------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T7250 @ 2.00GHz )
BIOS : Ver 1.00PARTTBL
USER : fuselier ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:141 Go (Free:100 Go)
D:\ (Local Disk) - NTFS - Total:7 Go (Free:2 Go)
E:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 07/11/2009|19:01 )
[ UAC => 1 ]
--------------------\\ Listing des dossiers dans Local
[19/12/2007|12:03] C:\Users\fuselier\AppData\Local\Adobe
[26/01/2008|16:14] C:\Users\fuselier\AppData\Local\Apple
[18/08/2008|08:45] C:\Users\fuselier\AppData\Local\Apple Computer
[12/12/2007|20:47] C:\Users\fuselier\AppData\Local\Application Data
[05/02/2008|11:28] C:\Users\fuselier\AppData\Local\Apps
[12/12/2007|20:59] C:\Users\fuselier\AppData\Local\AtStart.txt
[13/12/2007|23:17] C:\Users\fuselier\AppData\Local\capcom
[12/01/2009|18:16] C:\Users\fuselier\AppData\Local\cmzmilfd.bat
[04/11/2009|16:26] C:\Users\fuselier\AppData\Local\d3d9caps.dat
[24/08/2009|14:50] C:\Users\fuselier\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[05/02/2008|11:29] C:\Users\fuselier\AppData\Local\Deployment
[22/04/2009|23:30] C:\Users\fuselier\AppData\Local\Downloaded Installations
[12/12/2007|20:59] C:\Users\fuselier\AppData\Local\DSwitch.txt
[17/09/2008|08:11] C:\Users\fuselier\AppData\Local\FnF4.txt
[13/02/2009|16:23] C:\Users\fuselier\AppData\Local\GDIPFONTCACHEV1.DAT
[04/10/2008|08:47] C:\Users\fuselier\AppData\Local\Glowria
[07/11/2009|09:25] C:\Users\fuselier\AppData\Local\Google
[12/12/2007|20:47] C:\Users\fuselier\AppData\Local\Historique
[16/12/2007|02:02] C:\Users\fuselier\AppData\Local\HP
[06/11/2009|14:30] C:\Users\fuselier\AppData\Local\IconCache.db
[17/12/2007|20:10] C:\Users\fuselier\AppData\Local\IsolatedStorage
[17/01/2009|14:35] C:\Users\fuselier\AppData\Local\Microsoft
[04/02/2008|23:15] C:\Users\fuselier\AppData\Local\Microsoft Games
[20/12/2007|21:05] C:\Users\fuselier\AppData\Local\Microsoft Help
[28/02/2008|18:19] C:\Users\fuselier\AppData\Local\MigWiz
[06/04/2009|10:37] C:\Users\fuselier\AppData\Local\Mozilla
[06/01/2009|19:04] C:\Users\fuselier\AppData\Local\Orange
[22/04/2009|23:32] C:\Users\fuselier\AppData\Local\procaster
[12/12/2007|20:59] C:\Users\fuselier\AppData\Local\QSwitch.txt
[12/12/2007|18:59] C:\Users\fuselier\AppData\Local\QuickPlay
[13/12/2007|21:26] C:\Users\fuselier\AppData\Local\Steam
[15/12/2008|18:29] C:\Users\fuselier\AppData\Local\Symantec
[07/11/2009|19:01] C:\Users\fuselier\AppData\Local\Temp
[12/12/2007|20:47] C:\Users\fuselier\AppData\Local\Temporary Internet Files
[16/12/2007|02:03] C:\Users\fuselier\AppData\Local\VirtualStore
[07/01/2008|14:27] C:\Users\fuselier\AppData\Local\Windows Live Writer
[30/05/2009|12:05] C:\Users\fuselier\AppData\Local\X-Plane Installer.prf
[28/05/2009|19:32] C:\Users\fuselier\AppData\Local\x-plane_install.txt
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[07/11/2009 13:20][--a------] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[06/11/2009 14:42][--a------] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[26/10/2009 20:00][--a------] C:\Windows\tasks\Norton Internet Security - Effectuer une analyse complŠte du systŠme - fuselier.job
[07/11/2009 18:53][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{AB027A15-3301-4FB0-AACB-CAAA37702805}.job
[06/11/2009 14:33][--ah-----] C:\Windows\tasks\SA.DAT
[06/11/2009 14:31][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[26/11/2008|22:24] C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[25/06/2007|21:53] C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}
[03/06/2009|18:02] C:\ProgramData\Adobe
[26/01/2008|16:13] C:\ProgramData\Apple
[26/11/2008|22:23] C:\ProgramData\Apple Computer
[12/12/2007|20:44] C:\ProgramData\Application Data
[02/11/2009|10:02] C:\ProgramData\Avira
[12/12/2007|20:44] C:\ProgramData\Bureau
[14/04/2009|08:58] C:\ProgramData\CyberLink
[12/12/2007|20:44] C:\ProgramData\Documents
[25/04/2009|12:34] C:\ProgramData\Electronic Arts
[14/03/2009|18:53] C:\ProgramData\EPSON
[12/12/2007|20:44] C:\ProgramData\Favoris
[06/11/2009|09:53] C:\ProgramData\Google
[25/06/2007|22:27] C:\ProgramData\Hewlett-Packard
[12/12/2007|18:26] C:\ProgramData\HP
[25/06/2007|22:03] C:\ProgramData\hpzinstall.log
[18/03/2008|15:43] C:\ProgramData\LogiShrd
[18/03/2008|15:39] C:\ProgramData\Logitech
[02/11/2009|11:06] C:\ProgramData\Malwarebytes
[31/08/2008|13:02] C:\ProgramData\Media Center Programs
[12/12/2007|20:44] C:\ProgramData\Menu D‚marrer
[07/01/2008|11:12] C:\ProgramData\MGS
[11/04/2009|16:36] C:\ProgramData\Microsoft
[20/12/2007|22:37] C:\ProgramData\Microsoft Help
[12/12/2007|20:44] C:\ProgramData\ModŠles
[02/11/2009|14:03] C:\ProgramData\mp3 free delete.iogmyet
[02/11/2009|09:29] C:\ProgramData\Norton
[10/12/2008|12:40] C:\ProgramData\NortonInstaller
[03/11/2009|21:43] C:\ProgramData\NVIDIA
[07/11/2009|18:49] C:\ProgramData\nvModes.001
[07/11/2009|18:49] C:\ProgramData\nvModes.dat
[10/12/2008|12:40] C:\ProgramData\PCSettings
[05/11/2009|11:15] C:\ProgramData\Peak Upload Second
[25/06/2007|21:35] C:\ProgramData\Roxio
[12/05/2008|08:17] C:\ProgramData\Skype
[19/02/2008|15:53] C:\ProgramData\Sonic
[26/02/2009|15:01] C:\ProgramData\SPL182C.tmp
[03/11/2008|09:59] C:\ProgramData\SPL1A05.tmp
[28/03/2008|19:38] C:\ProgramData\SPL1C9.tmp
[28/01/2009|08:34] C:\ProgramData\SPL1D04.tmp
[14/09/2008|16:09] C:\ProgramData\SPL1E85.tmp
[27/09/2008|14:30] C:\ProgramData\SPL2010.tmp
[28/09/2008|16:01] C:\ProgramData\SPL2590.tmp
[18/04/2008|21:12] C:\ProgramData\SPL283A.tmp
[25/11/2008|21:16] C:\ProgramData\SPL28D2.tmp
[04/11/2008|19:06] C:\ProgramData\SPL2B31.tmp
[27/12/2007|17:04] C:\ProgramData\SPL2DAA.tmp
[04/11/2008|19:11] C:\ProgramData\SPL37E0.tmp
[11/09/2008|18:49] C:\ProgramData\SPL4374.tmp
[03/02/2009|11:28] C:\ProgramData\SPL456E.tmp
[02/05/2008|13:06] C:\ProgramData\SPL4FF8.tmp
[11/04/2008|13:21] C:\ProgramData\SPL5205.tmp
[03/03/2009|19:45] C:\ProgramData\SPL5407.tmp
[24/11/2008|20:58] C:\ProgramData\SPL5427.tmp
[15/10/2008|13:11] C:\ProgramData\SPL574D.tmp
[22/01/2009|13:49] C:\ProgramData\SPL5C17.tmp
[24/11/2008|09:25] C:\ProgramData\SPL5F0C.tmp
[27/04/2008|19:08] C:\ProgramData\SPL5F2F.tmp
[22/01/2009|12:45] C:\ProgramData\SPL649B.tmp
[11/04/2008|13:07] C:\ProgramData\SPL67CA.tmp
[27/12/2007|17:11] C:\ProgramData\SPL67DE.tmp
[30/04/2008|13:49] C:\ProgramData\SPL707F.tmp
[26/11/2008|14:34] C:\ProgramData\SPL74CD.tmp
[19/11/2008|06:19] C:\ProgramData\SPL74E0.tmp
[30/04/2008|13:54] C:\ProgramData\SPL781F.tmp
[22/01/2009|12:37] C:\ProgramData\SPL79C3.tmp
[28/01/2009|08:31] C:\ProgramData\SPL7D3C.tmp
[28/03/2008|19:30] C:\ProgramData\SPL7FEC.tmp
[23/10/2008|14:08] C:\ProgramData\SPL8E4B.tmp
[27/09/2008|14:51] C:\ProgramData\SPL954C.tmp
[03/11/2008|09:57] C:\ProgramData\SPL9A0B.tmp
[31/01/2009|18:54] C:\ProgramData\SPL9AC4.tmp
[22/01/2009|12:30] C:\ProgramData\SPLADAE.tmp
[11/04/2008|13:19] C:\ProgramData\SPLAE09.tmp
[02/05/2008|12:17] C:\ProgramData\SPLB705.tmp
[27/04/2008|19:00] C:\ProgramData\SPLB76A.tmp
[18/04/2008|21:08] C:\ProgramData\SPLB846.tmp
[26/02/2009|22:20] C:\ProgramData\SPLB940.tmp
[04/03/2009|12:09] C:\ProgramData\SPLBBEA.tmp
[08/06/2008|12:26] C:\ProgramData\SPLBF01.tmp
[11/06/2008|20:12] C:\ProgramData\SPLC4BB.tmp
[28/04/2008|16:58] C:\ProgramData\SPLC7BC.tmp
[03/03/2009|19:54] C:\ProgramData\SPLC9B5.tmp
[28/09/2008|16:00] C:\ProgramData\SPLD1B6.tmp
[13/09/2008|16:26] C:\ProgramData\SPLD767.tmp
[05/11/2008|20:22] C:\ProgramData\SPLD987.tmp
[27/09/2008|14:28] C:\ProgramData\SPLD99E.tmp
[18/11/2008|19:01] C:\ProgramData\SPLDA3A.tmp
[27/09/2008|14:53] C:\ProgramData\SPLE7BF.tmp
[18/11/2008|18:58] C:\ProgramData\SPLED3B.tmp
[31/01/2009|18:51] C:\ProgramData\SPLF014.tmp
[15/10/2008|13:08] C:\ProgramData\SPLFDD6.tmp
[10/12/2008|12:49] C:\ProgramData\Symantec
[10/12/2008|12:31] C:\ProgramData\Symantec Temporary Files
[02/11/2009|09:42] C:\ProgramData\TEMP
[02/11/2009|14:03] C:\ProgramData\Time Dead Warn Default
[09/07/2009|22:06] C:\ProgramData\Type Hole Hole.5yued
[02/11/2009|14:02] C:\ProgramData\Type Hole Hole.64ms1x
[02/11/2009|14:02] C:\ProgramData\Type Hole Hole.kz11b6
[14/03/2009|19:02] C:\ProgramData\UDL
[12/08/2008|09:31] C:\ProgramData\WLInstaller
--------------------\\ Listing des dossiers dans C:\Program Files
[25/06/2007|21:53] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
[03/06/2009|18:02] C:\Program Files\Adobe
[22/01/2008|15:47] C:\Program Files\AOL Pictures
[17/08/2008|09:52] C:\Program Files\Apple Software Update
[02/11/2009|10:02] C:\Program Files\Avira
[14/01/2009|21:59] C:\Program Files\Bonjour
[15/12/2007|17:11] C:\Program Files\BoontyGames
[02/11/2009|14:00] C:\Program Files\CCleaner
[02/11/2009|09:44] C:\Program Files\Common Files
[25/06/2007|22:05] C:\Program Files\EasyBits
[17/06/2009|23:12] C:\Program Files\Electronic Arts
[14/03/2009|19:00] C:\Program Files\epson
[12/12/2007|20:44] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[06/11/2009|14:30] C:\Program Files\Google
[09/10/2008|20:37] C:\Program Files\Hewlett-Packard
[27/08/2008|16:18] C:\Program Files\HP
[25/06/2007|22:11] C:\Program Files\HPQ
[17/06/2009|23:12] C:\Program Files\InstallShield Installation Information
[25/06/2007|21:16] C:\Program Files\Intel
[03/11/2009|21:00] C:\Program Files\Internet Explorer
[26/11/2008|22:24] C:\Program Files\iPod
[26/11/2008|22:24] C:\Program Files\iTunes
[26/03/2009|13:36] C:\Program Files\Java
[13/02/2009|16:13] C:\Program Files\JRE
[18/03/2008|15:39] C:\Program Files\Logitech
[10/03/2009|17:04] C:\Program Files\Lx_cats
[02/11/2009|11:06] C:\Program Files\Malwarebytes' Anti-Malware
[14/03/2009|18:11] C:\Program Files\MFP Server
[11/04/2009|16:31] C:\Program Files\Microsoft
[15/12/2007|09:08] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[20/12/2007|23:23] C:\Program Files\Microsoft FrontPage
[02/11/2006|13:37] C:\Program Files\Microsoft Games
[28/12/2007|16:54] C:\Program Files\Microsoft Hardware
[11/09/2009|12:45] C:\Program Files\Microsoft Silverlight
[14/12/2007|16:52] C:\Program Files\Microsoft SQL Server Compact Edition
[11/04/2009|16:36] C:\Program Files\Microsoft Sync Framework
[06/12/2008|19:39] C:\Program Files\Microsoft Works
[25/06/2007|20:55] C:\Program Files\Motorola
[03/11/2009|21:00] C:\Program Files\Movie Maker
[04/11/2009|15:14] C:\Program Files\Mozilla Firefox
[02/11/2006|13:37] C:\Program Files\MSBuild
[12/12/2007|21:33] C:\Program Files\MSXML 4.0
[16/07/2008|13:24] C:\Program Files\Neuf
[02/11/2009|09:34] C:\Program Files\Norton Internet Security
[13/02/2009|16:13] C:\Program Files\OpenOffice.org 3
[22/04/2009|23:02] C:\Program Files\Procaster
[26/11/2008|22:22] C:\Program Files\QuickTime
[25/06/2007|22:09] C:\Program Files\Realtek
[02/11/2006|13:37] C:\Program Files\Reference Assemblies
[25/06/2007|21:36] C:\Program Files\Roxio
[25/06/2007|22:06] C:\Program Files\Services en ligne
[12/05/2008|08:17] C:\Program Files\Skype
[31/12/2007|16:12] C:\Program Files\Sony
[20/12/2007|21:49] C:\Program Files\SP38015
[25/06/2007|21:01] C:\Program Files\Synaptics
[02/11/2006|14:01] C:\Program Files\Uninstall Information
[03/11/2009|21:00] C:\Program Files\Windows Calendar
[03/11/2009|21:00] C:\Program Files\Windows Collaboration
[03/11/2009|21:00] C:\Program Files\Windows Defender
[03/11/2009|21:00] C:\Program Files\Windows Journal
[11/04/2009|16:37] C:\Program Files\Windows Live
[14/12/2007|16:54] C:\Program Files\Windows Live Favorites
[11/04/2009|16:31] C:\Program Files\Windows Live SkyDrive
[11/04/2009|16:37] C:\Program Files\Windows Live Toolbar
[03/11/2009|21:00] C:\Program Files\Windows Mail
[03/11/2009|21:00] C:\Program Files\Windows Media Player
[12/12/2007|20:44] C:\Program Files\Windows NT
[03/11/2009|21:00] C:\Program Files\Windows Photo Gallery
[03/11/2009|21:00] C:\Program Files\Windows Sidebar
[04/01/2008|23:51] C:\Program Files\WMV9_VCM
[07/01/2009|19:29] C:\Program Files\Yahoo!
[10/12/2008|18:45] C:\Program Files\YesMessenger
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[03/06/2009|18:02] C:\Program Files\Common Files\Adobe
[26/11/2008|22:24] C:\Program Files\Common Files\Apple
[25/06/2007|22:03] C:\Program Files\Common Files\HP
[14/03/2009|18:24] C:\Program Files\Common Files\InstallShield
[25/06/2007|22:26] C:\Program Files\Common Files\Java
[25/06/2007|22:11] C:\Program Files\Common Files\LightScribe
[18/03/2008|15:39] C:\Program Files\Common Files\Logishrd
[07/03/2009|14:57] C:\Program Files\Common Files\Logitech
[06/03/2009|10:36] C:\Program Files\Common Files\microsoft shared
[25/06/2007|21:35] C:\Program Files\Common Files\Roxio Shared
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[25/06/2007|21:34] C:\Program Files\Common Files\Sonic Shared
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[13/10/2008|19:02] C:\Program Files\Common Files\Steam
[25/06/2007|21:36] C:\Program Files\Common Files\SureThing Shared
[02/11/2009|09:28] C:\Program Files\Common Files\Symantec Shared
[03/11/2009|21:00] C:\Program Files\Common Files\System
[11/04/2009|16:21] C:\Program Files\Common Files\Windows Live
[14/12/2007|16:49] C:\Program Files\Common Files\WindowsLiveInstaller
--------------------\\ Process
( 107 Processes )
iexplore.exe ~ [PID:2140]
iexplore.exe ~ [PID:2720]
iexplore.exe ~ [PID:5760]
iexplore.exe ~ [PID:6116]
iexplore.exe ~ [PID:4440]
iexplore.exe ~ [PID:5580]
iexplore.exe ~ [PID:4020]
iexplore.exe ~ [PID:4868]
iexplore.exe ~ [PID:5464]
iexplore.exe ~ [PID:5664]
iexplore.exe ~ [PID:6932]
iexplore.exe ~ [PID:7504]
iexplore.exe ~ [PID:8100]
iexplore.exe ~ [PID:6792]
iexplore.exe ~ [PID:7844]
iexplore.exe ~ [PID:7660]
iexplore.exe ~ [PID:7284]
iexplore.exe ~ [PID:5868]
iexplore.exe ~ [PID:7900]
iexplore.exe ~ [PID:3948]
iexplore.exe ~ [PID:8052]
iexplore.exe ~ [PID:8032]
iexplore.exe ~ [PID:7196]
iexplore.exe ~ [PID:8120]
--------------------\\ Recherche avec S_Lop
C:\ProgramData\Type Hole Hole.5yued
C:\ProgramData\Type Hole Hole.64ms1x
C:\ProgramData\Type Hole Hole.kz11b6
C:\ProgramData\mp3 free delete.iogmyet
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\ProgramData\Time Dead Warn Default
C:\ProgramData\Time Dead Warn Default\Bash List.dat
C:\ProgramData\Time Dead Warn Default\Bash List.exe
C:\Users\fuselier\AppData\Roaming\MICROS~1\Windows\Cookies\fuselier@advertising[1].txt
C:\Users\fuselier\AppData\Roaming\MICROS~1\Windows\Cookies\fuselier@advertising[2].txt
C:\Users\fuselier\AppData\Roaming\MICROS~1\Windows\Cookies\fuselier@cotedazurpalace[2].txt
C:\Users\fuselier\AppData\Roaming\MICROS~1\Windows\Cookies\fuselier@serve.cotedazurpalace[1].txt
C:\Users\fuselier\AppData\Roaming\MICROS~1\Windows\Cookies\fuselier@www.cotedazurpalace[2].txt
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Debug Locks"="\"C:\\ProgramData\\Type Hole Hole.kz11b6\""
"warn default inter for"="\"C:\\ProgramData\\mp3 free delete.iogmyet\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-07 19:01:39
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 2
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\fuselier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KLS4D265\mobifun_MBFII_AGR_CrackBonky_728x90_051109[1].gif
[F:93][D:19]-> C:\Users\fuselier\AppData\Local\Temp
[F:155][D:1]-> C:\Users\fuselier\AppData\Roaming\MICROS~1\Windows\Cookies
[F:2866][D:4]-> C:\Users\fuselier\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:40][D:5]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 27/07/2009|15:13 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 05/11/2009|10:14 - Option : [1]
3 - "C:\Lop SD\LopR_3.txt" - 06/11/2009|14:05 - Option : [1]
4 - "C:\Lop SD\LopR_4.txt" - 07/11/2009| 9:43 - Option : [1]
5 - "C:\Lop SD\LopR_5.txt" - 07/11/2009| 9:46 - Option : [1]
6 - "C:\Lop SD\LopR_6.txt" - 07/11/2009|19:03 - Option : [1]