MON PC REBOOT TOUT SEUL... snif...

Fermé
kaktusrouge - 12 juin 2009 à 02:19
 Utilisateur anonyme - 16 juin 2009 à 21:15
Bonjour,

J'ai un sérieux problème depuis peu... Lorsque je suis en train de jouer au poker online sur le logiciel PKR, ou lorsque je regarde des pages internet comportant de la vidéo (comme nbcsports.com par exemple) mon pc reboot tout seul. C'est dérangeant lorsque que l'on est à une table finale... Bref, quelqu'un pourrait-il m'aider à faire un check-up complet de ma machine afin de voir si c'est un problème de virus (spy, trojan...) ou matériel. Récemment j'ai changé mon boîtier d'alimentation, un pote m'en a mis un de récup'... Il me disait qu'il est peut-être pas assez puissant pour ma machine...
Du coup, qu'en pensez-vous ?... Ca serait cool de me filer un ptit coup de main sinon je vais payer un dépanneur... relou.
Merci d'avance !
A voir également:

9 réponses

Utilisateur anonyme
12 juin 2009 à 02:32
bonsoir :))

Pour voir ce qu'il en est,avoir un diagnostic et repérer les infections possibles et les neutraliser:


Télécharges et installes le logiciel de diagnostic :

ici Hijackthis
ou ici Hijackthis
ou ici Hijackthis


1- Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
A la fin de l'installe , le prg ce lance automatiquement : fermes le en cliquant sur la croix rouge .
Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
"C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

tuto pour utilisation :(merci balltrap34)
Regardes ici, c'est parfaitement expliqué en images ,

2- !! Déconnectes toi et fermes toute tes applications en cours !!

Cliques sur le raccourci du bureau pour lancer le prg :

S'il ne se lance pas clique ici

fais un scan HijackThis en cliquant sur : "Do a system scan and save a logfile"

--->copies-colles le rapport généré pour analyse
0
kaktusrouge
12 juin 2009 à 02:46
Merci pour le ptit coup de main !

Ouais je connaissais hijack j'avais oublié comment ça s'appellait. Je te mets l'analyse :


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:43:40, on 12/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
c:\program files\avira\antivir desktop\avcenter.exe
c:\program files\avira\antivir desktop\avscan.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - H:\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://H:\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://H:\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://H:\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://H:\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
0
Utilisateur anonyme
12 juin 2009 à 02:55
arretes le scan d antivir

ensuite :

Télécharge Désinstalleur d'Avast!.

redemarre en mode sans echec :

Comment aller en Mode sans échec
1) Redémarres ton ordi
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
3) Tu verras un écran avec options de démarrage apparaître
4) Choisis la duexieme option : Sans Échec avec prise en charge reseau, et valide avec "Entrée"
5) Choisis ton compte habituel, et non Administrateur (si besoin ... )

Désinstalle via Ajout/Suppression de Programmes (si présents) :

* Avast!


ensuite execute le desinstaller

Ceci effacera la majorité des traces du produit Avast! d'Alwil Software.

redemarre normalement

Télécharge Ccleaner sur ton Bureau. :

* Clique sur "download the latest version"
* Installe-le en laissant seulement les options suivantes cochées :

- Ajouter un raccourci sur le Bureau
- Contrôler automatiquement les mises à jour de CCleaner

* Lance le Nettoyage
* Clique sur Chercher des erreurs et sauvegarde si tu le souhaites.

plus de precision sur la configuration de ccleaner te seront donnees plus tard


tuto Comment utiliser CCleaner.

ensuite :


######## | XP _ Instal & recherche | #######


Telecharge et install UsbFix (de C_XX & Chiquitine29)

Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectés sans les ouvrir

# Double clic sur le raccourci UsbFix présent sur ton bureau .

# Choisi l option 1 ( Recherche )

# Laisse travailler l outil.

# Ensuite post le rapport UsbFix.txt qui apparaitra.

# Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

# Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

ensuite :


Télécharge Ad-remover ( de C_XX ) sur ton bureau :


! Déconnecte toi et ferme toutes applications en cours !

Double clique sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

Au menu principal choisis l'option "L" et tape sur [entrée] .

Laisse travailler l'outil et ne touche à rien ...

--> Poste le rapport qui apparait à la fin , sur le forum ...

( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

Aides en images (Installation)
Aides en images (Recherche)
0
kaktusrouge
12 juin 2009 à 03:02
ok, mais je comprends pas... Avast il est pas cool ?... Je fais ça et je t'envoies les rapports.
0
Utilisateur anonyme
12 juin 2009 à 03:06
Avast est une grosse daube lis les autres topics de desinfection si tu veux et tu verras qu'on fait virer Avast a tout le monde pour Antivir
0
kaktusrouge
12 juin 2009 à 03:34
Ok ok alors j'ai viré avast nickel, voila le rapport usbfix :



############################## [ UsbFix V3.030 | Scan ]

# User : Administrateur (Administrateurs) # TOM
# Update on 12/06/09 by Chiquitine29, C_XX & Chimay8
# WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 03:32:48 | 12/06/2009

# AMD Athlon(tm) XP 1800+
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Enabled
# AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]

# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 28,63 Go (2,34 Go free) # NTFS
# D:\ # Disque CD-ROM
# E:\ # Disque CD-ROM
# F:\ # Disque CD-ROM
# G:\ # Disque CD-ROM
# H:\ # Disque fixe local # 232,88 Go (90,67 Go free) [DISKDOUR] # NTFS
# L:\ # Disque CD-ROM
# M:\ # Disque CD-ROM

############################## [ Processus actifs ]

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## [ Registre Startup ]

HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
HKCU_Main: "Search Page"="https://actus.sfr.fr"
HKCU_Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="Administrateur"
HKLM_logon: "AltDefaultUserName"="Administrateur"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: ATIPTA=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
HKLM_Run: ATICCC="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
HKLM_Run: SoundMan=SOUNDMAN.EXE
HKLM_Run: Anti-Blaxx Manager=C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
HKLM_Run: PWRISOVM.EXE=C:\Program Files\PowerISO\PWRISOVM.EXE
HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKCU_Run: AlcoholAutomount="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
HKCU_Run: DAEMON Tools Lite="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
HKCU_Run: MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
HKCU_Run: AdobeBridge=
HKCU_Run: PC Suite Tray="C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray

################## [ Fichiers # Dossiers infectieux ]


################## [ Registre # Clés Run infectieuses ]

Found ! HKLM\software\microsoft\security center "AntiVirusOverride" ( 0x1 )

################## [ Registre # Mountpoints2 ]

HKCU\...\Explorer\MountPoints2\{f81ebe94-e571-11dd-ba7d-0010dcf3da79}\Shell\AutoRun\Command

################## [ ! Fin du rapport # UsbFix V3.030 ! ]




Je t'envoies le reste tout de suite
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
kaktusrouge
12 juin 2009 à 04:07
voila le rapport ad :


.
======= RAPPORT D'AD-REMOVER 1.1.4.5_H | UNIQUEMENT XP/VISTA/SEVEN =======
.
Mit à jour par C_XX le 11/06/2009 à 3:50 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 3:38:07, 12/06/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: TOM | Utilisateur actuel: Administrateur
.
Administrateur: Administrateur
N'est pas administrateur: ASPNET
N'est pas administrateur: HelpAssistant *Desactive*
N'est pas administrateur: Invité
N'est pas administrateur: SUPPORT_388945a0 *Desactive*
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
HKCR\CLSID\{06ADA938-0FB0-4BC0-B19B-0A38AB17F182}
HKCR\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}
HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
HKCR\Interface\{0C1CF2DF-05A3-4FEF-8CD4-F5CFC4355A16}
HKCR\Typelib\{710993A2-4F87-41D7-B6FE-F5A20368465F}
HKCU\Software\Casino Tropez
HKCU\Software\PartyGaming
HKLM\Software\Casino Tropez
HKLM\Software\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}
HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
HKCR\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
HKCR\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
HKCR\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
.
C:\Program Files\PartyGaming\announce.txt
C:\Program Files\PartyGaming\INSTALL.LOG
C:\Program Files\PartyGaming\Language
C:\Program Files\PartyGaming\PartyCasino
C:\Program Files\PartyGaming\PartyPoker
C:\Program Files\PartyGaming\PGImageDll.dll
C:\Program Files\PartyGaming\tmpUpgrade
C:\Program Files\PartyGaming\Language\en_US
C:\Program Files\PartyGaming\Language\fr_FR
C:\Program Files\PartyGaming\Language\en_US\temp
C:\Program Files\PartyGaming\Language\fr_FR\temp
C:\Program Files\PartyGaming\PartyCasino\format.ini
C:\Program Files\PartyGaming\PartyCasino\GRA.ini
C:\Program Files\PartyGaming\PartyCasino\language
C:\Program Files\PartyGaming\PartyCasino\LHN.txt
C:\Program Files\PartyGaming\PartyCasino\lobby.xml
C:\Program Files\PartyGaming\PartyCasino\lobbyconfig.txt
C:\Program Files\PartyGaming\PartyCasino\PartyCasino.dll
C:\Program Files\PartyGaming\PartyCasino\pc_uninstall.bat
C:\Program Files\PartyGaming\PartyCasino\ProductVersion.txt
C:\Program Files\PartyGaming\PartyCasino\sys.ini
C:\Program Files\PartyGaming\PartyCasino\Temp
C:\Program Files\PartyGaming\PartyCasino\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\allLangVersion.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR
C:\Program Files\PartyGaming\PartyCasino\language\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\articles
C:\Program Files\PartyGaming\PartyCasino\language\en_US\lang_pack_en_US.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\lang_pack_fr_FR.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\167058.html
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\169524.atc
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\169704.atc
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\169706.atc
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\169708.atc
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\71025.html
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\73847.atc
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\74111.atc
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\74113.atc
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\74115.atc
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\74135.atc
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\74201.html
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\Articles\74279.atc
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\account_but_newacocunt.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\ace.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\ace.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\allversion.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\BB-Numbers-comma.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\BB-Numbers-dot.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\bonus-icon.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\bottom-banners-left-buttons.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\bottom-banners-right-buttons.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\but.bmp
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\but.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\but.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\but_account.bmp
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\but_skin.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\but_skin.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\but_skin_account.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\but_skin_sliver.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\client_bottom.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\client_bottom_right.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\client_bottom_seperator.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\client_gradient.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\client_top.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\client_top_header.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\client_top_left.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\Common_background.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\Common_background_minimised.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\Common_buttons_380x23.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\Common_CloseContainer_black.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\Common_CloseContainer_white.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\create_account.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\deuce.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\deuce.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\down_arrow.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\down_arrow_o.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\icon_three.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\icon_ticked.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\jack.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\jack.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\king.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\king.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\left_bottom.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\LHN-sub-menu.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_account.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_account_background.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_account_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_account_divider.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_ani_refresh.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_background.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_badbeat_jackpot.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_bar_jackpot_numbers.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_bar_jackpot_numbers.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_bar_jackpot_numbers_small.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_bar_jackpot_numbers_small.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_bar_news.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_but_cashout.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_but_deposit.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_but_deposit_large.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_but_options.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_but_redeem.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_but_refresh.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_but_reload_play.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_but_status.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_cashier.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_cashier_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_casino.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_casino_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_collapse.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_details_open.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_expand.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_gammon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_gammon_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_link_arrow.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_poker.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_poker_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_preferences.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_preferences_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_separator.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_separator_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_separator_collapse.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_sub_nav.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_support.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_support_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lhn_tab_background.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\loading.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\LobbyClock.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lobby_but.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\lobby_skin.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\Main-area-top-bg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\Mainarea-Collapse-button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\Mainarea-Expand-button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-bg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-collapse-close-buttons.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-collapse-open-buttons.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-deposit-buttons.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-Loyality-A-gold.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-minimised-bg.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-minimised-bg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-refresh-icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-slider-bg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-slider-blue-button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-slider-blue.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-slider-green-button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-slider-green.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-slider-orange-button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\MAT-slider-orange.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\Message-icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\new-mail-icon.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\no-mail-icon.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\PartyCasino.ico
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\pokerLobby_bonusBack.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\pokerLobby_depositButtonLarge.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\pokerLobby_leftHandIconPoker.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\popup_login_bottom.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\popup_login_top.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\popup_register_bottomleft.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\popup_register_top.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\queen.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\queen.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\sign_up.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\skin.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\skin_account.bmp
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\spacer.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\splash_screen_bg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\star_icon.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_bets.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_bets_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_bingo.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_bingo_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_casino-27.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_casino.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_casino_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_connected.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_connected_good.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_connected_poor.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_disconnected.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_gammon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_gammon_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_poker.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_poker_collapse.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_security.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\system_but_security.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\ticker_bg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\up_arrow.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\up_arrow_o.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\vip.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\vip_elite.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\FCPeer.dll
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\Chip1.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\Chip100.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\Chip25.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\Chip5.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\Chip500.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\en_US.zip
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\fr_FR.zip
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\Game_product_assets.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\game_skins.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\GRA.ini
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\MultiHandBJ.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\party_assets.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\party_Cards.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\Sys.ini
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\cardgames\blackjack\multiplayerblackjack\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip0_5.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip1.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip10.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip100.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip100k.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip10k.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip1k.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip25.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip250.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip25k.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip2_5k.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip5.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip50.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip500.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip500k.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip50k.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Chip5k.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\en_US.zip
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\fr_FR.zip
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Game_product_assets.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\game_skins.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\GRA.ini
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Roulette.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\RouletteSounds.swf
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\Sys.ini
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\fcgames\roulette\europeanroulette\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\addplaymoney_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\aud.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\autospincancel_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\autospinoptions_background.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\autospinstart_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\balance_strip.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\bottombar_logo_net.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\bottombar_net.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\bottombar_net_big.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\bottombar_net_medium.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\BuyInConfig.ini
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\buyin_botbg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\buyin_cancelbutton.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\buyin_cashierbutton.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\buyin_midbg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\buyin_okbutton.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\buyin_topbg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cad.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cashier_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cashout_midbg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cent_strip.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\chf.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\chips.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\czk.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\dkk.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\eur.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\exit_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\FCPeer.dll
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\format.ini
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\gamelogs_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\game_topbar_pff.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\gbp.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\gp_slt_terminator.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\hkd.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\huf.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\ils.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\inr.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\jpy.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\krw.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\myr.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\nok.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\nzd.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\php.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\pln.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\popup_but_cancel.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\popup_but_cashier.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\popup_but_ok.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\popup_buyin_but_all.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\popup_buyin_tab.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\PushBut.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\quickdeposit_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\ron.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\rur.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\sek.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\sgd.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\skk.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\status_dlg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\system_but_close.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\system_but_inactive_close.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\system_but_inactive_minimise.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\system_but_minimise.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\sys_icons.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\table_logo_com.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\table_logo_net.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\thb.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\trny_buyin_botbg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\try.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\twd.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\usd.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\version_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\win.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\zar.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\6_bigcardback.bmp
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c0_5.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c1.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c10.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c100.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c100k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c10k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c1k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c25.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c250.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c25k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c2_5k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c5.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c50.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c500.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c500k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c50k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\c5k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\Card.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\CardFlip.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\card_deck.bmp
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\FRU_6_bigcardback.bmp
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\number_circle.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\pointer_R.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\qd_cashier_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\qd_exit_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\qd_gamelogs_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\qd_version_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc0_5.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc1.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc10.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc100.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc100k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc10k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc1k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc25.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc250.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc25k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc2_5k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc5.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc50.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc500.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc500k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc50k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rc5k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\Rr.bmp
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\rules_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_americanroulette_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_baccarat_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_bjbonuspairs_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_bjhighlimit_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_bjsingledeck_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_boardbabe_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_cashcruise_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_casinowar_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_coolbanana_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_deuceswild_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_europeanroulette_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_firedrake_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_flamingo_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_fruitparty_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_goannagold_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_goldenoasis_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_graveyardbash_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_hotjokerpoker_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_hotroller_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_job_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_junglerumble_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_kangacash_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_kookakeno_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_lir_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_logo_cover.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_magicman_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_mhvp_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_paigow_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_pcp_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_pc_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_piggypayback_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_predator_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_reddog_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_safecrackerkeno_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_sfw_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_silvercity_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_superjoker_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_supermystic_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_superstar_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_sweethawaii_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_tcp_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_tod_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bjbar_vegasclub_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\bj_check.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\blackjack
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\BlackJack.dll
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\blackjack.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\chip_pointer_R.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\clear_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\deal_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\double_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\hit_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\insurance.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\insure_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\number_circle.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\pointer_R.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\push.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\repeatbet_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\result_bj.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\result_bust.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\result_insure.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\result_lost.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\result_push.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\result_won.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\split.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\split_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\stand_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\surrender_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\blackjack\bj_table.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\blackjack\Config.ini
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\blackjack\blackjack\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\action_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\action_pending_panel.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\autostand.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\away_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\backcard.bmp
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\bj_check.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\blackjack.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\card_pointer.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\check_box.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\chip_pointer.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\clear_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\CommonConfig.ini
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\deal_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\double_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\first_hand.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\FRU_backcard.bmp
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\game_topbar_pff.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\hit_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\iam_back_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\insurance.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\leave_seat_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\looser.rgn
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\looser_popup.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\mhbj_clear_btn.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\mhbj_deal_btn.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\mhbj_double_bets_btn.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\mhbj_double_btn.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\mhbj_hit_btn.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\mhbj_repeatbet_btn.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\mhbj_split_btn.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\mhbj_stand_btn.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\mhbj_surrender_btn.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\mpbj_deck.bmp
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\MultiHandBJConfig.ini
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\MultiHandBJTrnyConfig.ini
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\multiplayerbj.dll
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\multiplayerblackjack
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\number_circle.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\player_area.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\push.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\repeatbet_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\result_bj.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\result_bust.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\result_push.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\result_won.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\sittingout_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\skip_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\split.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\split_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\stand_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\surrender_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\take_seat_button.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\trny_player_area.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\trny_watcher_area.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\watcher_area.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\winner.rgn
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\winners_closebutton.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\winners_popup.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\win_glow.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\multiplayerblackjack\mpbj_table.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\multiplayerblackjack\mpbj_trny_table.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\multiplayerblackjack\sp_mpbj_table.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\cardgames\multiplayerbj\multiplayerblackjack\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\0.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\00.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\1.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\10.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\11.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\12.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\13.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\14.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\15.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\16.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\17.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\18.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\19.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\2.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\20.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\21.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\22.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\23.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\24.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\25.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\26.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\27.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\28.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\29.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\3.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\30.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\31.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\32.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\33.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\34.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\35.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\36.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\4.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\5.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\6.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\7.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\8.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\9.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\ball_land.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\ball_outside.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\black.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c0_5.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c1.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c10.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c100.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c100k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c10k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c1k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c25.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c250.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c25k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c2_5k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c5.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c50.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c500.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c500k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c50k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\c5k.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\chip100_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\chip1_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\chip25_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\chip500_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\chip5_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\clear_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\config.ini
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\d1.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\d100.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\d25.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\d5.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\d500.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\even.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\green.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\marker.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\nodisplay_bg_strip.gif
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\odd.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\pointer.png
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\rebet_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\red.wav
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\Roulette.dll
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\rules_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\spin_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\0.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\00.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\1.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\10.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\11.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\12.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\13.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\14.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\15.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\16.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\17.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\18.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\19.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\2.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\20.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\21.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\22.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\23.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\24.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\25.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\26.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\27.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\28.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\29.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\3.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\30.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\31.mp3
C:\Program Files\PartyGaming\PartyCasino\language\fr_FR\images\games\roulette\europeanroulette\32.mp3
C:\Program Files\PartyGaming\PartyCasino\langua
0
Utilisateur anonyme
12 juin 2009 à 13:01
bonjour :


######## | Suppression | ########

Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectés sans les ouvrir

# Double clic sur le raccourci UsbFix présent sur ton bureau

# choisi l option 2 ( Suppression )

# Ton bureau disparaitra et le pc redémarrera .

# Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

# Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

# Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )


######### | Désinstallation | #######


# Double clic sur le raccourci UsbFix présent sur ton bureau

# Choisi l option Désinstaller ....
0
kaktusrouge
12 juin 2009 à 14:13
Bonjour Gen,

voilà le rapport usbfix :


############################## [ UsbFix V3.030 | Cleaning ]

# User : Administrateur (Administrateurs) # TOM
# Update on 12/06/09 by Chiquitine29, C_XX & Chimay8
# WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 14:04:57 | 12/06/2009

# AMD Athlon(tm) XP 1800+
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Enabled
# AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]

# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 28,63 Go (1,76 Go free) # NTFS
# D:\ # Disque CD-ROM
# E:\ # Disque CD-ROM
# F:\ # Disque CD-ROM
# G:\ # Disque CD-ROM
# H:\ # Disque fixe local # 232,88 Go (90,67 Go free) [DISKDOUR] # NTFS
# L:\ # Disque CD-ROM
# M:\ # Disque CD-ROM

############################## [ Processus actifs ]

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## [ Fichiers # Dossiers infectieux ]


################## [ Registre # Clés Run infectieuses ]

# HKLM\software\microsoft\security center\\ "AntiVirusOverride" # -> Reset sucessfully !

################## [ Registre # Mountpoints2 ]

Deleted ! HKCU\...\Explorer\MountPoints2\{f81ebe94-e571-11dd-ba7d-0010dcf3da79}\Shell\AutoRun\Command

################## [ Listing des fichiers présent ]

[12/06/2009 03:51|--a--c---|79508] - C:\Ad-Report-CLEAN.log
[23/02/2008 00:58|--a------|0] - C:\AUTOEXEC.BAT
[22/10/2008 00:52|---hsc---|212] - C:\boot.ini
[28/08/2001 14:00|-rahsc---|4952] - C:\Bootfont.bin
[23/02/2008 00:58|--a------|0] - C:\CONFIG.SYS
[?|?|?] - C:\hiberfil.sys
[23/02/2008 00:58|-rahs----|0] - C:\IO.SYS
[23/02/2008 00:58|-rahs----|0] - C:\MSDOS.SYS
[13/04/2008 09:43|-rahsc---|47564] - C:\NTDETECT.COM
[13/04/2008 11:31|-rahs----|252240] - C:\ntldr
[?|?|?] - C:\pagefile.sys
[09/03/2009 21:31|--ah-----|232] - C:\sqmdata00.sqm
[11/03/2009 20:11|--ah-----|232] - C:\sqmdata01.sqm
[12/03/2009 21:52|--ah-----|232] - C:\sqmdata02.sqm
[13/03/2009 13:29|--ah-c---|232] - C:\sqmdata03.sqm
[14/03/2009 22:43|--ah-c---|232] - C:\sqmdata04.sqm
[27/10/2008 23:15|--ah-c---|268] - C:\sqmdata05.sqm
[28/10/2008 12:51|--ah-c---|232] - C:\sqmdata06.sqm
[29/10/2008 05:45|--ah-c---|232] - C:\sqmdata07.sqm
[13/11/2008 18:25|--ah-c---|232] - C:\sqmdata08.sqm
[29/11/2008 18:46|--ah-c---|232] - C:\sqmdata09.sqm
[15/12/2008 19:30|--ah-c---|232] - C:\sqmdata10.sqm
[17/12/2008 22:39|--ah-c---|232] - C:\sqmdata11.sqm
[02/01/2009 02:42|--ah-c---|232] - C:\sqmdata12.sqm
[17/01/2009 20:12|--ah-c---|232] - C:\sqmdata13.sqm
[19/01/2009 07:52|--ah-c---|232] - C:\sqmdata14.sqm
[20/02/2009 19:50|--ah-c---|232] - C:\sqmdata15.sqm
[21/02/2009 16:48|--ah-c---|232] - C:\sqmdata16.sqm
[22/02/2009 20:18|--ah-c---|232] - C:\sqmdata17.sqm
[09/03/2009 04:44|--ah-c---|232] - C:\sqmdata18.sqm
[09/03/2009 20:15|--ah-c---|232] - C:\sqmdata19.sqm
[09/03/2009 21:31|--ah-----|244] - C:\sqmnoopt00.sqm
[11/03/2009 20:11|--ah-----|244] - C:\sqmnoopt01.sqm
[12/03/2009 21:52|--ah-----|244] - C:\sqmnoopt02.sqm
[13/03/2009 13:29|--ah-c---|244] - C:\sqmnoopt03.sqm
[14/03/2009 22:43|--ah-c---|244] - C:\sqmnoopt04.sqm
[27/10/2008 23:15|--ah-c---|244] - C:\sqmnoopt05.sqm
[28/10/2008 12:51|--ah-c---|244] - C:\sqmnoopt06.sqm
[29/10/2008 05:45|--ah-c---|244] - C:\sqmnoopt07.sqm
[13/11/2008 18:25|--ah-c---|244] - C:\sqmnoopt08.sqm
[29/11/2008 18:46|--ah-c---|244] - C:\sqmnoopt09.sqm
[15/12/2008 19:30|--ah-c---|244] - C:\sqmnoopt10.sqm
[17/12/2008 22:39|--ah-c---|244] - C:\sqmnoopt11.sqm
[02/01/2009 02:42|--ah-c---|244] - C:\sqmnoopt12.sqm
[17/01/2009 20:12|--ah-c---|244] - C:\sqmnoopt13.sqm
[19/01/2009 07:52|--ah-c---|244] - C:\sqmnoopt14.sqm
[20/02/2009 19:50|--ah-c---|244] - C:\sqmnoopt15.sqm
[21/02/2009 16:48|--ah-c---|244] - C:\sqmnoopt16.sqm
[22/02/2009 20:18|--ah-c---|244] - C:\sqmnoopt17.sqm
[09/03/2009 04:44|--ah-c---|244] - C:\sqmnoopt18.sqm
[09/03/2009 20:15|--ah-c---|244] - C:\sqmnoopt19.sqm
[12/06/2009 14:06|--a--c---|4926] - C:\UsbFix.txt
[10/03/2008 00:26|--a------|205] - C:\xmlin.ini
[23/02/2008 01:20|--a------|59] - C:\XPSP2+_Version.txt

################## [ Vaccination ]

# C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# H:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

################## [ ! Fin du rapport # UsbFix V3.030 ! ]

Quelle est la prochaine étape ?
Merci beaucoup en tout cas pour ton aide très précieuse !! :-)))
0
Utilisateur anonyme
12 juin 2009 à 15:03
hello

Télécharge OTL de OLDTimer

et enregistre le sur ton Bureau.

Double clic sur OTL.exe pour le lancer.

Coche les 2 cases Lop et Purity

Coche la case devant scan all users

Clic sur Run Scan.

A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)


Pour me le transmettre clique sur ce lien

Clique sur Parcourir et cherche le fichier ci-dessus.

Clique sur Ouvrir.

Clique sur "Cliquez ici pour déposer le fichier".

Un lien de cette forme :

hxxp://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt

est ajouté dans la page.

Copie ce lien dans ta réponse.
0
kaktusrouge
13 juin 2009 à 02:46
Bonjour Gen,

Voila le rapport OTL :


je me suis trompé avec ton site de depot de fichier... j'arrive plus a mettre le bon fichier à la place d'un autre que j'ai mis avant... j'avais fait un scan mais sans cocher "all users". je te le mets quand même :

http://www.cijoint.fr/cjlink.php?file=cj200906/cijs31iUWk.txt


je comprends pas... ça reboot encore quand je suis sur le logiciel de poker...


Le bon scan je te le mets là... je comprends pas pourquoi j'arrive pas a ajouter un deuxieme fichier sur ton site... je ferme puis je reclique sur ton lien, il me dit que le fichier OTL a déjà été ajouté avec succès et du coup y a plus le bouton d'envoi du fichier...


OTL logfile created on: 13/06/2009 02:36:21 - Run 2
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Administrateur.TOM\Bureau
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

1,50 Gb Total Physical Memory | 0,91 Gb Available Physical Memory | 60,52% Memory free
2,11 Gb Paging File | 1,42 Gb Available in Paging File | 67,37% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 28,63 Gb Total Space | 2,20 Gb Free Space | 7,68% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 232,88 Gb Total Space | 91,37 Gb Free Space | 39,24% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: TOM
Current User Name: Administrateur
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

[color=orange]========== Processes (SafeList) ==========/color

PRC - [2006/03/22 05:48:55 | 00,405,504 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2009/04/01 15:46:04 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2006/03/22 05:48:55 | 00,405,504 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2008/04/13 19:34:04 | 01,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2006/01/02 17:41:22 | 00,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2007/04/16 15:28:22 | 00,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2005/05/18 16:08:10 | 00,208,896 | ---- | M] (MB-Soft, HAANDI) -- C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
PRC - [2008/11/02 10:38:58 | 00,167,936 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2009/03/09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/03/02 13:08:11 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2008/07/24 17:02:06 | 00,490,952 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\daemon.exe
PRC - [2008/04/13 19:34:14 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
PRC - [2009/02/06 19:51:28 | 03,885,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
PRC - [2009/03/20 14:32:32 | 01,312,256 | ---- | M] (Nokia) -- C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
PRC - [2009/03/02 13:09:54 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2006/02/28 13:42:38 | 00,229,376 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2009/03/09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008/11/02 03:37:49 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe
PRC - [2009/06/04 00:57:25 | 00,201,440 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe
PRC - [2007/05/28 18:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2009/03/04 11:25:12 | 00,621,056 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2009/03/09 13:44:12 | 00,130,560 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2008/11/26 12:35:00 | 00,119,808 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2006/01/02 17:41:22 | 00,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2006/01/02 17:41:22 | 00,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2009/05/06 14:43:53 | 48,894,056 | ---- | M] (PKR Ltd) -- C:\Program Files\PKR\pokerapp.exe
PRC - [2009/02/06 18:07:48 | 00,027,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2008/04/13 19:34:16 | 00,070,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
PRC - [2008/04/13 19:34:16 | 00,070,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
PRC - [2009/06/12 12:51:02 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/06/13 01:16:43 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrateur.TOM\Bureau\OTL.exe

[color=orange]========== Win32 Services (SafeList) ==========/color

SRV - [2008/04/13 19:33:20 | 00,100,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\6to4svc.dll -- (6to4 [Auto | Running])
SRV - [2009/04/01 15:46:04 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService [Auto | Running])
SRV - [2009/03/02 13:09:54 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService [Auto | Running])
SRV - [2005/09/23 08:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2006/03/22 05:48:55 | 00,405,504 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
SRV - [2006/03/17 15:37:00 | 00,520,192 | ---- | M] () -- C:\WINDOWS\system32\ati2sgag.exe -- (ATI Smart [Auto | Stopped])
SRV - [2006/02/28 13:42:38 | 00,229,376 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2005/09/23 08:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/01/22 20:27:39 | 00,655,624 | ---- | M] (Acresso Software Inc.) -- C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped])
SRV - [2008/04/13 19:33:40 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2009/03/09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2008/09/02 16:14:04 | 00,191,656 | ---- | M] (CybelSoft) -- C:\Program Files\ma-config.com\maconfservice.exe -- (maconfservice [On_Demand | Stopped])
SRV - [2008/11/02 03:37:49 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
SRV - [2009/06/04 00:57:25 | 00,201,440 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe -- (PnkBstrB [Auto | Running])
SRV - [2009/03/04 11:25:12 | 00,621,056 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [On_Demand | Running])
SRV - [2007/05/28 18:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE [Auto | Running])
SRV - [2006/11/03 09:59:14 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

[color=orange]========== Driver Services (SafeList) ==========/color

DRV - [2008/09/24 10:40:22 | 04,122,368 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
DRV - [2006/03/22 05:56:22 | 01,522,688 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
DRV - [2009/02/13 12:34:33 | 00,011,608 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio [System | Running])
DRV - [2009/03/24 16:07:58 | 00,055,640 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\avgntflt.sys -- (avgntflt [Auto | Running])
DRV - [2009/03/30 10:32:47 | 00,096,104 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\avipbb.sys -- (avipbb [System | Running])
DRV - [2008/09/02 17:16:16 | 00,015,352 | ---- | M] (Ma-Config.com) -- C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys -- (driverhardwarev2 [On_Demand | Stopped])
DRV - [2001/08/17 22:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc. ) -- C:\WINDOWS\system32\DRIVERS\fetnd5.sys -- (FETNDIS [On_Demand | Running])
DRV - [2008/04/13 11:53:10 | 00,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\NMnt.sys -- (nm [On_Demand | Stopped])
DRV - [2008/04/13 11:56:08 | 00,088,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx [Auto | Running])
DRV - [2001/08/28 14:00:00 | 00,063,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnknb.sys -- (NwlnkNb [Auto | Running])
DRV - [2001/08/28 14:00:00 | 00,055,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys -- (NwlnkSpx [Auto | Running])
DRV - [2008/08/26 10:26:12 | 00,018,816 | ---- | M] (Nokia) -- C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys -- (pccsmcfd [On_Demand | Stopped])
DRV - [2009/06/04 00:57:39 | 00,138,512 | ---- | M] () -- C:\WINDOWS\system32\drivers\PnkBstrK.sys -- (PnkBstrK [On_Demand | Stopped])
DRV - [2001/08/28 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008/09/19 23:57:32 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2001/08/17 22:05:16 | 00,028,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\OVCD.sys -- (QCDonner [On_Demand | Stopped])
DRV - [2008/11/02 10:44:10 | 00,056,572 | ---- | M] (PowerISO Computing, Inc.) -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu [System | Running])
DRV - [2008/04/13 09:39:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008/10/23 17:58:00 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2009/02/13 12:49:30 | 00,028,376 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\ssmdrv.sys -- (ssmdrv [System | Running])
DRV - [2008/06/20 13:08:27 | 00,225,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\tcpip6.sys -- (Tcpip6 [System | Running])

[color=orange]========== Standard Registry (SafeList) ==========/color


[color=orange]========== Internet Explorer ==========/color

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Internet Explorer\Main,Default_page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Internet Explorer\Main,Default_search_url = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
IE - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\S-1-5-21-1390067357-2000478354-1606980848-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\S-1-5-21-1390067357-2000478354-1606980848-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color=orange]========== FireFox ==========/color

FF - prefs.js..browser.startup.homepage: "https://www.google.fr/?gws_rd=ssl"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {bb628310-0ab7-11db-9cd8-0800200c9a66}:3.1.2.0
FF - prefs.js..extensions.enabledItems: bkmrksync@nokia.com:1.0.0.704
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11


FF - HKLM\software\mozilla\Firefox\extensions\\bkmrksync@nokia.com: C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC\ [2009/05/25 13:14:14 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/10/26 22:22:53 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/12 12:51:09 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/12 12:51:09 | 00,000,000 | ---D | M]

[2008/10/22 16:34:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\mozilla\Extensions
[2008/10/22 16:34:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/12 04:55:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\mozilla\Firefox\Profiles\7okjshop.default\extensions
[2009/04/10 16:07:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\mozilla\Firefox\Profiles\7okjshop.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/03/16 02:16:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\mozilla\Firefox\Profiles\7okjshop.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}
[2008/10/23 18:00:35 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Application Data\Mozilla\FireFox\Profiles\7okjshop.default\searchplugins\daemon-search.xml
[2009/06/12 04:55:47 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/06/12 12:51:09 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/03/09 02:07:27 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/10/26 22:23:22 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2008/12/04 13:16:02 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/06/10 03:28:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/12 12:51:02 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/12 12:51:02 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/11/14 22:33:13 | 00,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2008/11/14 22:33:13 | 00,000,757 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2008/11/14 22:33:13 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/11/14 22:33:13 | 00,000,748 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\MediaDICO-fr.xml
[2008/11/14 22:33:13 | 00,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2008/11/14 22:33:13 | 00,000,652 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml

O1 HOSTS File: (790 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - H:\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe (MB-Soft, HAANDI)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min (Avira GmbH)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount (Alcohol Soft Development Team)
O4 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
O4 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray (Nokia)
O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 0
O7 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRun = 0
O7 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O8 - Extra context menu item: &D&ownload &with BitComet - res://H:\BitComet\BitComet.exe/AddLink.htm (www.BitComet.com)
O8 - Extra context menu item: &D&ownload all video with BitComet - res://H:\BitComet\BitComet.exe/AddVideo.htm (www.BitComet.com)
O8 - Extra context menu item: &D&ownload all with BitComet - res://H:\BitComet\BitComet.exe/AddAllLink.htm (www.BitComet.com)
O9 - Extra Button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - H:\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Protocole de transport compatible NWLink IPX/SPX/NetBIOS] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/23 00:58:49 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/06/12 14:06:17 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009/06/12 14:06:18 | 00,000,000 | RHSD | M] - H:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/13 02:36:41 | 00,000,000 | ---D | M]

[color=orange]========== Files/Folders - Created Within 30 Days ==========/color

[2009/06/13 01:16:39 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrateur.TOM\Bureau\OTL.exe
[2009/06/12 14:06:17 | 00,000,000 | RHSD | C] -- C:\autorun.inf
[2009/06/12 04:10:20 | 73,336,2176 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\Sunny.Et.L.Elephant.FRENCH.STV.DVDRip.XviD-FAN.avi
[2009/06/12 03:37:58 | 00,001,548 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\Ad-remover.lnk
[2009/06/12 03:37:57 | 00,000,000 | ---D | C] -- C:\Program Files\Ad-remover
[2009/06/12 03:32:21 | 00,001,336 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\UsbFix V3.030.lnk
[2009/06/12 03:32:18 | 00,000,000 | ---D | C] -- C:\UsbFix
[2009/06/12 03:24:55 | 00,001,548 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\CCleaner.lnk
[2009/06/12 03:24:54 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/06/12 03:16:03 | 16,101,41696 | -HS- | C] () -- C:\hiberfil.sys
[2009/06/12 02:42:47 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\HijackThis.lnk
[2009/06/12 02:42:46 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/06/12 02:25:08 | 00,001,707 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Avira AntiVir Control Center.lnk
[2009/06/12 02:24:48 | 00,096,104 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2009/06/12 02:24:48 | 00,055,640 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2009/06/12 02:24:48 | 00,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2009/06/12 02:24:48 | 00,028,376 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2009/06/12 02:24:48 | 00,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2009/06/12 02:24:41 | 00,000,000 | ---D | C] -- C:\Program Files\Avira
[2009/06/12 02:24:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
[2009/06/08 17:09:42 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mouhid.sys
[2009/06/08 17:09:42 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mouhid.sys
[2009/06/08 17:09:35 | 00,010,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidusb.sys
[2009/06/08 17:09:35 | 00,010,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidusb.sys
[2009/05/30 01:34:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrateur.TOM\Application Data\PokerAcademyPro2
[2009/05/30 01:34:31 | 00,001,669 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Poker Academy Pro 2 Demo.lnk
[2009/05/30 01:33:26 | 00,000,000 | ---D | C] -- C:\Program Files\PokerAcademyPro2
[2009/05/28 04:28:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Goto.Games
[2009/05/28 04:28:37 | 00,000,873 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\Funbridge2.lnk
[2009/05/28 04:28:22 | 00,000,000 | ---D | C] -- C:\Program Files\Goto.Games
[2009/05/27 15:46:59 | 39,079,476 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black Bass.wav
[2009/05/27 15:45:40 | 26,053,012 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black drumbox.wav
[2009/05/27 15:43:28 | 33,868,888 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black Voix.wav
[2009/05/27 15:40:45 | 18,237,136 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black effets.wav
[2009/05/27 15:33:40 | 45,592,704 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black batterie.wav
[2009/05/26 04:55:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Mes vidéos
[2009/05/25 13:14:23 | 00,001,763 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Nokia PC Suite.lnk
[2009/05/25 13:12:23 | 00,018,816 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\pccsmcfd.sys
[2009/05/22 16:01:17 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/05/22 14:09:51 | 00,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\DivX Shared
[2009/05/16 16:13:57 | 00,223,780 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\10052009061.jpg
[2009/05/16 16:13:56 | 00,380,703 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\10052009055.jpg
[2009/05/16 16:13:56 | 00,275,799 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\10052009057.jpg
[2009/05/16 16:13:56 | 00,268,485 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\10052009058.jpg
[2009/05/16 16:13:56 | 00,230,020 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\10052009060.jpg
[2009/05/16 16:13:56 | 00,220,107 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\10052009059.jpg
[2009/05/16 16:13:56 | 00,218,667 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\10052009056.jpg
[2009/05/16 16:13:55 | 00,364,363 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\10052009054.jpg
[2009/05/15 01:14:26 | 16,934,488 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black guitare.wav
[2009/05/15 01:03:51 | 00,239,530 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black.rns
[2009/05/14 23:06:12 | 00,202,324 | ---- | C] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black Venere.rns
[2009/01/04 00:09:15 | 00,000,051 | ---- | C] () -- C:\WINDOWS\npornap.INI
[2008/12/29 03:22:51 | 00,000,287 | ---- | C] () -- C:\WINDOWS\game.ini
[2008/11/09 01:59:44 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2008/11/09 01:59:44 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2008/11/09 01:59:44 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2008/11/02 03:24:46 | 00,138,512 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008/10/23 17:18:54 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008/10/22 21:18:46 | 00,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVS58.DLL
[2008/10/22 19:29:56 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008/09/19 23:57:34 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2001/08/28 14:00:00 | 00,000,507 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/28 14:00:00 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini

[color=orange]========== Files - Modified Within 30 Days ==========/color

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/06/13 01:19:21 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Administrateur.TOM\Local Settings\desktop.ini
[2009/06/13 01:19:20 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/06/13 01:19:18 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/06/13 01:19:15 | 16,101,41696 | -HS- | M] () -- C:\hiberfil.sys
[2009/06/13 01:16:43 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrateur.TOM\Bureau\OTL.exe
[2009/06/12 04:48:24 | 73,336,2176 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\Sunny.Et.L.Elephant.FRENCH.STV.DVDRip.XviD-FAN.avi
[2009/06/12 03:37:58 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\Ad-remover.lnk
[2009/06/12 03:32:21 | 00,001,336 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\UsbFix V3.030.lnk
[2009/06/12 03:24:56 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\CCleaner.lnk
[2009/06/12 03:22:47 | 00,003,072 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/06/12 03:12:53 | 02,170,544 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/12 02:42:47 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\HijackThis.lnk
[2009/06/12 02:25:08 | 00,001,707 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Avira AntiVir Control Center.lnk
[2009/06/12 02:02:18 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/06/04 00:57:39 | 00,138,512 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/06/04 00:57:25 | 00,201,440 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2009/06/01 18:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/30 01:34:31 | 00,001,669 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Poker Academy Pro 2 Demo.lnk
[2009/05/29 19:41:18 | 00,001,729 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Adobe Reader 9.lnk
[2009/05/28 04:28:37 | 00,000,873 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\Funbridge2.lnk
[2009/05/27 15:47:14 | 39,079,476 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black Bass.wav
[2009/05/27 15:46:21 | 00,202,324 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black Venere.rns
[2009/05/27 15:45:51 | 26,053,012 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black drumbox.wav
[2009/05/27 15:43:43 | 33,868,888 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black Voix.wav
[2009/05/27 15:40:54 | 18,237,136 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black effets.wav
[2009/05/27 15:33:55 | 45,592,704 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black batterie.wav
[2009/05/25 13:14:23 | 00,001,763 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Nokia PC Suite.lnk
[2009/05/22 16:01:22 | 00,000,754 | ---- | M] () -- C:\WINDOWS\WORDPAD.INI
[2009/05/22 14:11:04 | 00,000,795 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\DivX Player.lnk
[2009/05/22 14:10:43 | 00,000,831 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\DivX Converter.lnk
[2009/05/22 14:09:50 | 00,001,508 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Bureau\DivX Movies.lnk
[2009/05/15 01:14:35 | 16,934,488 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black guitare.wav
[2009/05/15 01:03:52 | 00,239,530 | ---- | M] () -- C:\Documents and Settings\Administrateur.TOM\Mes documents\Black.rns

[color=orange]========== LOP Check ==========/color

[2008/09/30 00:03:17 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Administrateur\Application Data
[2008/09/03 22:43:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Adobe
[2008/09/03 22:43:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\AdobeUM
[2008/09/28 00:26:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Apple Computer
[2008/02/25 02:57:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\ATI
[2008/09/18 02:13:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\DivX
[2008/04/06 05:19:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Help
[2008/02/23 01:50:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Macromedia
[2008/08/31 14:58:07 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Administrateur\Application Data\Microsoft
[2008/07/14 16:51:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Mozilla
[2008/07/18 15:38:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Nokia
[2008/04/02 14:08:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\PC Suite
[2008/09/15 18:41:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\skypePM
[2008/08/28 22:27:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Sony Ericsson
[2008/02/24 01:34:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Sun
[2008/02/23 05:07:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Talkback
[2008/08/29 10:46:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Teleca
[2008/06/18 03:29:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\uTorrent
[2008/02/23 06:06:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\vlc
[2008/09/30 03:21:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Winamp
[2008/02/26 04:02:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\WinRAR
[2009/05/30 01:34:43 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data
[2009/05/13 04:56:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Adobe
[2008/10/27 00:29:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Apple Computer
[2008/10/22 19:33:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\ATI
[2008/12/01 15:15:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Command & Conquer 3 Kane's Wrath
[2008/10/23 17:57:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\DAEMON Tools
[2008/11/04 15:53:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\DivX
[2008/12/18 04:55:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Download Manager
[2009/03/25 19:07:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\dvdcss
[2008/12/19 00:57:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\FMZilla
[2009/05/28 04:28:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Goto.Games
[2008/10/22 15:57:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Help
[2008/10/22 01:18:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Identities
[2009/01/18 17:10:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\InstallShield
[2008/11/22 02:16:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\InterVideo
[2008/10/22 01:54:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Macromedia
[2009/01/21 23:03:04 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Microsoft
[2008/10/22 16:34:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Mozilla
[2008/10/27 19:39:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\MSNInstaller
[2009/01/14 19:21:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\My Games
[2008/12/17 22:32:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Nokia
[2008/12/17 22:31:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\PC Suite
[2009/05/30 01:34:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\PokerAcademyPro2
[2008/12/15 23:45:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Propellerhead Software
[2009/02/14 04:05:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Real
[2009/05/14 22:51:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\skypePM
[2008/10/26 22:21:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\Sun
[2008/11/03 01:21:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\TigerPlayer
[2009/05/18 18:44:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\vghd
[2008/11/05 00:12:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur.TOM\Application Data\vlc
[2008/09/30 00:02:05 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/09/24 23:21:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2008/09/24 02:14:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2008/04/19 15:30:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/07/23 04:25:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2008/10/08 22:46:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NOS
[2008/02/24 06:27:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/05/30 01:34:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PokerAcademyPro2
[2008/09/15 18:51:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2008/09/24 02:19:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/09/30 00:02:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/02/24 05:46:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/06/12 02:24:41 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data
[2009/05/13 04:56:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
[2008/10/23 23:16:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple
[2009/03/19 03:15:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
[2009/06/12 02:24:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
[2009/01/22 20:02:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\FLEXnet
[2009/05/25 13:04:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Installations
[2008/10/23 15:45:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\ma-config.com
[2009/03/23 04:10:40 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
[2009/01/20 23:18:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Nokia
[2008/12/17 22:31:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Suite
[2008/12/15 23:45:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Propellerhead Software
[2009/05/26 04:54:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype
[2009/01/18 17:12:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\TomTom
[2008/10/22 21:07:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
[2008/10/23 15:41:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller
[2008/02/23 01:27:36 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Application Data
[2008/02/23 00:58:45 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Default User\Application Data\Microsoft
[2008/10/22 02:45:28 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User.WINDOWS\Application Data
[2008/10/22 01:06:01 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Default User.WINDOWS\Application Data\Microsoft
[2008/02/23 01:05:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data
[2008/02/23 06:02:24 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/10/22 01:13:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService.AUTORITE NT\Application Data
[2008/10/22 01:06:01 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService.AUTORITE NT\Application Data\Microsoft
[2008/02/23 01:04:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data
[2008/02/23 01:04:55 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/10/22 01:12:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService.AUTORITE NT\Application Data
[2008/10/22 01:06:01 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService.AUTORITE NT\Application Data\Microsoft
[2001/08/28 14:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/06/13 01:19:20 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

[color=orange]========== Purity Check ==========/color

< End of report >
0
kaktusrouge
13 juin 2009 à 15:18
Salut Gen,

J'ai toujours le même problème de reboot intempestif...

voila le rapport otl : http://www.cijoint.fr/cjlink.php?file=cj200906/cijpZo9U0q.txt

Tu crois que c'est quoi le problème ? virus ?...

Merci !
0
Utilisateur anonyme
15 juin 2009 à 14:26
hello

Clique sur le menu Demarrer /Panneau de configuration/Options des dossiers/ puis dans l'onglet Affichage
- Coche Afficher les fichiers et dossiers cachés
- Décoche Masquer les extensions des fichiers dont le type est connu
- Décoche Masquer les fichiers protégés du système d'exploitation (recommandé)
clique sur Appliquer, puis OK.

N'oublie pas de recacher à nouveau les fichiers cachés et protégés du système d'exploitation en fin de désinfection, c'est important

Fais analyser le(s) fichier(s) suivants sur Virustotal :

Virus Total

* Clique sur Parcourir en haut, choisis Poste de travail et cherche ces fichiers :

C:\WINDOWS\System32\Drivers\sptd.sys
C:\WINDOWS\System32\CNMVS58.DLL


* Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
* Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
* Lorsque l'analyse est terminée ("Situation actuelle: terminé"), clique sur Formaté
* Une nouvelle fenêtre de ton navigateur va apparaître
* Clique alors sur les deux fleches
* Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
* Enfin colle le résultat dans ta prochaine réponse.

ensuite :

Double clic sur OTL.exe pour le lancer.


Copie la liste qui se trouve en gras ci-dessous,

et colle-la dans la zone sous Customs Scans/Fixes

:processes
explorer.exe

:OTL
O3 - HKU\S-1-5-21-1390067357-2000478354-1606980848-500\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - Reg Error: Key error. File not found

:commands
[emptytemp]
[start explorer]


Clique sur RunFix pour lancer la suppression.


Poste le rapport.
0
kaktusrouge
16 juin 2009 à 20:50
Salut Gen ! Merci encore pour ton aide !! :-)

Alors pour Virus total et le fichier : C:\WINDOWS\System32\Drivers\sptd.sys un message d'erreur apparait et dit "0 bytes size received / Se ha recibido un archivo vacio"

pour l'autre , C:\WINDOWS\System32\CNMVS58.DLL :



Fichier CNMVS58.DLL reçu le 2009.06.16 18:48:49 (UTC)
Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.18 2009.06.16 -
AhnLab-V3 5.0.0.2 2009.06.16 -
AntiVir 7.9.0.187 2009.06.16 -
Antiy-AVL 2.0.3.1 2009.06.16 -
Authentium 5.1.2.4 2009.06.16 -
Avast 4.8.1335.0 2009.06.16 -
AVG 8.5.0.339 2009.06.16 -
BitDefender 7.2 2009.06.16 -
CAT-QuickHeal 10.00 2009.06.16 -
ClamAV 0.94.1 2009.06.16 -
Comodo 1341 2009.06.16 -
DrWeb 5.0.0.12182 2009.06.16 -
eSafe 7.0.17.0 2009.06.16 -
eTrust-Vet 31.6.6563 2009.06.16 -
F-Prot 4.4.4.56 2009.06.15 -
F-Secure 8.0.14470.0 2009.06.16 -
Fortinet 3.117.0.0 2009.06.16 -
GData 19 2009.06.16 -
Ikarus T3.1.1.59.0 2009.06.16 -
Jiangmin 11.0.706 2009.06.16 -
K7AntiVirus 7.10.765 2009.06.16 -
Kaspersky 7.0.0.125 2009.06.16 -
McAfee 5648 2009.06.16 -
McAfee+Artemis 5648 2009.06.16 -
McAfee-GW-Edition 6.7.6 2009.06.16 -
Microsoft 1.4701 2009.06.16 -
NOD32 4160 2009.06.16 -
Norman 6.01.09 2009.06.16 -
nProtect 2009.1.8.0 2009.06.16 -
Panda 10.0.0.14 2009.06.16 -
PCTools 4.4.2.0 2009.06.12 -
Prevx 3.0 2009.06.16 -
Rising 21.34.13.00 2009.06.16 -
Sophos 4.42.0 2009.06.16 -
Sunbelt 3.2.1858.2 2009.06.16 -
Symantec 1.4.4.12 2009.06.16 -
TheHacker 6.3.4.3.345 2009.06.15 -
TrendMicro 8.950.0.1094 2009.06.16 -
VBA32 3.12.10.7 2009.06.16 -
ViRobot 2009.6.16.1789 2009.06.16 -
Information additionnelle
File size: 6656 bytes
MD5...: 03a6d7b8b0171bfe8485578fe94a6186
SHA1..: 73cc9cda53cdd910ed21a1e8a8fab718c66a8011
SHA256: 55ed281359cfbce58497973dcb4a1ee626dd77ea939841c926631085d837b607
ssdeep: -<br>
PEiD..: -
TrID..: File type identification<br>Win32 Executable Generic (42.3%)<br>Win32 Dynamic Link Library (generic) (37.6%)<br>Generic Win/DOS Executable (9.9%)<br>DOS Executable Generic (9.9%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x12f2<br>timedatestamp.....: 0x401e5d6e (Mon Feb 02 14:23:42 2004)<br>machinetype.......: 0x14c (I386)<br><br>( 3 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x1362 0x1400 5.82 d974d056868079d0f46750a9452a3476<br>.data 0x3000 0x4 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br>.reloc 0x4000 0x1b2 0x200 3.58 1cc12fa7adb128e3ff705474f702b22b<br><br>( 6 imports ) <br>> ntdll.dll: wcsrchr, wcscpy<br>> USER32.dll: wsprintfW<br>> KERNEL32.dll: lstrcpyW, CloseHandle, CreateProcessW, lstrlenW, lstrcatW, GlobalFree, GetLastError, MultiByteToWideChar, GlobalAlloc, lstrcmpW<br>> WINSPOOL.DRV: -, OpenPrinterW, ClosePrinter, GetPrinterDriverW, GetPrinterW<br>> VERSION.dll: GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW<br>> ADVAPI32.dll: RegOpenKeyExW, RegQueryValueExW, RegCloseKey<br><br>( 1 exports ) <br>VendorSetupEntryPoint<br>
PDFiD.: -
RDS...: NSRL Reference Data Set<br>-

Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.18 2009.06.16 -
AhnLab-V3 5.0.0.2 2009.06.16 -
AntiVir 7.9.0.187 2009.06.16 -
Antiy-AVL 2.0.3.1 2009.06.16 -
Authentium 5.1.2.4 2009.06.16 -
Avast 4.8.1335.0 2009.06.16 -
AVG 8.5.0.339 2009.06.16 -
BitDefender 7.2 2009.06.16 -
CAT-QuickHeal 10.00 2009.06.16 -
ClamAV 0.94.1 2009.06.16 -
Comodo 1341 2009.06.16 -
DrWeb 5.0.0.12182 2009.06.16 -
eSafe 7.0.17.0 2009.06.16 -
eTrust-Vet 31.6.6563 2009.06.16 -
F-Prot 4.4.4.56 2009.06.15 -
F-Secure 8.0.14470.0 2009.06.16 -
Fortinet 3.117.0.0 2009.06.16 -
GData 19 2009.06.16 -
Ikarus T3.1.1.59.0 2009.06.16 -
Jiangmin 11.0.706 2009.06.16 -
K7AntiVirus 7.10.765 2009.06.16 -
Kaspersky 7.0.0.125 2009.06.16 -
McAfee 5648 2009.06.16 -
McAfee+Artemis 5648 2009.06.16 -
McAfee-GW-Edition 6.7.6 2009.06.16 -
Microsoft 1.4701 2009.06.16 -
NOD32 4160 2009.06.16 -
Norman 6.01.09 2009.06.16 -
nProtect 2009.1.8.0 2009.06.16 -
Panda 10.0.0.14 2009.06.16 -
PCTools 4.4.2.0 2009.06.12 -
Prevx 3.0 2009.06.16 -
Rising 21.34.13.00 2009.06.16 -
Sophos 4.42.0 2009.06.16 -
Sunbelt 3.2.1858.2 2009.06.16 -
Symantec 1.4.4.12 2009.06.16 -
TheHacker 6.3.4.3.345 2009.06.15 -
TrendMicro 8.950.0.1094 2009.06.16 -
VBA32 3.12.10.7 2009.06.16 -
ViRobot 2009.6.16.1789 2009.06.16 -

Information additionnelle
File size: 6656 bytes
MD5...: 03a6d7b8b0171bfe8485578fe94a6186
SHA1..: 73cc9cda53cdd910ed21a1e8a8fab718c66a8011
SHA256: 55ed281359cfbce58497973dcb4a1ee626dd77ea939841c926631085d837b607
ssdeep: -<br>
PEiD..: -
TrID..: File type identification<br>Win32 Executable Generic (42.3%)<br>Win32 Dynamic Link Library (generic) (37.6%)<br>Generic Win/DOS Executable (9.9%)<br>DOS Executable Generic (9.9%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x12f2<br>timedatestamp.....: 0x401e5d6e (Mon Feb 02 14:23:42 2004)<br>machinetype.......: 0x14c (I386)<br><br>( 3 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x1362 0x1400 5.82 d974d056868079d0f46750a9452a3476<br>.data 0x3000 0x4 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br>.reloc 0x4000 0x1b2 0x200 3.58 1cc12fa7adb128e3ff705474f702b22b<br><br>( 6 imports ) <br>> ntdll.dll: wcsrchr, wcscpy<br>> USER32.dll: wsprintfW<br>> KERNEL32.dll: lstrcpyW, CloseHandle, CreateProcessW, lstrlenW, lstrcatW, GlobalFree, GetLastError, MultiByteToWideChar, GlobalAlloc, lstrcmpW<br>> WINSPOOL.DRV: -, OpenPrinterW, ClosePrinter, GetPrinterDriverW, GetPrinterW<br>> VERSION.dll: GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW<br>> ADVAPI32.dll: RegOpenKeyExW, RegQueryValueExW, RegCloseKey<br><br>( 1 exports ) <br>VendorSetupEntryPoint<br>
PDFiD.: -
RDS...: NSRL Reference Data Set<br>-





Et voilà le rapport OTL :


========== PROCESSES ==========
Process explorer.exe killed successfully!
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-1390067357-2000478354-1606980848-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\NGLATempNokia\Nokia Sans Wide Bold v3.1.ttf scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\etilqs_kT21mSShc9s57z4lACL1 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\etilqs_m1E9uFb6S3HXZzVnLMPG scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\etilqs_MmhQUx1Mskyt03G2a6VC scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\NGLALog.txt scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\Perflib_Perfdata_10c.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\Perflib_Perfdata_2a0.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\Perflib_Perfdata_60c.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\~DF8BD8.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_650.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTL by OldTimer - Version 2.1.1.0 log created on 06162009_200632

Files moved on Reboot...
C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\NGLATempNokia\Nokia Sans Wide Bold v3.1.ttf moved successfully.
File C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\etilqs_kT21mSShc9s57z4lACL1 not found!
File C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\etilqs_m1E9uFb6S3HXZzVnLMPG not found!
File C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\etilqs_MmhQUx1Mskyt03G2a6VC not found!
C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\NGLALog.txt moved successfully.
File C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\Perflib_Perfdata_10c.dat not found!
File C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\Perflib_Perfdata_2a0.dat not found!
File C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\Perflib_Perfdata_60c.dat not found!
C:\Documents and Settings\Administrateur.TOM\Local Settings\Temp\~DF8BD8.tmp moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_650.dat not found!

Registry entries deleted on Reboot...


Que dois-je faire maintenant ?
Merci ;-)
0
Utilisateur anonyme
16 juin 2009 à 21:15
Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.



Télécharges :

Malwarebytes

ou :

Malwarebytes

* Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

(NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

* Potasses le Tuto pour te familiariser avec le prg :


( cela dit, il est très simple d'utilisation ).

relance malwarebytes en suivant scrupuleusement ces consignes :

! Déconnecte toi et ferme toutes applications en cours !

* Lance Malwarebyte's .

Fais un examen dit "Complet" .

--> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
--> à la fin tu cliques sur "résultat" .
--> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !


Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

0