télécharge Malwarebytes https://www.androidworld.fr/
* Tu auras un tutoriel à ta disposition pour l'installer et l'utiliser correctement.
* Fais la mise à jour du logiciel (elle se fait normalement à l'installation)
* Lance une analyse complète en cliquant sur "Exécuter un examen complet"
* Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"
* L'analyse peut durer un bon moment.....
* Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"
* Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"
* Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum


* Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée
0
Ok merci je v essayer de faire tt ça.Bonne nuit!
0
voilà le raport de Ad-report-scan:
------- LOGFILE OF AD-REMOVER 1.1.1.6 | ONLY XP/VISTA -------

Updated by C_XX on 07/03/2009 at 21:40

Start at: 22:54:16 | Dim 08/03/2009 | Boot mode: Normal Boot
Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
Computer Name: nouvellevie
Current User: sylk62 - Administrator
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: NTFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\

--- Running Processes: 70

+-----------------| Boonty/Boonty Games Elements Found:

.
.
D:\Documents and Settings\All Users\Application Data\BOONTY
D:\Documents and Settings\sylk62\Cookies\sylk62@payment.boonty[1].txt

+-----------------| Eorezo Elements Found:

.

+-----------------| Infected Poker Softwares Elements Found:

.

+-----------------| FunWebProducts/MyWay/MyWebSearch Elements Found:

.
.

+-----------------| It's TV Elements Found:

.

+-----------------| Sweetim Elements Found:

HKCR\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
HKCR\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCR\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
HKCR\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
HKCR\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
HKCR\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
HKCR\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
HKCR\MediaPlayer.GraphicsUtils
HKCR\MediaPlayer.GraphicsUtils.1
HKCR\MgMediaPlayer.GifAnimator
HKCR\MgMediaPlayer.GifAnimator.1
HKCR\SWEETIE.IEToolbar
HKCR\SWEETIE.IEToolbar.1
HKCR\SWEETIE.SWEETIE
HKCR\SWEETIE.SWEETIE.3
HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook
HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
HKCR\Toolbar3.SWEETIE
HKCR\Toolbar3.SWEETIE.1
HKCR\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
HKCR\Typelib\{EEE6C35E-6118-11DC-9C72-001320C79847}
HKCR\Typelib\{EEE6C35F-6118-11DC-9C72-001320C79847}
HKCU\Software\SweetIM
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
HKLM\Software\Classes\MediaPlayer.GraphicsUtils
HKLM\Software\Classes\MediaPlayer.GraphicsUtils.1
HKLM\Software\Classes\MgMediaPlayer.GifAnimator
HKLM\Software\Classes\MgMediaPlayer.GifAnimator.1
HKLM\Software\Classes\SWEETIE.IEToolbar
HKLM\Software\Classes\SWEETIE.IEToolbar.1
HKLM\Software\Classes\SWEETIE.SWEETIE
HKLM\Software\Classes\SWEETIE.SWEETIE.3
HKLM\Software\Classes\SweetIM_URLSearchHook.ToolbarURLSearchHook
HKLM\Software\Classes\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
HKLM\Software\Classes\Toolbar3.SWEETIE
HKLM\Software\Classes\Toolbar3.SWEETIE.1
HKLM\Software\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
HKLM\Software\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}
HKLM\Software\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}
HKLM\Software\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
HKLM\Software\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
HKLM\Software\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKLM\Software\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
HKLM\Software\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
HKLM\Software\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}
HKLM\Software\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
HKLM\Software\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
HKLM\Software\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
HKLM\Software\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{266C7330-C0F4-49E5-8F20-A56F9F822875}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
HKLM\Software\SweetIM
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Sweetim
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847}
HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\351716A953E21214898904032EAE2E81
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A189D17A469616C4688D23E192996267
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
.
C:\WINDOWS\Installer\291a4221.msi
C:\WINDOWS\Installer\291a4227.msi
C:\Program Files\SweetIM
D:\Documents and Settings\All Users\Application Data\SweetIM
D:\Documents and Settings\sylk62\Cookies\sylk62@content.sweetim[1].txt
D:\Documents and Settings\sylk62\Cookies\sylk62@search.sweetim[1].txt
D:\Documents and Settings\sylk62\Cookies\sylk62@sweetim[2].txt
D:\Documents and Settings\sylk62\Cookies\sylk62@www.sweetim[2].txt

+-----------------| Other Adwares Found:

.
.
D:\Documents and Settings\sylk62\Cookies\sylk62@atdmt[2].txt
D:\Documents and Settings\sylk62\Cookies\sylk62@bs.serving-sys[2].txt

+-----------------| Added Scan:

---- Internet Explorer Version 7.0.5730.13 ----

+-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

Search bar: hxxp://g.msn.fr/0SEFRFR/SAOS02
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start page: hxxp://home.sweetim.com

+-[HKEY_USERS\S-1-5-21-1722768690-2433286175-2781512135-1006\..\Internet Explorer\Main]

Search bar: hxxp://g.msn.fr/0SEFRFR/SAOS02
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start page: hxxp://home.sweetim.com

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: hxxp://ieframe.dll/tabswelcome.htm

+---------------------------------------------------------------------------+

11569 Byte(s) - C:\Ad-Report-Scan-08.03.2009.log

0 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
0 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

End at: 22:56:16 | 08/03/2009
.
+-----------------| E.O.F - 166 Lines
.Merci
0
Voilà le rapport de bitdefender:
BitDefender Online Scanner



Rapport d'analyse généré à: Mon, Mar 09, 2009 - 00:02:09





Voie d'analyse: C:\;D:\;E:\;F:\;







Statistiques

Temps
00:55:12

Fichiers
131104

Directoires
10457

Secteurs de boot
0

Archives
1436

Paquets programmes
9637




Résultats

Virus identifiés
14

Fichiers infectés
922

Fichiers suspects
9

Avertissements
0

Désinfectés
0

Fichiers effacés
929




Info sur les moteurs

Définition virus
2771415

Version des moteurs
AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

Analyse des plugins
17

Archive des plugins
45

Unpack des plugins
7

E-mail plugins
6

Système plugins
4




Paramètres d'analyse

Première action
Désinfecté

Seconde Action
Supprimé

Heuristique
Oui

Acceptez les avertissements
Oui

Extensions analysées
exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

Excludez les extensions


Analyse d'emails
Oui

Analyse des Archives
Oui

Analyser paquets programmes
Oui

Analyse des fichiers
Oui

Analyse de boot
Oui




Fichier analysé
Statut

C:\WINDOWS\system\xccef090305.exe
Infecté par: Generic.YSpammer.72B72EED

C:\WINDOWS\system\xccef090305.exe
Echec de la désinfection

C:\WINDOWS\system\xccef090305.exe
Supprimé

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\2HGPKZ4Z\bb021908[1].exe
Infecté par: Trojan.Generic.1541244

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\2HGPKZ4Z\bb021908[1].exe
Supprimé

C:\WINDOWS\system32\ICV.EXE
Infecté par: Generic.YSpammer.72B72EED

C:\WINDOWS\system32\ICV.EXE
Echec de la désinfection

C:\WINDOWS\system32\ICV.EXE
Supprimé

C:\WINDOWS\system32\inf\xccdfb16_090305.dll
Infecté par: Trojan.PWS.OnlineGames.ZMZ

C:\WINDOWS\system32\inf\xccdfb16_090305.dll
Supprimé

C:\WINDOWS\system32\inf\xccefb090305.scr
Infecté par: Generic.YSpammer.72B72EED

C:\WINDOWS\system32\inf\xccefb090305.scr
Echec de la désinfection

C:\WINDOWS\system32\inf\xccefb090305.scr
Supprimé

C:\WINDOWS\xccdf16_090305a.dll
Infecté par: Trojan.PWS.OnlineGames.ZMZ

C:\WINDOWS\xccdf16_090305a.dll
Supprimé

C:\WINDOWS\xccdf32_090305a.dll
Infecté par: Trojan.Spy.Pophot.K

C:\WINDOWS\xccdf32_090305a.dll
Echec de la désinfection

C:\WINDOWS\xccdf32_090305a.dll
Echec de la suppression

D:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\184251DD.exe=>(Quarantine-2)
Infecté par: Trojan.Generic.179160

D:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\184251DD.exe=>(Quarantine-2)
Supprimé

D:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\184251DD.exe
Supprimé

D:\Documents and Settings\sylk62\Local Settings\Temp\mousehook.dll
Infecté par: Gen:Trojan.Heur.P1048B7F7F7

D:\Documents and Settings\sylk62\Local Settings\Temp\mousehook.dll
Echec de la désinfection

D:\Documents and Settings\sylk62\Local Settings\Temp\mousehook.dll
Echec de la suppression

D:\Documents and Settings\sylk62\Local Settings\Temp\ntdll64.dll
Infecté par: Gen:Trojan.Heur.P307887C7C7

D:\Documents and Settings\sylk62\Local Settings\Temp\ntdll64.dll
Echec de la désinfection

D:\Documents and Settings\sylk62\Local Settings\Temp\ntdll64.dll
Echec de la suppression

D:\Documents and Settings\sylvie\Local Settings\Temp\NSIS_Install_WMP.exe=>(NSIS o)=>lzma_solid_nsis0006
Détecté avec: Adware.Navipromo.BYS

D:\Documents and Settings\sylvie\Local Settings\Temp\NSIS_Install_WMP.exe=>(NSIS o)=>lzma_solid_nsis0006
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temp\NSIS_Install_WMP.exe=>(NSIS o)
Echec de la mise à jour

D:\Documents and Settings\sylvie\Local Settings\Temp\NSIS_Install_WMP.exe=>(NSIS o)=>lzma_solid_nsis0008
Infecté par: GenPack:Trojan.Generic.586352

D:\Documents and Settings\sylvie\Local Settings\Temp\NSIS_Install_WMP.exe=>(NSIS o)=>lzma_solid_nsis0008
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temp\NSIS_Install_WMP.exe=>(NSIS o)
Echec de la mise à jour

D:\Documents and Settings\sylvie\Local Settings\Temp\NSIS_Install_WMP.exe=>(NSIS o)=>lzma_solid_nsis0014=>(NSIS g)=>lzma_solid_nsis0002
Détecté avec: Adware.Navipromo.BYS

D:\Documents and Settings\sylvie\Local Settings\Temp\NSIS_Install_WMP.exe=>(NSIS o)=>lzma_solid_nsis0014=>(NSIS g)=>lzma_solid_nsis0002
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temp\NSIS_Install_WMP.exe=>(NSIS o)=>lzma_solid_nsis0014=>(NSIS g)
Echec de la mise à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\021[1].htm=>(JAVASCRIPT 15)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\021[1].htm=>(JAVASCRIPT 15)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\021[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\0WL4CAM35AX3CAEBXEDMCALIIMGKCAZUFHXUCA0M5TBPCAVKSQ33CA8292MUCAQP8PIZCA2GI61UCAIQY8PWCA7QNNLLCAWSR2JCCAQZTZQMCAM3OO6XCA0V4KDLCAHX31SVCATXU7RXCAJN4GM5CAEZNAR0.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\0WL4CAM35AX3CAEBXEDMCALIIMGKCAZUFHXUCA0M5TBPCAVKSQ33CA8292MUCAQP8PIZCA2GI61UCAIQY8PWCA7QNNLLCAWSR2JCCAQZTZQMCAM3OO6XCA0V4KDLCAHX31SVCATXU7RXCAJN4GM5CAEZNAR0.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\0WL4CAM35AX3CAEBXEDMCALIIMGKCAZUFHXUCA0M5TBPCAVKSQ33CA8292MUCAQP8PIZCA2GI61UCAIQY8PWCA7QNNLLCAWSR2JCCAQZTZQMCAM3OO6XCA0V4KDLCAHX31SVCATXU7RXCAJN4GM5CAEZNAR0.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\1GBPCABKX4V9CATXGJ2MCA4KAJQ5CAS8378YCA1AI880CARZPELPCA6QIG68CA8DIP55CA1R802KCACFP7D0CAAT78HVCAPTF1D8CA629W2JCAWR9XRCCAJGUMKLCA6JV8VSCAKD2GRUCA3M2RAOCAGK01JL.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\1GBPCABKX4V9CATXGJ2MCA4KAJQ5CAS8378YCA1AI880CARZPELPCA6QIG68CA8DIP55CA1R802KCACFP7D0CAAT78HVCAPTF1D8CA629W2JCAWR9XRCCAJGUMKLCA6JV8VSCAKD2GRUCA3M2RAOCAGK01JL.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\1GBPCABKX4V9CATXGJ2MCA4KAJQ5CAS8378YCA1AI880CARZPELPCA6QIG68CA8DIP55CA1R802KCACFP7D0CAAT78HVCAPTF1D8CA629W2JCAWR9XRCCAJGUMKLCA6JV8VSCAKD2GRUCA3M2RAOCAGK01JL.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\20ZCCAKRV7FLCA0SDF0LCAHNR2W0CADVOLD8CAXJKS4ICARN2GRBCA4C28DLCAWFZ2E7CAH4HNIBCATICGI8CAXE5EB0CA6TU9ABCAMAJWR0CA54GI5JCASJ2NL1CAGTJWRGCAUVL8WOCA6AJEWRCASC22NA.htm=>(JAVASCRIPT 8)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\20ZCCAKRV7FLCA0SDF0LCAHNR2W0CADVOLD8CAXJKS4ICARN2GRBCA4C28DLCAWFZ2E7CAH4HNIBCATICGI8CAXE5EB0CA6TU9ABCAMAJWR0CA54GI5JCASJ2NL1CAGTJWRGCAUVL8WOCA6AJEWRCASC22NA.htm=>(JAVASCRIPT 8)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\20ZCCAKRV7FLCA0SDF0LCAHNR2W0CADVOLD8CAXJKS4ICARN2GRBCA4C28DLCAWFZ2E7CAH4HNIBCATICGI8CAXE5EB0CA6TU9ABCAMAJWR0CA54GI5JCASJ2NL1CAGTJWRGCAUVL8WOCA6AJEWRCASC22NA.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\22LJCAJPW7BFCAVN8FB1CARRXOMZCAY1MTMCCAFPW2J2CA33EKZLCAZW5DZKCAP3L2UYCA9TK3YDCANBD8YKCAXFGB8GCAHKCM05CADUDFM5CA2Q0EC8CA1PFJ80CAPD4H0MCAZON1NKCA8QRVT0CALKKLJ6.htm=>(JAVASCRIPT 17)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\22LJCAJPW7BFCAVN8FB1CARRXOMZCAY1MTMCCAFPW2J2CA33EKZLCAZW5DZKCAP3L2UYCA9TK3YDCANBD8YKCAXFGB8GCAHKCM05CADUDFM5CA2Q0EC8CA1PFJ80CAPD4H0MCAZON1NKCA8QRVT0CALKKLJ6.htm=>(JAVASCRIPT 17)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\22LJCAJPW7BFCAVN8FB1CARRXOMZCAY1MTMCCAFPW2J2CA33EKZLCAZW5DZKCAP3L2UYCA9TK3YDCANBD8YKCAXFGB8GCAHKCM05CADUDFM5CA2Q0EC8CA1PFJ80CAPD4H0MCAZON1NKCA8QRVT0CALKKLJ6.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\2U2XCAK3PXDVCABGEFE6CAZ3F0Q2CA3KPQ5JCAGK4W14CAEJKU04CA63FU9LCAIS6TGWCASGXIHDCA2MT6A1CAOL7H8PCARLSWMCCAVB9FVHCAHFBM8PCA35N7WHCAGXWBFLCAD3DT0JCAAMPE1OCAUMGZU8.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\2U2XCAK3PXDVCABGEFE6CAZ3F0Q2CA3KPQ5JCAGK4W14CAEJKU04CA63FU9LCAIS6TGWCASGXIHDCA2MT6A1CAOL7H8PCARLSWMCCAVB9FVHCAHFBM8PCA35N7WHCAGXWBFLCAD3DT0JCAAMPE1OCAUMGZU8.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\2U2XCAK3PXDVCABGEFE6CAZ3F0Q2CA3KPQ5JCAGK4W14CAEJKU04CA63FU9LCAIS6TGWCASGXIHDCA2MT6A1CAOL7H8PCARLSWMCCAVB9FVHCAHFBM8PCA35N7WHCAGXWBFLCAD3DT0JCAAMPE1OCAUMGZU8.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\3B9GCAJFP39FCAFGQNQ6CAZHDYPRCA7HQ9D9CALOZQK1CANGEETFCAJW0T7UCAKIQTW8CAKG3I9JCAD5UYEACATB871JCAWI9SHJCAWBE1KTCAQCPL3ACA5OQI8SCAJ6IGKOCAHNAXVYCA1X5L2ICAH446FI.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\3B9GCAJFP39FCAFGQNQ6CAZHDYPRCA7HQ9D9CALOZQK1CANGEETFCAJW0T7UCAKIQTW8CAKG3I9JCAD5UYEACATB871JCAWI9SHJCAWBE1KTCAQCPL3ACA5OQI8SCAJ6IGKOCAHNAXVYCA1X5L2ICAH446FI.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\3B9GCAJFP39FCAFGQNQ6CAZHDYPRCA7HQ9D9CALOZQK1CANGEETFCAJW0T7UCAKIQTW8CAKG3I9JCAD5UYEACATB871JCAWI9SHJCAWBE1KTCAQCPL3ACA5OQI8SCAJ6IGKOCAHNAXVYCA1X5L2ICAH446FI.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4BPLCAP4NC82CANN9DBVCA0DZVIACAQ3ICRPCAM5ABC6CA3275SECA15RWABCA9KR9WUCADEOYTRCACXNPZ9CAM4CQWVCAMMBVETCAB1PT08CA677N17CAIBKZRLCARR7CPCCAQN0RVKCAXRNA9SCAVV0GBX.htm=>(JAVASCRIPT 18)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4BPLCAP4NC82CANN9DBVCA0DZVIACAQ3ICRPCAM5ABC6CA3275SECA15RWABCA9KR9WUCADEOYTRCACXNPZ9CAM4CQWVCAMMBVETCAB1PT08CA677N17CAIBKZRLCARR7CPCCAQN0RVKCAXRNA9SCAVV0GBX.htm=>(JAVASCRIPT 18)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4BPLCAP4NC82CANN9DBVCA0DZVIACAQ3ICRPCAM5ABC6CA3275SECA15RWABCA9KR9WUCADEOYTRCACXNPZ9CAM4CQWVCAMMBVETCAB1PT08CA677N17CAIBKZRLCARR7CPCCAQN0RVKCAXRNA9SCAVV0GBX.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4L3KCA4M8T2VCA23ZF4BCAE7BR7ACA8CFI4UCAHH310NCAF4VKXQCAKOFV7QCAA7DO2UCAH28XOGCAUWRT02CAE1NQBICAOI3OR8CA5N0HK4CA9V8QVECANQI0U8CALRUS2ECA35U0IUCAKD9M2LCA3JBUX3.htm=>(JAVASCRIPT 31)
Infecté par: Trojan.JS.Injector.F

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4L3KCA4M8T2VCA23ZF4BCAE7BR7ACA8CFI4UCAHH310NCAF4VKXQCAKOFV7QCAA7DO2UCAH28XOGCAUWRT02CAE1NQBICAOI3OR8CA5N0HK4CA9V8QVECANQI0U8CALRUS2ECA35U0IUCAKD9M2LCA3JBUX3.htm=>(JAVASCRIPT 31)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4L3KCA4M8T2VCA23ZF4BCAE7BR7ACA8CFI4UCAHH310NCAF4VKXQCAKOFV7QCAA7DO2UCAH28XOGCAUWRT02CAE1NQBICAOI3OR8CA5N0HK4CA9V8QVECANQI0U8CALRUS2ECA35U0IUCAKD9M2LCA3JBUX3.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4S5DCAYMEIHSCA8V6TP6CARDH23MCAQGOLHUCA2PHHU4CA5U8LXNCANXDJD0CA0HDLS5CA4F4ZL3CA4D8BMMCAUTW529CA95MD2TCAYY2LB6CAVFB9ZTCAY40BXICANYVA1UCAYEBM91CA66PK7LCAHSZYEP.htm=>(JAVASCRIPT 29)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4S5DCAYMEIHSCA8V6TP6CARDH23MCAQGOLHUCA2PHHU4CA5U8LXNCANXDJD0CA0HDLS5CA4F4ZL3CA4D8BMMCAUTW529CA95MD2TCAYY2LB6CAVFB9ZTCAY40BXICANYVA1UCAYEBM91CA66PK7LCAHSZYEP.htm=>(JAVASCRIPT 29)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4S5DCAYMEIHSCA8V6TP6CARDH23MCAQGOLHUCA2PHHU4CA5U8LXNCANXDJD0CA0HDLS5CA4F4ZL3CA4D8BMMCAUTW529CA95MD2TCAYY2LB6CAVFB9ZTCAY40BXICANYVA1UCAYEBM91CA66PK7LCAHSZYEP.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4VW8CA1P7J27CA046GWFCAY2KNZ2CAMUO2F7CAGHR80NCA68L7YFCAE87PGQCAUDP2L7CAIWQ1UPCA5MGWASCAYGHMJRCAZDTCI6CABLJHU9CA2C49HZCA58P038CAXED54FCA12YD24CARZNGVNCAWR321R.htm=>(JAVASCRIPT 24)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4VW8CA1P7J27CA046GWFCAY2KNZ2CAMUO2F7CAGHR80NCA68L7YFCAE87PGQCAUDP2L7CAIWQ1UPCA5MGWASCAYGHMJRCAZDTCI6CABLJHU9CA2C49HZCA58P038CAXED54FCA12YD24CARZNGVNCAWR321R.htm=>(JAVASCRIPT 24)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\4VW8CA1P7J27CA046GWFCAY2KNZ2CAMUO2F7CAGHR80NCA68L7YFCAE87PGQCAUDP2L7CAIWQ1UPCA5MGWASCAYGHMJRCAZDTCI6CABLJHU9CA2C49HZCA58P038CAXED54FCA12YD24CARZNGVNCAWR321R.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\5CTZCAB8R6Q8CAFS9MVVCA6QXFFACAMWHDDGCAH11Z75CAKSZHDICAT5EENUCAR5JLJACAFMSCJLCA013Y1CCA8NSIGSCAPSNFPMCAMWZQ7YCASBU2XSCADCZ7PPCA7YP0JICAC2RCS7CA2KXPZQCA377TDY.htm=>(JAVASCRIPT 40)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\5CTZCAB8R6Q8CAFS9MVVCA6QXFFACAMWHDDGCAH11Z75CAKSZHDICAT5EENUCAR5JLJACAFMSCJLCA013Y1CCA8NSIGSCAPSNFPMCAMWZQ7YCASBU2XSCADCZ7PPCA7YP0JICAC2RCS7CA2KXPZQCA377TDY.htm=>(JAVASCRIPT 40)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\5CTZCAB8R6Q8CAFS9MVVCA6QXFFACAMWHDDGCAH11Z75CAKSZHDICAT5EENUCAR5JLJACAFMSCJLCA013Y1CCA8NSIGSCAPSNFPMCAMWZQ7YCASBU2XSCADCZ7PPCA7YP0JICAC2RCS7CA2KXPZQCA377TDY.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\6LL6CASURN5TCAWS6BABCAQDKQSDCAG6YJQSCAE82W6DCAR09PI3CAIVXYFZCA3WBCFNCA0KISAXCA3WFV3TCA5CCORDCALAN1E0CADTUJXTCA6SMDYVCAMAN3AACA8IS2FDCAKOJSWOCAU7LHT8CAB9F4TI.htm=>(JAVASCRIPT 24)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\6LL6CASURN5TCAWS6BABCAQDKQSDCAG6YJQSCAE82W6DCAR09PI3CAIVXYFZCA3WBCFNCA0KISAXCA3WFV3TCA5CCORDCALAN1E0CADTUJXTCA6SMDYVCAMAN3AACA8IS2FDCAKOJSWOCAU7LHT8CAB9F4TI.htm=>(JAVASCRIPT 24)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\6LL6CASURN5TCAWS6BABCAQDKQSDCAG6YJQSCAE82W6DCAR09PI3CAIVXYFZCA3WBCFNCA0KISAXCA3WFV3TCA5CCORDCALAN1E0CADTUJXTCA6SMDYVCAMAN3AACA8IS2FDCAKOJSWOCAU7LHT8CAB9F4TI.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\6ZARCAOFL32TCAPTZIJ3CA1GU56MCAH1FPFTCAJIWBUCCAMKPSGRCAQYN42ACA86CRK2CAJPM2SFCAORCT4ACA32NENVCA1YFW4JCAME3I0JCA9PYTU0CAL6TKF1CAE67YEACAU52BL0CAAUQY21CA5QLSI7.htm=>(JAVASCRIPT 18)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\6ZARCAOFL32TCAPTZIJ3CA1GU56MCAH1FPFTCAJIWBUCCAMKPSGRCAQYN42ACA86CRK2CAJPM2SFCAORCT4ACA32NENVCA1YFW4JCAME3I0JCA9PYTU0CAL6TKF1CAE67YEACAU52BL0CAAUQY21CA5QLSI7.htm=>(JAVASCRIPT 18)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\6ZARCAOFL32TCAPTZIJ3CA1GU56MCAH1FPFTCAJIWBUCCAMKPSGRCAQYN42ACA86CRK2CAJPM2SFCAORCT4ACA32NENVCA1YFW4JCAME3I0JCA9PYTU0CAL6TKF1CAE67YEACAU52BL0CAAUQY21CA5QLSI7.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads.htm=>(JAVASCRIPT 29)
Infecté par: Trojan.JS.Injector.F

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads.htm=>(JAVASCRIPT 29)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[10].htm=>(JAVASCRIPT 29)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[10].htm=>(JAVASCRIPT 29)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[10].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[11].htm=>(JAVASCRIPT 29)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[11].htm=>(JAVASCRIPT 29)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[11].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[1].htm=>(JAVASCRIPT 30)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[1].htm=>(JAVASCRIPT 30)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[2].htm=>(JAVASCRIPT 11)
Infecté par: Trojan.JS.Injector.F

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[2].htm=>(JAVASCRIPT 11)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[2].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[3].htm=>(JAVASCRIPT 11)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[3].htm=>(JAVASCRIPT 11)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[3].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[4].htm=>(JAVASCRIPT 11)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[4].htm=>(JAVASCRIPT 11)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[4].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[5].htm=>(JAVASCRIPT 29)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[5].htm=>(JAVASCRIPT 29)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[5].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[6].htm=>(JAVASCRIPT 30)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[6].htm=>(JAVASCRIPT 30)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[6].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[7].htm=>(JAVASCRIPT 30)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[7].htm=>(JAVASCRIPT 30)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[7].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[8].htm=>(JAVASCRIPT 30)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[8].htm=>(JAVASCRIPT 30)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[8].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[9].htm=>(JAVASCRIPT 11)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[9].htm=>(JAVASCRIPT 11)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ads[9].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\affsex[1].htm=>(JAVASCRIPT 12)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\affsex[1].htm=>(JAVASCRIPT 12)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\affsex[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\B7WGCAY0OEX0CAD81TQGCA1DCHXPCAFQCABDCA4PU9BPCAGPVTWUCAAW71Q9CAQ5RD72CA1WXAQLCAONW076CAT2G4QGCAL6MBHKCAF1G6P5CAPDVKL2CAO6QZOICAVY7GSLCAIK4B26CAZK2W6LCAY1TOYO.htm=>(JAVASCRIPT 29)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\B7WGCAY0OEX0CAD81TQGCA1DCHXPCAFQCABDCA4PU9BPCAGPVTWUCAAW71Q9CAQ5RD72CA1WXAQLCAONW076CAT2G4QGCAL6MBHKCAF1G6P5CAPDVKL2CAO6QZOICAVY7GSLCAIK4B26CAZK2W6LCAY1TOYO.htm=>(JAVASCRIPT 29)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\B7WGCAY0OEX0CAD81TQGCA1DCHXPCAFQCABDCA4PU9BPCAGPVTWUCAAW71Q9CAQ5RD72CA1WXAQLCAONW076CAT2G4QGCAL6MBHKCAF1G6P5CAPDVKL2CAO6QZOICAVY7GSLCAIK4B26CAZK2W6LCAY1TOYO.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\B913CA6TF0FLCAU19JB1CAGKFHVFCA52CA5ICAOHKSQZCAL0YHHMCAJFT5M8CAX0CTP5CAR5ZR6ACAYM72EICAY4QFU1CAAR7IVECA6JEFNSCA9JNW85CABN9Y1ZCAGRJC3TCAPZNK2SCATYG1Z0CAUCMQ33.htm=>(JAVASCRIPT 24)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\B913CA6TF0FLCAU19JB1CAGKFHVFCA52CA5ICAOHKSQZCAL0YHHMCAJFT5M8CAX0CTP5CAR5ZR6ACAYM72EICAY4QFU1CAAR7IVECA6JEFNSCA9JNW85CABN9Y1ZCAGRJC3TCAPZNK2SCATYG1Z0CAUCMQ33.htm=>(JAVASCRIPT 24)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\B913CA6TF0FLCAU19JB1CAGKFHVFCA52CA5ICAOHKSQZCAL0YHHMCAJFT5M8CAX0CTP5CAR5ZR6ACAYM72EICAY4QFU1CAAR7IVECA6JEFNSCA9JNW85CABN9Y1ZCAGRJC3TCAPZNK2SCATYG1Z0CAUCMQ33.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\bep-1ere--annee-compta_lycee-sainte-marie[1].htm=>(JAVASCRIPT 10)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\bep-1ere--annee-compta_lycee-sainte-marie[1].htm=>(JAVASCRIPT 10)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\bep-1ere--annee-compta_lycee-sainte-marie[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\BRWHCA2HMOASCA955E2BCAM2YBUHCA94XQUWCANL93E4CA79YA62CABH7TM7CAG5DYNVCA8NXMM3CAL4HKVWCATVG0OICA1D99VDCA0W5Q8NCAO5UCN8CAN9WKM3CASX3P5KCAUCF3W2CAOLEBRYCA8FHZST.htm=>(JAVASCRIPT 17)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\BRWHCA2HMOASCA955E2BCAM2YBUHCA94XQUWCANL93E4CA79YA62CABH7TM7CAG5DYNVCA8NXMM3CAL4HKVWCATVG0OICA1D99VDCA0W5Q8NCAO5UCN8CAN9WKM3CASX3P5KCAUCF3W2CAOLEBRYCA8FHZST.htm=>(JAVASCRIPT 17)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\BRWHCA2HMOASCA955E2BCAM2YBUHCA94XQUWCANL93E4CA79YA62CABH7TM7CAG5DYNVCA8NXMM3CAL4HKVWCATVG0OICA1D99VDCA0W5Q8NCAO5UCN8CAN9WKM3CASX3P5KCAUCF3W2CAOLEBRYCA8FHZST.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\C3R6CAF2HCBHCAK3S071CANJTNH1CARAIYHDCARDL1OSCAQAJ4XECANFT3A2CA82U706CA79VZ1ACAA7QQHDCAAMT7R1CAM4XENCCAAPR68ZCA7RM1VYCART70J9CA9XKR2TCAILGC0VCAV30LPNCAE0Z694.htm=>(JAVASCRIPT 29)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\C3R6CAF2HCBHCAK3S071CANJTNH1CARAIYHDCARDL1OSCAQAJ4XECANFT3A2CA82U706CA79VZ1ACAA7QQHDCAAMT7R1CAM4XENCCAAPR68ZCA7RM1VYCART70J9CA9XKR2TCAILGC0VCAV30LPNCAE0Z694.htm=>(JAVASCRIPT 29)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\C3R6CAF2HCBHCAK3S071CANJTNH1CARAIYHDCARDL1OSCAQAJ4XECANFT3A2CA82U706CA79VZ1ACAA7QQHDCAAMT7R1CAM4XENCCAAPR68ZCA7RM1VYCART70J9CA9XKR2TCAILGC0VCAV30LPNCAE0Z694.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\chvx[1].htm=>(JAVASCRIPT 15)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\chvx[1].htm=>(JAVASCRIPT 15)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\chvx[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\CJJXCA9LH72UCA0Y0UAOCA65TKERCACWS0YMCA0VLNVMCAH8CVW5CAXGD4NDCAPS42GZCATV4FK8CAJT7JAYCA81DXW6CAB25LUSCANB0O3NCA4OBV6XCA0TTHSRCAUO26GBCACCDR27CATY6KIOCABRNCXN.htm=>(JAVASCRIPT 17)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\CJJXCA9LH72UCA0Y0UAOCA65TKERCACWS0YMCA0VLNVMCAH8CVW5CAXGD4NDCAPS42GZCATV4FK8CAJT7JAYCA81DXW6CAB25LUSCANB0O3NCA4OBV6XCA0TTHSRCAUO26GBCACCDR27CATY6KIOCABRNCXN.htm=>(JAVASCRIPT 17)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\CJJXCA9LH72UCA0Y0UAOCA65TKERCACWS0YMCA0VLNVMCAH8CVW5CAXGD4NDCAPS42GZCATV4FK8CAJT7JAYCA81DXW6CAB25LUSCANB0O3NCA4OBV6XCA0TTHSRCAUO26GBCACCDR27CATY6KIOCABRNCXN.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\course[1].htm=>(JAVASCRIPT 20)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\course[1].htm=>(JAVASCRIPT 20)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\course[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\CZA3CAE1IPI0CARFHKRHCANMPO3KCA7SNHYOCAY5PTB7CA3KYONWCAW0D3OSCAXR4ATMCAE2JO1BCAJNYFNDCA73FMG7CAR9U6TMCAC35OHQCA8KHPMHCACMHPYQCA8HNLLECA7R912ECAPR55RECA975N1T.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\CZA3CAE1IPI0CARFHKRHCANMPO3KCA7SNHYOCAY5PTB7CA3KYONWCAW0D3OSCAXR4ATMCAE2JO1BCAJNYFNDCA73FMG7CAR9U6TMCAC35OHQCA8KHPMHCACMHPYQCA8HNLLECA7R912ECAPR55RECA975N1T.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\CZA3CAE1IPI0CARFHKRHCANMPO3KCA7SNHYOCAY5PTB7CA3KYONWCAW0D3OSCAXR4ATMCAE2JO1BCAJNYFNDCA73FMG7CAR9U6TMCAC35OHQCA8KHPMHCACMHPYQCA8HNLLECA7R912ECAPR55RECA975N1T.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\D649CA4Y6XBQCAVS9LCLCABGLS2XCA3RQEG8CA7U3UL4CA4WAXSECA5M9QB7CA6D50I9CABS3A5JCA8J2IYACAEN6JR3CAFY11UWCAZS15FKCA9AHEKWCALSKPMDCAFGU8RKCA1T2NBUCAWF5W5QCALW68VJ.htm=>(JAVASCRIPT 24)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\D649CA4Y6XBQCAVS9LCLCABGLS2XCA3RQEG8CA7U3UL4CA4WAXSECA5M9QB7CA6D50I9CABS3A5JCA8J2IYACAEN6JR3CAFY11UWCAZS15FKCA9AHEKWCALSKPMDCAFGU8RKCA1T2NBUCAWF5W5QCALW68VJ.htm=>(JAVASCRIPT 24)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\D649CA4Y6XBQCAVS9LCLCABGLS2XCA3RQEG8CA7U3UL4CA4WAXSECA5M9QB7CA6D50I9CABS3A5JCA8J2IYACAEN6JR3CAFY11UWCAZS15FKCA9AHEKWCALSKPMDCAFGU8RKCA1T2NBUCAWF5W5QCALW68VJ.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\default[1].htm=>(JAVASCRIPT 128)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\default[1].htm=>(JAVASCRIPT 128)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\default[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\F303CAEUX02DCAV40IL5CAILN190CAIUQHQZCAIDAQG4CA6JUEXACAWZISY3CA7N68XSCA1KKJ6ECAUL6VFECAAY0BMTCAM086SZCABJ7OXWCAEE79L6CA8EB0A9CA9RL7ZHCAOR5LOCCAAU6P6KCA1G7KZ8.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\F303CAEUX02DCAV40IL5CAILN190CAIUQHQZCAIDAQG4CA6JUEXACAWZISY3CA7N68XSCA1KKJ6ECAUL6VFECAAY0BMTCAM086SZCABJ7OXWCAEE79L6CA8EB0A9CA9RL7ZHCAOR5LOCCAAU6P6KCA1G7KZ8.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\F303CAEUX02DCAV40IL5CAILN190CAIUQHQZCAIDAQG4CA6JUEXACAWZISY3CA7N68XSCA1KKJ6ECAUL6VFECAAY0BMTCAM086SZCABJ7OXWCAEE79L6CA8EB0A9CA9RL7ZHCAOR5LOCCAAU6P6KCA1G7KZ8.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\F8KMCA3MUACFCA6DTNYSCAZG70DCCA5QECQUCAW21BXGCAOBQDMICAL00I61CAVQFUN0CARM78VGCAWUHWX2CAWFHO33CATLTW9XCAVL85TZCA6TC15DCA6YIGPPCAX7R4SECAVZXDCSCAD2LP99CACM6E4E.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\F8KMCA3MUACFCA6DTNYSCAZG70DCCA5QECQUCAW21BXGCAOBQDMICAL00I61CAVQFUN0CARM78VGCAWUHWX2CAWFHO33CATLTW9XCAVL85TZCA6TC15DCA6YIGPPCAX7R4SECAVZXDCSCAD2LP99CACM6E4E.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\F8KMCA3MUACFCA6DTNYSCAZG70DCCA5QECQUCAW21BXGCAOBQDMICAL00I61CAVQFUN0CARM78VGCAWUHWX2CAWFHO33CATLTW9XCAVL85TZCA6TC15DCA6YIGPPCAX7R4SECAVZXDCSCAD2LP99CACM6E4E.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\footer_auto[1].htm=>(JAVASCRIPT 5)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\footer_auto[1].htm=>(JAVASCRIPT 5)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\footer_auto[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\FR_300x250_11[1].htm
Infecté par: Trojan.JS.Injector.F

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\FR_300x250_11[1].htm
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\FR_300x250_48[1].htm
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\FR_300x250_48[1].htm
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\FR_300x250_49[1].htm
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\FR_300x250_49[1].htm
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\FR_468x60_31[1].htm
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\FR_468x60_31[1].htm
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\H41LCA7K24CQCA0L60GNCAKRSRY6CAKMTO9HCAMVUFOWCAAYSG69CAFJ6VE4CAWFUY0ZCAR9A9UMCA5U5CWZCAWQCJQDCACBHPOKCANNPJBDCAF3BDZLCAA0UY8BCA2BMJO5CAO15JGYCA74Q9JVCAPOTB8L.htm=>(JAVASCRIPT 17)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\H41LCA7K24CQCA0L60GNCAKRSRY6CAKMTO9HCAMVUFOWCAAYSG69CAFJ6VE4CAWFUY0ZCAR9A9UMCA5U5CWZCAWQCJQDCACBHPOKCANNPJBDCAF3BDZLCAA0UY8BCA2BMJO5CAO15JGYCA74Q9JVCAPOTB8L.htm=>(JAVASCRIPT 17)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\H41LCA7K24CQCA0L60GNCAKRSRY6CAKMTO9HCAMVUFOWCAAYSG69CAFJ6VE4CAWFUY0ZCAR9A9UMCA5U5CWZCAWQCJQDCACBHPOKCANNPJBDCAF3BDZLCAA0UY8BCA2BMJO5CAO15JGYCA74Q9JVCAPOTB8L.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\haus[1].htm=>(JAVASCRIPT 16)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\haus[1].htm=>(JAVASCRIPT 16)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\haus[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ig_080819[1].htm
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\ig_080819[1].htm
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\inbox[1].htm
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\inbox[1].htm
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\index[1].htm=>(JAVASCRIPT 2)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\index[1].htm=>(JAVASCRIPT 2)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\index[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\index[3].htm=>(JAVASCRIPT 126)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\index[3].htm=>(JAVASCRIPT 126)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\index[3].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\index[5].htm=>(JAVASCRIPT 22)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\index[5].htm=>(JAVASCRIPT 22)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\index[5].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\KUIGCA68ELX0CAJ4X45ACAJA6V11CA9OXCXXCAO3NQOACAHR50J7CAYUBHJICAVLTPILCAQ3HTIBCAOX0BGYCA7QSGBSCAFXAS1JCA6394VQCACG43WFCACIIFOACAYY7OXCCA2WKLLFCA5IM739CAXQUBYU.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\KUIGCA68ELX0CAJ4X45ACAJA6V11CA9OXCXXCAO3NQOACAHR50J7CAYUBHJICAVLTPILCAQ3HTIBCAOX0BGYCA7QSGBSCAFXAS1JCA6394VQCACG43WFCACIIFOACAYY7OXCCA2WKLLFCA5IM739CAXQUBYU.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\KUIGCA68ELX0CAJ4X45ACAJA6V11CA9OXCXXCAO3NQOACAHR50J7CAYUBHJICAVLTPILCAQ3HTIBCAOX0BGYCA7QSGBSCAFXAS1JCA6394VQCACG43WFCACIIFOACAYY7OXCCA2WKLLFCA5IM739CAXQUBYU.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\N6LTCAT501K2CAOHDF3GCAZGLC2CCAHAM7EOCAC9B96TCAWQVJKFCAADPGWNCAYVTFA5CA6SKX89CAWAV1Q5CA8WJ23ICA819MYXCADQ87OBCAS4BUWFCACUOTU9CA53FSJOCAWVO8IYCAPJD2U9CA24GTJ1.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\N6LTCAT501K2CAOHDF3GCAZGLC2CCAHAM7EOCAC9B96TCAWQVJKFCAADPGWNCAYVTFA5CA6SKX89CAWAV1Q5CA8WJ23ICA819MYXCADQ87OBCAS4BUWFCACUOTU9CA53FSJOCAWVO8IYCAPJD2U9CA24GTJ1.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\N6LTCAT501K2CAOHDF3GCAZGLC2CCAHAM7EOCAC9B96TCAWQVJKFCAADPGWNCAYVTFA5CA6SKX89CAWAV1Q5CA8WJ23ICA819MYXCADQ87OBCAS4BUWFCACUOTU9CA53FSJOCAWVO8IYCAPJD2U9CA24GTJ1.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\NEI8CATH4VQICA8VD7G3CADMGYJICAIIJ0ZLCAW8KS54CAFE9ZYNCAJICXG8CAMLPTPUCAS5W90GCAAHCSAGCA5FS0CICAPSF40PCAZRT4IRCALWBQTCCA7XOBASCAHOO0ZGCAGICIEOCAATEZAACATY5IKZ.htm=>(JAVASCRIPT 96)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\NEI8CATH4VQICA8VD7G3CADMGYJICAIIJ0ZLCAW8KS54CAFE9ZYNCAJICXG8CAMLPTPUCAS5W90GCAAHCSAGCA5FS0CICAPSF40PCAZRT4IRCALWBQTCCA7XOBASCAHOO0ZGCAGICIEOCAATEZAACATY5IKZ.htm=>(JAVASCRIPT 96)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\NEI8CATH4VQICA8VD7G3CADMGYJICAIIJ0ZLCAW8KS54CAFE9ZYNCAJICXG8CAMLPTPUCAS5W90GCAAHCSAGCA5FS0CICAPSF40PCAZRT4IRCALWBQTCCA7XOBASCAHOO0ZGCAGICIEOCAATEZAACATY5IKZ.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\NVTICALD84QOCAZE22WBCAMBSVRXCARAR7Y3CAM77SWOCANK88BSCA6ZY7Z2CAAX86B5CANRZQSLCAJ8U113CAQYVPRKCACWTJL1CA2HNJRWCAC7SNPZCAFCWLHGCA2RQJZACAEGMZ13CAEG623XCA0NCB97.htm=>(JAVASCRIPT 24)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\NVTICALD84QOCAZE22WBCAMBSVRXCARAR7Y3CAM77SWOCANK88BSCA6ZY7Z2CAAX86B5CANRZQSLCAJ8U113CAQYVPRKCACWTJL1CA2HNJRWCAC7SNPZCAFCWLHGCA2RQJZACAEGMZ13CAEG623XCA0NCB97.htm=>(JAVASCRIPT 24)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\NVTICALD84QOCAZE22WBCAMBSVRXCARAR7Y3CAM77SWOCANK88BSCA6ZY7Z2CAAX86B5CANRZQSLCAJ8U113CAQYVPRKCACWTJL1CA2HNJRWCAC7SNPZCAFCWLHGCA2RQJZACAEGMZ13CAEG623XCA0NCB97.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\OVK4CA2B7RYCCA5YVXKOCA4IIF3JCADOHIQ4CAN8Y4A9CAYL9DDLCA6DG4KKCA33ZW03CA41KYKXCAIP4B4PCA6AWCOJCAF1NITBCABZO6R5CA081YFPCAL6VM3CCAVZASM3CAFQBYGQCAOR7EYWCAKEZ8VL.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\OVK4CA2B7RYCCA5YVXKOCA4IIF3JCADOHIQ4CAN8Y4A9CAYL9DDLCA6DG4KKCA33ZW03CA41KYKXCAIP4B4PCA6AWCOJCAF1NITBCABZO6R5CA081YFPCAL6VM3CCAVZASM3CAFQBYGQCAOR7EYWCAKEZ8VL.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\OVK4CA2B7RYCCA5YVXKOCA4IIF3JCADOHIQ4CAN8Y4A9CAYL9DDLCA6DG4KKCA33ZW03CA41KYKXCAIP4B4PCA6AWCOJCAF1NITBCABZO6R5CA081YFPCAL6VM3CCAVZASM3CAFQBYGQCAOR7EYWCAKEZ8VL.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\P73VCAURGN21CA3AOOR8CARRNZLOCAV33SUUCA3ZLU53CAQ1KGNICA6NELGJCA9OQOGDCAFNL2D4CALM2XHYCA8LWETDCADT6TP8CALDIFM1CAZ80SK5CAKOAS71CATGPQBZCAVO5F3DCAA9JYZBCA3JU6RT.htm=>(JAVASCRIPT 17)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\P73VCAURGN21CA3AOOR8CARRNZLOCAV33SUUCA3ZLU53CAQ1KGNICA6NELGJCA9OQOGDCAFNL2D4CALM2XHYCA8LWETDCADT6TP8CALDIFM1CAZ80SK5CAKOAS71CATGPQBZCAVO5F3DCAA9JYZBCA3JU6RT.htm=>(JAVASCRIPT 17)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\P73VCAURGN21CA3AOOR8CARRNZLOCAV33SUUCA3ZLU53CAQ1KGNICA6NELGJCA9OQOGDCAFNL2D4CALM2XHYCA8LWETDCADT6TP8CALDIFM1CAZ80SK5CAKOAS71CATGPQBZCAVO5F3DCAA9JYZBCA3JU6RT.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\pilotes-aff[1].htm=>(JAVASCRIPT 11)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\pilotes-aff[1].htm=>(JAVASCRIPT 11)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\pilotes-aff[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\R0BDCAQ7TQHACAY4Q6MECAILC065CA8KBTV7CAMAQDQWCA6976OICAYYEH38CAJ1RVGPCACMQZNRCAHLBIN5CAPMEG0BCAJSJLP0CAW202YDCAL41UK1CAP8OHD8CALFTWLPCARICA4ZCAZ180A5CALZPHGD.htm=>(JAVASCRIPT 18)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\R0BDCAQ7TQHACAY4Q6MECAILC065CA8KBTV7CAMAQDQWCA6976OICAYYEH38CAJ1RVGPCACMQZNRCAHLBIN5CAPMEG0BCAJSJLP0CAW202YDCAL41UK1CAP8OHD8CALFTWLPCARICA4ZCAZ180A5CALZPHGD.htm=>(JAVASCRIPT 18)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\R0BDCAQ7TQHACAY4Q6MECAILC065CA8KBTV7CAMAQDQWCA6976OICAYYEH38CAJ1RVGPCACMQZNRCAHLBIN5CAPMEG0BCAJSJLP0CAW202YDCAL41UK1CAP8OHD8CALFTWLPCARICA4ZCAZ180A5CALZPHGD.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\R9F5CAE1VAJBCAKRXYJYCAC368IMCATJNNQJCANF6URGCAMHOZU9CAIH6TBDCATZX128CAYEXNSPCAHJ68WHCAN8N0GKCAQSFFFBCAZY0IO1CAWNHC45CAIC7G4DCA2XFZ4JCAED52LOCAN55418CAM38VKD.htm=>(JAVASCRIPT 24)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\R9F5CAE1VAJBCAKRXYJYCAC368IMCATJNNQJCANF6URGCAMHOZU9CAIH6TBDCATZX128CAYEXNSPCAHJ68WHCAN8N0GKCAQSFFFBCAZY0IO1CAWNHC45CAIC7G4DCA2XFZ4JCAED52LOCAN55418CAM38VKD.htm=>(JAVASCRIPT 24)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\R9F5CAE1VAJBCAKRXYJYCAC368IMCATJNNQJCANF6URGCAMHOZU9CAIH6TBDCATZX128CAYEXNSPCAHJ68WHCAN8N0GKCAQSFFFBCAZY0IO1CAWNHC45CAIC7G4DCA2XFZ4JCAED52LOCAN55418CAM38VKD.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\RZH2CAN4S0ZFCAIB7QPZCAN2UBDZCAFXSY5NCAF0TGPSCAQY42LQCA3OU71YCAB130YTCAXWIQPFCA625J35CAPTDYXHCAOM8XNLCA4HJT5PCA4K1JUSCAF2N052CAW69NCACAWA5Y08CAYYA7LMCA0OHXXN.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\RZH2CAN4S0ZFCAIB7QPZCAN2UBDZCAFXSY5NCAF0TGPSCAQY42LQCA3OU71YCAB130YTCAXWIQPFCA625J35CAPTDYXHCAOM8XNLCA4HJT5PCA4K1JUSCAF2N052CAW69NCACAWA5Y08CAYYA7LMCA0OHXXN.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\RZH2CAN4S0ZFCAIB7QPZCAN2UBDZCAFXSY5NCAF0TGPSCAQY42LQCA3OU71YCAB130YTCAXWIQPFCA625J35CAPTDYXHCAOM8XNLCA4HJT5PCA4K1JUSCAF2N052CAW69NCACAWA5Y08CAYYA7LMCA0OHXXN.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\S2QDCACATLEZCA3JCX4VCAYWE9QPCAI7H3BOCAOC35YBCAMJ6WFICADYX5NXCA2B813ICA2HPU34CA8B2DRGCAXS8WU1CAK50PFQCA40XBQBCAA2NT40CAEBYS0TCALXYS0DCA4JY3Q0CABH1PGDCAQYCU2D.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\S2QDCACATLEZCA3JCX4VCAYWE9QPCAI7H3BOCAOC35YBCAMJ6WFICADYX5NXCA2B813ICA2HPU34CA8B2DRGCAXS8WU1CAK50PFQCA40XBQBCAA2NT40CAEBYS0TCALXYS0DCA4JY3Q0CABH1PGDCAQYCU2D.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\S2QDCACATLEZCA3JCX4VCAYWE9QPCAI7H3BOCAOC35YBCAMJ6WFICADYX5NXCA2B813ICA2HPU34CA8B2DRGCAXS8WU1CAK50PFQCA40XBQBCAA2NT40CAEBYS0TCALXYS0DCA4JY3Q0CABH1PGDCAQYCU2D.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\tarot_couple[1].htm=>(JAVASCRIPT 3)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\tarot_couple[1].htm=>(JAVASCRIPT 3)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\tarot_couple[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\tel_control[1].htm
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\tel_control[1].htm
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\TJOOCA7W9LYVCAJQJQOFCAYEJ7IDCAV1M07WCAWSGY8VCA7CJGW3CAV9E5VMCAAM3ZHSCASVOO59CA7SSDDKCAGWOMY4CA1KNHOBCAWNQ670CAPCE8GRCAME2DKZCAUZE38UCANG0HZDCADQNJ5ICA15KW2L.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\TJOOCA7W9LYVCAJQJQOFCAYEJ7IDCAV1M07WCAWSGY8VCA7CJGW3CAV9E5VMCAAM3ZHSCASVOO59CA7SSDDKCAGWOMY4CA1KNHOBCAWNQ670CAPCE8GRCAME2DKZCAUZE38UCANG0HZDCADQNJ5ICA15KW2L.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\TJOOCA7W9LYVCAJQJQOFCAYEJ7IDCAV1M07WCAWSGY8VCA7CJGW3CAV9E5VMCAAM3ZHSCASVOO59CA7SSDDKCAGWOMY4CA1KNHOBCAWNQ670CAPCE8GRCAME2DKZCAUZE38UCANG0HZDCADQNJ5ICA15KW2L.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\top_new[1].htm=>(JAVASCRIPT 40)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\top_new[1].htm=>(JAVASCRIPT 40)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\top_new[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\TVCVCAC8PU4GCAZ0REWHCALQQ8XZCA2A8D7OCASMH7MICAFYHNSFCARVY37ZCAE9H7A0CACLJB2FCAV4G69XCAAIEDJ7CA95VTWTCA0P1QR2CA0KXL0UCA0R65J5CAZ0LVBSCAQ2NS5QCAV8DT8GCAINBQ3F.htm=>(JAVASCRIPT 17)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\TVCVCAC8PU4GCAZ0REWHCALQQ8XZCA2A8D7OCASMH7MICAFYHNSFCARVY37ZCAE9H7A0CACLJB2FCAV4G69XCAAIEDJ7CA95VTWTCA0P1QR2CA0KXL0UCA0R65J5CAZ0LVBSCAQ2NS5QCAV8DT8GCAINBQ3F.htm=>(JAVASCRIPT 17)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\TVCVCAC8PU4GCAZ0REWHCALQQ8XZCA2A8D7OCASMH7MICAFYHNSFCARVY37ZCAE9H7A0CACLJB2FCAV4G69XCAAIEDJ7CA95VTWTCA0P1QR2CA0KXL0UCA0R65J5CAZ0LVBSCAQ2NS5QCAV8DT8GCAINBQ3F.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\UVHECAVVVQMYCAZG9OSRCAXF19UPCAQYOJC3CAT5DC64CABMQY26CA9KOGQRCA628PHQCA07B1GCCAS5UTEMCAVWU522CA9YL88RCA6NXNF3CANQZM77CAXB6W30CAIDJD3NCAQ13J0PCAFP6RAGCACV5L75.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\UVHECAVVVQMYCAZG9OSRCAXF19UPCAQYOJC3CAT5DC64CABMQY26CA9KOGQRCA628PHQCA07B1GCCAS5UTEMCAVWU522CA9YL88RCA6NXNF3CANQZM77CAXB6W30CAIDJD3NCAQ13J0PCAFP6RAGCACV5L75.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\UVHECAVVVQMYCAZG9OSRCAXF19UPCAQYOJC3CAT5DC64CABMQY26CA9KOGQRCA628PHQCA07B1GCCAS5UTEMCAVWU522CA9YL88RCA6NXNF3CANQZM77CAXB6W30CAIDJD3NCAQ13J0PCAFP6RAGCACV5L75.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\UZY0CAAJB38TCAP8XSY6CA3DQR07CA8CB6HLCAOD2V3DCAWBGF77CAVE8UGHCAZBAT69CACPYB4MCA6UJ35TCA2VNOYRCAWJ3SCFCANC10BPCA9WSJ0BCA0COJTUCAV9BWGLCARBKNAFCAQBZLHSCAFR7SJB.htm=>(JAVASCRIPT 17)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\UZY0CAAJB38TCAP8XSY6CA3DQR07CA8CB6HLCAOD2V3DCAWBGF77CAVE8UGHCAZBAT69CACPYB4MCA6UJ35TCA2VNOYRCAWJ3SCFCANC10BPCA9WSJ0BCA0COJTUCAV9BWGLCARBKNAFCAQBZLHSCAFR7SJB.htm=>(JAVASCRIPT 17)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\UZY0CAAJB38TCAP8XSY6CA3DQR07CA8CB6HLCAOD2V3DCAWBGF77CAVE8UGHCAZBAT69CACPYB4MCA6UJ35TCA2VNOYRCAWJ3SCFCANC10BPCA9WSJ0BCA0COJTUCAV9BWGLCARBKNAFCAQBZLHSCAFR7SJB.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\voir_message[1].htm=>(JAVASCRIPT 5)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\voir_message[1].htm=>(JAVASCRIPT 5)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\voir_message[1].htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VQV4CAW6JRMBCAU6GDEKCAX790AQCAI42OSJCAW9GB1MCAGDA2IICAQAK6A2CA82EN0ICAW7BC94CADN1VP1CA2SKIBNCAX6TG7FCAAQHFAZCAL6VHZOCAEHZEMOCAYM305LCA668FL5CAJF8NWDCAQKW38I.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.F

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VQV4CAW6JRMBCAU6GDEKCAX790AQCAI42OSJCAW9GB1MCAGDA2IICAQAK6A2CA82EN0ICAW7BC94CADN1VP1CA2SKIBNCAX6TG7FCAAQHFAZCAL6VHZOCAEHZEMOCAYM305LCA668FL5CAJF8NWDCAQKW38I.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VQV4CAW6JRMBCAU6GDEKCAX790AQCAI42OSJCAW9GB1MCAGDA2IICAQAK6A2CA82EN0ICAW7BC94CADN1VP1CA2SKIBNCAX6TG7FCAAQHFAZCAL6VHZOCAEHZEMOCAYM305LCA668FL5CAJF8NWDCAQKW38I.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VRW9CA1MP914CA5923QECARRQ8RQCA9QB4VLCA5HAE90CA9QFCL9CAWQO0DLCAY203XTCAPRTEHUCAC7UQ4ZCAUL8N1OCA4PYV4NCAB01L02CAH71TL4CAMKP284CA0EXVX9CA7RH48ECAW7BJ10CA3JBG0I.htm=>(JAVASCRIPT 2)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VRW9CA1MP914CA5923QECARRQ8RQCA9QB4VLCA5HAE90CA9QFCL9CAWQO0DLCAY203XTCAPRTEHUCAC7UQ4ZCAUL8N1OCA4PYV4NCAB01L02CAH71TL4CAMKP284CA0EXVX9CA7RH48ECAW7BJ10CA3JBG0I.htm=>(JAVASCRIPT 2)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VRW9CA1MP914CA5923QECARRQ8RQCA9QB4VLCA5HAE90CA9QFCL9CAWQO0DLCAY203XTCAPRTEHUCAC7UQ4ZCAUL8N1OCA4PYV4NCAB01L02CAH71TL4CAMKP284CA0EXVX9CA7RH48ECAW7BJ10CA3JBG0I.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VWOLCAW7Z7RKCAI0ZZBXCA164OM1CAMO3H1ICAULB7Y8CAJ8EWGACA3BYBBRCAVDMD9NCAQD0ZNBCAGZS9D3CAF95IYDCAFLSIVQCACT7L0PCAS242K5CAZ6VCCNCAFVHRXQCAI6HKT9CAXQREANCAQIU6EN.htm=>(JAVASCRIPT 17)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VWOLCAW7Z7RKCAI0ZZBXCA164OM1CAMO3H1ICAULB7Y8CAJ8EWGACA3BYBBRCAVDMD9NCAQD0ZNBCAGZS9D3CAF95IYDCAFLSIVQCACT7L0PCAS242K5CAZ6VCCNCAFVHRXQCAI6HKT9CAXQREANCAQIU6EN.htm=>(JAVASCRIPT 17)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VWOLCAW7Z7RKCAI0ZZBXCA164OM1CAMO3H1ICAULB7Y8CAJ8EWGACA3BYBBRCAVDMD9NCAQD0ZNBCAGZS9D3CAF95IYDCAFLSIVQCACT7L0PCAS242K5CAZ6VCCNCAFVHRXQCAI6HKT9CAXQREANCAQIU6EN.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VYT7CA473MY4CA5BW7RBCAP0WPQFCAHD5333CAATZ8QSCAN619KQCAFUXVRACAIX2YHCCAMNSOI4CAKKPKZ9CAZYHNU7CAX2JQ6VCAWTMMYLCALOW0HLCAPTCRVICABFQK9OCA612XM1CAQVCO2RCANTMAQ3.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VYT7CA473MY4CA5BW7RBCAP0WPQFCAHD5333CAATZ8QSCAN619KQCAFUXVRACAIX2YHCCAMNSOI4CAKKPKZ9CAZYHNU7CAX2JQ6VCAWTMMYLCALOW0HLCAPTCRVICABFQK9OCA612XM1CAQVCO2RCANTMAQ3.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\VYT7CA473MY4CA5BW7RBCAP0WPQFCAHD5333CAATZ8QSCAN619KQCAFUXVRACAIX2YHCCAMNSOI4CAKKPKZ9CAZYHNU7CAX2JQ6VCAWTMMYLCALOW0HLCAPTCRVICABFQK9OCA612XM1CAQVCO2RCANTMAQ3.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\XEJZCAZPVE7BCAMI0VDOCA90FFN6CAT9K2BNCA7SU0RDCATSQQKRCA9GZ8P3CAXGZMB6CAON1HXECAB3GK3NCAJX0GXTCA1A7RN3CA7AWOERCA9LI5JKCAPX8MLECA50RL8ZCAZF5IYKCA9BT94ECA1QQG2H.htm=>(JAVASCRIPT 17)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\XEJZCAZPVE7BCAMI0VDOCA90FFN6CAT9K2BNCA7SU0RDCATSQQKRCA9GZ8P3CAXGZMB6CAON1HXECAB3GK3NCAJX0GXTCA1A7RN3CA7AWOERCA9LI5JKCAPX8MLECA50RL8ZCAZF5IYKCA9BT94ECA1QQG2H.htm=>(JAVASCRIPT 17)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\XEJZCAZPVE7BCAMI0VDOCA90FFN6CAT9K2BNCA7SU0RDCATSQQKRCA9GZ8P3CAXGZMB6CAON1HXECAB3GK3NCAJX0GXTCA1A7RN3CA7AWOERCA9LI5JKCAPX8MLECA50RL8ZCAZF5IYKCA9BT94ECA1QQG2H.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\YF2UCAJW1LW7CABVY3IBCAXJX25KCAQOMANMCAIHQ72CCA7K6X48CA17LYFCCAV9H66HCAQWRSARCA0FLB0BCA92Y2QBCAMNSUW6CAQFV3NSCABOE232CA5IVTCHCAKE6PILCA0HGAJGCAXJCJ0HCARSR7N2.htm=>(JAVASCRIPT 7)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\YF2UCAJW1LW7CABVY3IBCAXJX25KCAQOMANMCAIHQ72CCA7K6X48CA17LYFCCAV9H66HCAQWRSARCA0FLB0BCA92Y2QBCAMNSUW6CAQFV3NSCABOE232CA5IVTCHCAKE6PILCA0HGAJGCAXJCJ0HCARSR7N2.htm=>(JAVASCRIPT 7)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\YF2UCAJW1LW7CABVY3IBCAXJX25KCAQOMANMCAIHQ72CCA7K6X48CA17LYFCCAV9H66HCAQWRSARCA0FLB0BCA92Y2QBCAMNSUW6CAQFV3NSCABOE232CA5IVTCHCAKE6PILCA0HGAJGCAXJCJ0HCARSR7N2.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\_freescan[1].htm
Détecté avec: Adware.FakeAntiVirus.M

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\_freescan[1].htm
Echec de la désinfection

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\_freescan[1].htm
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\_freescan[2].htm
Détecté avec: Adware.FakeAntiVirus.M

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\_freescan[2].htm
Echec de la désinfection

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\0XTU4C89\_freescan[2].htm
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\2C4YZT57\2ELSCAGXG1C7CAVGR49WCA3FO2YMCA3NV6ZCCA4ESKCJCA2H0L5ACA24RSQPCA7KF92TCARKK9EMCAL5S0KJCARFXI3LCAHCJU4ECA26CBIOCAN9DDW0CA6LOEUCCAKBLVPBCA0OARL6CA66JWI4CAH6K7Z7.htm=>(JAVASCRIPT 30)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\2C4YZT57\2ELSCAGXG1C7CAVGR49WCA3FO2YMCA3NV6ZCCA4ESKCJCA2H0L5ACA24RSQPCA7KF92TCARKK9EMCAL5S0KJCARFXI3LCAHCJU4ECA26CBIOCAN9DDW0CA6LOEUCCAKBLVPBCA0OARL6CA66JWI4CAH6K7Z7.htm=>(JAVASCRIPT 30)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\2C4YZT57\2ELSCAGXG1C7CAVGR49WCA3FO2YMCA3NV6ZCCA4ESKCJCA2H0L5ACA24RSQPCA7KF92TCARKK9EMCAL5S0KJCARFXI3LCAHCJU4ECA26CBIOCAN9DDW0CA6LOEUCCAKBLVPBCA0OARL6CA66JWI4CAH6K7Z7.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\2C4YZT57\4OP7CAB7ZTUBCAY9TTNKCA25XAF1CAANUGVNCAWP478LCAFVA4F9CAHT34ESCACE6QVACA3DIP0FCAVAPCPJCAGPE4C0CAJGA8KUCAOGOVXUCAMNSILVCAJ5DKC8CA6VKV88CA82RMY6CAKWCOLACAGMAP47.htm=>(JAVASCRIPT 2)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\2C4YZT57\4OP7CAB7ZTUBCAY9TTNKCA25XAF1CAANUGVNCAWP478LCAFVA4F9CAHT34ESCACE6QVACA3DIP0FCAVAPCPJCAGPE4C0CAJGA8KUCAOGOVXUCAMNSILVCAJ5DKC8CA6VKV88CA82RMY6CAKWCOLACAGMAP47.htm=>(JAVASCRIPT 2)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\2C4YZT57\4OP7CAB7ZTUBCAY9TTNKCA25XAF1CAANUGVNCAWP478LCAFVA4F9CAHT34ESCACE6QVACA3DIP0FCAVAPCPJCAGPE4C0CAJGA8KUCAOGOVXUCAMNSILVCAJ5DKC8CA6VKV88CA82RMY6CAKWCOLACAGMAP47.htm
Mis à jour

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\2C4YZT57\56NFCAO21BQJCAWLLD9LCA4UYODACAL396KYCAUQU152CAPBCVPICAD6TS5GCAJJGI0SCAOSLGD4CAJLBBNRCA3CO97ECAZ3ZDIDCA0EIW7JCAWR3BNLCAP6LNAMCAZE02LDCAGLHVTKCAO7WU2KCA60GMBB.htm=>(JAVASCRIPT 17)
Infecté par: Trojan.JS.Injector.E

D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\2C4YZT57\56NFCAO21BQJCAWLLD9LCA4UYODACAL396KYCAUQU152CAPBCVPICAD6TS5GCAJJGI0SCAOSLGD4CAJLBBNRCA3CO97ECAZ3ZDIDCA0EIW7JCAWR3BNLCAP6LNAMCAZE02LDCAGLHVTKCAO7WU2KCA60GMBB.htm=>(JAVASCRIPT 17)
Supprimé

D:\Documents and Settings\sylvie\Local Settings\T
0
sylk62 Messages postés 10 Date d'inscription lundi 9 mars 2009 Statut Membre Dernière intervention 27 octobre 2011
9 mars 2009 à 02:09
Suite,le rapport par Malwarebytes'..:
Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1827
Windows 5.1.2600 Service Pack 3

09/03/2009 02:06:09
mbam-log-2009-03-09 (02-06-09).txt

Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
Eléments examinés: 206128
Temps écoulé: 1 hour(s), 39 minute(s), 52 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 7
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 9
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 15

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdss.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EKRN.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GUARD.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MCSHIELD.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xcommsvr.exe (Security.Hijack) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows UDP Control Center (Backdoor.Bot) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\txtfile\shell\open\command\ (Hijack.Notepad) -> Bad: ("C:\WINDOWS\system32\nxtepad.exe" "%1") Good: (notepad.exe %1) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
D:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
D:\Documents and Settings\sylvie\Local Settings\Temporary Internet Files\Content.IE5\2C4YZT57\kbc41256[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\afisicx.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\comsa32.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\umtcdtw.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\warning.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ahtn.htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
D:\Documents and Settings\sylk62\Local Settings\Temp\ntdll64.dll (Trojan.FakeAlert) -> Delete on reboot.
D:\Documents and Settings\sylk62\Local Settings\Temp\mousehook.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\WINDOWS\system32\senekabrnlmsfy.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\senekabxmjctvx.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\senekagknktuxc.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\senekaoymqtaaq.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\senekapmeudlya.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\seneka.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\senekafeyhvkfh.sys (Trojan.Agent) -> Quarantined and deleted successfully.
Voilà je pense avoir tout fait,j'espère que tu verras clair ds tt ça.
En tt cas merci bcp.
Bisous.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
sylk62 Messages postés 10 Date d'inscription lundi 9 mars 2009 Statut Membre Dernière intervention 27 octobre 2011
9 mars 2009 à 02:37
Petit trucs en +, après cette dernière analyse le pc a demandé à redemarrer ce que j'aie fait et maintenant l'arrière plan du bureau n'est plus noir avec le message "warning....." mais gris et il n'y a plus rien d'inscrit sauf mes icones du bureau.
Voilà.
0
plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
9 mars 2009 à 08:10
bonjour

! Déconnectes toi et fermes toutes applications en cours !


* Relances "Ad-remover" : au menu principal choisi l'option "B" .
* Coche à l'écran de sélection :

1. Suppression Boonty/BoontyGames
6. Suppression Sweetim
7. autres suppression

* Tape les chiffres correspondant à la suppression demandée et valide par ENTER pour les cocher.
* Puis choisi "S" , le programme va travailler,
* Postes le rapport qui apparait à la fin.



( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

(CTRL A Pour tout selectionner , CTRL C pour copier et CTRL V pour coller )

/!\ Si le Bureau ne réapparait pas presse Ctrl Alt Suppr , Onglet "Fichier" , "Nouvelle tâche", tapes explorer.exe et valid


ensuite ton fond d'ecran a changer c'est normal, vu le nombre de virus qui on etait supprimé, on leur a mit un grand coup

Télécharge Random's System Information Tool (RSIT) par random/random et sauvegarde-le sur ton Bureau.
http://images.malwareremoval.com/random/RSIT.exe
Clique sur Continue
Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront poste les 2 rapports SEPAREMENT
0
sylk62 Messages postés 10 Date d'inscription lundi 9 mars 2009 Statut Membre Dernière intervention 27 octobre 2011
9 mars 2009 à 14:19
salut, voilà le rapport:

------- LOGFILE OF AD-REMOVER 1.1.1.6 | ONLY XP/VISTA -------

Updated by C_XX on 07/03/2009 at 21:40

**** LIMITED TO ****

Boonty/BoontyGames
Sweetim
Other Adwares

********************

Start at: 14:10:27 | Lun 09/03/2009 | Boot mode: Normal Boot
Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
Computer Name: nouvellevie
Current User: sylk62 - Administrator
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: NTFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\

--- Running Processes: 80

(!) ---- IE start pages/Tabs reset

+-----------------| Boonty/Boonty Games Elements Deleted :

.
.
D:\Documents and Settings\All Users\Application Data\BOONTY
D:\Documents and Settings\sylk62\Cookies\sylk62@payment.boonty[1].txt

+-----------------| Sweetim Elements Deleted :

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Sweetim
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847}
HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCR\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
HKCR\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCR\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
HKCR\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
HKCR\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
HKCR\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
HKCR\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
HKCR\MediaPlayer.GraphicsUtils
HKCR\MediaPlayer.GraphicsUtils.1
HKCR\MgMediaPlayer.GifAnimator
HKCR\MgMediaPlayer.GifAnimator.1
HKCR\SWEETIE.IEToolbar
HKCR\SWEETIE.IEToolbar.1
HKCR\SWEETIE.SWEETIE
HKCR\SWEETIE.SWEETIE.3
HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook
HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
HKCR\Toolbar3.SWEETIE
HKCR\Toolbar3.SWEETIE.1
HKCR\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
HKCR\Typelib\{EEE6C35E-6118-11DC-9C72-001320C79847}
HKCR\Typelib\{EEE6C35F-6118-11DC-9C72-001320C79847}
HKCU\Software\SweetIM
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
HKLM\Software\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}
HKLM\Software\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{266C7330-C0F4-49E5-8F20-A56F9F822875}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
HKLM\Software\SweetIM
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\351716A953E21214898904032EAE2E81
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A189D17A469616C4688D23E192996267
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
.
C:\WINDOWS\Installer\291a4221.msi
C:\WINDOWS\Installer\291a4227.msi
/!\ NOT DELETED - C:\Program Files\SweetIM
/!\ NOT DELETED - C:\Program Files\SweetIM\Messenger
/!\ NOT DELETED - C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll
/!\ NOT DELETED - C:\Program Files\SweetIM\Messenger\msvcr71.dll
D:\Documents and Settings\All Users\Application Data\SweetIM
C:\WINDOWS\Prefetch\SWEETIM.EXE-19615F6D.pf
D:\Documents and Settings\sylk62\Cookies\sylk62@content.sweetim[1].txt
D:\Documents and Settings\sylk62\Cookies\sylk62@search.sweetim[2].txt
D:\Documents and Settings\sylk62\Cookies\sylk62@sweetim[2].txt
D:\Documents and Settings\sylk62\Cookies\sylk62@www.sweetim[2].txt

+-----------------| Other Adwares Deleted:

.
.
D:\Documents and Settings\sylk62\Cookies\sylk62@bs.serving-sys[2].txt

(!) ---- Temp files deleted.
(!) ---- Recycle bin emptied in all drives.


************* /!\ FILE(S)/FOLDER(S) NOT DELETED /!\ *************

"C:\Program Files\SweetIM\Messenger"
"C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll"
"C:\Program Files\SweetIM\Messenger\msvcr71.dll"

Second run ...

/!\ RESIST ! - "C:\Program Files\SweetIM\Messenger"
/!\ RESIST ! - "C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll"
/!\ RESIST ! - "C:\Program Files\SweetIM\Messenger\msvcr71.dll"


+-----------------| Added Scan :

---- Internet Explorer Version 7.0.5730.13 ----

+-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

+-[HKEY_USERS\S-1-5-21-1722768690-2433286175-2781512135-1006\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start page: hxxp://fr.msn.com/

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: hxxp://ieframe.dll/tabswelcome.htm

+---------------------------------------------------------------------------+

11284 Byte(s) - C:\Ad-Report-Clean-09.03.2009.log
11811 Byte(s) - C:\Ad-Report-Scan-08.03.2009.log

0 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
9 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

End at: 14:16:25 | 09/03/2009
.
+-----------------| E.O.F - 158 Lines
.
0
sylk62 Messages postés 10 Date d'inscription lundi 9 mars 2009 Statut Membre Dernière intervention 27 octobre 2011
9 mars 2009 à 14:23
suite:
Logfile of random's system information tool 1.05 (written by random/random)
Run by sylk62 at 2009-03-09 14:21:34
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 10 GB (32%) free of 31 GB
Total RAM: 1022 MB (29% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:22:14, on 09/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe
C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE
C:\Program Files\SFR\Pack Sécurité\Anti-Virus\FSGK32.EXE
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Apps\Softex\OmniPass\Omniserv.exe
C:\Program Files\SFR\Pack Sécurité\Common\FSMB32.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\SFR\Pack Sécurité\Common\FCH32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\SFR\Pack Sécurité\Common\FAMEH32.EXE
C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsqh.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\SFR\Pack Sécurité\FSAUA\program\fsaua.exe
C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fssm32.exe
C:\Apps\Softex\OmniPass\OPXPApp.exe
C:\Program Files\SFR\Pack Sécurité\FWES\Program\fsdfwd.exe
C:\Program Files\SFR\Pack Sécurité\FSAUA\program\fsus.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsav32.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Apps\Softex\OmniPass\scureapp.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\APPS\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\QuickTime\QTTask.exe
C:\apps\ABoard\AOSD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
C:\Program Files\Hercules\Deluxe Optical Glass\Camservice.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\SFR\Pack Sécurité\Common\FSM32.EXE
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\APPS\SMP\SmpSys.exe
C:\Program Files\SFR\Pack Sécurité\FSGUI\fsguidll.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Documents and Settings\sylk62\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
D:\Documents and Settings\sylk62\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\SFR\Pack Sécurité\FSGUI\scanwizard.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\taskmgr.exe
D:\Documents and Settings\sylk62\Local Settings\Temporary Internet Files\Content.IE5\G6VQR6Y2\RSIT[1].exe
C:\Program Files\trend micro\sylk62.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATICCC] "c:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [PCMService] "c:\APPS\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [VadeRetro Desktop] C:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CamserviceDeluxe2] C:\Program Files\Hercules\Deluxe Optical Glass\Camservice.exe /startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\SFR\Pack Sécurité\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\SFR\Pack Sécurité\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Outil de notification Live Search.lnk = D:\Documents and Settings\sylk62\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: xccstart.lnk = C:\WINDOWS\system\xccef090305.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game06.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE
O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\ORSP Client\fsorsp.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
0
sylk62 Messages postés 10 Date d'inscription lundi 9 mars 2009 Statut Membre Dernière intervention 27 octobre 2011
9 mars 2009 à 14:26
2è rapport:
info.txt logfile of random's system information tool 1.05 2009-03-09 14:22:17

======Uninstall list======

-->"c:\apps\skype\phone\unins000.exe"
-->"C:\Program Files\Fichiers communs\aolshare\Coach\AolCInUn.exe" -lang="fr-fr"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Spyware Scanner"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Spyware"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Virus Client Security Installer"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Virus"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Automatic Update Agent"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure DAAS"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure DAAS2"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Diagnostics"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure E-mail Scanning"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure FWES"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure GateKeeper Interface"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Gemini"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure GUI"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Help"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure HIPS"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Internet Shield"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure ISP News"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Localization API"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Management Agent"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure ORSP Client"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Pegasus Engine"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Protocol Scanner"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Spam Control"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Spam Scanner"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure TNB"
-->"C:\Program Files\SFR\Pack Sécurité\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Uninstall"
-->C:\PROGRA~1\FICHIE~1\AOL\ACS\AcsUninstall.exe /c
-->C:\PROGRA~1\GOTOSO~1\VADERE~1\UNWISE.EXE C:\PROGRA~1\GOTOSO~1\VADERE~1\INSTALL.LOG
-->C:\PROGRA~1\Norman\NORMAN~1\UNWISE.EXE C:\PROGRA~1\Norman\NORMAN~1\INSTALL.LOG
-->C:\Program Files\Fichiers communs\AOL\Screensaver\uninst_ygpss.exe
-->C:\Program Files\Fichiers communs\aolshare\Aolunins_fr.exe
-->C:\Program Files\Fichiers communs\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
-->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
-->MsiExec.exe /I{8B543A39-9401-44F4-B572-069E64C15189}
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" -uninstall
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F9CFBD8-8F77-4DCD-8CB5-CDD5F653C872}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4F1DA6BF-3614-48A1-9970-9E90F646789E}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5A065EA0-0EEC-4E94-A2A0-40812576C122}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5AFA4872-16B2-419E-ADCA-8E96E739115D}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F4E57F49-84B4-4CF2-B0A1-8CA1752BDF7E}\setup.exe" -l0x40c
-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Ad-remover-->C:\Program Files\Ad-remover\Uninstall ADR.exe
AlauxSoft Comptes et Budget Free V5.0-->"C:\Program Files\Comptes et Budget Free V5.0\unins000.exe"
Apple Software Update-->MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
ATI Catalyst Control Center-->MsiExec.exe /I{0121AE72-B262-4EFA-8E3D-9D626950679F}
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
eMule-->"C:\Program Files\eMule\Uninstall.exe"
Family Flights-->"C:\Program Files\MSN Games\Family Flights\Uninstall.exe" "C:\Program Files\MSN Games\Family Flights\install.log"
Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
getPlus(R) for Adobe-->"C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
Hercules Deluxe Optical Glass-->C:\Program Files\InstallShield Installation Information\{56298F72-C2CC-4FE5-ACEA-30C7A866BF4C}\setup.exe -runfromtemp -l0x040c -removeonly
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Extended Capabilities 4.7-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Image Zone 4.7-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
HP PSC & OfficeJet 4.7-->"C:\Program Files\HP\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup\hpzscr01.exe" -datfile hposcr05.dat
HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
J2SE Runtime Environment 5.0 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150040}
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
Kiwee Toolbar-->"C:\Program Files\AGI\common\bootstrapper.exe" -uninstall"\"C:/Program Files/AGI/Python25\pythonw.exe\" \"C:\Program Files\AGI\common\pyagcore\installer.pyc\" -u KiweeToolbar"
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Macromedia Shockwave Player-->MsiExec.exe /X{7D1D6A24-65D4-454C-8815-4F08A5FFF12C}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Mise à jour de sécurité pour le Codeur Windows Media (KB954156)-->"C:\WINDOWS\$NtUninstallKB954156_WM9L$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Pack sécurité-->"C:\Program Files\SFR\Pack Sécurité\FSGUI\PostInstall.exe" /tUnInstall
QuickTime-->MsiExec.exe /I{5B09BD67-4C99-46A1-8161-B7208CE18121}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
SFR - Kit de connexion-->C:\Program Files\SFR\Kit\uninstall.exe
Sonic MyDVD-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
SweetIM for Messenger 2.6-->MsiExec.exe /X{04A6A912-A6DB-4EF2-99FF-6D6199BA3C8C}
Vade Retro Outlook, Outlook Express, Windows Mail (Vista)-->C:\Program Files\Goto Software\Vade Retro\uninst.exe
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

======Security center information======

AV: Pack sécurité 8.00
FW: Norton Internet Worm Protection (disabled)
FW: Pack sécurité 8.00

System event log

Computer Name: nouvellevie
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

Record Number: 19912
Source Name: Service Control Manager
Time Written: 20090124213332.000000+060
Event Type: Informations
User: nouvellevie\sylk62

Computer Name: nouvellevie
Event Code: 7036
Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

Record Number: 19911
Source Name: Service Control Manager
Time Written: 20090124213332.000000+060
Event Type: Informations
User:

Computer Name: nouvellevie
Event Code: 7036
Message: Le service Pml Driver HPZ12 est entré dans l'état : arrêté.

Record Number: 19910
Source Name: Service Control Manager
Time Written: 20090124213132.000000+060
Event Type: Informations
User:

Computer Name: nouvellevie
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

Record Number: 19909
Source Name: Service Control Manager
Time Written: 20090124213132.000000+060
Event Type: Informations
User: nouvellevie\sylk62

Computer Name: nouvellevie
Event Code: 7036
Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

Record Number: 19908
Source Name: Service Control Manager
Time Written: 20090124213132.000000+060
Event Type: Informations
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Apps\Softex\OmniPass;C:\Program Files\Fichiers communs\Ulead Systems\MPEG;C:\PROGRA~1\FICHIE~1\SONICS~1\;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 6 Stepping 2, GenuineIntel
"PROCESSOR_REVISION"=0602
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_04\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.5.0_04\lib\ext\QTJava.zip

-----------------EOF-----------------
0
plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
9 mars 2009 à 15:55
bonjour, il reste des virus

• Télécharge OTMoveIt3 (de OldTimer) sur ton Bureau : http://oldtimer.geekstogo.com/OTMoveIt3.exe
• Double-clique sur OTMoveIt3.exe afin de le lancer.
• Copie/colle le texte suivant dans le cadre « Paste Instructions for Items to be Moved » et clique sur Moveit :

:processes
explorer.exe

:files
C:\Program Files\SweetIM
C:\WINDOWS\system32\tmp.txt
C:\WINDOWS\system32\drivers\senekafeyhvkfh.sys
C:\Program Files\AGI\common\win32\PythonService.exe
C:\Program Files\AGI\common\agcutils.dll

:services
AGWinService
seneka

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]


• Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.

• Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles
Le nom du rapport correspond au moment de sa création : date_heure.log



puis clic ici https://www.virustotal.com/gui/ et fait et clic sur parcourir et fait analyser ce fichier et poste le rapport en entier de TOUT en HAUT jusqye TOUT en BAS stp

C:\WINDOWS\system\xccef090305.exe



ensuite RSIT montre un dossier infectieux concernat LOP qui provoque des pop up CID

* Télécharger et enregistrer lopSD sur ton bureau https://www.androidworld.fr/

(c est le numéro 4 en bas de la page) :
* Double-clic Lop S&D
* Faire l'installation
* Fermer toutes les applications
* Le lancer par un double-clic sur le raccourci qui est sur le bureau

* Avec VISTA => clic-droit et => Exécuter en tant qu'administrateur
* Taper F pour français , puis presser entrée
* Taper 1
* Presser Entrée
* Le PC va redémarrer

* Note= si l'antivirus annonce une infection dans TEMP , l'ignorer
* Attendre l'apparition du rapport
* Copier le rapport et le coller dans la réponse


* le rapport se trouve aussi à C:\lopR
0
sylk62 Messages postés 10 Date d'inscription lundi 9 mars 2009 Statut Membre Dernière intervention 27 octobre 2011
9 mars 2009 à 15:57
Voilà j'aie finie tout ce que tu m'as dit,est-ce que dans les rapports tu vois si tout est ok?
J'aie recupérée mon fond d'écran habituel et c'est tant mieux.
Tout cela grace à toi,un grand MERCI à toi ,c super tu doit être un sacré pro du pc.
0
sylk62 Messages postés 10 Date d'inscription lundi 9 mars 2009 Statut Membre Dernière intervention 27 octobre 2011
9 mars 2009 à 15:59
Juste un petit truc,dans la barre en bas a droite de l'écran il y a un carré noir,quand je survole avec la souris ça marque "Windows live messenger deconnecté"pourtant dans la fenetre de messenger tout a l'air normal,c bon comme mm?
0
plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
9 mars 2009 à 16:00
pour l'instant on s'en occupe pas, et a vrai dire je sais pas du tout fait la suite car il reste des betes
0
plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
9 mars 2009 à 16:20
au passage j'ai oublié de mettre des fichiers et après quelques recherches tu as encore un ver internet, jte fait un autre script pour ne pas utiliser combobix qui est a eviter le + possible

donc tu referas cette avec otmoveit


• Double-clique sur OTMoveIt3.exe afin de le lancer.
• Copie/colle le texte suivant dans le cadre « Paste Instructions for Items to be Moved » et clique sur Moveit :

:processes
explorer.exe

:files
C:\WINDOWS\system32\pcistub.sys
C:\WINDOWS\system32\sopidkc.exe
C:\WINDOWS\system32\xcchit32.ini
C:\WINDOWS\xccwinsys.ini

:services
pcistub

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]


• Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.

• Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles
Le nom du rapport correspond au moment de sa création : date_heure.log
0
Voilà pour OT Move it,je sais pas si c le bon rapport,quand il fait l'analyse il me demande yes ou no (comme tu as ecrit)donc je tape yes et il redemarre tout le pc donc ça c le rapport qui s'affichent tt seul quand le pc se remet en route (ap avoir executer ot move it):
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder C:\Program Files\SweetIM not found.
File/Folder C:\WINDOWS\system32\tmp.txt not found.
File/Folder C:\WINDOWS\system32\drivers\senekafeyhvkfh.sys not found.
File/Folder C:\Program Files\AGI\common\win32\PythonService.exe not found.
File/Folder C:\Program Files\AGI\common\agcutils.dll not found.
========== SERVICES/DRIVERS ==========
Unable to stop service AGWinService .
Unable to stop service seneka .
========== COMMANDS ==========
File delete failed. D:\DOCUME~1\sylk62\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
File delete failed. D:\DOCUME~1\sylk62\LOCALS~1\Temp\Perflib_Perfdata_79c.dat scheduled to be deleted on reboot.
File delete failed. D:\DOCUME~1\sylk62\LOCALS~1\Temp\Perflib_Perfdata_7c0.dat scheduled to be deleted on reboot.
File delete failed. D:\DOCUME~1\sylk62\LOCALS~1\Temp\Perflib_Perfdata_7c8.dat scheduled to be deleted on reboot.
File delete failed. D:\DOCUME~1\sylk62\LOCALS~1\Temp\~DF120.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. D:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\CLML_AGENT_LOG1.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\nvcbin.def.76167175.TMP scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_70c.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_yAYJ5ThlVGcXVbj scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03092009_213627

Files moved on Reboot...
D:\DOCUME~1\sylk62\LOCALS~1\Temp\hpodvd09.log moved successfully.
File D:\DOCUME~1\sylk62\LOCALS~1\Temp\Perflib_Perfdata_79c.dat not found!
File D:\DOCUME~1\sylk62\LOCALS~1\Temp\Perflib_Perfdata_7c0.dat not found!
File D:\DOCUME~1\sylk62\LOCALS~1\Temp\Perflib_Perfdata_7c8.dat not found!
File D:\DOCUME~1\sylk62\LOCALS~1\Temp\~DF120.tmp not found!
File move failed. D:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. D:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. D:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
File move failed. D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\CLML_AGENT_LOG1.txt scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\nvcbin.def.76167175.TMP scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\Perflib_Perfdata_70c.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\sqlite_yAYJ5ThlVGcXVbj not found!
0
Je sais pas si c bien ça:

Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español | English
Virustotal est un service qui analyse les fichiers suspects et facilite la détection rapide des virus, vers, chevaux de Troie et toutes sortes de malwares détectés par les moteurs antivirus. Plus d'informations...
Fichier 03092009_213627.log reçu le 2009.03.09 21:52:47 (CET)
Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE


Résultat: 0/39 (0%)
en train de charger les informations du serveur...
Votre fichier est dans la file d'attente, en position: 3.
L'heure estimée de démarrage est entre 50 et 72 secondes.
Ne fermez pas la fenêtre avant la fin de l'analyse.
L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
les résultats seront affichés au fur et à mesure de leur génération.
Formaté Impression des résultats
Votre fichier a expiré ou n'existe pas.
Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
Email:


Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.101 2009.03.09 -
AhnLab-V3 5.0.0.2 2009.02.27 -
AntiVir 7.9.0.107 2009.03.09 -
Authentium 5.1.0.4 2009.03.09 -
Avast 4.8.1335.0 2009.03.09 -
AVG 8.0.0.237 2009.03.09 -
BitDefender 7.2 2009.03.09 -
CAT-QuickHeal 10.00 2009.03.09 -
ClamAV 0.94.1 2009.03.09 -
Comodo 1039 2009.03.09 -
DrWeb 4.44.0.09170 2009.03.09 -
eSafe 7.0.17.0 2009.03.09 -
eTrust-Vet 31.6.6387 2009.03.09 -
F-Prot 4.4.4.56 2009.03.09 -
F-Secure 8.0.14470.0 2009.03.09 -
Fortinet 3.117.0.0 2009.03.09 -
GData 19 2009.03.09 -
Ikarus T3.1.1.45.0 2009.03.09 -
K7AntiVirus 7.10.664 2009.03.09 -
Kaspersky 7.0.0.125 2009.03.09 -
McAfee 5548 2009.03.09 -
McAfee+Artemis 5548 2009.03.09 -
Microsoft 1.4405 2009.03.09 -
NOD32 3922 2009.03.09 -
Norman 6.00.06 2009.03.09 -
nProtect 2009.1.8.0 2009.03.09 -
Panda 10.0.0.10 2009.03.09 -
PCTools 4.4.2.0 2009.03.09 -
Prevx1 V2 2009.03.09 -
Rising 21.20.02.00 2009.03.09 -
SecureWeb-Gateway 6.7.6 2009.03.09 -
Sophos 4.39.0 2009.03.09 -
Sunbelt 3.2.1858.2 2009.03.09 -
Symantec 1.4.4.12 2009.03.09 -
TheHacker 6.3.3.0.277 2009.03.09 -
TrendMicro 8.700.0.1004 2009.03.09 -
VBA32 3.12.10.1 2009.03.09 -
ViRobot 2009.3.9.1641 2009.03.09 -
VirusBuster 4.5.11.0 2009.03.09 -
Information additionnelle
File size: 7566 bytes
MD5...: 1693d83e219c7ff07304203131659143
SHA1..: f459dbeb43764e4065d8809dbf6eaf95416eb5fa
SHA256: 4853faadde1486b7d8d68431e3d169233865ecdd1289bf28dab08af345a8fd73
SHA512: 55ff1fbeeeae691eef980054e37a5697bfec32c05fc2ab923bde299f190f3bae
d38f68564329ac102bc9695d0d77e2f65729df542f8523e41644e37b3b898c57
ssdeep: 96:xB4b8dPU1fvesOSyszQ4C80umJAbaNC2y3/dfM98OSCsh4CA2JQbuNy:xOb7m
JAWNCM2JQyNy

PEiD..: -
TrID..: File type identification
Text - UTF-16 (LE) encoded (64.4%)
MP3 audio (32.2%)
Lumena CEL bitmap (2.0%)
Corel Photo Paint (1.3%)
PEInfo: -
packers (F-Prot): Unicode


ATTENTION: VirusTotal est un service gratuit offert par Hispasec Sistemas. Il n'y a aucune garantie quant à la disponibilité et la continuité de ce service. Bien que le taux de détection permis par l'utilisation de multiples moteurs antivirus soit bien supérieur à celui offert par seulement un produit, ces résultats NE garantissent PAS qu'un fichier est sans danger. Il n'y a actuellement aucune solution qui offre un taux d'efficacité de 100% pour la détection des virus et malwares.

VirusTotal © Hispasec Sistemas - Blog - Contact: info@virustotal.com - Terms of Service & Privacy Policy
0
plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
9 mars 2009 à 21:54
bon fait le reste mais je croix qu'on va devoir passé par combofix...
0
Voilà le dernier rapport:
--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 3.00GHz )
BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
USER : sylk62 ( Administrator )
BOOT : Normal boot
Antivirus : Pack sécurité 8.00 8.00 (Activated)
Firewall : Pack sécurité 8.00 8.00 (Activated)
C:\ (Local Disk) - NTFS - Total:29 Go (Free:9 Go)
D:\ (Local Disk) - NTFS - Total:148 Go (Free:135 Go)
E:\ (CD or DVD)
F:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 09/03/2009|22:00 )

--------------------\\ Listing des dossiers dans APPLIC~1

[23/02/2009|00:34] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[24/01/2009|15:09] D:\DOCUME~1\ALLUSE~1\APPLIC~1\agi
[18/05/2006|00:48] D:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[26/10/2008|21:12] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/10/2008|21:14] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[23/02/2009|00:18] D:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[14/01/2007|11:38] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Ciel
[18/05/2006|00:58] D:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[15/02/2009|16:49] D:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[27/12/2008|15:09] D:\DOCUME~1\ALLUSE~1\APPLIC~1\EscapeTheMuseum
[16/02/2009|20:14] D:\DOCUME~1\ALLUSE~1\APPLIC~1\FamilyFlights
[18/03/2008|17:56] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Farm Frenzy
[31/01/2009|22:45] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[09/09/2007|18:25] D:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[28/12/2008|16:49] D:\DOCUME~1\ALLUSE~1\APPLIC~1\FlyWheelGames
[14/02/2009|15:45] D:\DOCUME~1\ALLUSE~1\APPLIC~1\f-secure
[14/02/2009|15:44] D:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
[04/02/2009|23:42] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii
[26/05/2008|18:25] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/08/2007|00:28] D:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA
[08/09/2006|13:53] D:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[06/01/2009|20:17] D:\DOCUME~1\ALLUSE~1\APPLIC~1\HP Product Assistant
[18/01/2009|23:16] D:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[24/01/2009|15:24] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Kiwee Toolbar
[08/03/2009|16:37] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch
[09/03/2009|00:13] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[20/05/2008|22:52] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/10/2007|08:22] D:\DOCUME~1\ALLUSE~1\APPLIC~1\MGS
[19/02/2009|09:30] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/08/2008|22:44] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[30/04/2008|21:27] D:\DOCUME~1\ALLUSE~1\APPLIC~1\MonteCristo
[12/08/2007|14:51] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[31/12/2008|11:33] D:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[14/02/2009|16:49] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games
[18/05/2006|00:47] D:\DOCUME~1\ALLUSE~1\APPLIC~1\OD2
[15/05/2008|17:00] D:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[18/05/2006|00:48] D:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[16/01/2008|14:19] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[18/05/2006|09:27] D:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[10/11/2006|09:50] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[07/11/2008|07:40] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[24/02/2009|17:31] D:\DOCUME~1\ALLUSE~1\APPLIC~1\SpinTop Games
[12/12/2008|00:53] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[20/02/2009|23:08] D:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[14/01/2009|23:15] D:\DOCUME~1\ALLUSE~1\APPLIC~1\TheRace_dev
[18/05/2006|00:55] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[25/12/2008|20:42] D:\DOCUME~1\ALLUSE~1\APPLIC~1\VadeRetro
[18/05/2006|00:48] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[13/10/2006|18:13] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[03/10/2006|21:33] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[12/01/2008|23:07] D:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[14/11/2006|23:21] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[27/09/2008|03:55] D:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI
[27/09/2008|03:55] D:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[27/09/2008|03:55] D:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[27/09/2008|03:55] D:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[27/09/2008|03:55] D:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver

[24/01/2009|15:25] D:\DOCUME~1\LOCALS~1\APPLIC~1\agi
[18/05/2006|09:27] D:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[30/09/2007|08:16] D:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[18/05/2006|09:27] D:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[19/12/2008|14:07] D:\DOCUME~1\sylk62\APPLIC~1\Adobe
[07/11/2008|07:25] D:\DOCUME~1\sylk62\APPLIC~1\AdobeUM
[24/01/2009|15:09] D:\DOCUME~1\sylk62\APPLIC~1\agi
[21/02/2009|18:59] D:\DOCUME~1\sylk62\APPLIC~1\AlauxSoft
[07/11/2008|07:59] D:\DOCUME~1\sylk62\APPLIC~1\Apple Computer
[27/09/2008|03:55] D:\DOCUME~1\sylk62\APPLIC~1\ATI
[23/02/2009|00:19] D:\DOCUME~1\sylk62\APPLIC~1\AVS4YOU
[16/02/2009|20:09] D:\DOCUME~1\sylk62\APPLIC~1\BeachPartyCraze
[20/01/2009|23:55] D:\DOCUME~1\sylk62\APPLIC~1\cerasus.media
[15/12/2008|09:37] D:\DOCUME~1\sylk62\APPLIC~1\CyberLink
[15/02/2009|17:00] D:\DOCUME~1\sylk62\APPLIC~1\DeepBurner
[31/01/2009|22:45] D:\DOCUME~1\sylk62\APPLIC~1\Flood Light Games
[08/03/2009|14:29] D:\DOCUME~1\sylk62\APPLIC~1\F-Secure
[11/01/2009|23:12] D:\DOCUME~1\sylk62\APPLIC~1\Google
[27/09/2008|03:55] D:\DOCUME~1\sylk62\APPLIC~1\Identities
[02/01/2009|22:25] D:\DOCUME~1\sylk62\APPLIC~1\InstallShield
[03/01/2009|15:03] D:\DOCUME~1\sylk62\APPLIC~1\Leadertech
[29/01/2009|23:41] D:\DOCUME~1\sylk62\APPLIC~1\LimeWire
[24/12/2008|14:23] D:\DOCUME~1\sylk62\APPLIC~1\Macromedia
[09/03/2009|00:13] D:\DOCUME~1\sylk62\APPLIC~1\Malwarebytes
[24/01/2009|17:45] D:\DOCUME~1\sylk62\APPLIC~1\Microsoft
[24/12/2008|14:26] D:\DOCUME~1\sylk62\APPLIC~1\MSNInstaller
[14/02/2009|16:49] D:\DOCUME~1\sylk62\APPLIC~1\Oberon Games
[07/11/2008|07:38] D:\DOCUME~1\sylk62\APPLIC~1\OD2
[23/02/2009|01:25] D:\DOCUME~1\sylk62\APPLIC~1\OpenOffice.org
[01/10/2008|02:13] D:\DOCUME~1\sylk62\APPLIC~1\Skype
[03/01/2009|15:03] D:\DOCUME~1\sylk62\APPLIC~1\Sonic
[01/01/2009|02:04] D:\DOCUME~1\sylk62\APPLIC~1\Sun
[01/01/2009|11:39] D:\DOCUME~1\sylk62\APPLIC~1\Ulead Systems
[25/12/2008|20:41] D:\DOCUME~1\sylk62\APPLIC~1\VadeRetro
[28/12/2008|01:46] D:\DOCUME~1\sylk62\APPLIC~1\Windows Live Writer
[27/09/2008|03:55] D:\DOCUME~1\sylk62\APPLIC~1\You've Got Pictures Screensaver

[01/04/2008|16:16] D:\DOCUME~1\sylvie\APPLIC~1\Abra Academy2
[03/02/2008|11:08] D:\DOCUME~1\sylvie\APPLIC~1\Adobe
[14/01/2007|18:37] D:\DOCUME~1\sylvie\APPLIC~1\AdobeUM
[23/01/2008|21:53] D:\DOCUME~1\sylvie\APPLIC~1\Anuman Interactive
[18/05/2006|07:40] D:\DOCUME~1\sylvie\APPLIC~1\ATI
[10/09/2007|08:11] D:\DOCUME~1\sylvie\APPLIC~1\Big Fish Games
[02/08/2008|23:02] D:\DOCUME~1\sylvie\APPLIC~1\cerasus.media
[09/09/2006|00:46] D:\DOCUME~1\sylvie\APPLIC~1\CyberLink
[26/12/2007|22:53] D:\DOCUME~1\sylvie\APPLIC~1\Flood Light Games
[09/09/2007|18:25] D:\DOCUME~1\sylvie\APPLIC~1\FloodLightGames
[04/11/2007|18:15] D:\DOCUME~1\sylvie\APPLIC~1\Gaijin Ent
[14/01/2007|18:26] D:\DOCUME~1\sylvie\APPLIC~1\Google
[07/01/2007|01:26] D:\DOCUME~1\sylvie\APPLIC~1\Help
[07/01/2007|12:36] D:\DOCUME~1\sylvie\APPLIC~1\Hemera
[13/08/2007|00:28] D:\DOCUME~1\sylvie\APPLIC~1\Hotbar
[18/03/2008|17:55] D:\DOCUME~1\sylvie\APPLIC~1\Identities
[20/01/2008|19:03] D:\DOCUME~1\sylvie\APPLIC~1\Jane s Hotel
[16/10/2006|09:23] D:\DOCUME~1\sylvie\APPLIC~1\Leadertech
[28/03/2008|11:57] D:\DOCUME~1\sylvie\APPLIC~1\Legends of pirates
[21/05/2007|23:10] D:\DOCUME~1\sylvie\APPLIC~1\Macromedia
[16/05/2008|22:18] D:\DOCUME~1\sylvie\APPLIC~1\Magic Academy
[07/11/2006|18:17] D:\DOCUME~1\sylvie\APPLIC~1\MessengerSkinner
[19/12/2007|20:26] D:\DOCUME~1\sylvie\APPLIC~1\Micro Application
[10/08/2008|16:08] D:\DOCUME~1\sylvie\APPLIC~1\Microsoft
[19/06/2007|14:41] D:\DOCUME~1\sylvie\APPLIC~1\Mozilla
[01/04/2008|16:22] D:\DOCUME~1\sylvie\APPLIC~1\MSNInstaller
[08/03/2009|16:36] D:\DOCUME~1\sylvie\APPLIC~1\new help rect
[07/01/2007|01:46] D:\DOCUME~1\sylvie\APPLIC~1\Norman
[08/09/2006|14:51] D:\DOCUME~1\sylvie\APPLIC~1\OD2
[26/09/2008|19:08] D:\DOCUME~1\sylvie\APPLIC~1\OFFICE One v6
[15/08/2008|22:45] D:\DOCUME~1\sylvie\APPLIC~1\OfficeUpdate12
[15/05/2008|17:00] D:\DOCUME~1\sylvie\APPLIC~1\PlayFirst
[19/06/2007|14:43] D:\DOCUME~1\sylvie\APPLIC~1\SecondLife
[10/04/2008|18:41] D:\DOCUME~1\sylvie\APPLIC~1\SecuROM
[19/04/2007|18:59] D:\DOCUME~1\sylvie\APPLIC~1\Shareaza
[14/01/2007|20:47] D:\DOCUME~1\sylvie\APPLIC~1\Skype
[16/10/2006|09:26] D:\DOCUME~1\sylvie\APPLIC~1\Sonic
[08/09/2006|14:13] D:\DOCUME~1\sylvie\APPLIC~1\Sun
[08/09/2006|23:55] D:\DOCUME~1\sylvie\APPLIC~1\Ulead Systems
[02/10/2006|14:19] D:\DOCUME~1\sylvie\APPLIC~1\VadeRetro
[13/08/2007|00:28] D:\DOCUME~1\sylvie\APPLIC~1\WeatherDPA
[06/10/2007|12:44] D:\DOCUME~1\sylvie\APPLIC~1\Windows Desktop Search
[08/10/2007|09:04] D:\DOCUME~1\sylvie\APPLIC~1\Windows Live Writer
[30/07/2007|08:15] D:\DOCUME~1\sylvie\APPLIC~1\XINEK
[18/05/2006|07:48] D:\DOCUME~1\sylvie\APPLIC~1\You've Got Pictures Screensaver
[18/03/2008|17:55] D:\DOCUME~1\sylvie\APPLIC~1\Zylom

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[09/03/2009 02:23][--a------] C:\WINDOWS\tasks\Scheduled scanning task.job
[09/03/2009 21:37][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[31/12/2008|11:36] C:\Program Files\Adobe
[09/03/2009|14:16] C:\Program Files\Ad-remover
[24/01/2009|15:09] C:\Program Files\AGI
[26/09/2008|19:12] C:\Program Files\AOL 9.0
[27/09/2008|03:48] C:\Program Files\AOL Compagnon
[26/10/2008|21:13] C:\Program Files\Apple Software Update
[23/02/2009|00:27] C:\Program Files\Astonsoft
[27/09/2008|03:47] C:\Program Files\ATI Technologies
[23/02/2009|00:28] C:\Program Files\AVS4YOU
[27/09/2008|03:47] C:\Program Files\ComPlus Applications
[21/02/2009|18:59] C:\Program Files\Comptes et Budget Free V5.0
[27/09/2008|03:47] C:\Program Files\CyberLink
[09/03/2009|21:41] C:\Program Files\eMule
[23/02/2009|00:16] C:\Program Files\Fichiers communs
[27/09/2008|03:47] C:\Program Files\GMixon
[16/01/2009|22:49] C:\Program Files\Google
[27/09/2008|03:47] C:\Program Files\Goto Software
[02/01/2009|22:26] C:\Program Files\Hercules
[06/01/2009|20:18] C:\Program Files\Hewlett-Packard
[06/01/2009|20:18] C:\Program Files\HP
[02/01/2009|22:26] C:\Program Files\InstallShield Installation Information
[12/02/2009|00:23] C:\Program Files\Internet Explorer
[23/02/2009|01:12] C:\Program Files\Java
[23/02/2009|01:13] C:\Program Files\JRE
[24/01/2009|15:24] C:\Program Files\Kiwee Toolbar
[27/09/2008|03:47] C:\Program Files\Learn2.com
[29/01/2009|23:45] C:\Program Files\LimeWire
[09/03/2009|02:05] C:\Program Files\Malwarebytes' Anti-Malware
[29/12/2008|10:39] C:\Program Files\Messenger
[24/12/2008|15:05] C:\Program Files\Microsoft
[26/12/2008|03:02] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/09/2008|03:47] C:\Program Files\microsoft frontpage
[27/02/2009|10:18] C:\Program Files\Microsoft Silverlight
[24/12/2008|15:06] C:\Program Files\Microsoft SQL Server Compact Edition
[24/12/2008|15:07] C:\Program Files\Microsoft Sync Framework
[29/12/2008|10:36] C:\Program Files\Movie Maker
[07/11/2008|08:15] C:\Program Files\MSN
[20/02/2009|23:10] C:\Program Files\MSN Games
[27/09/2008|03:47] C:\Program Files\MSN Gaming Zone
[26/12/2008|03:00] C:\Program Files\MSXML 4.0
[27/12/2008|02:21] C:\Program Files\MSXML 6.0
[29/12/2008|10:35] C:\Program Files\NetMeeting
[27/09/2008|03:47] C:\Program Files\Norman
[31/12/2008|11:33] C:\Program Files\NOS
[20/02/2009|11:59] C:\Program Files\Oberon Media
[27/09/2008|03:51] C:\Program Files\Online Services
[23/02/2009|01:13] C:\Program Files\OpenOffice.org 3
[29/12/2008|10:35] C:\Program Files\Outlook Express
[07/11/2008|07:52] C:\Program Files\QuickTime
[27/09/2008|03:47] C:\Program Files\Real
[27/09/2008|03:47] C:\Program Files\Realtek
[27/09/2008|03:52] C:\Program Files\Services en ligne
[14/02/2009|15:45] C:\Program Files\SFR
[27/09/2008|03:53] C:\Program Files\ShowTime
[27/09/2008|03:47] C:\Program Files\Sonic
[09/03/2009|14:22] C:\Program Files\trend micro
[27/09/2008|03:47] C:\Program Files\Ulead Systems
[27/09/2008|03:47] C:\Program Files\Uninstall Information
[27/09/2008|03:47] C:\Program Files\Viewpoint
[19/02/2009|09:31] C:\Program Files\Windows Live
[24/12/2008|15:05] C:\Program Files\Windows Live SkyDrive
[27/09/2008|03:47] C:\Program Files\Windows Media Components
[02/01/2009|00:10] C:\Program Files\Windows Media Connect 2
[02/01/2009|00:10] C:\Program Files\Windows Media Player
[29/12/2008|10:35] C:\Program Files\Windows NT
[27/09/2008|03:47] C:\Program Files\WindowsUpdate
[27/09/2008|03:47] C:\Program Files\xerox

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[31/12/2008|11:36] C:\Program Files\Fichiers communs\Adobe
[27/09/2008|03:50] C:\Program Files\Fichiers communs\AOL
[27/09/2008|03:50] C:\Program Files\Fichiers communs\aolshare
[23/02/2009|00:27] C:\Program Files\Fichiers communs\AVSMedia
[26/10/2008|20:37] C:\Program Files\Fichiers communs\Hewlett-Packard
[26/10/2008|20:40] C:\Program Files\Fichiers communs\HP
[27/09/2008|03:47] C:\Program Files\Fichiers communs\InstallShield
[27/09/2008|03:47] C:\Program Files\Fichiers communs\Java
[19/02/2009|09:27] C:\Program Files\Fichiers communs\Microsoft Shared
[27/09/2008|03:47] C:\Program Files\Fichiers communs\MSSoap
[27/09/2008|03:47] C:\Program Files\Fichiers communs\Nullsoft
[27/09/2008|03:47] C:\Program Files\Fichiers communs\ODBC
[27/09/2008|03:47] C:\Program Files\Fichiers communs\Real
[27/09/2008|03:50] C:\Program Files\Fichiers communs\Services
[27/09/2008|03:50] C:\Program Files\Fichiers communs\Sonic Shared
[27/09/2008|03:47] C:\Program Files\Fichiers communs\SpeechEngines
[27/09/2008|03:50] C:\Program Files\Fichiers communs\SureThing Shared
[12/12/2008|00:53] C:\Program Files\Fichiers communs\Symantec Shared
[29/12/2008|10:35] C:\Program Files\Fichiers communs\System
[27/09/2008|03:47] C:\Program Files\Fichiers communs\Ulead Systems
[24/12/2008|14:57] C:\Program Files\Fichiers communs\Windows Live

--------------------\\ Process

( 76 Processes )

IEXPLORE.EXE ~ [PID:4564]

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

D:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch
D:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch\License Bold.0xe

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-09 22:01:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
folder error: D:\DOCUME~1\sylk62\LOCALS~1\APPLIC~1

--------------------\\ Recherche d'autres infections

D:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\WebMediaPlayer
D:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\WebMediaPlayer\Conditions g‚n‚rales.lnk
D:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\WebMediaPlayer\Confidentialit‚.lnk
D:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\WebMediaPlayer\Website.lnk
[b]==> EGDACCESS <==/b



[F:9][D:5]-> D:\DOCUME~1\sylk62\LOCALS~1\Temp
[F:19][D:0]-> D:\DOCUME~1\sylk62\Cookies
[F:727][D:26]-> D:\DOCUME~1\sylk62\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 09/03/2009|22:01 - Option : [1]

--------------------\\ Fin du rapport a 22:01:49
0
plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
9 mars 2009 à 22:08
* Relance Lop S&D

* Choisis cette fois-ci l'option 2 (Suppression)

* Ne ferme pas la fenêtre lors de la suppression !

* Poste le rapport généré (C:\lopR.txt)


* (Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)

puis une infection navipromo vient ce rajouter

Navipromo est une infection qui affiche des fenêtres publicitaires intempestives.

Les programmes suivants installent cette infection :

* Funky Emoticons
* Games Attack
* Go-astro
* GoRecord
* HotTVPlayer
* Live Player
* MailSkinner
* Messenger Skinner
* Instant Access
* InternetGameBox
* Sudoplanet
* WebMediaPlayer

donc

* Télécharge sur le bureau Navilog1 https://www.androidworld.fr/

(c est le numéro 1 en bas de la page) :
* Si ton antivirus s'affole , le désactiver
* sous vista : Clic-droit sur le raccourci Navilog1 présent sur le bureau et choisis "Exécuter en tant qu'administrateur
* sous XP : double-clic dessus pour l'installer et le lancer
* taper F
* Appuyer sur une touche jusqu' arriver aux options
* Choisir Recherche ( = taper 1 )

ne pas utiliser les autres sans avis , il peut y avoir des processus légitimes
* un rapport : fixnavi.txt dans ==> C :
* le copier et le coller dans la réponse
0
suite:
--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 3.00GHz )
BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
USER : sylk62 ( Administrator )
BOOT : Normal boot
Antivirus : Pack sécurité 8.00 8.00 (Activated)
Firewall : Pack sécurité 8.00 8.00 (Activated)
C:\ (Local Disk) - NTFS - Total:29 Go (Free:9 Go)
D:\ (Local Disk) - NTFS - Total:148 Go (Free:135 Go)
E:\ (CD or DVD)
F:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 09/03/2009|22:11 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - D:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch\License Bold.0xe
Supprime! - D:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Supprime! - C:\Program Files\Viewpoint
Supprime! - D:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans APPLIC~1

[23/02/2009|00:34] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[24/01/2009|15:09] D:\DOCUME~1\ALLUSE~1\APPLIC~1\agi
[18/05/2006|00:48] D:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[26/10/2008|21:12] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/10/2008|21:14] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[23/02/2009|00:18] D:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[14/01/2007|11:38] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Ciel
[18/05/2006|00:58] D:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[15/02/2009|16:49] D:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[27/12/2008|15:09] D:\DOCUME~1\ALLUSE~1\APPLIC~1\EscapeTheMuseum
[16/02/2009|20:14] D:\DOCUME~1\ALLUSE~1\APPLIC~1\FamilyFlights
[18/03/2008|17:56] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Farm Frenzy
[31/01/2009|22:45] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[09/09/2007|18:25] D:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[28/12/2008|16:49] D:\DOCUME~1\ALLUSE~1\APPLIC~1\FlyWheelGames
[14/02/2009|15:45] D:\DOCUME~1\ALLUSE~1\APPLIC~1\f-secure
[14/02/2009|15:44] D:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
[04/02/2009|23:42] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Gogii
[26/05/2008|18:25] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/08/2007|00:28] D:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA
[08/09/2006|13:53] D:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[06/01/2009|20:17] D:\DOCUME~1\ALLUSE~1\APPLIC~1\HP Product Assistant
[18/01/2009|23:16] D:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[24/01/2009|15:24] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Kiwee Toolbar
[09/03/2009|00:13] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[20/05/2008|22:52] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/10/2007|08:22] D:\DOCUME~1\ALLUSE~1\APPLIC~1\MGS
[19/02/2009|09:30] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/08/2008|22:44] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[30/04/2008|21:27] D:\DOCUME~1\ALLUSE~1\APPLIC~1\MonteCristo
[12/08/2007|14:51] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[31/12/2008|11:33] D:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[14/02/2009|16:49] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games
[18/05/2006|00:47] D:\DOCUME~1\ALLUSE~1\APPLIC~1\OD2
[15/05/2008|17:00] D:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[18/05/2006|00:48] D:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[16/01/2008|14:19] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[18/05/2006|09:27] D:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[10/11/2006|09:50] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[07/11/2008|07:40] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[24/02/2009|17:31] D:\DOCUME~1\ALLUSE~1\APPLIC~1\SpinTop Games
[12/12/2008|00:53] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[20/02/2009|23:08] D:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[14/01/2009|23:15] D:\DOCUME~1\ALLUSE~1\APPLIC~1\TheRace_dev
[18/05/2006|00:55] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[25/12/2008|20:42] D:\DOCUME~1\ALLUSE~1\APPLIC~1\VadeRetro
[13/10/2006|18:13] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[03/10/2006|21:33] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[12/01/2008|23:07] D:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[14/11/2006|23:21] D:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[27/09/2008|03:55] D:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI
[27/09/2008|03:55] D:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[27/09/2008|03:55] D:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[27/09/2008|03:55] D:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[27/09/2008|03:55] D:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver

[24/01/2009|15:25] D:\DOCUME~1\LOCALS~1\APPLIC~1\agi
[18/05/2006|09:27] D:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[30/09/2007|08:16] D:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[18/05/2006|09:27] D:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[19/12/2008|14:07] D:\DOCUME~1\sylk62\APPLIC~1\Adobe
[07/11/2008|07:25] D:\DOCUME~1\sylk62\APPLIC~1\AdobeUM
[24/01/2009|15:09] D:\DOCUME~1\sylk62\APPLIC~1\agi
[21/02/2009|18:59] D:\DOCUME~1\sylk62\APPLIC~1\AlauxSoft
[07/11/2008|07:59] D:\DOCUME~1\sylk62\APPLIC~1\Apple Computer
[27/09/2008|03:55] D:\DOCUME~1\sylk62\APPLIC~1\ATI
[23/02/2009|00:19] D:\DOCUME~1\sylk62\APPLIC~1\AVS4YOU
[16/02/2009|20:09] D:\DOCUME~1\sylk62\APPLIC~1\BeachPartyCraze
[20/01/2009|23:55] D:\DOCUME~1\sylk62\APPLIC~1\cerasus.media
[15/12/2008|09:37] D:\DOCUME~1\sylk62\APPLIC~1\CyberLink
[15/02/2009|17:00] D:\DOCUME~1\sylk62\APPLIC~1\DeepBurner
[31/01/2009|22:45] D:\DOCUME~1\sylk62\APPLIC~1\Flood Light Games
[08/03/2009|14:29] D:\DOCUME~1\sylk62\APPLIC~1\F-Secure
[11/01/2009|23:12] D:\DOCUME~1\sylk62\APPLIC~1\Google
[27/09/2008|03:55] D:\DOCUME~1\sylk62\APPLIC~1\Identities
[02/01/2009|22:25] D:\DOCUME~1\sylk62\APPLIC~1\InstallShield
[03/01/2009|15:03] D:\DOCUME~1\sylk62\APPLIC~1\Leadertech
[29/01/2009|23:41] D:\DOCUME~1\sylk62\APPLIC~1\LimeWire
[24/12/2008|14:23] D:\DOCUME~1\sylk62\APPLIC~1\Macromedia
[09/03/2009|00:13] D:\DOCUME~1\sylk62\APPLIC~1\Malwarebytes
[24/01/2009|17:45] D:\DOCUME~1\sylk62\APPLIC~1\Microsoft
[24/12/2008|14:26] D:\DOCUME~1\sylk62\APPLIC~1\MSNInstaller
[14/02/2009|16:49] D:\DOCUME~1\sylk62\APPLIC~1\Oberon Games
[07/11/2008|07:38] D:\DOCUME~1\sylk62\APPLIC~1\OD2
[23/02/2009|01:25] D:\DOCUME~1\sylk62\APPLIC~1\OpenOffice.org
[01/10/2008|02:13] D:\DOCUME~1\sylk62\APPLIC~1\Skype
[03/01/2009|15:03] D:\DOCUME~1\sylk62\APPLIC~1\Sonic
[01/01/2009|02:04] D:\DOCUME~1\sylk62\APPLIC~1\Sun
[01/01/2009|11:39] D:\DOCUME~1\sylk62\APPLIC~1\Ulead Systems
[25/12/2008|20:41] D:\DOCUME~1\sylk62\APPLIC~1\VadeRetro
[28/12/2008|01:46] D:\DOCUME~1\sylk62\APPLIC~1\Windows Live Writer
[27/09/2008|03:55] D:\DOCUME~1\sylk62\APPLIC~1\You've Got Pictures Screensaver

[01/04/2008|16:16] D:\DOCUME~1\sylvie\APPLIC~1\Abra Academy2
[03/02/2008|11:08] D:\DOCUME~1\sylvie\APPLIC~1\Adobe
[14/01/2007|18:37] D:\DOCUME~1\sylvie\APPLIC~1\AdobeUM
[23/01/2008|21:53] D:\DOCUME~1\sylvie\APPLIC~1\Anuman Interactive
[18/05/2006|07:40] D:\DOCUME~1\sylvie\APPLIC~1\ATI
[10/09/2007|08:11] D:\DOCUME~1\sylvie\APPLIC~1\Big Fish Games
[02/08/2008|23:02] D:\DOCUME~1\sylvie\APPLIC~1\cerasus.media
[09/09/2006|00:46] D:\DOCUME~1\sylvie\APPLIC~1\CyberLink
[26/12/2007|22:53] D:\DOCUME~1\sylvie\APPLIC~1\Flood Light Games
[09/09/2007|18:25] D:\DOCUME~1\sylvie\APPLIC~1\FloodLightGames
[04/11/2007|18:15] D:\DOCUME~1\sylvie\APPLIC~1\Gaijin Ent
[14/01/2007|18:26] D:\DOCUME~1\sylvie\APPLIC~1\Google
[07/01/2007|01:26] D:\DOCUME~1\sylvie\APPLIC~1\Help
[07/01/2007|12:36] D:\DOCUME~1\sylvie\APPLIC~1\Hemera
[13/08/2007|00:28] D:\DOCUME~1\sylvie\APPLIC~1\Hotbar
[18/03/2008|17:55] D:\DOCUME~1\sylvie\APPLIC~1\Identities
[20/01/2008|19:03] D:\DOCUME~1\sylvie\APPLIC~1\Jane s Hotel
[16/10/2006|09:23] D:\DOCUME~1\sylvie\APPLIC~1\Leadertech
[28/03/2008|11:57] D:\DOCUME~1\sylvie\APPLIC~1\Legends of pirates
[21/05/2007|23:10] D:\DOCUME~1\sylvie\APPLIC~1\Macromedia
[16/05/2008|22:18] D:\DOCUME~1\sylvie\APPLIC~1\Magic Academy
[07/11/2006|18:17] D:\DOCUME~1\sylvie\APPLIC~1\MessengerSkinner
[19/12/2007|20:26] D:\DOCUME~1\sylvie\APPLIC~1\Micro Application
[10/08/2008|16:08] D:\DOCUME~1\sylvie\APPLIC~1\Microsoft
[19/06/2007|14:41] D:\DOCUME~1\sylvie\APPLIC~1\Mozilla
[01/04/2008|16:22] D:\DOCUME~1\sylvie\APPLIC~1\MSNInstaller
[08/03/2009|16:36] D:\DOCUME~1\sylvie\APPLIC~1\new help rect
[07/01/2007|01:46] D:\DOCUME~1\sylvie\APPLIC~1\Norman
[08/09/2006|14:51] D:\DOCUME~1\sylvie\APPLIC~1\OD2
[26/09/2008|19:08] D:\DOCUME~1\sylvie\APPLIC~1\OFFICE One v6
[15/08/2008|22:45] D:\DOCUME~1\sylvie\APPLIC~1\OfficeUpdate12
[15/05/2008|17:00] D:\DOCUME~1\sylvie\APPLIC~1\PlayFirst
[19/06/2007|14:43] D:\DOCUME~1\sylvie\APPLIC~1\SecondLife
[10/04/2008|18:41] D:\DOCUME~1\sylvie\APPLIC~1\SecuROM
[19/04/2007|18:59] D:\DOCUME~1\sylvie\APPLIC~1\Shareaza
[14/01/2007|20:47] D:\DOCUME~1\sylvie\APPLIC~1\Skype
[16/10/2006|09:26] D:\DOCUME~1\sylvie\APPLIC~1\Sonic
[08/09/2006|14:13] D:\DOCUME~1\sylvie\APPLIC~1\Sun
[08/09/2006|23:55] D:\DOCUME~1\sylvie\APPLIC~1\Ulead Systems
[02/10/2006|14:19] D:\DOCUME~1\sylvie\APPLIC~1\VadeRetro
[13/08/2007|00:28] D:\DOCUME~1\sylvie\APPLIC~1\WeatherDPA
[06/10/2007|12:44] D:\DOCUME~1\sylvie\APPLIC~1\Windows Desktop Search
[08/10/2007|09:04] D:\DOCUME~1\sylvie\APPLIC~1\Windows Live Writer
[30/07/2007|08:15] D:\DOCUME~1\sylvie\APPLIC~1\XINEK
[18/05/2006|07:48] D:\DOCUME~1\sylvie\APPLIC~1\You've Got Pictures Screensaver
[18/03/2008|17:55] D:\DOCUME~1\sylvie\APPLIC~1\Zylom

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[09/03/2009 02:23][--a------] C:\WINDOWS\tasks\Scheduled scanning task.job
[09/03/2009 21:37][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[31/12/2008|11:36] C:\Program Files\Adobe
[09/03/2009|14:16] C:\Program Files\Ad-remover
[24/01/2009|15:09] C:\Program Files\AGI
[26/09/2008|19:12] C:\Program Files\AOL 9.0
[27/09/2008|03:48] C:\Program Files\AOL Compagnon
[26/10/2008|21:13] C:\Program Files\Apple Software Update
[23/02/2009|00:27] C:\Program Files\Astonsoft
[27/09/2008|03:47] C:\Program Files\ATI Technologies
[23/02/2009|00:28] C:\Program Files\AVS4YOU
[27/09/2008|03:47] C:\Program Files\ComPlus Applications
[21/02/2009|18:59] C:\Program Files\Comptes et Budget Free V5.0
[27/09/2008|03:47] C:\Program Files\CyberLink
[09/03/2009|21:41] C:\Program Files\eMule
[23/02/2009|00:16] C:\Program Files\Fichiers communs
[27/09/2008|03:47] C:\Program Files\GMixon
[16/01/2009|22:49] C:\Program Files\Google
[27/09/2008|03:47] C:\Program Files\Goto Software
[02/01/2009|22:26] C:\Program Files\Hercules
[06/01/2009|20:18] C:\Program Files\Hewlett-Packard
[06/01/2009|20:18] C:\Program Files\HP
[02/01/2009|22:26] C:\Program Files\InstallShield Installation Information
[12/02/2009|00:23] C:\Program Files\Internet Explorer
[23/02/2009|01:12] C:\Program Files\Java
[23/02/2009|01:13] C:\Program Files\JRE
[24/01/2009|15:24] C:\Program Files\Kiwee Toolbar
[27/09/2008|03:47] C:\Program Files\Learn2.com
[29/01/2009|23:45] C:\Program Files\LimeWire
[09/03/2009|02:05] C:\Program Files\Malwarebytes' Anti-Malware
[29/12/2008|10:39] C:\Program Files\Messenger
[24/12/2008|15:05] C:\Program Files\Microsoft
[26/12/2008|03:02] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/09/2008|03:47] C:\Program Files\microsoft frontpage
[27/02/2009|10:18] C:\Program Files\Microsoft Silverlight
[24/12/2008|15:06] C:\Program Files\Microsoft SQL Server Compact Edition
[24/12/2008|15:07] C:\Program Files\Microsoft Sync Framework
[29/12/2008|10:36] C:\Program Files\Movie Maker
[07/11/2008|08:15] C:\Program Files\MSN
[20/02/2009|23:10] C:\Program Files\MSN Games
[27/09/2008|03:47] C:\Program Files\MSN Gaming Zone
[26/12/2008|03:00] C:\Program Files\MSXML 4.0
[27/12/2008|02:21] C:\Program Files\MSXML 6.0
[29/12/2008|10:35] C:\Program Files\NetMeeting
[27/09/2008|03:47] C:\Program Files\Norman
[31/12/2008|11:33] C:\Program Files\NOS
[20/02/2009|11:59] C:\Program Files\Oberon Media
[27/09/2008|03:51] C:\Program Files\Online Services
[23/02/2009|01:13] C:\Program Files\OpenOffice.org 3
[29/12/2008|10:35] C:\Program Files\Outlook Express
[07/11/2008|07:52] C:\Program Files\QuickTime
[27/09/2008|03:47] C:\Program Files\Real
[27/09/2008|03:47] C:\Program Files\Realtek
[27/09/2008|03:52] C:\Program Files\Services en ligne
[14/02/2009|15:45] C:\Program Files\SFR
[27/09/2008|03:53] C:\Program Files\ShowTime
[27/09/2008|03:47] C:\Program Files\Sonic
[09/03/2009|14:22] C:\Program Files\trend micro
[27/09/2008|03:47] C:\Program Files\Ulead Systems
[27/09/2008|03:47] C:\Program Files\Uninstall Information
[19/02/2009|09:31] C:\Program Files\Windows Live
[24/12/2008|15:05] C:\Program Files\Windows Live SkyDrive
[27/09/2008|03:47] C:\Program Files\Windows Media Components
[02/01/2009|00:10] C:\Program Files\Windows Media Connect 2
[02/01/2009|00:10] C:\Program Files\Windows Media Player
[29/12/2008|10:35] C:\Program Files\Windows NT
[27/09/2008|03:47] C:\Program Files\WindowsUpdate
[27/09/2008|03:47] C:\Program Files\xerox

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[31/12/2008|11:36] C:\Program Files\Fichiers communs\Adobe
[27/09/2008|03:50] C:\Program Files\Fichiers communs\AOL
[27/09/2008|03:50] C:\Program Files\Fichiers communs\aolshare
[23/02/2009|00:27] C:\Program Files\Fichiers communs\AVSMedia
[26/10/2008|20:37] C:\Program Files\Fichiers communs\Hewlett-Packard
[26/10/2008|20:40] C:\Program Files\Fichiers communs\HP
[27/09/2008|03:47] C:\Program Files\Fichiers communs\InstallShield
[27/09/2008|03:47] C:\Program Files\Fichiers communs\Java
[19/02/2009|09:27] C:\Program Files\Fichiers communs\Microsoft Shared
[27/09/2008|03:47] C:\Program Files\Fichiers communs\MSSoap
[27/09/2008|03:47] C:\Program Files\Fichiers communs\Nullsoft
[27/09/2008|03:47] C:\Program Files\Fichiers communs\ODBC
[27/09/2008|03:47] C:\Program Files\Fichiers communs\Real
[27/09/2008|03:50] C:\Program Files\Fichiers communs\Services
[27/09/2008|03:50] C:\Program Files\Fichiers communs\Sonic Shared
[27/09/2008|03:47] C:\Program Files\Fichiers communs\SpeechEngines
[27/09/2008|03:50] C:\Program Files\Fichiers communs\SureThing Shared
[12/12/2008|00:53] C:\Program Files\Fichiers communs\Symantec Shared
[29/12/2008|10:35] C:\Program Files\Fichiers communs\System
[27/09/2008|03:47] C:\Program Files\Fichiers communs\Ulead Systems
[24/12/2008|14:57] C:\Program Files\Fichiers communs\Windows Live

--------------------\\ Process

( 75 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-09 22:12:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
folder error: D:\DOCUME~1\sylk62\LOCALS~1\APPLIC~1

--------------------\\ Recherche d'autres infections

D:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\WebMediaPlayer
D:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\WebMediaPlayer\Conditions g‚n‚rales.lnk
D:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\WebMediaPlayer\Confidentialit‚.lnk
D:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\WebMediaPlayer\Website.lnk
[b]==> EGDACCESS <==/b



[F:9][D:5]-> D:\DOCUME~1\sylk62\LOCALS~1\Temp
[F:20][D:0]-> D:\DOCUME~1\sylk62\Cookies
[F:832][D:26]-> D:\DOCUME~1\sylk62\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 09/03/2009|22:01 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 09/03/2009|22:13 - Option : [2]

--------------------\\ Fin du rapport a 22:13:08
0
v'là le reste:
Search Navipromo version 3.7.5 commencé le 09/03/2009 à 22:19:00,60

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1

Mise à jour le 26.02.2009 à 18h00 par IL-MAFIOSO

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 3.00GHz )
BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
USER : sylk62 ( Administrator )
BOOT : Normal boot

Antivirus : Pack sécurité 8.00 8.00 (Activated)
Firewall : Pack sécurité 8.00 8.00 (Activated)

C:\ (Local Disk) - NTFS - Total:29 Go (Free:9 Go)
D:\ (Local Disk) - NTFS - Total:148 Go (Free:135 Go)
E:\ (CD or DVD)
F:\ (USB)


Recherche executé en mode normal

*** Recherche Programmes installés ***


*** Recherche dossiers dans "C:\WINDOWS" ***


*** Recherche dossiers dans "C:\Program Files" ***


*** Recherche dossiers dans "D:\Documents and Settings\All Users\menudm~1\progra~1" ***

...\WebMediaPlayer trouvé !

*** Recherche dossiers dans "D:\Documents and Settings\All Users\menudm~1" ***


*** Recherche dossiers dans "d:\docume~1\alluse~1\applic~1" ***


*** Recherche dossiers dans "D:\Documents and Settings\sylk62\applic~1" ***


*** Recherche dossiers dans "D:\Documents and Settings\sylk62\locals~1\applic~1" ***


*** Recherche dossiers dans "D:\Documents and Settings\sylk62\menudm~1\progra~1" ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans "C:\WINDOWS\system32" *

* Recherche dans "D:\Documents and Settings\sylk62\locals~1\applic~1" *



*** Recherche fichiers ***



*** Recherche clés spécifiques dans le Registre ***
!! Les clés trouvées ne sont pas forcément infectées !!


*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :


2)Recherche Heuristique :

* Dans "C:\WINDOWS\system32" :


* Dans "D:\Documents and Settings\sylk62\locals~1\applic~1" :


3)Recherche Certificats :

Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche autres dossiers et fichiers connus :



*** Analyse terminée le 09/03/2009 à 22:21:51,56 ***
0
plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
9 mars 2009 à 22:27
* Relance navilog1

* Choisis cette fois option 2

* note : le bureau disparaît

* redémarrage du pc

* mettre le rapport dans ta prochaine réponse


puis desactive ton antivirus et tes defence en temps réel

et telecharge sur TON BUREAU combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
DECONNECTE toi d'internet

lance le suit les instruction et ne touche + a rien et poste le rapport
0
j'aie essayer de télécharger combofix apres avoir arreté mon anti-virus et fermer tt mes fenetres mais il me donne une fenetre bleue av 1curseur qui clignote et il se passe plus rien,j'aie attendu 5minutes environ.
Le fichier ne se met pas non plus sur mon bureau.
0
Rapport:
Clean Navipromo version 3.7.5 commencé le 09/03/2009 à 22:38:10,67

Outil exécuté depuis C:\Program Files\navilog1

Mise à jour le 26.02.2009 à 18h00 par IL-MAFIOSO

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 3.00GHz )
BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
USER : sylk62 ( Administrator )
BOOT : Normal boot

Antivirus : Pack sécurité 8.00 8.00 (Activated)
Firewall : Pack sécurité 8.00 8.00 (Activated)

C:\ (Local Disk) - NTFS - Total:29 Go (Free:9 Go)
D:\ (Local Disk) - NTFS - Total:148 Go (Free:135 Go)
E:\ (CD or DVD)
F:\ (USB)


Mode suppression automatique
avec prise en charge résultats Catchme et GNS


Nettoyage exécuté au redémarrage de l'ordinateur


*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)


*** Suppression avec sauvegardes résultats GenericNaviSearch ***

* Suppression dans "C:\WINDOWS\System32" *


* Suppression dans "D:\Documents and Settings\sylk62\locals~1\applic~1" *



*** Suppression dossiers dans "C:\WINDOWS" ***


*** Suppression dossiers dans "C:\Program Files" ***


*** Suppression dossiers dans "D:\Documents and Settings\All Users\menudm~1\progra~1" ***

...\WebMediaPlayer ...suppression...
...\WebMediaPlayer supprimé !


*** Suppression dossiers dans "D:\Documents and Settings\All Users\menudm~1" ***


*** Suppression dossiers dans "d:\docume~1\alluse~1\applic~1" ***


*** Suppression dossiers dans "D:\Documents and Settings\sylk62\applic~1" ***


*** Suppression dossiers dans "D:\Documents and Settings\sylk62\locals~1\applic~1" ***


*** Suppression dossiers dans "D:\Documents and Settings\sylk62\menudm~1\progra~1" ***



*** Suppression fichiers ***


*** Suppression fichiers temporaires ***

Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu D:\Documents and Settings\sylk62\locals~1\Temp effectué !

*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

2)Recherche, création sauvegardes et suppression Heuristique :


* Dans "C:\WINDOWS\system32" *


* Dans "D:\Documents and Settings\sylk62\locals~1\applic~1" *


*** Sauvegarde du Registre vers dossier Safebackup ***

sauvegarde du Registre réalisée avec succès !

*** Nettoyage Registre ***

Nettoyage Registre Ok


*** Certificats ***

Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltdt absent !

*** Recherche autres dossiers et fichiers connus ***



*** Nettoyage terminé le 09/03/2009 à 22:42:20,00 ***
0