Virtumonde

Fermé
fripouille68 - 27 déc. 2009 à 11:18
 Utilisateur anonyme - 11 janv. 2010 à 20:57
Bonjour,
quand je passe spybot, je vois qu'il lit un assez long moment des lignes intitulées "virtumonde dll". j'ai regardé un peu dans le forum de comment ca marche et j'ai passé HijackThis après l'avoir renommé en CCMexe. Voilà le résultat de scan. Pouvez vous me dire si mon pc est infecté et comment m'en débarrasser. Merci beaucoup d'avance. Je suis sous xp.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:21, on 27/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_service.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\scvhost\svchost.exe
C:\WINDOWS\system32\wuauserv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Vista Drive Icon\DrvIcon.exe
C:\Program Files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\Program Files\X'nBeep 1.1\XnBeep.exe
C:\Program Files\CursorXP.exe
C:\PROGRA~1\Magentic\bin\MgApp.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Calendrier\Cld2000.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hercules\WiFi Station\WifiStation.exe
C:\Program Files\DateInTray\DateInTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_watchop.exe
C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Laurent\Bureau\CCM.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.cherche.us/keyword/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.cherche.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.cherche.us
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system32\scvhost\svchost.exe,wuauserv.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: GamesBarBHO Class - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files\GamesBar\oberontb.dll
O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: SHOUTcast Radio Toolbar - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DrvIcon] C:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [VirusKeeper] C:\Program Files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [X'nBeep] C:\Program Files\X'nBeep 1.1\XnBeep.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Y'z Toolbar.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe (User 'Default user')
O4 - .DEFAULT Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe (User 'Default user')
O4 - .DEFAULT Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe (User 'Default user')
O4 - .DEFAULT Startup: Y'z Toolbar.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe (User 'Default user')
O4 - Startup: DateInTray.lnk = C:\Program Files\DateInTray\DateInTray.exe
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
O4 - Startup: Y'z Toolbar.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: WiFi Station.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Recherche avec cherche.us - C:\Documents and Settings\Laurent\scriptjava.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.chat-land.org
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} - http://m6video.m6.fr/1click/install/files/installer2.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} (TE) - http://www.3dfunchal.com/resources/te/TE.cab
O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,96/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www3.ca.com/securityadvisor/pestscan/pestscan.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://metaboli.clubic.com/components/Metaboli.ocx
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://axis_680446.axiscam.net:9000/activex/AMC.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game08.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} (CamfrogWEB Advanced Unicode Control) - http://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4754/mcfscan.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by109fd.bay109.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Update Service (gupdate1c981f2ac729e12) (gupdate1c981f2ac729e12) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: VirusKeeper antivirus/antispyware (vkservice) - AxBx - C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_service.exe

30 réponses

Utilisateur anonyme
27 déc. 2009 à 11:19
▶ Télécharge Ad-remover ( de C_XX ) sur ton bureau :


▶ Déconnecte toi et ferme toutes applications en cours !

▶ Double clique sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

▶ Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

▶ Au menu principal choisis l'option "L" et tape sur [entrée] .

▶ Laisse travailler l'outil et ne touche à rien ...

▶ Poste le rapport qui apparait à la fin , sur le forum ...

( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

▶ Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
0
flo-91 Messages postés 5646 Date d'inscription mardi 19 mai 2009 Statut Contributeur sécurité Dernière intervention 31 octobre 2019 1 118
27 déc. 2009 à 11:19
Je laisse la main à gen-hackman :)


Bonne continuation.


0
fripouille68
27 déc. 2009 à 13:26
re bonjour, merci beaucoup pour vos réponses très rapides. c'est sympa. Flo 91 m'a demandé de télécharger COMBOFIX et de mettre le rapport. Le voici ;
ComboFix 09-12-26.04 - Laurent 27/12/2009 12:15:39.1.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1022.367 [GMT 1:00]
Lancé depuis: c:\documents and settings\Laurent\Bureau\ComboFix.exe
AV: VirusKeeper 2009 Pro antivirus *On-access scanning disabled* (Updated) {165EE528-D666-4745-B14E-AA998BBEC191}
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\David\eula.txt
c:\documents and settings\David\Local Settings\Application Data\ygcgcuy.dat
c:\documents and settings\David\Local Settings\Application Data\ygcgcuy_nav.dat
c:\documents and settings\David\Local Settings\Application Data\ygcgcuy_navps.dat
c:\documents and settings\David\Local Settings\Application Data\ygqcygq.dat
c:\documents and settings\David\Local Settings\Application Data\ygqcygq_nav.dat
c:\documents and settings\David\Local Settings\Temporary Internet Files\TR010127481036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TR010178471036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TR011218611036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TR060894321036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TR061893791036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010127481036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010127991036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010128051036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010178471036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010219531036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010808371036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT011218001036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT011218611036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT011433111036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT060894321036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT061061871036.gif
c:\documents and settings\David\Local Settings\Temporary Internet Files\TT061893791036.gif
c:\documents and settings\Laurent\Local Settings\Application Data\sgaflity.dat
c:\documents and settings\Laurent\Local Settings\Application Data\sgaflity_nav.dat
c:\documents and settings\Laurent\Local Settings\Application Data\sgaflity_navps.dat
c:\documents and settings\Laurent\winternet.exe
C:\LOG.TXT
c:\program files\GamesBar\obERontb.dll
c:\program files\INSTALL.LOG
c:\program files\webmediaplayer
c:\program files\webmediaplayer\resources\languages.xml
c:\program files\webmediaplayer\resources\webmedias
c:\program files\webmediaplayer\skins\classic.skn
c:\program files\webmediaplayer\sqlite3.dll
c:\program files\webmediaplayer\WebMediaPlayer.url
c:\recycler\S-1-5-21-2328322012-3734155301-851506153-1006(2)
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Downloaded Program Files\Quarantine
c:\windows\pack.epk
c:\windows\patch.exe
c:\windows\system32\kmfejasuhs.dat
c:\windows\system32\kmfejasuhs_nav.dat
c:\windows\system32\kmfejasuhs_navps.dat
c:\windows\system32\reboot.txt
c:\windows\system32\scvhost
c:\windows\system32\scvhost\svchost.exe
c:\windows\system32\usb2.exe
c:\windows\unins000.dat
c:\windows\unins000.exe

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games


((((((((((((((((((((((((((((( Fichiers créés du 2009-11-27 au 2009-12-27 ))))))))))))))))))))))))))))))))))))
.

2009-12-26 13:57 . 2009-12-26 13:57 -------- d-----w- c:\documents and settings\Laurent\Application Data\Malwarebytes
2009-12-26 13:57 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-26 13:57 . 2009-12-26 13:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-26 13:57 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-26 13:57 . 2009-12-26 13:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-26 12:52 . 2009-12-26 12:54 -------- d-----w- c:\program files\BHODemon 2
2009-12-26 10:10 . 2009-12-26 11:31 -------- d-----w- C:\VundoFix Backups
2009-12-25 19:17 . 2009-12-25 19:17 -------- d-----w- c:\documents and settings\David\Application Data\MyPhoneExplorer
2009-12-25 19:17 . 2009-12-25 19:17 -------- d-----w- c:\program files\MyPhoneExplorer
2009-12-25 10:33 . 2008-03-21 12:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-12-23 08:43 . 2002-07-17 08:05 16512 ----a-w- c:\windows\system32\drivers\ASPI32.SYS
2009-12-23 08:43 . 2001-03-17 21:34 22528 ----a-w- c:\windows\system32\WNASPI32.DLL
2009-12-23 08:43 . 2009-12-23 08:44 -------- d-----w- c:\program files\4Musics MP3 Bitrate Changer
2009-12-23 08:37 . 2009-02-03 17:01 364544 ----a-w- c:\windows\system32\MACDll.dll
2009-12-23 08:37 . 2009-01-19 17:39 246424 ----a-w- c:\windows\system32\unicows.dll
2009-12-23 08:37 . 2009-12-23 08:38 -------- d-----w- c:\program files\Monkey's Audio
2009-12-17 15:35 . 2009-12-17 15:35 -------- d-s---w- c:\documents and settings\NetworkService\Favoris
2009-12-16 16:34 . 2009-12-27 10:44 172 --sh--w- c:\windows\system32\bootrun.reg
2009-12-16 16:34 . 2009-12-27 09:47 457 --sh--w- c:\windows\system32\boothide.reg
2009-12-16 11:17 . 2009-12-25 20:16 -------- d-----w- c:\documents and settings\David\Application Data\vlc
2009-12-09 10:56 . 2009-12-09 10:56 -------- d-----w- c:\documents and settings\All Users\Application Data\3DVIA
2009-12-09 10:56 . 2009-12-09 10:56 -------- d-----w- c:\documents and settings\David\Local Settings\Application Data\3DVIA
2009-12-09 10:53 . 2007-07-19 17:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2009-12-09 10:53 . 2006-09-28 15:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2009-12-09 10:53 . 2009-12-09 10:53 -------- d-----w- c:\windows\Logs
2009-12-09 10:53 . 2009-12-09 10:53 -------- d-----w- c:\program files\Virtools
2009-12-05 12:14 . 2009-12-05 12:14 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2009-12-05 12:14 . 2009-12-05 12:14 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2009-12-05 12:14 . 2009-12-05 12:14 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2009-12-02 19:36 . 2009-12-25 12:36 -------- d-----w- c:\documents and settings\Laurent\Application Data\vlc
2009-12-02 10:30 . 2009-12-02 10:30 -------- d-----w- c:\documents and settings\David\Application Data\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
2009-12-02 10:30 . 2009-12-02 10:30 -------- d-----w- c:\documents and settings\David\Application Data\app
2009-12-02 10:29 . 2009-12-02 10:47 -------- d-----w- c:\documents and settings\David\Application Data\Dofus 2
2009-12-02 10:29 . 2009-12-02 10:29 -------- d-----w- c:\documents and settings\David\Application Data\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
2009-12-02 09:48 . 2009-12-02 09:48 -------- d-----w- c:\program files\Dofus 2
2009-12-02 09:36 . 2009-12-02 09:36 -------- d-----w- c:\program files\Fichiers communs\MAGIX Shared
2009-12-02 09:36 . 2009-12-02 09:36 -------- d-----w- c:\program files\MAGIX
2009-12-02 09:36 . 2007-04-27 09:43 120200 ----a-w- c:\windows\system32\DLLDEV32i.dll
2009-12-02 09:35 . 2009-12-02 09:36 -------- d-----w- c:\windows\system32\MAGIX
2009-12-02 09:35 . 2007-06-19 15:26 667648 ----a-w- c:\windows\system32\mgxoschk.dll
2009-12-02 09:27 . 2009-12-02 09:27 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-12-02 09:26 . 2009-12-02 09:31 -------- d-----w- c:\documents and settings\David\Application Data\AVS4YOU
2009-12-02 09:26 . 2009-12-02 09:26 -------- d-----w- c:\program files\AVS4YOU
2009-12-02 09:12 . 2009-12-05 12:13 -------- d-----w- c:\program files\Sony Ericsson

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-27 11:34 . 2009-06-04 18:02 -------- d-----w- c:\program files\GamesBar
2009-12-26 09:26 . 2009-11-12 16:05 -------- d-----w- c:\program files\Mozilla Firefox 3.6 Beta 2
2009-12-26 09:26 . 2009-11-02 11:02 -------- d-----w- c:\program files\Mozilla Firefox 3.6 Beta 1
2009-12-25 19:19 . 2006-12-12 15:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-25 10:34 . 2009-12-25 10:34 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2009-12-25 10:33 . 2009-12-25 10:33 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-23 08:42 . 2008-03-12 14:58 -------- d-----w- c:\documents and settings\David\Application Data\foobar2000
2009-12-23 08:39 . 2008-03-12 14:58 -------- d-----w- c:\program files\foobar2000
2009-12-22 21:16 . 2006-02-04 10:51 -------- d-----w- c:\documents and settings\David\Application Data\Apple Computer
2009-12-21 10:11 . 2009-06-29 14:19 -------- d-----w- c:\documents and settings\David\Application Data\dvdcss
2009-12-16 16:41 . 2008-01-06 16:58 -------- d-----w- c:\program files\DivX
2009-12-16 16:40 . 2009-10-17 16:11 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-12-16 07:07 . 2005-12-11 09:12 530984 ----a-w- c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-16 07:05 . 2009-04-10 16:43 8224 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-12-14 19:16 . 2005-11-09 19:02 530984 ----a-w- c:\documents and settings\Laurent\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-11 17:11 . 2004-08-20 10:24 592376 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-11 17:11 . 2004-08-20 10:24 118714 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-06 11:10 . 2008-12-07 19:38 -------- d-----w- c:\documents and settings\Laurent\Application Data\dvdcss
2009-12-02 10:51 . 2008-03-29 10:27 308628 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-02 09:26 . 2007-07-08 09:38 -------- d-----w- c:\program files\Fichiers communs\AVSMedia
2009-11-28 16:18 . 2009-05-13 18:25 1118 ----a-w- c:\documents and settings\Laurent\errorlog.tmp
2009-11-28 13:15 . 2009-06-24 17:08 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-28 12:12 . 2005-11-05 17:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-27 17:45 . 2005-11-05 17:31 -------- d-----w- c:\program files\Java
2009-11-25 16:48 . 2007-05-29 18:04 -------- d-----w- c:\program files\Opera
2009-11-16 14:37 . 2009-01-24 14:00 -------- d-----w- c:\program files\Safari
2009-11-16 14:31 . 2009-11-16 14:30 -------- d-----w- c:\program files\iTunes
2009-11-16 14:31 . 2009-11-16 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-16 14:30 . 2009-11-16 14:30 -------- d-----w- c:\program files\iPod
2009-11-16 14:30 . 2007-08-12 16:05 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-11-16 14:26 . 2009-11-16 14:25 -------- d-----w- c:\program files\QuickTime
2009-11-14 00:47 . 2009-11-14 00:47 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
2009-11-13 19:41 . 2009-11-11 14:05 -------- d-----w- c:\program files\Zylom Games
2009-11-13 19:39 . 2009-11-13 19:36 -------- d-----w- c:\program files\Zumas Revenge! - Adventure
2009-11-13 19:31 . 2007-03-28 14:27 -------- d-----w- c:\program files\RealArcade
2009-11-11 14:05 . 2009-11-11 14:05 -------- d-----w- c:\documents and settings\Laurent\Application Data\Zylom
2009-11-10 15:58 . 2009-11-10 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\PhotoMail
2009-11-10 15:58 . 2009-11-10 15:58 -------- d-----w- c:\program files\PhotoMail Maker
2009-11-10 15:56 . 2005-11-09 19:44 -------- d-----w- c:\program files\IncrediMail
2009-11-09 16:07 . 2009-11-09 16:07 -------- d-----w- c:\program files\CFWebAdvancedU
2009-11-09 15:59 . 2009-03-27 10:33 -------- d-----w- c:\program files\Messenger Plus! Live
2009-11-04 08:20 . 2005-11-09 19:29 -------- d-----w- c:\program files\Google
2009-11-01 20:19 . 2008-11-10 19:09 -------- d-----w- c:\program files\Radio Fr Solo
2009-10-31 14:27 . 2005-11-15 17:11 -------- d-----w- c:\program files\Microsoft Games
2009-10-31 14:26 . 2007-12-10 13:00 -------- d-----w- c:\program files\Dofus
2009-10-31 14:24 . 2009-02-14 07:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Skyline
2009-10-31 14:21 . 2009-10-26 16:44 -------- d-----w- c:\documents and settings\Laurent\Application Data\MagicBall4
2009-10-31 14:17 . 2006-08-14 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-10-31 14:11 . 2005-11-30 18:19 -------- d-----w- c:\program files\BoontyGames
2009-10-29 07:42 . 2004-08-20 10:24 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:39 . 2004-08-20 10:24 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:39 . 2004-08-20 10:23 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-03 23:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-17 08:42 . 2009-10-17 08:42 1607184 ----a-w- c:\windows\system32\Aquarium Exotique.scr
2009-10-13 10:33 . 2004-08-20 10:23 271360 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:39 . 2004-08-20 10:24 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:39 . 2004-08-20 10:24 150528 ----a-w- c:\windows\system32\rastls.dll
2009-10-11 03:17 . 2008-11-28 09:21 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-11 05:50 . 2009-08-11 05:50 15098 ----a-w- c:\program files\license.rtf
2009-08-11 05:30 . 2009-08-11 05:30 4012328 ----a-w- c:\program files\opera.dll
2009-08-11 05:30 . 2009-08-11 05:30 121128 ----a-w- c:\program files\opera.exe
2009-08-11 05:26 . 2009-08-11 05:26 20480 ----a-w- c:\program files\OUniAnsi.dll
2009-08-11 05:26 . 2009-08-11 05:26 653419 ----a-w- c:\program files\encoding.bin
2009-07-16 13:13 . 2009-06-18 17:15 168 ----a-w- c:\program files\operaprefs_default.ini
2009-06-17 13:41 . 2009-06-17 13:41 3870 ----a-w- c:\program files\lngcode.txt
2008-06-09 09:17 . 2008-06-09 09:17 301 ----a-w- c:\program files\c3nform.vxml
2006-03-29 10:14 . 2002-12-08 18:04 108 ----a-w- c:\program files\Mess with MSN Messenger skins, nicknames, add-ons, bots and secrets.url
2006-03-29 10:14 . 2001-10-03 20:22 161 ----a-w- c:\program files\read1st.txt
2004-02-26 12:35 . 2004-02-26 12:35 7904 ----a-w- c:\program files\html40_entities.dtd
1999-12-09 09:19 . 2006-01-02 15:34 147456 ----a-w- c:\program files\Zip32.dll
2006-09-01 10:54 . 2006-09-02 12:44 7168 --sh--w- c:\windows\system32\wuauserv.exe
.

------- Sigcheck -------

[-] 2008-04-14 . 5158A1C542A355B3A67E59538BBD894D . 3200000 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . 5158A1C542A355B3A67E59538BBD894D . 3200000 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . D0288319660EDCFED07C7E74C4EA38A5 . 1037312 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2007-06-13 . B795475444D6D57A572C14B9E1A29839 . 1037312 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[7] 2004-08-05 . 4C33E5B9A6197B6ED215F6CFBA0A2DAA . 1036288 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 16:20 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-20 67128]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"Magentic"="c:\progra~1\Magentic\bin\Magentic.exe" [2006-11-19 319532]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-28 68856]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2009-11-10 280008]
"X'nBeep"="c:\program files\X'nBeep 1.1\XnBeep.exe" [2007-01-06 1067520]
"CursorXP"="c:\program files\CursorXP.exe" [2005-01-19 128000]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-03-18 630784]
"Google Update"="c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-27 133104]
"Cld2000.exe"="c:\program files\Calendrier\Cld2000.exe" [2009-04-16 2993664]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-09 344064]
"DrvIcon"="c:\program files\Vista Drive Icon\DrvIcon.exe" [2007-07-04 45056]
"VirusKeeper"="c:\program files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe" [2009-09-22 3768688]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-28 141600]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

c:\documents and settings\Laurent\Menu D‚marrer\Programmes\D‚marrage\
DateInTray.lnk - c:\program files\DateInTray\DateInTray.exe [2005-12-12 78848]
RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
WiFi Station.lnk - c:\program files\Hercules\WiFi Station\WifiStation.exe [2009-10-8 654336]

c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-28 19:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magentic]
2006-11-19 12:23 319532 ----a-w- c:\progra~1\Magentic\bin\Magentic.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
2007-09-06 12:53 169264 ----a-w- c:\program files\Maxtor\OneTouch Status\MaxMenuMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"LogitechVideoTray"=c:\program files\Logitech\Video\LogiTray.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImLc.exe"=
"c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImPackr.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Codemasters\\Worms 4 Mayhem Demo\\Worms 4 Mayhem Demo.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Commandos II\\comm2.exe"=
"c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Documents and Settings\\David\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\umi.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\VideoSpin.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Mindscape\\Mission Président - Geo-Political Simulator\\MISSION.EXE"=
"c:\\Program Files\\Ivicam\\backsurvey.exe"=
"c:\\Program Files\\Icecast2 Win32\\Icecast2win.exe"=
"c:\\Program Files\\SHOUTcast\\sc_serv.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\WINDOWS\\system32\\wuauserv.exe"=
"c:\\WINDOWS\\system32\\tftp.exe"=

R2 MSSQL$RADIONOMY536765;SQL Server (RADIONOMY536765);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [27/05/2009 02:27 29262680]
R2 vkservice;VirusKeeper antivirus/antispyware;c:\program files\AxBx\VirusKeeper 2009 Pro\vk_service.exe [22/05/2008 14:27 1119576]
S2 gupdate1c981f2ac729e12;Google Update Service (gupdate1c981f2ac729e12);c:\program files\Google\Update\GoogleUpdate.exe [29/01/2009 10:19 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [23/12/2009 09:43 16512]
S3 DCamUSBUVT;ICM532A;c:\windows\system32\drivers\usbuvt.sys [11/11/2005 10:13 95232]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [05/12/2009 13:14 13224]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [23/09/2009 13:50 238960]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [06/11/2007 21:22 34064]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E4066320-E4AE-11CF-B1B0-00AA00BBAD66}]
2009-03-08 02:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://mystart.incredimail.com/
uSearchMigratedDefaultURL = hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.cherche.us/keyword/
uInternet Connection Wizard,ShellNext = hxxp://www.dell.fr/myway
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://www.cherche.us/keyword/%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Recherche avec cherche.us - c:\documents and settings\Laurent\scriptjava.html
Trusted Zone: chat-land.org
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} - hxxp://m6video.m6.fr/1click/install/files/installer2.cab
DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} - hxxp://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} - hxxp://www.3dfunchal.com/resources/te/TE.cab
DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} - hxxp://www.powerchallenge.com/applet/PowerLoader.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game08.zylom.com/activex/zylomgamesplayer.cab
DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - hxxp://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\documents and settings\Laurent\Application Data\Mozilla\Firefox\Profiles\nhizwkb4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://mystart.incredimail.com/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=PMXMAS09FFAB&search=
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\np32dsw.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\NPOFFICE.DLL
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nppdf32.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nppl3260.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nprjplug.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicdclient.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npredoute.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Opera\program\plugins\npgcplug.dll
FF - plugin: c:\program files\Opera\program\plugins\npmio.dll
FF - plugin: c:\program files\Opera\program\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\Rawflow\npicdclient.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCE08D86A-A41A-410A-943C-13BABB7DC474", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA9EDC9ED-603A-4F3F-BBEA-59C8853A3236", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID90D10942-D952-4863-9DD6-A2BDBBAD456E", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0ECEE744-7B69-4912-AB91-AE76D61ECB04", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF25635B2-1AB9-47B5-88D1-8877B22C86DE", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID27B7F812-4159-45B9-A389-B7A118A58DE4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF849DF29-393B-4F8B-99D1-117A70D66FC7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBF1E9C3D-637C-4171-BD12-28A7360B879A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDDE1C0601-7947-4D7F-A6E5-E68BF6BA1E37", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EA0DCCE-4D98-4876-9C6A-E5C563D0820A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID446462BA-2AAD-4C88-BC63-5210E2F31465", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0862E368-A40E-4E55-83EB-FBC5571BABA4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDD2A96E3C-FFB3-4D38-9AC3-B127527BEA35", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4B05B39A-9DDC-4650-A7F8-D5B134E5FFE5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC8E2574A-7BCE-4B93-A22E-61831DFD6DB8", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID659796C0-8B5D-48D7-A4EB-7E6874E26274", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID78071AB5-E729-414E-8D02-9C1D034F82E7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCC3F71E1-17F3-4C5B-997D-44CA56943197", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE67D5C78-B2D4-4BA0-8D69-1C7AF4BB08B5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFC5F3D7A-D321-412C-8A5D-9AD0C8041941", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6EC5CD16-81BC-4515-9EDD-9265C906F56E", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID67CFB2C5-E491-4395-977B-CD45E4124655", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID73600569-52E6-4760-8BAB-B68202937D98", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB02EBD42-6885-401A-9389-E089F7DDC872", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBAE5CB8C-4075-4743-B2E4-78DA8D8CDC64", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID28B07B04-DA99-4FD3-BF27-4972F2B8142B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D53448F-D12B-4102-8CE2-697DAE8D6643", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE3266A47-A141-47B8-AAA8-5F16FB4F8CCD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB33AB7AF-76D7-4B1C-B709-5D6BF9E7B1C7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID153B7451-0BB5-4B37-95C0-44D89E2F1F2B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID3BBE8E21-0D3D-4BAA-AC6F-C7BCEF750849", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9B5B4F2D-A7D9-4329-B0FE-92B301A8CAAD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA5C42921-8CD0-4924-97C3-01B5B0610BC6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID06969252-F90F-4CF2-9074-33772EB64859", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFBF37655-1236-4C0D-96C5-F94E1724841B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC1A3F035-B68F-4B2B-9FD5-E36DAAAF26DD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID368F3685-543E-4812-9FDE-96E097E453FC", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID43969873-56AA-4113-84CB-4AB2AEB9AA31", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA205DD80-63D4-4E41-B785-26EC3D90B97B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID068D43E7-7551-4A2F-AE96-4A38A9AD1953", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF443E9CB-9EEC-456E-8AE7-F3102D5CD47D", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE36A7B16-645D-4261-BFF8-3A7E69C5F7A5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID379805E3-E0E2-40DC-B51B-6DC1AE5802AA", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF6240D69-A06D-44A1-8003-8496CCEF2C53", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID26C3113D-5A71-4F1B-A2CB-BE59E1279DDA", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID92B97F2B-7565-4CE9-9AC7-0598DFD731F8", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID2AA5E7CF-9696-42F0-B76A-8655296EADF2", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0AAACE0B-ACEF-4781-83F4-BFB52EEC995A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D56FF58-A39D-4E8C-A40B-2E3711251772", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID946121C2-11F1-49DD-A7E3-CF793DE827A4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB853303D-1BAB-43F3-9D7D-101D0DA8E7A5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9E578247-FE29-4F8C-8202-A24A5688CF2A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6D065A8F-FFC0-4A0F-B863-1D724B8C786B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4451D291-6940-42CE-9D3C-CA1D4C96549C", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID064B722D-079D-4EBB-B3CF-9FCBF64FFF5D", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID38F8AB0F-5DFB-43D9-889E-8717CC4AB59B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EC68CD1-0EF1-4CB9-9EF1-3D64AB266149", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID44F96B27-CFAD-41E1-83A1-6B28040C3BDE", "AllAccess");
.
- - - - ORPHELINS SUPPRIMES - - - -

MSConfigStartUp-TomTomHOME - c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
AddRemove-HijackThis - c:\documents and settings\Laurent\Bureau\HijackThis.exe
AddRemove-Spybot - Search & Destroy_is1 - c:\windows\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-27 12:55
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(944)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2732)
c:\program files\RocketDock\RocketDock.dll
c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\eappprxy.dll
c:\program files\IncrediMail\bin\B4ImApp.dll
c:\program files\CurXP0.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\stobject.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\program files\Maxtor\Sync\SyncServices.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\progra~1\Magentic\bin\MgApp.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\IncrediMail\bin\IMApp.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
.
**************************************************************************
.
Heure de fin: 2009-12-27 13:11:06 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-12-27 12:11

Avant-CF: 74 687 811 584 octets libres
Après-CF: 80 209 203 200 octets libres

WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn /bootlogo

- - End Of File - - A99F3C0A9462297A2572057C292B05BA
0
fripouille68
27 déc. 2009 à 14:01
Voila maintenant le rapport après le scan de ad-remover, merci d'avance pour vos réponses.
.
======= RAPPORT D'AD-REMOVER 1.1.4.6_F | UNIQUEMENT XP/VISTA/7 =======
.
Mit à jour par C_XX le 26.12.2009 à 20:47
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 13:32:04, 27/12/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-Remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: FAMILLE | Utilisateur actuel: Laurent

Bonnes fêtes de fin d'année à vous tous :)
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.

C:\DOCUME~1\Laurent\APPLIC~1\Mozilla\FireFox\Profiles\nhizwkb4.default\searchplugins\ask.xml
C:\Program Files\Mozilla FireFox\Components\AskSearch.js
C:\Program Files\AskBarDis
C:\Program Files\eoRezo
C:\Program Files\GamesBar
C:\Program Files\Trymedia
C:\Program Files\Viewpoint
C:\DOCUME~1\Laurent\APPLIC~1\EoRezo
C:\DOCUME~1\Laurent\APPLIC~1\Viewpoint
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
C:\Documents and Settings\David\Application Data\EoRezo
C:\Documents and Settings\David\Local Settings\Application Data\SHOUTcast Radio Toolbar\ieToolbar
C:\Documents and Settings\David\Menu D‚marrer\Programmes\WebMediaPlayer

(!) -- Fichiers temporaires supprimés.

.
HKCU\software\appdatalow\AskBarDis
HKCU\software\EoRezo
HKCU\software\GamesBar
HKCU\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\software\AskBarDis
HKLM\software\classes\AxMetaStream.MetaStreamCtl
HKLM\software\classes\AxMetaStream.MetaStreamCtl.1
HKLM\software\classes\AxMetaStream.MetaStreamCtlSecondary
HKLM\software\classes\AxMetaStream.MetaStreamCtlSecondary.1
HKLM\Software\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
HKLM\Software\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
HKLM\Software\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}
HKLM\Software\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
HKLM\Software\Classes\CLSID\{4260e0cc-0f75-462e-88a3-1e05c248bf4c}
HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
HKLM\software\EoRezo
HKLM\software\GamesBar
HKLM\software\GamesBarSetup
HKLM\software\MetaStream
HKLM\Software\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
HKLM\Software\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
HKLM\Software\Microsoft\Code Store Database\Distribution Units\CabBuilder
HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}
HKLM\software\Trymedia Systems
HKLM\software\Viewpoint
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 3.5.6 [fr] *
.
Nom du profil: nhizwkb4.default (Laurent)
.
(Laurent, prefs.js) Browser.download.lastDir, C:\Documents and Settings\Laurent\Bureau
(Laurent, prefs.js) Browser.search.defaultenginename, MyStart Rechercher
(Laurent, prefs.js) Browser.search.defaulturl, hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
(Laurent, prefs.js) Browser.search.selectedEngine, Google
(Laurent, prefs.js) Browser.startup.homepage, hxxp://mystart.incredimail.com/
(Laurent, prefs.js) Extensions.enabledItems, fsonlinescanner@f-secure.com:1.01,splash@aldreneo.com:2.0.2,{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01,{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6
(Laurent, prefs.js) Keyword.URL, hxxp://mystart.incredimail.com/?loc=PMXMAS09FFAB&search=
(Laurent, prefs.js) Privacy.popups.showBrowserMessage, false
.
(Laurent, prefs.js) EFFACE - Extensions.snipit.chromeURL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q={searchTerms}&crm=1
.
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Do404Search: 01000000
Local Page: C:\WINDOWS\system32\blank.htm
Show_ToolBar: yes
Start Page: hxxp://mystart.incredimail.com/
Use Search Asst: no
Enable Browser Extensions: yes
Start Page Redirect Cache: hxxp://fr.msn.com/?ocid=iehp
Start Page Redirect Cache_TIMESTAMP: e6d4383bb91eca01
Start Page Redirect Cache AcceptLangs: fr
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Delete_Temp_Files_On_Exit: yes
Local Page: %SystemRoot%\system32\blank.htm
Start Page: hxxp://fr.msn.com/
Search bar: hxxp://search.msn.com/spbasic.htm
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\Start Page
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
============== Suspect (Cracks, Serials, ...) ==============
.
C:\Documents and Settings\Laurent\Local Settings\Application Data\Opera\Opera\profile\cache4\temporary_download\flock_patch_v1_03.zip
C:\Documents and Settings\Laurent\Mes documents\Mises … jour de programme t‚l‚charg‚es\Dell Paint Shop Photo Album 5\MyPublisher Update for Paint Shop Photo Album 5\PSPA_MyPublisherPatch_French.exe
.
===================================
.
6261 Octet(s) - C:\Ad-Report-CLEAN[1].log
.
0 Fichier(s) - C:\DOCUME~1\Laurent\LOCALS~1\Temp
2 Fichier(s) - C:\WINDOWS\Temp
0 Fichier(s) - C:\WINDOWS\Prefetch
.
19 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
224 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
Fin à: 13:57:35 | 27/12/2009 - CLEAN[1]
.
============== E.O.F ==============
.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
27 déc. 2009 à 16:04
bien desinstalle AD-Remover


▶ télécharge LOP S&D sur ton Bureau.

▶ Double-clique dessus pour lancer l'installation
▶ Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
▶ Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
▶ Patiente jusqu'à la fin du scan

▶ Poste le rapport généré (C:\lopR.txt)
0
fripouille68
27 déc. 2009 à 16:22
Quand je clique sur ton lien voilà le message qui apparait :

The bandwidth or page view limit for this site has been exceeded and the page cannot be viewed at this time. Once the site is below the limit, it will once again begin serving as normal.
0
Utilisateur anonyme
27 déc. 2009 à 16:23
desactive ton antivirus pour le telecharger
0
fripouille68
27 déc. 2009 à 16:56
Excuse moi,

juste pour savoir, si tu as bien reçu le rapport LOP SD ? Merci beaucoup.
0
fripouille68
27 déc. 2009 à 17:23
Je ne sais pas si tu as reçu le rapport de LOP SD je te l'envoie :


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.00GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A00
USER : Laurent ( Administrator )
BOOT : Normal boot
Antivirus : VirusKeeper 2009 Pro antivirus 9.0 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:145 Go (Free:74 Go)
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 27/12/2009|16:29 )

--------------------\\ Listing des dossiers dans APPLIC~1

[20/08/2004|11:41] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[05/11/2005|18:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\Jasc Software Inc
[20/08/2004|11:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[05/11/2005|18:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[05/11/2005|18:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver

[19/04/2008|16:42] C:\DOCUME~1\ADMINI~2\APPLIC~1\21cnPPS

[03/06/2009|16:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{55A29068-F2CE-456C-9148-C869879E2357}
[16/11/2009|15:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[13/04/2009|14:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[09/12/2009|11:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\3DVIA
[14/10/2009|19:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[27/12/2005|17:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[09/11/2005|20:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[12/08/2007|17:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[12/08/2007|17:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[10/04/2009|17:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ATI
[26/03/2009|18:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avanquest
[16/05/2007|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
[16/06/2008|19:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[02/12/2009|10:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[27/10/2009|20:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
[30/11/2005|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[27/12/2005|18:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Buena Vista Games
[27/01/2008|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ENJOY Plus!
[22/06/2008|09:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ESET
[30/08/2009|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\F-Secure
[29/10/2007|09:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GeoVid
[13/11/2008|13:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[24/11/2008|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hagel Technologies
[30/04/2007|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HipSoft
[11/10/2009|14:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\humyo.com
[12/08/2008|10:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[12/08/2008|10:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[05/11/2005|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[17/09/2006|11:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin
[18/10/2009|11:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[19/12/2005|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[26/12/2009|14:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[08/07/2008|20:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Maxtor
[08/02/2006|17:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[04/02/2006|17:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com Personal Firewall
[03/07/2006|18:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[20/12/2008|17:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Micro Application
[09/12/2009|08:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[10/02/2007|09:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Corporation
[27/02/2007|12:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[25/10/2006|19:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSScanAppDataDir
[06/06/2009|15:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[12/03/2009|17:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\My Games
[18/07/2009|09:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NCH Software
[10/04/2009|20:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NCH Swift Sound
[29/10/2008|09:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[10/11/2009|16:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PhotoMail
[18/04/2008|21:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[18/04/2008|21:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle VideoSpin
[16/11/2005|13:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\pixelStorm
[31/10/2009|15:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[21/02/2007|14:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Playtonium Games
[30/11/2005|13:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
[11/01/2006|16:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[24/06/2009|11:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\RadioManager
[20/05/2007|17:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
[20/08/2004|11:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[12/02/2009|15:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SHOUTcast Radio Toolbar
[31/10/2009|15:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skyline
[13/06/2008|17:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[18/12/2007|20:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[18/08/2007|14:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SugarGames
[26/02/2008|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[02/02/2006|15:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TDK
[25/12/2009|20:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[01/01/2009|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TomTom
[03/06/2009|16:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TuneUp Software
[09/02/2008|21:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TVU networks
[18/04/2008|21:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\VideoSpin
[10/11/2005|17:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[06/10/2007|15:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[03/12/2007|14:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[07/01/2006|16:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
[19/01/2008|13:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ZoomBrowser
[14/10/2008|16:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[15/08/2009|18:28] C:\DOCUME~1\David\APPLIC~1\Adobe
[10/04/2009|15:14] C:\DOCUME~1\David\APPLIC~1\Ahead
[02/12/2009|11:30] C:\DOCUME~1\David\APPLIC~1\app
[22/12/2009|22:16] C:\DOCUME~1\David\APPLIC~1\Apple Computer
[11/04/2009|12:48] C:\DOCUME~1\David\APPLIC~1\ATI
[27/03/2009|11:33] C:\DOCUME~1\David\APPLIC~1\Avanquest
[16/05/2007|15:45] C:\DOCUME~1\David\APPLIC~1\AVG7
[02/12/2009|10:31] C:\DOCUME~1\David\APPLIC~1\AVS4YOU
[08/07/2007|10:41] C:\DOCUME~1\David\APPLIC~1\AVSMedia
[18/03/2008|18:20] C:\DOCUME~1\David\APPLIC~1\CDBurnerXP_Soft
[29/10/2007|10:12] C:\DOCUME~1\David\APPLIC~1\CursorArts
[09/01/2006|19:37] C:\DOCUME~1\David\APPLIC~1\CyberLink
[20/03/2008|09:30] C:\DOCUME~1\David\APPLIC~1\DeepBurner
[24/02/2009|09:15] C:\DOCUME~1\David\APPLIC~1\DivX
[02/12/2009|11:47] C:\DOCUME~1\David\APPLIC~1\Dofus 2
[02/12/2009|11:29] C:\DOCUME~1\David\APPLIC~1\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[21/12/2009|11:11] C:\DOCUME~1\David\APPLIC~1\dvdcss
[27/01/2008|15:55] C:\DOCUME~1\David\APPLIC~1\ENJOY Plus!
[22/06/2008|14:35] C:\DOCUME~1\David\APPLIC~1\ESET
[29/10/2008|12:54] C:\DOCUME~1\David\APPLIC~1\FastStone
[26/06/2008|08:58] C:\DOCUME~1\David\APPLIC~1\FileZilla
[23/12/2009|09:42] C:\DOCUME~1\David\APPLIC~1\foobar2000
[29/10/2007|09:25] C:\DOCUME~1\David\APPLIC~1\GeoVid
[10/11/2007|22:29] C:\DOCUME~1\David\APPLIC~1\GetRightToGo
[24/09/2006|17:41] C:\DOCUME~1\David\APPLIC~1\Google
[15/10/2009|20:30] C:\DOCUME~1\David\APPLIC~1\gtk-2.0
[31/12/2005|11:58] C:\DOCUME~1\David\APPLIC~1\Help
[11/12/2005|10:24] C:\DOCUME~1\David\APPLIC~1\Hewlett-Packard
[28/12/2005|12:02] C:\DOCUME~1\David\APPLIC~1\Identities
[19/03/2008|16:00] C:\DOCUME~1\David\APPLIC~1\InfraRecorder
[02/09/2007|16:56] C:\DOCUME~1\David\APPLIC~1\Inkscape
[24/12/2008|18:23] C:\DOCUME~1\David\APPLIC~1\KC Softwares
[04/01/2008|22:52] C:\DOCUME~1\David\APPLIC~1\KompoZer
[16/05/2007|15:41] C:\DOCUME~1\David\APPLIC~1\Lavasoft
[31/12/2007|11:58] C:\DOCUME~1\David\APPLIC~1\Leadertech
[04/02/2009|15:13] C:\DOCUME~1\David\APPLIC~1\LimeWire
[04/12/2005|11:08] C:\DOCUME~1\David\APPLIC~1\Macromedia
[04/12/2005|11:41] C:\DOCUME~1\David\APPLIC~1\McAfee.com Personal Firewall
[28/12/2008|21:39] C:\DOCUME~1\David\APPLIC~1\Microsoft
[20/11/2007|16:02] C:\DOCUME~1\David\APPLIC~1\mioObjects
[20/02/2008|10:44] C:\DOCUME~1\David\APPLIC~1\Momindum
[19/04/2008|16:19] C:\DOCUME~1\David\APPLIC~1\Mozilla
[05/01/2008|11:59] C:\DOCUME~1\David\APPLIC~1\MPEG Streamclip
[25/12/2009|20:17] C:\DOCUME~1\David\APPLIC~1\MyPhoneExplorer
[04/07/2008|12:21] C:\DOCUME~1\David\APPLIC~1\NCH Software
[04/07/2008|12:26] C:\DOCUME~1\David\APPLIC~1\NCH Swift Sound
[14/10/2007|19:13] C:\DOCUME~1\David\APPLIC~1\NetAppel
[06/04/2009|17:50] C:\DOCUME~1\David\APPLIC~1\Nosibay
[29/10/2007|10:26] C:\DOCUME~1\David\APPLIC~1\Notepad++
[08/10/2007|14:04] C:\DOCUME~1\David\APPLIC~1\Nvu
[06/02/2009|13:25] C:\DOCUME~1\David\APPLIC~1\OpenOffice.org
[27/06/2009|17:01] C:\DOCUME~1\David\APPLIC~1\Opera
[14/01/2008|14:25] C:\DOCUME~1\David\APPLIC~1\Participatory Culture Foundation
[26/10/2006|08:06] C:\DOCUME~1\David\APPLIC~1\PC Tools
[14/01/2008|15:05] C:\DOCUME~1\David\APPLIC~1\PCF-VLC
[06/05/2006|15:33] C:\DOCUME~1\David\APPLIC~1\Picajet.com
[14/08/2006|14:29] C:\DOCUME~1\David\APPLIC~1\PlayFirst
[08/03/2008|22:33] C:\DOCUME~1\David\APPLIC~1\PowerChallenge
[18/04/2007|11:07] C:\DOCUME~1\David\APPLIC~1\Real
[02/12/2009|11:30] C:\DOCUME~1\David\APPLIC~1\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[04/10/2006|17:50] C:\DOCUME~1\David\APPLIC~1\SecuROM
[31/05/2008|21:03] C:\DOCUME~1\David\APPLIC~1\Skype
[31/05/2008|21:02] C:\DOCUME~1\David\APPLIC~1\skypePM
[19/12/2005|14:58] C:\DOCUME~1\David\APPLIC~1\Sonic
[26/06/2007|12:17] C:\DOCUME~1\David\APPLIC~1\STOIK
[06/12/2005|19:48] C:\DOCUME~1\David\APPLIC~1\Sun
[26/02/2008|17:46] C:\DOCUME~1\David\APPLIC~1\Symantec
[23/04/2009|13:30] C:\DOCUME~1\David\APPLIC~1\TomTom
[09/02/2008|21:10] C:\DOCUME~1\David\APPLIC~1\TVU networks
[25/12/2009|21:16] C:\DOCUME~1\David\APPLIC~1\vlc
[03/09/2007|16:15] C:\DOCUME~1\David\APPLIC~1\VoipBuster
[18/02/2006|11:40] C:\DOCUME~1\David\APPLIC~1\Wallpaper
[18/02/2006|11:37] C:\DOCUME~1\David\APPLIC~1\Webshots
[16/07/2009|13:13] C:\DOCUME~1\David\APPLIC~1\Winamp
[11/04/2009|12:48] C:\DOCUME~1\David\APPLIC~1\Windows Desktop Search
[29/06/2009|18:53] C:\DOCUME~1\David\APPLIC~1\Windows Search
[01/02/2009|01:39] C:\DOCUME~1\David\APPLIC~1\WinRAR
[23/06/2008|14:41] C:\DOCUME~1\David\APPLIC~1\www.TheXSoft.com
[28/12/2005|12:02] C:\DOCUME~1\David\APPLIC~1\Zylom

[20/08/2004|11:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[05/11/2005|18:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Jasc Software Inc
[20/05/2009|21:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[20/08/2004|11:30] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[05/11/2005|18:31] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun
[05/11/2005|18:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver

[17/05/2009|11:17] C:\DOCUME~1\INVIT~1\APPLIC~1\ATI
[20/08/2004|11:41] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[05/11/2005|18:39] C:\DOCUME~1\INVIT~1\APPLIC~1\Jasc Software Inc
[17/05/2009|11:18] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[17/05/2009|11:20] C:\DOCUME~1\INVIT~1\APPLIC~1\Opera
[22/02/2006|11:54] C:\DOCUME~1\INVIT~1\APPLIC~1\Real
[05/11/2005|18:31] C:\DOCUME~1\INVIT~1\APPLIC~1\Sun
[17/05/2009|11:17] C:\DOCUME~1\INVIT~1\APPLIC~1\Windows Desktop Search
[05/11/2005|18:37] C:\DOCUME~1\INVIT~1\APPLIC~1\You've Got Pictures Screensaver

[19/02/2006|12:28] C:\DOCUME~1\Laurent\APPLIC~1\7Wonders
[16/01/2008|19:54] C:\DOCUME~1\Laurent\APPLIC~1\Adobe
[15/02/2006|17:57] C:\DOCUME~1\Laurent\APPLIC~1\Ahead
[26/03/2006|11:01] C:\DOCUME~1\Laurent\APPLIC~1\alawar
[24/02/2009|20:38] C:\DOCUME~1\Laurent\APPLIC~1\Apple Computer
[10/04/2009|17:40] C:\DOCUME~1\Laurent\APPLIC~1\ATI
[27/03/2009|11:33] C:\DOCUME~1\Laurent\APPLIC~1\Avanquest
[16/05/2007|15:45] C:\DOCUME~1\Laurent\APPLIC~1\AVG7
[04/08/2007|16:08] C:\DOCUME~1\Laurent\APPLIC~1\AVSMedia
[16/09/2008|17:16] C:\DOCUME~1\Laurent\APPLIC~1\Beep Industries
[15/04/2009|19:36] C:\DOCUME~1\Laurent\APPLIC~1\Bump Technologies, Inc
[12/02/2007|17:04] C:\DOCUME~1\Laurent\APPLIC~1\CamfrogWEB
[19/01/2008|16:01] C:\DOCUME~1\Laurent\APPLIC~1\Canon
[11/11/2005|18:57] C:\DOCUME~1\Laurent\APPLIC~1\CyberLink
[03/05/2009|19:11] C:\DOCUME~1\Laurent\APPLIC~1\DeepBurner
[02/12/2005|10:19] C:\DOCUME~1\Laurent\APPLIC~1\Desktop Sidebar
[15/03/2008|16:39] C:\DOCUME~1\Laurent\APPLIC~1\DivX
[06/12/2009|12:10] C:\DOCUME~1\Laurent\APPLIC~1\dvdcss
[22/06/2008|09:39] C:\DOCUME~1\Laurent\APPLIC~1\ESET
[29/10/2008|18:51] C:\DOCUME~1\Laurent\APPLIC~1\FastStone
[22/01/2009|19:03] C:\DOCUME~1\Laurent\APPLIC~1\FireShot
[11/01/2006|16:16] C:\DOCUME~1\Laurent\APPLIC~1\FotoWire
[11/10/2009|15:32] C:\DOCUME~1\Laurent\APPLIC~1\funkitron
[12/03/2009|17:43] C:\DOCUME~1\Laurent\APPLIC~1\gemsweeperextractedgfx
[21/02/2009|15:33] C:\DOCUME~1\Laurent\APPLIC~1\GlarySoft
[20/09/2006|18:13] C:\DOCUME~1\Laurent\APPLIC~1\Google
[30/03/2009|17:44] C:\DOCUME~1\Laurent\APPLIC~1\gtk-2.0
[28/05/2007|09:12] C:\DOCUME~1\Laurent\APPLIC~1\Help
[10/11/2005|18:30] C:\DOCUME~1\Laurent\APPLIC~1\Hewlett-Packard
[11/11/2009|15:05] C:\DOCUME~1\Laurent\APPLIC~1\Identities
[08/10/2009|18:56] C:\DOCUME~1\Laurent\APPLIC~1\InstallShield
[14/09/2008|18:05] C:\DOCUME~1\Laurent\APPLIC~1\iWin
[05/11/2005|18:39] C:\DOCUME~1\Laurent\APPLIC~1\Jasc Software Inc
[17/04/2006|10:38] C:\DOCUME~1\Laurent\APPLIC~1\Lavasoft
[09/11/2005|20:00] C:\DOCUME~1\Laurent\APPLIC~1\Leadertech
[18/11/2005|19:11] C:\DOCUME~1\Laurent\APPLIC~1\Macromedia
[30/01/2006|18:34] C:\DOCUME~1\Laurent\APPLIC~1\Magic Match
[15/09/2008|18:56] C:\DOCUME~1\Laurent\APPLIC~1\MagicBall3
[31/10/2009|15:21] C:\DOCUME~1\Laurent\APPLIC~1\MagicBall4
[26/12/2009|14:57] C:\DOCUME~1\Laurent\APPLIC~1\Malwarebytes
[10/11/2005|16:45] C:\DOCUME~1\Laurent\APPLIC~1\McAfee.com Personal Firewall
[24/11/2008|12:19] C:\DOCUME~1\Laurent\APPLIC~1\Micro Application
[23/07/2009|17:25] C:\DOCUME~1\Laurent\APPLIC~1\Microsoft
[19/04/2008|12:42] C:\DOCUME~1\Laurent\APPLIC~1\Mozilla
[13/04/2006|19:32] C:\DOCUME~1\Laurent\APPLIC~1\MSNInstaller
[10/04/2009|20:28] C:\DOCUME~1\Laurent\APPLIC~1\NCH Swift Sound
[25/07/2009|07:44] C:\DOCUME~1\Laurent\APPLIC~1\Open Source Applications Foundation
[05/02/2009|22:52] C:\DOCUME~1\Laurent\APPLIC~1\OpenOffice.org2
[18/06/2009|18:16] C:\DOCUME~1\Laurent\APPLIC~1\Opera
[21/01/2006|09:50] C:\DOCUME~1\Laurent\APPLIC~1\OrphansRemover
[24/10/2006|19:24] C:\DOCUME~1\Laurent\APPLIC~1\PC Tools
[20/10/2008|16:55] C:\DOCUME~1\Laurent\APPLIC~1\PlayFirst
[25/07/2009|07:43] C:\DOCUME~1\Laurent\APPLIC~1\Python-Eggs
[27/06/2009|08:54] C:\DOCUME~1\Laurent\APPLIC~1\Real
[19/03/2007|16:49] C:\DOCUME~1\Laurent\APPLIC~1\Screenshot Sender
[13/06/2008|17:35] C:\DOCUME~1\Laurent\APPLIC~1\skypePM
[09/11/2005|20:00] C:\DOCUME~1\Laurent\APPLIC~1\Sonic
[23/12/2007|10:31] C:\DOCUME~1\Laurent\APPLIC~1\SpaceTime 3D
[05/11/2005|18:31] C:\DOCUME~1\Laurent\APPLIC~1\Sun
[26/02/2008|17:36] C:\DOCUME~1\Laurent\APPLIC~1\Symantec
[30/11/2005|10:22] C:\DOCUME~1\Laurent\APPLIC~1\Talkback
[09/11/2005|19:26] C:\DOCUME~1\Laurent\APPLIC~1\Template
[30/11/2005|10:22] C:\DOCUME~1\Laurent\APPLIC~1\Thunderbird
[23/12/2007|10:18] C:\DOCUME~1\Laurent\APPLIC~1\Todae
[01/01/2009|19:43] C:\DOCUME~1\Laurent\APPLIC~1\TomTom
[03/06/2009|16:07] C:\DOCUME~1\Laurent\APPLIC~1\TuneUp Software
[02/10/2009|19:32] C:\DOCUME~1\Laurent\APPLIC~1\Uniblue
[25/12/2009|13:36] C:\DOCUME~1\Laurent\APPLIC~1\vlc
[11/08/2006|08:54] C:\DOCUME~1\Laurent\APPLIC~1\Wallpaper
[23/04/2006|16:14] C:\DOCUME~1\Laurent\APPLIC~1\Wildfire
[10/04/2009|17:39] C:\DOCUME~1\Laurent\APPLIC~1\Windows Desktop Search
[10/04/2009|19:14] C:\DOCUME~1\Laurent\APPLIC~1\Windows Search
[28/12/2008|21:02] C:\DOCUME~1\Laurent\APPLIC~1\WinRAR
[17/03/2006|16:28] C:\DOCUME~1\Laurent\APPLIC~1\wxMozze
[05/11/2005|18:37] C:\DOCUME~1\Laurent\APPLIC~1\You've Got Pictures Screensaver
[19/01/2008|13:36] C:\DOCUME~1\Laurent\APPLIC~1\ZoomBrowser EX
[11/11/2009|15:05] C:\DOCUME~1\Laurent\APPLIC~1\Zylom

[10/01/2007|19:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
[09/11/2005|18:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\McAfee.com Personal Firewall
[20/08/2004|11:30] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[30/05/2006|17:34] C:\DOCUME~1\LOCALS~1\APPLIC~1\Mozilla

[08/03/2009|19:28] C:\DOCUME~1\NETWOR~1\APPLIC~1\DivX
[17/12/2009|16:35] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[10/11/2005|20:53] C:\DOCUME~1\PROPRI~1\APPLIC~1\You've Got Pictures Screensaver

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[27/12/2009 15:50][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1006UA.job
[25/12/2009 23:50][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1006Core.job
[27/12/2009 16:22][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1007UA.job
[25/12/2009 21:22][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1007Core.job
[27/12/2009 16:20][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[27/12/2009 14:57][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[27/12/2009 16:08][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{42B0BBB3-FCB6-43E5-AB31-CB35954FB4E3}.job
[27/12/2009 14:57][--a------] C:\WINDOWS\tasks\GlaryInitialize.job
[16/11/2009 15:12][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[27/12/2009 10:46][--a------] C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1167816979.job
[10/11/2005 21:30][--a------] C:\WINDOWS\tasks\Rappel d'abonnement 1 auprŠs de l'ISP.job
[27/12/2009 14:56][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[20/04/2008|11:26] C:\Program Files\21cn
[14/08/2007|17:05] C:\Program Files\3DO
[23/12/2009|09:44] C:\Program Files\4Musics MP3 Bitrate Changer
[13/12/2006|13:51] C:\Program Files\A!K Research Labs
[11/11/2005|16:58] C:\Program Files\ACE Mega CoDecS Pack
[29/10/2007|10:24] C:\Program Files\ActivIcons
[28/11/2006|20:16] C:\Program Files\Activision
[09/10/2006|18:53] C:\Program Files\Activision Value
[28/10/2008|20:52] C:\Program Files\Adobe
[27/12/2009|16:15] C:\Program Files\Ad-Remover
[10/10/2009|11:36] C:\Program Files\adslTV
[15/02/2006|17:50] C:\Program Files\Ahead
[20/06/2008|20:19] C:\Program Files\AIDA32
[16/08/2007|11:05] C:\Program Files\AIST
[25/04/2008|16:19] C:\Program Files\Alice
[26/06/2007|12:32] C:\Program Files\ALO SOFT
[10/01/2007|19:14] C:\Program Files\Alwil Software
[02/09/2007|19:47] C:\Program Files\AmitySource
[19/12/2007|13:24] C:\Program Files\Ankama Games
[28/08/2008|12:48] C:\Program Files\Apple Software Update
[05/05/2009|16:36] C:\Program Files\Astonsoft
[10/04/2009|17:35] C:\Program Files\ATI Technologies
[29/09/2006|19:09] C:\Program Files\AticiaPlanning
[15/08/2007|12:57] C:\Program Files\ATP
[16/02/2008|16:33] C:\Program Files\Audacity
[26/03/2009|17:51] C:\Program Files\Avanquest
[23/02/2008|22:59] C:\Program Files\AviSynth 2.5
[02/12/2009|10:26] C:\Program Files\AVS4YOU
[08/07/2007|10:38] C:\Program Files\AVSMedia
[27/03/2009|11:59] C:\Program Files\AWicons Lite
[21/10/2008|19:25] C:\Program Files\AxBx
[08/03/2008|21:47] C:\Program Files\Axis Communications
[24/03/2006|14:43] C:\Program Files\BarreConfCMCIC
[30/11/2006|10:32] C:\Program Files\Batman
[24/04/2008|18:04] C:\Program Files\Beneton Movie GIF
[25/05/2007|18:55] C:\Program Files\Bethesda Softworks
[18/10/2009|13:33] C:\Program Files\bfgclient
[26/12/2009|13:54] C:\Program Files\BHODemon 2
[13/04/2009|14:39] C:\Program Files\Bonjour
[02/05/2008|14:16] C:\Program Files\Boonty
[31/10/2009|15:11] C:\Program Files\BoontyGames
[28/06/2007|14:59] C:\Program Files\Bullfrog
[15/04/2009|19:40] C:\Program Files\BumpTop
[12/03/2008|16:11] C:\Program Files\Buzz
[28/07/2009|16:40] C:\Program Files\Calendrier
[28/12/2008|13:41] C:\Program Files\CamStudio
[19/01/2008|13:32] C:\Program Files\Canon
[22/04/2009|14:29] C:\Program Files\CCleaner
[18/03/2008|18:20] C:\Program Files\CDBurnerXP
[09/11/2009|17:07] C:\Program Files\CFWebAdvancedU
[07/05/2007|14:34] C:\Program Files\CFWebAdvancedU_BOBTV.FR
[28/12/2008|13:41] C:\Program Files\Christmas Time 3D Screensaver
[13/07/2006|20:16] C:\Program Files\Classfoot Worldcup 2006
[21/06/2006|08:28] C:\Program Files\Codemasters
[04/03/2006|18:37] C:\Program Files\Commandos II
[14/10/2008|18:06] C:\Program Files\Common Files
[28/08/2009|19:28] C:\Program Files\CPUID
[04/10/2006|17:31] C:\Program Files\Cryer
[05/11/2005|18:35] C:\Program Files\CyberLink
[13/10/2008|16:18] C:\Program Files\DateInTray
[15/08/2009|19:52] C:\Program Files\defaults
[28/12/2008|13:41] C:\Program Files\Dell
[05/11/2005|18:39] C:\Program Files\Dell Inc
[23/12/2007|10:24] C:\Program Files\DesktopEyes
[08/05/2006|09:58] C:\Program Files\DIFX
[05/04/2006|18:07] C:\Program Files\directx
[16/12/2009|17:41] C:\Program Files\DivX
[23/02/2008|22:08] C:\Program Files\djDecks
[31/01/2008|19:55] C:\Program Files\Documalis Free
[31/10/2009|15:26] C:\Program Files\Dofus
[02/12/2009|10:48] C:\Program Files\Dofus 2
[12/11/2005|13:11] C:\Program Files\Doom 3 Demo
[26/01/2008|12:15] C:\Program Files\DVDVideoSoft
[12/08/2006|12:01] C:\Program Files\e.t
[22/04/2007|15:58] C:\Program Files\e-anim701
[04/04/2009|13:19] C:\Program Files\EBP
[22/01/2009|13:26] C:\Program Files\Eidos Interactive
[26/04/2006|12:24] C:\Program Files\Eko
[01/02/2009|00:47] C:\Program Files\eMule
[18/10/2008|09:05] C:\Program Files\ENJOY Plus!
[08/12/2005|20:58] C:\Program Files\Europress
[17/03/2006|16:27] C:\Program Files\Evermore
[15/08/2009|19:52] C:\Program Files\extra
[29/10/2008|12:53] C:\Program Files\FastStone Image Viewer
[15/08/2009|18:28] C:\Program Files\Feedio
[27/12/2009|12:25] C:\Program Files\Fichiers communs
[22/04/2009|14:27] C:\Program Files\filehippo.com
[24/06/2008|14:35] C:\Program Files\FileZilla Client
[22/04/2007|16:01] C:\Program Files\Flux_2
[26/01/2008|11:59] C:\Program Files\FLVPlayer
[05/06/2006|18:01] C:\Program Files\fond-ecran-wallpaper.com
[23/12/2009|09:39] C:\Program Files\foobar2000
[16/02/2008|16:30] C:\Program Files\Freecorder
[25/10/2009|10:05] C:\Program Files\Funkitron
[10/08/2007|17:20] C:\Program Files\Future Pinball
[01/07/2006|12:07] C:\Program Files\Gamenext
[09/12/2005|18:38] C:\Program Files\GameSpy Arcade
[28/12/2008|13:41] C:\Program Files\GenIconXP
[29/10/2007|09:24] C:\Program Files\GeoVid
[01/02/2006|12:38] C:\Program Files\Giant
[14/11/2008|19:14] C:\Program Files\GIMP-2.0
[21/02/2009|15:24] C:\Program Files\Glary Utilities
[04/11/2009|09:20] C:\Program Files\Google
[14/10/2008|17:34] C:\Program Files\Gpotato.eu
[18/09/2006|09:21] C:\Program Files\Graphex3
[16/05/2007|15:45] C:\Program Files\Grisoft
[07/07/2008|19:27] C:\Program Files\HardwareDetection
[08/10/2009|18:56] C:\Program Files\Hercules
[26/03/2009|14:13] C:\Program Files\Heredis 8
[13/10/2008|16:19] C:\Program Files\Hewlett-Packard
[09/08/2006|09:06] C:\Program Files\HomeSite
[17/05/2007|08:54] C:\Program Files\Horloge 2005
[12/02/2009|14:35] C:\Program Files\Icecast2 Win32
[12/08/2007|16:42] C:\Program Files\Ihsv
[14/08/2007|10:39] C:\Program Files\Illustrate
[26/10/2009|18:57] C:\Program Files\Incredijeux
[10/11/2009|16:56] C:\Program Files\IncrediMail
[11/11/2005|10:23] C:\Program Files\Infogrames
[19/03/2008|15:58] C:\Program Files\InfraRecorder
[02/09/2007|22:48] C:\Program Files\Inkscape
[28/11/2009|13:12] C:\Program Files\InstallShield Installation Information
[05/11/2005|18:34] C:\Program Files\Intel
[10/12/2009|20:21] C:\Program Files\Internet Explorer
[22/06/2008|17:55] C:\Program Files\Intuisphere
[16/11/2009|15:30] C:\Program Files\iPod
[20/01/2008|18:44] C:\Program Files\IrfanView
[16/11/2009|15:31] C:\Program Files\iTunes
[26/01/2009|14:56] C:\Program Files\IviCam
[09/01/2006|19:04] C:\Program Files\Jasc Software Inc
[27/11/2009|18:45] C:\Program Files\Java
[12/03/2008|16:11] C:\Program Files\Jeskola Buzz
[08/06/2009|18:10] C:\Program Files\JRE
[16/11/2005|11:16] C:\Program Files\JVTorrent
[20/05/2007|09:02] C:\Program Files\Kaspersky Lab
[24/12/2008|18:21] C:\Program Files\KC Softwares
[02/01/2006|16:34] C:\Program Files\Languages
[05/11/2005|18:37] C:\Program Files\Learn2.com
[13/07/2006|20:16] C:\Program Files\LeechFTP
[04/02/2009|14:46] C:\Program Files\LimeWire
[02/01/2007|20:37] C:\Program Files\LM Version-2.5-F
[15/08/2009|19:52] C:\Program Files\locale
[31/08/2008|13:34] C:\Program Files\Logitech
[21/12/2008|11:10] C:\Program Files\LucasArts
[28/06/2009|09:25] C:\Program Files\Luxor 2
[08/06/2009|15:01] C:\Program Files\M6 Jeux
[18/10/2009|11:21] C:\Program Files\ma-config.com
[08/12/2006|16:53] C:\Program Files\Magentic
[02/12/2009|10:36] C:\Program Files\MAGIX
[16/10/2007|18:54] C:\Program Files\Ma‹do Production
[26/12/2009|14:57] C:\Program Files\Malwarebytes' Anti-Malware
[01/07/2006|15:21] C:\Program Files\Maxis
[28/12/2008|13:39] C:\Program Files\Maxtor
[28/12/2008|13:39] C:\Program Files\Maxtor(2)
[10/04/2008|13:24] C:\Program Files\MediaCoder
[30/12/2006|13:54] C:\Program Files\MediaInfo
[31/03/2006|17:16] C:\Program Files\Mes Jeux T‚l‚charg‚s
[27/08/2008|17:19] C:\Program Files\Messenger
[09/11/2009|16:59] C:\Program Files\Messenger Plus! Live
[10/04/2009|14:06] C:\Program Files\Metal Gear Solid
[12/07/2009|08:47] C:\Program Files\Micro Application
[28/12/2008|19:07] C:\Program Files\Microsoft
[10/05/2007|14:21] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[28/01/2007|12:48] C:\Program Files\Microsoft Encarta
[20/08/2004|11:37] C:\Program Files\microsoft frontpage
[27/05/2009|14:36] C:\Program Files\Microsoft FrontPage Express
[31/10/2009|15:27] C:\Program Files\Microsoft Games
[27/02/2007|12:17] C:\Program Files\Microsoft Office
[01/10/2009|18:07] C:\Program Files\Microsoft Office Outlook Connector
[25/08/2009|14:37] C:\Program Files\Microsoft Picture It! PhotoPub
[10/09/2009|16:14] C:\Program Files\Microsoft Silverlight
[16/10/2009|16:08] C:\Program Files\Microsoft SQL Server
[01/10/2009|18:04] C:\Program Files\Microsoft SQL Server Compact Edition
[17/12/2008|20:33] C:\Program Files\Microsoft Sync Framework
[27/02/2007|12:18] C:\Program Files\Microsoft Works
[24/06/2009|11:24] C:\Program Files\Microsoft.NET
[14/06/2008|16:44] C:\Program Files\Mindscape
[20/11/2007|16:02] C:\Program Files\Mioplanet
[23/12/2009|09:38] C:\Program Files\Monkey's Audio
[29/04/2006|17:31] C:\Program Files\Monte Cristo
[27/08/2008|17:58] C:\Program Files\Movie Maker
[26/12/2009|13:25] C:\Program Files\Mozilla Firefox
[19/08/2009|14:26] C:\Program Files\Mozilla Firefox 3 Beta 5
[19/08/2009|14:26] C:\Program Files\Mozilla Firefox 3.1 Beta 3
[19/08/2009|14:27] C:\Program Files\Mozilla Firefox 3.5 Beta 4
[19/08/2009|14:27] C:\Program Files\Mozilla Firefox 3.5 Preview
[26/12/2009|10:26] C:\Program Files\Mozilla Firefox 3.6 Beta 1
[26/12/2009|10:26] C:\Program Files\Mozilla Firefox 3.6 Beta 2
[30/11/2005|10:31] C:\Program Files\Mozilla Thunderbird
[08/05/2006|16:17] C:\Program Files\MP3 Player Utilities
[20/02/2008|11:57] C:\Program Files\MP3 Player Utilities 3.57
[05/01/2008|11:35] C:\Program Files\mp3DirectCut
[27/07/2009|09:00] C:\Program Files\MP3Gain
[05/01/2008|11:50] C:\Program Files\mp3splt-gtk
[10/04/2009|18:00] C:\Program Files\MSBuild
[13/06/2009|21:18] C:\Program Files\MSECache
[12/11/2005|14:11] C:\Program Files\MSN
[26/06/2006|10:03] C:\Program Files\MSN Games
[20/08/2004|11:34] C:\Program Files\MSN Gaming Zone
[16/12/2007|18:51] C:\Program Files\MSN Messenger
[14/08/2006|12:52] C:\Program Files\MSXML 4.0
[15/08/2007|09:33] C:\Program Files\MSXML 6.0
[24/12/2007|14:28] C:\Program Files\MyMPxPlayer.org
[25/12/2009|20:17] C:\Program Files\MyPhoneExplorer
[01/11/2006|09:32] C:\Program Files\MySight 2006
[28/12/2008|13:39] C:\Program Files\Navilog1
[18/07/2009|09:21] C:\Program Files\NCH Software
[10/04/2009|20:28] C:\Program Files\NCH Swift Sound
[15/02/2006|17:55] C:\Program Files\Nero
[27/08/2008|17:14] C:\Program Files\NetMeeting
[10/03/2009|18:54] C:\Program Files\Network Stumbler
[28/12/2008|18:27] C:\Program Files\nLite
[29/10/2008|09:29] C:\Program Files\NOS
[29/10/2007|10:26] C:\Program Files\Notepad++
[28/12/2008|13:42] C:\Program Files\Nvu
[14/10/2009|19:56] C:\Program Files\Oberon Media
[20/08/2004|11:34] C:\Program Files\Online Services
[06/02/2009|13:19] C:\Program Files\OpenOffice.org 2.4
[08/06/2009|18:10] C:\Program Files\OpenOffice.org 3
[25/11/2009|17:48] C:\Program Files\Opera
[08/06/2009|16:54] C:\Program Files\Opera 10 Preview
[04/06/2009|19:02] C:\Program Files\orange
[21/01/2006|09:50] C:\Program Files\OrphansRemover
[15/08/2009|22:53] C:\Program Files\Outlook Express
[21/10/2008|19:11] C:\Program Files\Panda Security
[13/05/2007|18:25] C:\Program Files\Panicware
[08/12/2008|19:04] C:\Program Files\PDFCreator
[14/08/2007|17:08] C:\Program Files\PeerTV
[09/06/2008|09:39] C:\Program Files\Photo Viewer
[10/11/2009|16:58] C:\Program Files\PhotoMail Maker
[01/02/2008|18:57] C:\Program Files\PhotoRapido
[06/05/2006|15:32] C:\Program Files\PicaFr
[18/04/2008|21:34] C:\Program Files\Pinnacle
[26/02/2006|11:46] C:\Program Files\Player Metaboli
[04/02/2006|16:56] C:\Program Files\Plus!
[18/06/2009|18:15] C:\Program Files\program
[16/11/2009|15:26] C:\Program Files\QuickTime
[10/08/2007|17:54] C:\Program Files\RacingPitch
[01/11/2009|21:19] C:\Program Files\Radio Fr Solo
[27/09/2009|11:03] C:\Program Files\Radio Stream Player
[24/06/2009|11:19] C:\Program Files\Radionomy
[01/05/2006|11:39] C:\Program Files\Ratajik Software
[04/08/2007|21:17] C:\Program Files\RawFlow
[11/11/2006|15:23] C:\Program Files\Real
[13/11/2009|20:31] C:\Program Files\RealArcade
[10/04/2009|18:00] C:\Program Files\Reference Assemblies
[13/12/2005|17:55] C:\Program Files\ReflexiveArcade
[25/10/2009|09:56] C:\Program Files\Retro64 Games
[18/04/2006|16:42] C:\Program Files\Ricochet Xtreme
[23/02/2008|22:56] C:\Program Files\Ripp-it_AM
[14/10/2009|16:00] C:\Program Files\RocketDock
[15/04/2006|16:54] C:\Program Files\Rockstar Games
[16/11/2009|15:37] C:\Program Files\Safari
[18/03/2006|13:47] C:\Program Files\SereneScreen
[20/08/2004|11:35] C:\Program Files\Services en ligne
[09/04/2009|13:44] C:\Program Files\Shareaza
[12/02/2009|15:27] C:\Program Files\SHOUTcast
[12/02/2009|15:30] C:\Program Files\SHOUTcast Radio Toolbar
[04/10/2006|17:41] C:\Program Files\Sierra
[05/11/2005|18:33] C:\Program Files\Sigmatel
[05/05/2007|20:41] C:\Program Files\Sim AQUARIUM 2
[03/02/2008|14:09] C:\Program Files\SimpleOCR
[15/08/2009|19:52] C:\Program Files\skin
[13/06/2008|17:40] C:\Program Files\Skype
[17/10/2009|13:46] C:\Program Files\Snowball
[12/04/2008|11:07] C:\Program Files\SoftChris
[08/02/2006|17:13] C:\Program Files\Softwin
[12/11/2005|16:45] C:\Program Files\Sonic
[05/12/2009|13:13] C:\Program Files\Sony Ericsson
[16/03/2008|19:12] C:\Program Files\SopCast
[18/10/2007|15:30] C:\Program Files\Sporever
[12/09/2009|09:07] C:\Program Files\Spybot - Search & Destroy
[21/03/2007|18:45] C:\Program Files\Spyware Doctor(2)
[02/01/2006|16:39] C:\Program Files\Stardock
[24/12/2007|17:14] C:\Program Files\STOIK Imaging
[15/08/2009|19:52] C:\Program Files\styles
[07/04/2006|19:05] C:\Program Files\Surreal
[18/07/2009|09:04] C:\Program Files\Sweet Home 3D
[02/05/2008|14:17] C:\Program Files\T‚l‚chargeur de Singles
[04/02/2006|17:18] C:\Program Files\TGTSoft
[31/10/2008|23:08] C:\Program Files\The All-Seeing Eye
[02/01/2006|16:34] C:\Program Files\Themes
[25/12/2007|15:42] C:\Program Files\THQ
[05/11/2005|18:40] C:\Program Files\Tiscali
[01/01/2009|19:39] C:\Program Files\TomTom DesktopSuite
[03/08/2006|16:33] C:\Program Files\TopDesk Trial
[10/04/2009|19:51] C:\Program Files\TubeMaster
[27/09/2009|11:04] C:\Program Files\TubeMaster++
[03/06/2009|16:59] C:\Program Files\TuneUp Utilities 2009
[17/05/2006|14:57] C:\Program Files\UberSoldier Demo
[14/08/2007|17:03] C:\Program Files\Ubi Soft
[15/08/2009|19:52] C:\Program Files\ui
[01/07/2006|16:17] C:\Program Files\Ulead Systems
[03/09/2007|10:00] C:\Program Files\Ultimate generator
[03/11/2006|15:23] C:\Program Files\Uninstall Information
[21/10/2006|11:24] C:\Program Files\Universal Interactive
[14/08/2007|17:09] C:\Program Files\URUSoft
[31/10/2007|11:39] C:\Program Files\VCW VicMan's Photo Editor
[31/10/2008|23:08] C:\Program Files\VideoCap
[27/11/2005|10:24] C:\Program Files\VideoLAN
[09/12/2009|11:53] C:\Program Files\Virtools
[14/08/2007|16:57] C:\Program Files\Vista Drive Icon
[20/09/2009|12:53] C:\Program Files\VivilProject SpeedTest
[14/10/2009|17:35] C:\Program Files\Wakfu
[31/10/2007|11:40] C:\Program Files\Web Photo Album
[16/07/2009|13:11] C:\Program Files\Winamp
[10/06/2009|16:18] C:\Program Files\Windows Desktop Search
[01/10/2009|18:05] C:\Program Files\Windows Live
[28/12/2008|19:03] C:\Program Files\Windows Live SkyDrive
[28/12/2008|19:06] C:\Program Files\Windows Live Toolbar
[08/03/2009|11:59] C:\Program Files\Windows Media Connect
[12/12/2006|20:06] C:\Program Files\Windows Media Connect 2
[26/03/2009|18:35] C:\Program Files\Windows Media Player
[27/08/2008|17:14] C:\Program Files\Windows NT
[29/09/2007|16:02] C:\Program Files\WindowsUpdate
[26/12/2007|13:06] C:\Program Files\WinMPG VideoConvert
[17/08/2009|12:45] C:\Program Files\WinPcap
[07/12/2008|09:51] C:\Program Files\WinRAR
[14/01/2006|10:31] C:\Program Files\WinZip
[26/03/2009|18:35] C:\Program Files\Worms
[20/08/2004|11:37] C:\Program Files\xerox
[20/02/2008|11:44] C:\Program Files\Xilisoft
[17/02/2007|11:03] C:\Program Files\X'nBeep 1.1
[24/03/2006|08:43] C:\Program Files\Yahoo!
[11/07/2009|09:46] C:\Program Files\YourWare Solutions
[13/11/2009|20:39] C:\Program Files\Zumas Revenge! - Adventure
[13/11/2009|20:41] C:\Program Files\Zylom Games

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[03/02/2007|13:45] C:\Program Files\Fichiers communs\3DO Shared
[14/10/2009|15:37] C:\Program Files\Fichiers communs\Adobe
[15/08/2009|18:28] C:\Program Files\Fichiers communs\Adobe AIR
[10/04/2009|15:15] C:\Program Files\Fichiers communs\Ahead
[27/03/2009|11:35] C:\Program Files\Fichiers communs\AntiVirus
[09/11/2005|20:16] C:\Program Files\Fichiers communs\AOL
[16/11/2009|15:30] C:\Program Files\Fichiers communs\Apple
[02/12/2009|10:26] C:\Program Files\Fichiers communs\AVSMedia
[30/11/2005|19:42] C:\Program Files\Fichiers communs\BOONTY Shared
[19/01/2008|13:24] C:\Program Files\Fichiers communs\Canon
[27/02/2007|19:21] C:\Program Files\Fichiers communs\DESIGNER
[16/12/2009|17:40] C:\Program Files\Fichiers communs\DivX Shared
[27/02/2008|17:00] C:\Program Files\Fichiers communs\DVDVideoSoft
[11/01/2006|16:16] C:\Program Files\Fichiers communs\FotoWire
[29/10/2007|09:24] C:\Program Files\Fichiers communs\GeoVid
[28/06/2007|13:41] C:\Program Files\Fichiers communs\GTK
[10/11/2005|18:21] C:\Program Files\Fichiers communs\Hewlett-Packard
[09/11/2005|19:11] C:\Program Files\Fichiers communs\InstallShield
[05/11/2005|18:31] C:\Program Files\Fichiers communs\Java
[11/01/2006|16:15] C:\Program Files\Fichiers communs\Logitech
[19/12/2005|13:44] C:\Program Files\Fichiers communs\Macrovision Shared
[02/12/2009|10:36] C:\Program Files\Fichiers communs\MAGIX Shared
[23/05/2006|17:46] C:\Program Files\Fichiers communs\Micro Application Shared
[24/06/2009|11:24] C:\Program Files\Fichiers communs\Microsoft Shared
[20/08/2004|11:35] C:\Program Files\Fichiers communs\MSSoap
[05/04/2009|17:40] C:\Program Files\Fichiers communs\Nosibay
[12/03/2008|17:42] C:\Program Files\Fichiers communs\NSV
[05/11/2005|18:37] C:\Program Files\Fichiers communs\Nullsoft
[04/06/2009|19:02] C:\Program Files\Fichiers communs\Oberon Media
[07/03/2006|19:36] C:\Program Files\Fichiers communs\ODBC
[21/03/2007|17:24] C:\Program Files\Fichiers communs\PC Tools
[01/07/2009|20:36] C:\Program Files\Fichiers communs\Real
[20/05/2007|17:22] C:\Program Files\Fichiers communs\Sandlot Shared
[20/08/2004|11:35] C:\Program Files\Fichiers communs\Services
[08/02/2006|17:13] C:\Program Files\Fichiers communs\Softwin
[27/05/2007|10:05] C:\Program Files\Fichiers communs\Sonic Shared
[20/08/2004|11:30] C:\Program Files\Fichiers communs\SpeechEngines
[02/01/2006|16:39] C:\Program Files\Fichiers communs\Stardock
[27/04/2009|07:05] C:\Program Files\Fichiers communs\Symantec Shared
[01/10/2009|18:07] C:\Program Files\Fichiers communs\System
[15/08/2007|11:36] C:\Program Files\Fichiers communs\Vbox
[16/12/2008|20:29] C:\Program Files\Fichiers communs\Windows Live
[03/12/2007|14:16] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[01/07/2009|20:37] C:\Program Files\Fichiers communs\xing shared
[18/04/2008|21:34] C:\Program Files\Fichiers communs\Yahoo!

--------------------\\ Process

( 72 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-27 16:30:21
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Recherche d'autres infections


C:\WINDOWS\System32\ntbifflrye.dat.ren
C:\WINDOWS\System32\ntbifflrye.exe.ren
C:\WINDOWS\System32\ntbifflrye_nav.dat.ren
C:\WINDOWS\System32\ntbifflrye_navps.dat.ren
[b]==> EGDACCESS <==/b



[F:32][D:8]-> C:\DOCUME~1\Laurent\LOCALS~1\Temp
[F:15][D:0]-> C:\DOCUME~1\Laurent\Cookies
[F:49][D:4]-> C:\DOCUME~1\Laurent\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 27/12/2009|16:44 - Option : [1]

--------------------\\ Fin du rapport a 16:44:37
0
Utilisateur anonyme
27 déc. 2009 à 18:01
Télécharge Navilog1 depuis-ce lien

▶ Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
▶ Ensuite double clique sur navilog1.exe pour lancer l'installation.

Une fois l'installation terminée, le fix s'exécutera automatiquement.

▶ Au menu principal, Fais le choix 1 >> Recherche / suppression automatique

Patiente jusqu'au message :
*** Analyse Termine le ..... ***

>>>>> Le fix peut durer une dizaine de minutes ;)

▶ Appuie sur une touche le bloc note va s'ouvrir.

▶ Copie-colle le rapport ici.

0
fripouille68
27 déc. 2009 à 18:35
Voilà le rapport de NAVILOG1 : As tu trouvé ce qui infeste mon pc ? merci beaucoup pour ton aide.

Fix Navipromo version 4.0.5 commencé le 27/12/2009 18:26:14,82

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!

Outil exécuté depuis C:\Program Files\navilog1

Mise à jour le 10.11.2009 à 18h00 par IL-MAFIOSO

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.00GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A00
USER : Laurent ( Administrator )
BOOT : Normal boot

Antivirus : VirusKeeper 2009 Pro antivirus 9.0 (Activated)


A:\ (USB)
C:\ (Local Disk) - NTFS - Total:145 Go (Free:74 Go)
D:\ (CD or DVD)


Recherche executée en mode normal

Nettoyage exécuté au redémarrage de l'ordinateur


C:\WINDOWS\system32\ntbifflrye.exe.ren supprimé !
C:\WINDOWS\system32\ntbifflrye.dat.ren supprimé !
C:\WINDOWS\system32\ntbifflrye_nav.dat.ren supprimé !
C:\WINDOWS\system32\ntbifflrye_navps.dat.ren supprimé !


Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\Laurent\locals~1\Temp effectué !


*** Sauvegarde du Registre vers dossier Safebackup ***

sauvegarde du Registre réalisée avec succès !

*** Nettoyage Registre ***

Nettoyage Registre Ok




*** Scan terminé 27/12/2009 18:29:24,03 ***
0
Utilisateur anonyme
27 déc. 2009 à 20:43
Télécharge OTL de OLDTimer

enregistre le sur ton Bureau.

▶ Double clic ( pour vista => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.

▶ Coche les 2 cases Lop et Purity

▶ Coche la case devant scan all users

▶ règle-le sur "60 Days"

▶ dans la colonne de gauche , mets tout sur all

ne modifie pas ceci :

"files created whithin" et "files modified whithin"


▶Clic sur Run Scan.

A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

▶▶▶ NE LE POSTE PAS SUR LE FORUM

Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

▶ Clique sur Parcourir et cherche le fichier ci-dessus.

▶ Clique sur Ouvrir.

▶ Clique sur "Cliquez ici pour déposer le fichier".

Un lien de cette forme :

http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

est ajouté dans la page.

▶ Copie ce lien dans ta réponse.

▶▶ Tu feras la meme chose avec le "Extra.txt".
0
fripouille68
28 déc. 2009 à 10:29
Salut gen-hackman,
voilà le résultat de otl.txt : http://www.cijoint.fr/cjlink.php?file=cj200912/cijQsvVH8z.txt

et celui pour extra.tnt : http://www.cijoint.fr/cjlink.php?file=cj200912/cijsZRozDQ.txt

Merci d'avance.
0
Utilisateur anonyme
28 déc. 2009 à 11:14
peux-tu repasser AD-Remover option "L" en mode sans echec stp ?
0
fripouille68
28 déc. 2009 à 12:08
rapport d' AD-Remover en mode sans échec :
.
======= RAPPORT D'AD-REMOVER 1.1.4.6_F | UNIQUEMENT XP/VISTA/7 =======
.
Mit à jour par C_XX le 26.12.2009 à 20:47
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 11:31:18, 28/12/2009 | Mode sans echec | Option: CLEAN
Exécuté de: C:\Program Files\Ad-Remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: FAMILLE | Utilisateur actuel: Laurent

Bonnes fêtes de fin d'année à vous tous :)
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.


(!) -- Fichiers temporaires supprimés.

.
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 3.5.6 [fr] *
.
Nom du profil: nhizwkb4.default (Laurent)
.
(Laurent, prefs.js) Browser.download.lastDir, C:\Documents and Settings\Laurent\Bureau
(Laurent, prefs.js) Browser.search.defaultenginename, MyStart Rechercher
(Laurent, prefs.js) Browser.search.defaulturl, hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
(Laurent, prefs.js) Browser.search.selectedEngine, Google
(Laurent, prefs.js) Browser.startup.homepage, hxxp://mystart.incredimail.com/
(Laurent, prefs.js) Extensions.enabledItems, fsonlinescanner@f-secure.com:1.01,splash@aldreneo.com:2.0.2,{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01,{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6
(Laurent, prefs.js) Keyword.URL, hxxp://mystart.incredimail.com/?loc=PMXMAS09FFAB&search=
(Laurent, prefs.js) Privacy.popups.showBrowserMessage, false
.
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Do404Search: 01000000
Local Page: C:\WINDOWS\system32\blank.htm
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/
Use Search Asst: no
Enable Browser Extensions: yes
Start Page Redirect Cache: hxxp://fr.msn.com/?ocid=iehp
Start Page Redirect Cache_TIMESTAMP: e6d4383bb91eca01
Start Page Redirect Cache AcceptLangs: fr
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: %SystemRoot%\system32\blank.htm
Start Page: hxxp://fr.msn.com/
Search bar: hxxp://search.msn.com/spbasic.htm
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\Start Page
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
============== Suspect (Cracks, Serials, ...) ==============
.
C:\Documents and Settings\Laurent\Local Settings\Application Data\Opera\Opera\profile\cache4\temporary_download\flock_patch_v1_03.zip
C:\Documents and Settings\Laurent\Mes documents\Mises … jour de programme t‚l‚charg‚es\Dell Paint Shop Photo Album 5\MyPublisher Update for Paint Shop Photo Album 5\PSPA_MyPublisherPatch_French.exe
.
===================================
.
6629 Octet(s) - C:\Ad-Report-CLEAN[1].log
3561 Octet(s) - C:\Ad-Report-CLEAN[2].log
.
0 Fichier(s) - C:\DOCUME~1\Laurent\LOCALS~1\Temp
0 Fichier(s) - C:\WINDOWS\Temp
0 Fichier(s) - C:\WINDOWS\Prefetch
.
36 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
224 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
Fin à: 11:56:20 | 28/12/2009 - CLEAN[2]
.
============== E.O.F ==============
.
0
Utilisateur anonyme
28 déc. 2009 à 13:31
Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau

double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

coche la case "creer une icone sur le bureau"

une fois terminée , clic sur "terminer" et le programme se lancera seul

choisis la langue puis choisis l'option 1 = Mode Recherche

▶ laisse travailler l'outil

à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

tu peux supprimer le rapport catchme.log de ton bureau maintenant.

0
fripouille68
28 déc. 2009 à 14:07
voila le résultat :

List'em by g3n-h@ckm@n 1.1.6.2

Thx to Chiquitine29.....& CCM team

User : Laurent (Administrateurs) # FAMILLE
Update on 28/12/2009 by g3n-h@ckm@n ::::: 01:30
Start at: 13:40:03 | 28/12/2009
Contact : g3n-h@ckm@n sur CCM

Intel(R) Pentium(R) 4 CPU 3.00GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : VirusKeeper 2009 Pro antivirus 9.0 [ Enabled | Updated ]

A:\ -> Lecteur de disquettes 3 ½ pouces
C:\ -> Disque fixe local | 145,95 Go (74,26 Go free) [DISQUE DUR ] | NTFS
D:\ -> Disque CD-ROM

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

C:\WINDOWS\System32\smss.exe 420
C:\WINDOWS\system32\csrss.exe 844
C:\WINDOWS\system32\winlogon.exe 1012
C:\WINDOWS\system32\services.exe 1168
C:\WINDOWS\system32\lsass.exe 1180
C:\WINDOWS\system32\Ati2evxx.exe 1512
C:\WINDOWS\system32\svchost.exe 1548
C:\WINDOWS\system32\svchost.exe 1672
C:\WINDOWS\System32\svchost.exe 1784
C:\WINDOWS\system32\svchost.exe 1844
C:\WINDOWS\system32\Ati2evxx.exe 1888
C:\WINDOWS\system32\svchost.exe 2008
C:\WINDOWS\system32\svchost.exe 240
C:\WINDOWS\system32\spoolsv.exe 464
C:\WINDOWS\system32\svchost.exe 572
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 700
C:\Program Files\Bonjour\mDNSResponder.exe 768
C:\WINDOWS\system32\drivers\CDAC11BA.EXE 860
C:\WINDOWS\System32\svchost.exe 1428
C:\Program Files\Java\jre6\bin\jqs.exe 1484
C:\Program Files\Maxtor\Sync\SyncServices.exe 1748
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe 1752
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe 600
C:\WINDOWS\Explorer.EXE 1684
C:\Program Files\CDBurnerXP\NMSAccessU.exe 1944
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 344
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe 752
C:\WINDOWS\system32\svchost.exe 684
C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_service.exe 1100
C:\WINDOWS\system32\SearchIndexer.exe 2072
C:\WINDOWS\system32\svchost.exe 2380
C:\Program Files\Windows Media Player\WMPNetwk.exe 2828
C:\Program Files\Canon\CAL\CALMAIN.exe 3100
C:\WINDOWS\System32\alg.exe 2740
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe 2084
C:\WINDOWS\stsystra.exe 2160
C:\WINDOWS\system32\dla\tfswctrl.exe 1228
C:\WINDOWS\system32\LVCOMSX.EXE 2188
C:\Program Files\Vista Drive Icon\DrvIcon.exe 972
C:\Program Files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe 2332
C:\Program Files\Logitech\Video\LogiTray.exe 2420
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe 2504
C:\Program Files\iTunes\iTunesHelper.exe 3040
C:\Program Files\Java\jre6\bin\jusched.exe 3176
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe 3276
C:\Program Files\IncrediMail\bin\IncMail.exe 3584
C:\Program Files\X'nBeep 1.1\XnBeep.exe 2324
C:\Program Files\CursorXP.exe 3928
C:\Program Files\RocketDock\RocketDock.exe 4040
C:\Program Files\Calendrier\Cld2000.exe 2116
C:\Program Files\Windows Media Player\WMPNSCFG.exe 2260
C:\WINDOWS\system32\ctfmon.exe 1852
C:\PROGRA~1\Magentic\bin\MgApp.exe 2352
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe 2776
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe 3364
C:\Program Files\Hercules\WiFi Station\WifiStation.exe 224
C:\Program Files\DateInTray\DateInTray.exe 3620
C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe 1608
C:\Program Files\Logitech\Video\FxSvr2.exe 3980
C:\Program Files\IncrediMail\bin\IMApp.exe 3456
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe 2544
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe 616
C:\WINDOWS\system32\HPZipm12.exe 1300
C:\Program Files\iPod\bin\iPodService.exe 3168
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe 852
C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_watchop.exe 2932
C:\WINDOWS\system32\SearchProtocolHost.exe 2124
C:\WINDOWS\system32\SearchFilterHost.exe 1956
C:\Program Files\List_Kill'em\List_Kill'em.exe 2068
C:\WINDOWS\system32\cmd.exe 400
C:\WINDOWS\system32\wbem\wmiprvse.exe 3216
C:\Documents and Settings\Laurent\Local Settings\temp\4B.tmp\pv.exe 3212

======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
LDM REG_SZ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
LogitechSoftwareUpdate REG_SZ "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
Magentic REG_SZ C:\PROGRA~1\Magentic\bin\Magentic.exe /c
swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
IncrediMail REG_SZ C:\Program Files\IncrediMail\bin\IncMail.exe /c
X'nBeep REG_SZ C:\Program Files\X'nBeep 1.1\XnBeep.exe
CursorXP REG_SZ C:\Program Files\CursorXP.exe
RocketDock REG_SZ "C:\Program Files\RocketDock\RocketDock.exe"
Google Update REG_SZ "C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
Cld2000.exe REG_SZ C:\Program Files\Calendrier\Cld2000.exe
WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe
ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ISUSPM Startup REG_SZ C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
ISUSScheduler REG_SZ "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
SigmatelSysTrayApp REG_SZ stsystra.exe
dla REG_SZ C:\WINDOWS\system32\dla\tfswctrl.exe
LVCOMSX REG_SZ C:\WINDOWS\system32\LVCOMSX.EXE
LogitechVideoRepair REG_SZ C:\Program Files\Logitech\Video\ISStart.exe
ATIPTA REG_SZ "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
DrvIcon REG_SZ C:\Program Files\Vista Drive Icon\DrvIcon.exe
VirusKeeper REG_SZ C:\Program Files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe
AppleSyncNotifier REG_SZ C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
StartCCC REG_SZ "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
LogitechVideoTray REG_SZ C:\Program Files\Logitech\Video\LogiTray.exe
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe ARM REG_SZ "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
DisableRegistryTools REG_DWORD 0 (0x0)

===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 323 (0x143)
NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
NoDrives REG_DWORD 0 (0x0)

===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
HonorAutoRunSetting REG_DWORD 1 (0x1)
NoCDBurning REG_DWORD 0 (0x0)
NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
NoDriveTypeAutoRun REG_DWORD 323 (0x143)
NoDrives REG_DWORD 0 (0x0)

===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
{56F9679E-7826-4C84-81F3-532071A8BCC5} REG_SZ

===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
C:\Program Files\IncrediMail\bin\IMApp.exe REG_SZ C:\Program Files\IncrediMail\bin\IMApp.exe:*:Enabled:IncrediMail
C:\Program Files\IncrediMail\bin\IncMail.exe REG_SZ C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail
C:\Program Files\IncrediMail\bin\ImpCnt.exe REG_SZ C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail
C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImpCnt.exe REG_SZ C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail
C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImLc.exe REG_SZ C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImLc.exe:*:Enabled:IncrediMail
C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImPackr.exe REG_SZ C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImPackr.exe:*:Enabled:IncrediMail
C:\Program Files\Magentic\bin\MgImp.exe REG_SZ C:\Program Files\Magentic\bin\MgImp.exe:*:Enabled:Magentic
C:\Program Files\Magentic\bin\Magentic.exe REG_SZ C:\Program Files\Magentic\bin\Magentic.exe:*:Enabled:Magentic
C:\Program Files\Magentic\bin\MgApp.exe REG_SZ C:\Program Files\Magentic\bin\MgApp.exe:*:Enabled:Magentic
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\IncrediMail_Install.exe REG_SZ C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\IncrediMail_Install.exe:*:Enabled:IncrediMail Installer
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe REG_SZ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
C:\Program Files\Codemasters\Worms 4 Mayhem Demo\Worms 4 Mayhem Demo.exe REG_SZ C:\Program Files\Codemasters\Worms 4 Mayhem Demo\Worms 4 Mayhem Demo.exe:*:Enabled:Worms 4 Mayhem Demo
C:\Program Files\Mozilla Firefox\firefox.exe REG_SZ C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Browser
C:\Program Files\Commandos II\comm2.exe REG_SZ C:\Program Files\Commandos II\comm2.exe:*:Enabled:comm2
C:\Program Files\The All-Seeing Eye\eye.exe REG_SZ C:\Program Files\The All-Seeing Eye\eye.exe:*:Enabled:Yahoo! All-Seeing Eye
C:\Program Files\Opera\Opera.exe REG_SZ C:\Program Files\Opera\Opera.exe:*:Enabled:Opera Internet Browser
C:\WINDOWS\system32\dpvsetup.exe REG_SZ C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test
C:\WINDOWS\system32\java.exe REG_SZ C:\WINDOWS\system32\java.exe:*:Enabled:Java(TM) Platform SE binary
C:\Program Files\Real\RealPlayer\realplay.exe REG_SZ C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer
C:\Program Files\SopCast\SopCast.exe REG_SZ C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application
C:\Program Files\SopCast\adv\SopAdver.exe REG_SZ C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver
C:\Documents and Settings\David\Application Data\PowerChallenge\PowerSoccer\PowerSoccer.exe REG_SZ C:\Documents and Settings\David\Application Data\PowerChallenge\PowerSoccer\PowerSoccer.exe:*:Enabled:PowerSoccer
C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe REG_SZ C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager
C:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe REG_SZ C:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile
C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe REG_SZ C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe:*:Enabled:umi
C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe REG_SZ C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin
C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe REG_SZ C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix
C:\Program Files\VideoLAN\VLC\vlc.exe REG_SZ C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player
C:\Program Files\Mindscape\Mission Président - Geo-Political Simulator\MISSION.EXE REG_SZ C:\Program Files\Mindscape\Mission Président - Geo-Political Simulator\MISSION.EXE:*:Enabled:Application _geolgps
C:\Program Files\Ivicam\backsurvey.exe REG_SZ C:\Program Files\Ivicam\backsurvey.exe:*:Enabled:Ivisible_BackSurvey
C:\Program Files\Icecast2 Win32\Icecast2win.exe REG_SZ C:\Program Files\Icecast2 Win32\Icecast2win.exe:*:Enabled:Icecast2win
C:\Program Files\SHOUTcast\sc_serv.exe REG_SZ C:\Program Files\SHOUTcast\sc_serv.exe:*:Enabled:sc_serv
C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
C:\Program Files\QuickTime\QuickTimePlayer.exe REG_SZ C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
C:\Program Files\ma-config.com\maconfservice.exe REG_SZ C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice
C:\WINDOWS\system32\rtcshare.exe REG_SZ C:\WINDOWS\system32\rtcshare.exe:*:Enabled:Partage de l'application RTC
C:\Program Files\NetMeeting\conf.exe REG_SZ C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting®
C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
C:\Program Files\Sony Ericsson\Update Service\Update Service.exe REG_SZ C:\Program Files\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service
C:\WINDOWS\system32\wuauserv.exe REG_SZ C:\WINDOWS\system32\wuauserv.exe:*:Enabled:TCP
C:\WINDOWS\system32\tftp.exe REG_SZ C:\WINDOWS\system32\tftp.exe:*:Enabled:Tftp

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe REG_SZ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare

===============
BHO :
======
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{B56A7D7D-6927-48C8-A975-17DF180C71AC}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{ccec60fc-2608-4e58-9659-3ffc159e8ea9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ http://mystart.incredimail.com/

========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

Ndisuio : 0x3
EapHost : 0x3
SharedAccess : 0x2
wuauserv : 0x2

=========

=======
Drive :
=======

D‚fragmenteur de disque Windows
Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

Rapport d'analyse
146 Go total, 74,27 Go libre (50%), 5% fragment‚ (fragmentation du fichier 10%)

Il ne vous est pas n‚cessaire de d‚fragmenter ce volume.

¤¤¤¤¤¤¤¤¤¤ Files/folders :

C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
C:\Program Files\WinPCap
C:\WINDOWS\aucfg.ini
C:\WINDOWS\Fonts\GRGAREF.TTF
C:\WINDOWS\iun6002.exe
C:\WINDOWS\System32\ACTSKN43.ocx
C:\WINDOWS\System32\drivers\etc\hosts.msn
C:\WINDOWS\System32\drivers\npf.sys
C:\WINDOWS\System32\MSINET.oca
C:\WINDOWS\System32\Packet.dll
C:\WINDOWS\System32\pthreadVC.dll
C:\WINDOWS\System32\WanPacket.dll
C:\WINDOWS\System32\wpcap.dll

¤¤¤¤¤¤¤¤¤¤ Keys :

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
HKCR\Install.Install
HKCR\Install.Install\CLSID
HKCR\Install.Install\CurVer
HKCR\Install.Install.1
HKCR\Install.Install.1\CLSID
HKCR\Interface\{daa37aad-f156-4c2c-ac48-3c22ef92ae2f}
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_NPF
HKLM\SYSTEM\ControlSet001\Services\npf
HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_NPF
HKLM\SYSTEM\ControlSet002\Services\npf

================
Other infections
================

catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-28 13:44:03
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK

==========
Programs
==========

21cn
3DO
4Musics MP3 Bitrate Changer
A!K Research Labs
ACE Mega CoDecS Pack
ActivIcons
Activision
Activision Value
Ad-Remover
Adobe
adslTV
Ahead
AIDA32
AIST
Alice
ALO SOFT
Alwil Software
AmitySource
AniUtil.exe
Ankama Games
Apple Software Update
Astonsoft
ATI Technologies
AticiaPlanning
ATP
Audacity
Avanquest
AviSynth 2.5
AVS4YOU
AVSMedia
AWicons Lite
AxBx
Axis Communications
BarreConfCMCIC
Batman
Beneton Movie GIF
Bethesda Softworks
bfgclient
BHODemon 2
Bonjour
Boonty
BoontyGames
Bullfrog
BumpTop
Buzz c3nform.vxml
Calendrier
CamStudio
Canon
CCleaner
CDBurnerXP
CFWebAdvancedU
CFWebAdvancedU_BOBTV.FR
Christmas Time 3D Screensaver
Classfoot Worldcup 2006
Codemasters
Commandos II
Common Files
CPUID
Cryer
CursorXP.exe
CurXP0.dll
CurXP1.dll
CurXPCpl.dll
CurXPCpl.exe
CurXPUtil.exe
CyberLink
DateInTray
defaults
Dell
Dell Inc
DesktopEyes
DIFX
directx
DivX
djDecks
Documalis Free
Dofus
Dofus 2
Doom 3 Demo
DVDVideoSoft
e-anim701
e.t
EBP
Eidos Interactive
Eko
eMule
encoding.bin
ENJOY Plus!
eula.txt
Europress
Evermore
extra
FastStone Image Viewer
Feedio
Fichiers communs
filehippo.com
FileZilla Client
Flux_2
FLVPlayer
fond-ecran-wallpaper.com
foobar2000
Freecorder
Funkitron
Future Pinball
Gamenext
GameSpy Arcade
GenIconXP
GeoVid
Giant
GIMP-2.0
Glary Utilities
Google
Gpotato.eu
Graphex3
Grisoft
HardwareDetection
Hercules
Heredis 8
Hewlett-Packard
HomeSite
Horloge 2005
html40_entities.dtd
Icecast2 Win32
Ihsv
Illustrate
Incredijeux
IncrediMail
Infogrames
InfraRecorder
Inkscape
InstallShield Installation Information
Intel
Internet Explorer
Intuisphere
iPod
IrfanView
iTunes
IviCam
Jasc Software Inc
Java
Jeskola Buzz
JRE
JVTorrent
Kaspersky Lab
KC Softwares
Languages
Learn2.com
LeechFTP
license.rtf
LimeWire
List_Kill'em
LM Version-2.5-F
lngcode.txt
locale
Logitech
LucasArts
Luxor 2
M6 Jeux
ma-config.com
Magentic
MAGIX
Malwarebytes' Anti-Malware
Maxis
Maxtor
Maxtor(2)
Ma‹do Production
MediaCoder
MediaInfo
Mes Jeux T‚l‚charg‚s
Mess with MSN Messenger skins, nicknames, add-ons, bots and secrets.url
Messenger
Messenger Plus! Live
Metal Gear Solid
Micro Application
Microsoft
Microsoft CAPICOM 2.1.0.2
Microsoft Encarta
microsoft frontpage
Microsoft FrontPage Express
Microsoft Games
Microsoft Office
Microsoft Office Outlook Connector
Microsoft Picture It! PhotoPub
Microsoft Silverlight
Microsoft SQL Server
Microsoft SQL Server Compact Edition
Microsoft Sync Framework
Microsoft Works
Microsoft.NET
Mindscape
Mioplanet
Monkey's Audio
Monte Cristo
Movie Maker
Mozilla Firefox
Mozilla Firefox 3 Beta 5
Mozilla Firefox 3.1 Beta 3
Mozilla Firefox 3.5 Beta 4
Mozilla Firefox 3.5 Preview
Mozilla Firefox 3.6 Beta 1
Mozilla Firefox 3.6 Beta 2
Mozilla Thunderbird
MP3 Player Utilities
MP3 Player Utilities 3.57
mp3DirectCut
MP3Gain
mp3splt-gtk
MSBuild
MSECache
MSN
MSN Games
MSN Gaming Zone
MSN Messenger
MSXML 4.0
MSXML 6.0
MyMPxPlayer.org
MyPhoneExplorer
MySight 2006
Navilog1
NCH Software
NCH Swift Sound
Nero
NetMeeting
Network Stumbler
nLite
NOS
Notepad++
Nvu
Oberon Media
Online Services
OpenOffice.org 2.4
OpenOffice.org 3
Opera
Opera 10 Preview
opera.dll
opera.exe
operaprefs_default.ini
orange
OrphansRemover
OUniAnsi.dll
Outlook Express
Panda Security
Panicware
PDFCreator
PeerTV
Photo Viewer
PhotoMail Maker
PhotoRapido
PicaFr
Pinnacle
Player Metaboli
Plus!
program
QuickTime
RacingPitch
Radio Fr Solo
Radio Stream Player
Radionomy
Ratajik Software
RawFlow
read1st.txt
Readme.txt
Real
RealArcade
Reference Assemblies
ReflexiveArcade
Reset theme.lnk
Retro64 Games
Ricochet Xtreme
Ripp-it_AM
RngInterstitial.dll
RocketDock
Rockstar Games
Safari
SereneScreen
Services en ligne
Shareaza
SHOUTcast
SHOUTcast Radio Toolbar
Sierra
Sigmatel
Sim AQUARIUM 2
SimpleOCR
skin
Skype
Snowball
SoftChris
Softwin
Sonic
Sony Ericsson
SopCast
Sporever
Spybot - Search & Destroy
Spyware Doctor(2)
Stardock
STOIK Imaging
styles
Surreal
Sweet Home 3D
TGTSoft
The All-Seeing Eye
Themes
THQ
Tiscali
TomTom DesktopSuite
TopDesk Trial
TubeMaster
TubeMaster++
TuneUp Utilities 2009
T‚l‚chargeur de Singles
UberSoldier Demo
Ubi Soft
ui
Ulead Systems
Ultimate generator
Uninstall Information
Uninstall.lnk
Universal Interactive
Unzip32.dll
URUSoft
VCW VicMan's Photo Editor
VideoCap
VideoLAN
Virtools
Vista Drive Icon
VivilProject SpeedTest
Wakfu
Web Photo Album
Winamp
Windows Desktop Search
Windows Live
Windows Live SkyDrive
Windows Live Toolbar
Windows Media Connect
Windows Media Connect 2
Windows Media Player
Windows NT
WindowsUpdate
WinMPG VideoConvert
WinPcap
WinRAR
WinZip
Worms
X'nBeep 1.1
xerox
Xilisoft
Yahoo!
YourWare Solutions
Zip32.dll
Zumas Revenge! - Adventure
Zylom Games

============
Lecteur C:
============

projet
$VAULT$.AVG
5b65fb94b65b57c50b17538d
a67a334ca6418fa49cd78dda214627
Ad-Report-CLEAN[1].log
Ad-Report-CLEAN[2].log
ageofjapan_RADRMEx.dll
asoutput.log
ASY.log
ATI
AUTOEXEC.BAT
AVG7QT.DAT
bink_log.txt
Boot.bak
BOOT.BKK
boot.ini
boot.ini.back
boot.uni
Bootfont.bin
c
c7660d5d5134ab059248ac8db796d7a7
Cadre Photo Num‚rique
cannonblast_RADRMEx.dll
CAPTURE.AVI
cleannavi.txt
cmdcons
cmldr
CodeRED Alien Arena
ComboFix.txt
Config.Msi
CONFIG.SYS
debugInstaller.txt
Default.Bmp
default.txt
dell
dell.sdr
diamonddetective_RADRMEx.dll
Documents and Settings
DownloadLog.txt
Downloads
drivers
e8e1d80abd6e6a2e88
error.log
f02e2174e5e8740c4d
fizzball_RADRMEx.dll
flowershopbigcitybreak_RADRMEx.dll
found.000
found.001
giftshop_RADRMEx.dll
hpfr3420.xml
hpfr3425.log
i386
INFCACHE.1
Intel
IO.SYS
IPH.PH
Kill'em
LGSInst.Log
lifetimersvp_RADRMEx.dll
List'em.txt
LogiSetup.log
Lop SD
lopR.txt
magicball3_RADRMEx.dll
MAPISVC.INF
MAPISVC.PNF
Mes t‚l‚chargements
mpeg.txt
MSDOS.SYS
My Download Files
My Games
My Music
NTDETECT.COM
ntldr
orange.bmp
os466477.bin
pagefile.sys
picajet.log
PMAIL
Program Files
Qoobox
rainbowmystery_RADRMEx.dll
RECYCLER
Remote Programs
sandscripttm_RADRMEx.dll
sound_bank_log.txt
sqmdata00.sqm
sqmdata01.sqm
sqmnoopt00.sqm
sqmnoopt01.sqm
sqmnoopt02.sqm
sqmnoopt03.sqm
sqmnoopt04.sqm
sqmnoopt05.sqm
sqmnoopt06.sqm
sqmnoopt07.sqm
sqmnoopt08.sqm
sqmnoopt09.sqm
sqmnoopt10.sqm
sqmnoopt11.sqm
sqmnoopt12.sqm
sqmnoopt13.sqm
sqmnoopt14.sqm
sqmnoopt15.sqm
sqmnoopt16.sqm
sqmnoopt17.sqm
sqmnoopt18.sqm
sqmnoopt19.sqm
supergranny3_RADRMEx.dll
System Volume Information
team17
Temp
test.avi
test.jpg
TEST.XML
thelegendofeldorado_RADRMEx.dll
TLK GAMES
tmp
transparency
users
Video surveillance facile
VundoFix Backups
VundoFix.txt
WINDOWS
X-Plane
X-Plane Installer.prf
xscan.txt
zodiactower_RADRMEx.dll
_Backup
_Backup.RC
_table.txt

¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

C:\Documents and Settings\David\Mes documents\A d‚plac‚ sur la cl‚\PortableGIMP\gimp\share\gimp\2.0\gimpressionist\Presets\Patchwork
C:\Documents and Settings\David\Mes documents\A d‚plac‚ sur la cl‚\PortableGIMP\gimp\share\gimp\2.0\patterns\cracked.pat
C:\Documents and Settings\Laurent\Mes documents\TomTom\HOME\Backup\ONE\Backup01\InternalMemory\France\PatchFilter.dat
C:\Program Files\GIMP-2.0\share\gimp\2.0\gimpressionist\Presets\Patchwork
C:\Program Files\GIMP-2.0\share\gimp\2.0\patterns\cracked.pat
C:\Program Files\Gpotato.eu\Flyff\PatchLog.txt
C:\Program Files\Heredis 8\Models\Patchwork.hm7
C:\Program Files\Inkscape\python\Lib\site-packages\numpy\f2py\crackfortran.py
C:\Program Files\Inkscape\python\Lib\site-packages\numpy\f2py\crackfortran.pyc
C:\Program Files\Inkscape\python\Lib\site-packages\numpy\f2py\crackfortran.pyo
C:\Program Files\Jeskola Buzz\Patcher.exe
C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\Patch
C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\Patch\Sql
C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\Patch\Sql\SqlRun_SLP_SQL.msp
C:\Documents and Settings\David\Mes documents\Autre\Install.exe
C:\Program Files\Ripp-it_AM\dlls\AACPatch.exe
C:\Program Files\Snowball\Install.exe




¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
0
Utilisateur anonyme
28 déc. 2009 à 14:34
▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
mais cette fois-ci :

▶ choisis l'option 2 = Mode Suppression

laisse travailler l'outil.

en fin de scan un rapport s'ouvre

▶ colle le contenu dans ta reponse
0
fripouille68
28 déc. 2009 à 17:11
resultat list&kill'em option 2 : mode suppression.

Kill'em by g3n-h@ckm@n 1.1.6.2

User : Laurent (Administrateurs) # FAMILLE
Update on 28/12/2009 by g3n-h@ckm@n ::::: 01:30
Start at: 16:55:32 | 28/12/2009
Contact : g3n-h@ckm@n sur CCM

Intel(R) Pentium(R) 4 CPU 3.00GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : VirusKeeper 2009 Pro antivirus 9.0 [ Enabled | Updated ]

A:\ -> Lecteur de disquettes 3 ½ pouces
C:\ -> Disque fixe local | 145,95 Go (74,26 Go free) [DISQUE DUR ] | NTFS
D:\ -> Disque CD-ROM


¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

C:\WINDOWS\System32\smss.exe 420
C:\WINDOWS\system32\csrss.exe 844
C:\WINDOWS\system32\winlogon.exe 1012
C:\WINDOWS\system32\services.exe 1168
C:\WINDOWS\system32\lsass.exe 1180
C:\WINDOWS\system32\Ati2evxx.exe 1512
C:\WINDOWS\system32\svchost.exe 1548
C:\WINDOWS\system32\svchost.exe 1672
C:\WINDOWS\System32\svchost.exe 1784
C:\WINDOWS\system32\svchost.exe 1844
C:\WINDOWS\system32\Ati2evxx.exe 1888
C:\WINDOWS\system32\svchost.exe 2008
C:\WINDOWS\system32\svchost.exe 240
C:\WINDOWS\system32\spoolsv.exe 464
C:\WINDOWS\system32\svchost.exe 572
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 700
C:\Program Files\Bonjour\mDNSResponder.exe 768
C:\WINDOWS\system32\drivers\CDAC11BA.EXE 860
C:\WINDOWS\System32\svchost.exe 1428
C:\Program Files\Java\jre6\bin\jqs.exe 1484
C:\Program Files\Maxtor\Sync\SyncServices.exe 1748
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe 1752
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe 600
C:\WINDOWS\Explorer.EXE 1684
C:\Program Files\CDBurnerXP\NMSAccessU.exe 1944
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 344
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe 752
C:\WINDOWS\system32\svchost.exe 684
C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_service.exe 1100
C:\WINDOWS\system32\SearchIndexer.exe 2072
C:\WINDOWS\system32\svchost.exe 2380
C:\Program Files\Windows Media Player\WMPNetwk.exe 2828
C:\Program Files\Canon\CAL\CALMAIN.exe 3100
C:\WINDOWS\System32\alg.exe 2740
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe 2084
C:\WINDOWS\stsystra.exe 2160
C:\WINDOWS\system32\dla\tfswctrl.exe 1228
C:\WINDOWS\system32\LVCOMSX.EXE 2188
C:\Program Files\Vista Drive Icon\DrvIcon.exe 972
C:\Program Files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe 2332
C:\Program Files\Logitech\Video\LogiTray.exe 2420
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe 2504
C:\Program Files\iTunes\iTunesHelper.exe 3040
C:\Program Files\Java\jre6\bin\jusched.exe 3176
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe 3276
C:\Program Files\X'nBeep 1.1\XnBeep.exe 2324
C:\Program Files\CursorXP.exe 3928
C:\Program Files\RocketDock\RocketDock.exe 4040
C:\Program Files\Calendrier\Cld2000.exe 2116
C:\Program Files\Windows Media Player\WMPNSCFG.exe 2260
C:\WINDOWS\system32\ctfmon.exe 1852
C:\PROGRA~1\Magentic\bin\MgApp.exe 2352
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe 2776
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe 3364
C:\Program Files\Hercules\WiFi Station\WifiStation.exe 224
C:\Program Files\DateInTray\DateInTray.exe 3620
C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe 1608
C:\Program Files\Logitech\Video\FxSvr2.exe 3980
C:\Program Files\IncrediMail\bin\IMApp.exe 3456
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe 2544
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe 616
C:\WINDOWS\system32\HPZipm12.exe 1300
C:\Program Files\iPod\bin\iPodService.exe 3168
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe 852
C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_watchop.exe 2932
C:\Program Files\IncrediMail\Bin\IncMail.exe 3480
C:\Program Files\List_Kill'em\List_Kill'em.exe 1364
C:\WINDOWS\system32\cmd.exe 2216
C:\WINDOWS\system32\wbem\wmiprvse.exe 3612
C:\Documents and Settings\Laurent\Local Settings\temp\8A.tmp\pv.exe 2368

Detections :
==========


¤¤¤¤¤¤¤¤¤¤ Files/folders :

C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
"C:\Program Files\WinPCap"
"C:\WINDOWS\aucfg.ini"
"C:\WINDOWS\Fonts\GRGAREF.TTF"
"C:\WINDOWS\iun6002.exe"
"C:\WINDOWS\System32\ACTSKN43.ocx"
"C:\WINDOWS\System32\drivers\etc\hosts.msn"
"C:\WINDOWS\system32\drivers\npf.sys"
"C:\WINDOWS\system32\MSINET.oca"
"C:\WINDOWS\system32\Packet.dll"
"C:\WINDOWS\system32\pthreadVC.dll"
"C:\WINDOWS\system32\WanPacket.dll"
"C:\WINDOWS\system32\wpcap.dll"


¤¤¤¤¤¤¤¤¤¤ Files/folders deleted :

Quarantine :

actskn43.ocx.Kill'em
aucfg.ini.Kill'em
GRGAREF.TTF.Kill'em
hosts.msn.Kill'em
iun6002.exe.Kill'em
MSINET.oca.Kill'em
npf.sys.Kill'em
Packet.dll.Kill'em
pthreadVC.dll.Kill'em
QTSBandwidthCache.Kill'em
WanPacket.dll.Kill'em
WinPcap.Kill'em
wpcap.dll.Kill'em

==============
host file OK !
==============

========
Registry
========
Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe
Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe
Deleted : HKCR\Install.Install
Deleted : HKCR\Install.Install.1
Deleted : HKCR\Interface\{daa37aad-f156-4c2c-ac48-3c22ef92ae2f}
Deleted : HKLM\SYSTEM\ControlSet001\Services\npf
Deleted : HKLM\SYSTEM\ControlSet002\Services\npf

============
Disk Cleaned
============

================
Prefetch cleaned
================



¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
0
fripouille68
29 déc. 2009 à 10:11
Bonjour à tout le monde,

ce matin j'ai passé de nouveau spybot, et il lit encore des dizaines de lignes nommées virtumonde. Je pense qu'il infeste encore mon pc. Voyez vous d'autres choses pour s'en débarasser ? Merci d'avances pour vos réponses.
0
Utilisateur anonyme
30 déc. 2009 à 12:13
▶ Télécharge : Gmer (by Przemyslaw Gmerek)


▶ Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

▶ Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)

Ensuite

▶ sur les lignes rouge:

▶ Services:cliques droit delete service
▶ Process:cliques droit kill process
▶ Adl ,file:cliques droit delete files
0
fripouille68
30 déc. 2009 à 17:42
Salut gen-hackman, merci encore pour ton aide.

Avec gmer, quelques petits soucis :

quand je dézippe comme tu me le demande, un scan se lance tout seul, sans que j'aie à cliquer sur l'onglet rootkit. au bout de 30 secondes environs, 4 lignes apparaissent, mais aucune en rouge. Et enfin je ne trouve pas le bloc notes dans démarrer. Excuse moi, mais je ne suis pas balaise !!!
0
fripouille68 > fripouille68
2 janv. 2010 à 15:43
Bonjour, y a t'il encore quelqu'un pour s'occuper de mon soucis ? Merci beaucoup d'avance.
0
Utilisateur anonyme
2 janv. 2010 à 19:01
salut

desole pris par les travaux ^^


Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.



▶ Télécharge :

Malwarebytes

ou :

Malwarebytes

▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

(NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

▶ Potasses le Tuto pour te familiariser avec le prg :


( cela dit, il est très simple d'utilisation ).

relance malwarebytes en suivant scrupuleusement ces consignes :

! Déconnecte toi et ferme toutes applications en cours !

▶ Lance Malwarebyte's .

Fais un examen dit "Complet" .

▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
▶ à la fin tu cliques sur "résultat" .
Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !


Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

0
Salut gen-hackman, tout d'abord merci beaucoup de m'aider, très sympa de ta part. Bonne soirée.
Voici le résultat du scan de malwarebytes :

Malwarebytes' Anti-Malware 1.43
Version de la base de données: 3480
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

02/01/2010 23:10:19
mbam-log-2010-01-02 (23-10-19).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 489772
Temps écoulé: 3 hour(s), 40 minute(s), 12 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Program Files\OUniAnsi.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
0
re,
les lignes qui sont en quarantaines dans malwarebyte's, dois je les supprimer ou les laisser ? Merci.
0
Bonjour tout le monde, suis encore infecté par virtumonde ? merci d'avance pour votre réponse.
0
Utilisateur anonyme
4 janv. 2010 à 19:53
tu as reessayé des cracks entre temps ?
0
Salut,

excuse moi mais je ne sais pas ce que c'est des craks. je n'ai rien fais depuis la dernière fois.
0
Utilisateur anonyme
4 janv. 2010 à 20:52

__________________________________________________________
=>/!\ ATTENTION /!\ Le script qui suit a été écrit spécialement cet ordinateur,<=
=>il est fort déconseillé de le transposer sur un autre ordinateur !<=====|
---------------------------------------------------------------


Toujours avec toutes les protections désactivées, fais ceci :

▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

----------------------------------------------------------
KillAll::

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"=-
"LogitechSoftwareUpdate"=-
"swg"=-
"IncrediMail"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"=-
"SigmatelSysTrayApp"=-
"LVCOMSX"=-
"Adobe Reader Speed Launcher"=-
"QuickTime Task"=-
"iTunesHelper"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=-
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=-
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Messenger\msmsgs.exe"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NPF]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NPF]

------------------------------------------------------------------

▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
▶ Quitte le Bloc Notes

▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt


0
fripouille1968 Messages postés 3 Date d'inscription lundi 24 mars 2008 Statut Membre Dernière intervention 5 janvier 2010
5 janv. 2010 à 09:12
Salut Gen-hackman,
Le rapport après combofix, merci d'avance :

ComboFix 10-01-04.01 - Laurent 05/01/2010 8:30.2.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1022.338 [GMT 1:00]
Lancé depuis: c:\documents and settings\Laurent\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Laurent\Bureau\CFScript.txt
AV: VirusKeeper 2009 Pro antivirus *On-access scanning disabled* (Updated) {165EE528-D666-4745-B14E-AA998BBEC191}
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF


((((((((((((((((((((((((((((( Fichiers créés du 2009-12-05 au 2010-01-05 ))))))))))))))))))))))))))))))))))))
.

2010-01-03 16:12 . 2010-01-04 10:35 -------- d-----w- c:\program files\trend micro
2010-01-03 16:12 . 2010-01-03 16:12 -------- d-----w- C:\rsit
2010-01-03 14:36 . 2010-01-03 14:36 -------- d-----w- c:\documents and settings\David\Application Data\AskToolbar
2010-01-03 14:36 . 2010-01-03 14:37 -------- d-----w- c:\documents and settings\David\Local Settings\Application Data\AskToolbar
2010-01-02 09:58 . 2010-01-02 09:58 -------- d-----w- c:\documents and settings\Laurent\Application Data\TeamViewer
2010-01-02 09:58 . 2010-01-02 09:58 -------- d-----w- c:\documents and settings\Laurent\temp
2009-12-31 10:28 . 2009-12-31 10:29 -------- dc-h--w- c:\windows\ie8
2009-12-31 10:09 . 2007-12-24 16:37 138384 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-12-31 10:08 . 2009-12-31 10:16 -------- d-----w- c:\documents and settings\Laurent\Application Data\HouseCall 6.6
2009-12-31 10:03 . 2009-12-31 10:05 -------- d-----w- c:\documents and settings\Laurent\Local Settings\Application Data\AskToolbar
2009-12-30 09:23 . 2009-12-30 09:23 37440 ----a-w- c:\windows\system32\drivers\pssdklbf.drv
2009-12-30 09:23 . 2009-12-30 09:23 30272 ----a-w- c:\windows\system32\drivers\pssdk31.drv
2009-12-30 09:14 . 2009-12-30 09:14 -------- d-----w- c:\documents and settings\David\Application Data\Canneverbe_Limited
2009-12-30 09:14 . 2009-12-30 09:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
2009-12-29 22:11 . 2009-12-29 22:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-12-29 22:11 . 2009-12-29 22:11 -------- d-----w- c:\program files\Fichiers communs\Nero
2009-12-29 22:04 . 2009-12-29 22:04 -------- d-----w- c:\program files\Ask.com
2009-12-29 11:16 . 1998-04-24 18:09 368912 ----a-w- c:\windows\system32\Vbar332.dll
2009-12-29 11:16 . 1998-04-24 17:40 123664 ----a-w- c:\windows\system32\Msjint35.dll
2009-12-29 11:16 . 1998-04-24 17:40 407312 ----a-w- c:\windows\system32\Msrepl35.dll
2009-12-29 11:16 . 1998-04-24 17:40 252176 ----a-w- c:\windows\system32\Msrd2x35.dll
2009-12-29 11:16 . 1998-04-24 17:40 24848 ----a-w- c:\windows\system32\Msjter35.dll
2009-12-29 11:16 . 1998-04-24 17:40 1045776 ----a-w- c:\windows\system32\Msjet35.dll
2009-12-29 11:16 . 2009-12-29 11:22 -------- d-----w- c:\program files\Virtuosa
2009-12-28 15:55 . 2009-12-28 15:55 -------- d-----w- C:\Kill'em
2009-12-28 12:39 . 2009-12-28 12:39 -------- d-----w- c:\program files\List_Kill'em
2009-12-27 15:28 . 2009-12-27 15:44 -------- d-----w- C:\Lop SD
2009-12-27 12:32 . 2010-01-04 09:50 -------- d-----w- c:\program files\Ad-Remover
2009-12-26 13:57 . 2009-12-26 13:57 -------- d-----w- c:\documents and settings\Laurent\Application Data\Malwarebytes
2009-12-26 13:57 . 2009-12-30 13:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-26 13:57 . 2009-12-26 13:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-26 13:57 . 2009-12-30 13:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-26 13:57 . 2010-01-02 16:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-26 12:52 . 2009-12-26 12:54 -------- d-----w- c:\program files\BHODemon 2
2009-12-26 10:10 . 2009-12-26 11:31 -------- d-----w- C:\VundoFix Backups
2009-12-25 19:17 . 2009-12-25 19:17 -------- d-----w- c:\documents and settings\David\Application Data\MyPhoneExplorer
2009-12-25 19:17 . 2009-12-25 19:17 -------- d-----w- c:\program files\MyPhoneExplorer
2009-12-25 10:33 . 2008-03-21 12:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-12-23 08:43 . 2002-07-17 08:05 16512 ----a-w- c:\windows\system32\drivers\ASPI32.SYS
2009-12-23 08:43 . 2001-03-17 21:34 22528 ----a-w- c:\windows\system32\WNASPI32.DLL
2009-12-23 08:43 . 2009-12-23 08:44 -------- d-----w- c:\program files\4Musics MP3 Bitrate Changer
2009-12-23 08:37 . 2009-02-03 17:01 364544 ----a-w- c:\windows\system32\MACDll.dll
2009-12-23 08:37 . 2009-01-19 17:39 246424 ----a-w- c:\windows\system32\unicows.dll
2009-12-23 08:37 . 2009-12-23 08:38 -------- d-----w- c:\program files\Monkey's Audio
2009-12-17 15:35 . 2009-12-17 15:35 -------- d-s---w- c:\documents and settings\NetworkService\Favoris
2009-12-16 16:34 . 2009-12-27 10:44 172 --sh--w- c:\windows\system32\bootrun.reg
2009-12-16 16:34 . 2009-12-27 09:47 457 --sh--w- c:\windows\system32\boothide.reg
2009-12-16 11:17 . 2009-12-29 22:17 -------- d-----w- c:\documents and settings\David\Application Data\vlc
2009-12-09 10:56 . 2009-12-09 10:56 -------- d-----w- c:\documents and settings\All Users\Application Data\3DVIA
2009-12-09 10:56 . 2009-12-09 10:56 -------- d-----w- c:\documents and settings\David\Local Settings\Application Data\3DVIA
2009-12-09 10:53 . 2007-07-19 17:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2009-12-09 10:53 . 2006-09-28 15:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2009-12-09 10:53 . 2009-12-09 10:53 -------- d-----w- c:\windows\Logs
2009-12-09 10:53 . 2009-12-09 10:53 -------- d-----w- c:\program files\Virtools

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-30 09:13 . 2008-03-18 17:20 -------- d-----w- c:\program files\CDBurnerXP
2009-12-30 09:04 . 2005-12-27 16:31 -------- d-----w- c:\program files\Ahead
2009-12-29 22:11 . 2006-02-15 16:55 -------- d-----w- c:\program files\Nero
2009-12-29 21:13 . 2005-12-27 16:31 -------- d-----w- c:\program files\Fichiers communs\Ahead
2009-12-29 21:11 . 2009-06-29 14:19 -------- d-----w- c:\documents and settings\David\Application Data\dvdcss
2009-12-29 11:16 . 2005-11-05 17:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-27 21:03 . 2007-06-28 12:47 -------- d-----w- c:\documents and settings\David\Application Data\gtk-2.0
2009-12-27 17:30 . 2008-12-28 09:53 -------- d-----w- c:\program files\Navilog1
2009-12-26 09:26 . 2009-11-12 16:05 -------- d-----w- c:\program files\Mozilla Firefox 3.6 Beta 2
2009-12-26 09:26 . 2009-11-02 11:02 -------- d-----w- c:\program files\Mozilla Firefox 3.6 Beta 1
2009-12-25 19:19 . 2006-12-12 15:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-25 12:36 . 2009-12-02 19:36 -------- d-----w- c:\documents and settings\Laurent\Application Data\vlc
2009-12-25 10:34 . 2009-12-25 10:34 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2009-12-25 10:33 . 2009-12-25 10:33 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-23 08:42 . 2008-03-12 14:58 -------- d-----w- c:\documents and settings\David\Application Data\foobar2000
2009-12-23 08:39 . 2008-03-12 14:58 -------- d-----w- c:\program files\foobar2000
2009-12-22 21:16 . 2006-02-04 10:51 -------- d-----w- c:\documents and settings\David\Application Data\Apple Computer
2009-12-16 16:41 . 2008-01-06 16:58 -------- d-----w- c:\program files\DivX
2009-12-16 16:40 . 2009-10-17 16:11 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-12-16 07:07 . 2005-12-11 09:12 530984 ----a-w- c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-16 07:05 . 2009-04-10 16:43 8224 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-12-14 19:16 . 2005-11-09 19:02 530984 ----a-w- c:\documents and settings\Laurent\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-11 17:11 . 2004-08-20 10:24 592376 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-11 17:11 . 2004-08-20 10:24 118714 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-06 11:10 . 2008-12-07 19:38 -------- d-----w- c:\documents and settings\Laurent\Application Data\dvdcss
2009-12-05 12:14 . 2009-12-05 12:14 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2009-12-05 12:14 . 2009-12-05 12:14 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2009-12-05 12:14 . 2009-12-05 12:14 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2009-12-05 12:13 . 2009-12-02 09:12 -------- d-----w- c:\program files\Sony Ericsson
2009-12-02 10:51 . 2008-03-29 10:27 308628 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-02 10:47 . 2009-12-02 10:29 -------- d-----w- c:\documents and settings\David\Application Data\Dofus 2
2009-12-02 10:30 . 2009-12-02 10:30 -------- d-----w- c:\documents and settings\David\Application Data\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
2009-12-02 10:30 . 2009-12-02 10:30 -------- d-----w- c:\documents and settings\David\Application Data\app
2009-12-02 10:29 . 2009-12-02 10:29 -------- d-----w- c:\documents and settings\David\Application Data\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
2009-12-02 09:48 . 2009-12-02 09:48 -------- d-----w- c:\program files\Dofus 2
2009-12-02 09:36 . 2009-12-02 09:36 -------- d-----w- c:\program files\Fichiers communs\MAGIX Shared
2009-12-02 09:36 . 2009-12-02 09:36 -------- d-----w- c:\program files\MAGIX
2009-12-02 09:31 . 2009-12-02 09:26 -------- d-----w- c:\documents and settings\David\Application Data\AVS4YOU
2009-12-02 09:27 . 2009-12-02 09:27 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-12-02 09:26 . 2007-07-08 09:38 -------- d-----w- c:\program files\Fichiers communs\AVSMedia
2009-12-02 09:26 . 2009-12-02 09:26 -------- d-----w- c:\program files\AVS4YOU
2009-11-28 16:18 . 2009-05-13 18:25 1118 ----a-w- c:\documents and settings\Laurent\errorlog.tmp
2009-11-28 13:15 . 2009-06-24 17:08 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-27 17:45 . 2005-11-05 17:31 -------- d-----w- c:\program files\Java
2009-11-25 16:48 . 2007-05-29 18:04 -------- d-----w- c:\program files\Opera
2009-11-16 14:37 . 2009-01-24 14:00 -------- d-----w- c:\program files\Safari
2009-11-16 14:31 . 2009-11-16 14:30 -------- d-----w- c:\program files\iTunes
2009-11-16 14:31 . 2009-11-16 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-16 14:30 . 2009-11-16 14:30 -------- d-----w- c:\program files\iPod
2009-11-16 14:30 . 2007-08-12 16:05 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-11-16 14:26 . 2009-11-16 14:25 -------- d-----w- c:\program files\QuickTime
2009-11-14 00:47 . 2009-11-14 00:47 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
2009-11-13 19:41 . 2009-11-11 14:05 -------- d-----w- c:\program files\Zylom Games
2009-11-13 19:39 . 2009-11-13 19:36 -------- d-----w- c:\program files\Zumas Revenge! - Adventure
2009-11-13 19:31 . 2007-03-28 14:27 -------- d-----w- c:\program files\RealArcade
2009-11-11 14:05 . 2009-11-11 14:05 -------- d-----w- c:\documents and settings\Laurent\Application Data\Zylom
2009-11-10 15:58 . 2009-11-10 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\PhotoMail
2009-11-10 15:58 . 2009-11-10 15:58 -------- d-----w- c:\program files\PhotoMail Maker
2009-11-10 15:56 . 2005-11-09 19:44 -------- d-----w- c:\program files\IncrediMail
2009-11-09 16:07 . 2009-11-09 16:07 -------- d-----w- c:\program files\CFWebAdvancedU
2009-11-09 15:59 . 2009-03-27 10:33 -------- d-----w- c:\program files\Messenger Plus! Live
2009-10-29 07:42 . 2004-08-20 10:24 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:39 . 2004-08-20 10:24 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:39 . 2004-08-20 10:23 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-03 23:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-17 08:42 . 2009-10-17 08:42 1607184 ----a-w- c:\windows\system32\Aquarium Exotique.scr
2009-10-13 10:33 . 2004-08-20 10:23 271360 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:39 . 2004-08-20 10:24 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:39 . 2004-08-20 10:24 150528 ----a-w- c:\windows\system32\rastls.dll
2009-10-11 03:17 . 2008-11-28 09:21 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-11 05:50 . 2009-08-11 05:50 15098 ----a-w- c:\program files\license.rtf
2009-08-11 05:30 . 2009-08-11 05:30 4012328 ----a-w- c:\program files\opera.dll
2009-08-11 05:30 . 2009-08-11 05:30 121128 ----a-w- c:\program files\opera.exe
2009-08-11 05:26 . 2009-08-11 05:26 653419 ----a-w- c:\program files\encoding.bin
2009-07-16 13:13 . 2009-06-18 17:15 168 ----a-w- c:\program files\operaprefs_default.ini
2009-06-17 13:41 . 2009-06-17 13:41 3870 ----a-w- c:\program files\lngcode.txt
2008-06-09 09:17 . 2008-06-09 09:17 301 ----a-w- c:\program files\c3nform.vxml
2006-03-29 10:14 . 2002-12-08 18:04 108 ----a-w- c:\program files\Mess with MSN Messenger skins, nicknames, add-ons, bots and secrets.url
2006-03-29 10:14 . 2001-10-03 20:22 161 ----a-w- c:\program files\read1st.txt
2004-02-26 12:35 . 2004-02-26 12:35 7904 ----a-w- c:\program files\html40_entities.dtd
1999-12-09 09:19 . 2006-01-02 15:34 147456 ----a-w- c:\program files\Zip32.dll
.

------- Sigcheck -------

[-] 2008-04-14 . 5158A1C542A355B3A67E59538BBD894D . 3200000 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . 5158A1C542A355B3A67E59538BBD894D . 3200000 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . D0288319660EDCFED07C7E74C4EA38A5 . 1037312 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2007-06-13 . B795475444D6D57A572C14B9E1A29839 . 1037312 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[7] 2004-08-05 . 4C33E5B9A6197B6ED215F6CFBA0A2DAA . 1036288 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-09-30 09:40 1182088 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-30 1182088]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-30 1182088]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Magentic"="c:\progra~1\Magentic\bin\Magentic.exe" [2006-11-19 319532]
"X'nBeep"="c:\program files\X'nBeep 1.1\XnBeep.exe" [2007-01-06 1067520]
"CursorXP"="c:\program files\CursorXP.exe" [2005-01-19 128000]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-03-18 630784]
"Google Update"="c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-27 133104]
"Cld2000.exe"="c:\program files\Calendrier\Cld2000.exe" [2009-04-16 2993664]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-09 344064]
"DrvIcon"="c:\program files\Vista Drive Icon\DrvIcon.exe" [2007-07-04 45056]
"VirusKeeper"="c:\program files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe" [2009-09-22 3768688]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

c:\documents and settings\Laurent\Menu D‚marrer\Programmes\D‚marrage\
DateInTray.lnk - c:\program files\DateInTray\DateInTray.exe [2005-12-12 78848]
RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
WiFi Station.lnk - c:\program files\Hercules\WiFi Station\WifiStation.exe [2009-10-8 654336]

c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-28 19:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magentic]
2006-11-19 12:23 319532 ----a-w- c:\progra~1\Magentic\bin\Magentic.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
2007-09-06 12:53 169264 ----a-w- c:\program files\Maxtor\OneTouch Status\MaxMenuMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"LogitechVideoTray"=c:\program files\Logitech\Video\LogiTray.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImLc.exe"=
"c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImPackr.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Codemasters\\Worms 4 Mayhem Demo\\Worms 4 Mayhem Demo.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Commandos II\\comm2.exe"=
"c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Documents and Settings\\David\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\umi.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\VideoSpin.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Mindscape\\Mission Président - Geo-Political Simulator\\MISSION.EXE"=
"c:\\Program Files\\Ivicam\\backsurvey.exe"=
"c:\\Program Files\\Icecast2 Win32\\Icecast2win.exe"=
"c:\\Program Files\\SHOUTcast\\sc_serv.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\WINDOWS\\system32\\tftp.exe"=

R2 MSSQL$RADIONOMY536765;SQL Server (RADIONOMY536765);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [27/05/2009 02:27 29262680]
R2 vkservice;VirusKeeper antivirus/antispyware;c:\program files\AxBx\VirusKeeper 2009 Pro\vk_service.exe [22/05/2008 14:27 1119576]
S2 gupdate1c981f2ac729e12;Google Update Service (gupdate1c981f2ac729e12);c:\program files\Google\Update\GoogleUpdate.exe [29/01/2009 10:19 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [23/12/2009 09:43 16512]
S3 DCamUSBUVT;ICM532A;c:\windows\system32\drivers\usbuvt.sys [11/11/2005 10:13 95232]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [05/12/2009 13:14 13224]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [23/09/2009 13:50 238960]
S3 PsSdk31;PsSdk31;c:\windows\system32\drivers\pssdk31.drv [30/12/2009 10:23 30272]
S3 PsSdkLBF;PsSdkLBF;c:\windows\system32\drivers\pssdklbf.drv [30/12/2009 10:23 37440]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E4066320-E4AE-11CF-B1B0-00AA00BBAD66}]
2009-03-08 03:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contenu du dossier 'Tâches planifiées'

2009-12-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-01-04 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8167816979.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]

2010-01-05 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-02-21 16:10]

2010-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-29 09:19]

2010-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-29 09:19]

2010-01-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1006Core.job
- c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-27 09:17]

2010-01-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1006UA.job
- c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-27 09:17]

2010-01-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1007Core.job
- c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-06 18:05]

2010-01-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1007UA.job
- c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-06 18:05]

2005-11-10 c:\windows\Tasks\Rappel d'abonnement 1 auprès de l'ISP.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-20 02:34]

2010-01-05 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-09-30 09:40]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://mystart.incredimail.com/
uSearchMigratedDefaultURL = hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearch Page =
uInternet Connection Wizard,ShellNext = hxxp://www.dell.fr/myway
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://www.cherche.us/keyword/%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Recherche avec cherche.us - c:\documents and settings\Laurent\scriptjava.html
Trusted Zone: chat-land.org
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} - hxxp://m6video.m6.fr/1click/install/files/installer2.cab
DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} - hxxp://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} - hxxp://www.3dfunchal.com/resources/te/TE.cab
DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} - hxxp://www.powerchallenge.com/applet/PowerLoader.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game08.zylom.com/activex/zylomgamesplayer.cab
DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - hxxp://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\documents and settings\Laurent\Application Data\Mozilla\Firefox\Profiles\nhizwkb4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://mystart.incredimail.com/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=PMXMAS09FFAB&search=
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\np32dsw.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\NPOFFICE.DLL
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nppdf32.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nppl3260.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nprjplug.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicdclient.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npredoute.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Opera\program\plugins\npgcplug.dll
FF - plugin: c:\program files\Opera\program\plugins\npmio.dll
FF - plugin: c:\program files\Opera\program\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\Rawflow\npicdclient.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCE08D86A-A41A-410A-943C-13BABB7DC474", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA9EDC9ED-603A-4F3F-BBEA-59C8853A3236", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID90D10942-D952-4863-9DD6-A2BDBBAD456E", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0ECEE744-7B69-4912-AB91-AE76D61ECB04", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF25635B2-1AB9-47B5-88D1-8877B22C86DE", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID27B7F812-4159-45B9-A389-B7A118A58DE4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF849DF29-393B-4F8B-99D1-117A70D66FC7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBF1E9C3D-637C-4171-BD12-28A7360B879A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDDE1C0601-7947-4D7F-A6E5-E68BF6BA1E37", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EA0DCCE-4D98-4876-9C6A-E5C563D0820A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID446462BA-2AAD-4C88-BC63-5210E2F31465", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0862E368-A40E-4E55-83EB-FBC5571BABA4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDD2A96E3C-FFB3-4D38-9AC3-B127527BEA35", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4B05B39A-9DDC-4650-A7F8-D5B134E5FFE5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC8E2574A-7BCE-4B93-A22E-61831DFD6DB8", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID659796C0-8B5D-48D7-A4EB-7E6874E26274", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID78071AB5-E729-414E-8D02-9C1D034F82E7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCC3F71E1-17F3-4C5B-997D-44CA56943197", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE67D5C78-B2D4-4BA0-8D69-1C7AF4BB08B5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFC5F3D7A-D321-412C-8A5D-9AD0C8041941", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6EC5CD16-81BC-4515-9EDD-9265C906F56E", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID67CFB2C5-E491-4395-977B-CD45E4124655", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID73600569-52E6-4760-8BAB-B68202937D98", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB02EBD42-6885-401A-9389-E089F7DDC872", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBAE5CB8C-4075-4743-B2E4-78DA8D8CDC64", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID28B07B04-DA99-4FD3-BF27-4972F2B8142B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D53448F-D12B-4102-8CE2-697DAE8D6643", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE3266A47-A141-47B8-AAA8-5F16FB4F8CCD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB33AB7AF-76D7-4B1C-B709-5D6BF9E7B1C7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID153B7451-0BB5-4B37-95C0-44D89E2F1F2B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID3BBE8E21-0D3D-4BAA-AC6F-C7BCEF750849", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9B5B4F2D-A7D9-4329-B0FE-92B301A8CAAD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA5C42921-8CD0-4924-97C3-01B5B0610BC6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID06969252-F90F-4CF2-9074-33772EB64859", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFBF37655-1236-4C0D-96C5-F94E1724841B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC1A3F035-B68F-4B2B-9FD5-E36DAAAF26DD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID368F3685-543E-4812-9FDE-96E097E453FC", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID43969873-56AA-4113-84CB-4AB2AEB9AA31", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA205DD80-63D4-4E41-B785-26EC3D90B97B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID068D43E7-7551-4A2F-AE96-4A38A9AD1953", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF443E9CB-9EEC-456E-8AE7-F3102D5CD47D", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE36A7B16-645D-4261-BFF8-3A7E69C5F7A5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID379805E3-E0E2-40DC-B51B-6DC1AE5802AA", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF6240D69-A06D-44A1-8003-8496CCEF2C53", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID26C3113D-5A71-4F1B-A2CB-BE59E1279DDA", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID92B97F2B-7565-4CE9-9AC7-0598DFD731F8", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID2AA5E7CF-9696-42F0-B76A-8655296EADF2", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0AAACE0B-ACEF-4781-83F4-BFB52EEC995A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D56FF58-A39D-4E8C-A40B-2E3711251772", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID946121C2-11F1-49DD-A7E3-CF793DE827A4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB853303D-1BAB-43F3-9D7D-101D0DA8E7A5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9E578247-FE29-4F8C-8202-A24A5688CF2A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6D065A8F-FFC0-4A0F-B863-1D724B8C786B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4451D291-6940-42CE-9D3C-CA1D4C96549C", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID064B722D-079D-4EBB-B3CF-9FCBF64FFF5D", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID38F8AB0F-5DFB-43D9-889E-8717CC4AB59B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EC68CD1-0EF1-4CB9-9EF1-3D64AB266149", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID44F96B27-CFAD-41E1-83A1-6B28040C3BDE", "AllAccess");
.
- - - - ORPHELINS SUPPRIMES - - - -

AddRemove-Ask Toolbar_is1 - c:\program files\AskBarDis\unins000.exe
AddRemove-GamesBar - c:\program files\GamesBar\uninst.exe
AddRemove-ViewpointMediaPlayer - c:\program files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe
AddRemove-WinPcapInst - c:\program files\WinPcap\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-05 08:50
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdk31]
"ImagePath"="\??\c:\windows\system32\Drivers\pssdk31.drv"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdkLBF]
"ImagePath"="\??\c:\windows\system32\Drivers\pssdklbf.drv"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(1032)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3232)
c:\program files\RocketDock\RocketDock.dll
c:\windows\system32\ntshrui.dll
c:\program files\CurXP0.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\stobject.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\progra~1\SPYBOT~1\SDHelper.dll
c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXEV.DLL
c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\progra~1\ACEMEG~1\SystemS\avimszh.dll
c:\progra~1\ACEMEG~1\SystemS\avizlib.dll
c:\progra~1\ACEMEG~1\SystemS\Qpeg32.dll
c:\progra~1\ACEMEG~1\SystemS\ASUS\asusasv1.dll
c:\progra~1\ACEMEG~1\SystemS\ASUS\asusasv2.dll
c:\progra~1\ACEMEG~1\SystemS\Aware\icmw_32.dll
c:\progra~1\ACEMEG~1\SystemS\BROOKT~1\btvvc32.drv
c:\progra~1\ACEMEG~1\SystemS\Core\COREPN~1.DLL
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\program files\Maxtor\Sync\SyncServices.exe
c:\program files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wscntfy.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\LVComsX.exe
c:\progra~1\Magentic\bin\MgApp.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\AxBx\VirusKeeper 2009 Pro\vk_watchop.exe
.
**************************************************************************
.
Heure de fin: 2010-01-05 09:06:35 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-01-05 08:06
ComboFix2.txt 2009-12-27 12:11

Avant-CF: 75 408 936 960 octets libres
Après-CF: 77 320 470 528 octets libres

- - End Of File - - 4D03680E2ED4D2EDA5FE2B7B3A7C6919
0
Utilisateur anonyme
5 janv. 2010 à 21:21
hello desinstalle ASToolbar , Ask.com puis

Télécharge OTL de OLDTimer

enregistre le sur ton Bureau.

▶ Double clic ( pour vista => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.

▶ Coche les 2 cases Lop et Purity

▶ Coche la case devant scan all users

▶ règle-le sur "60 Days"

▶ dans la colonne de gauche , mets tout sur all

ne modifie pas ceci :

"files created whithin" et "files modified whithin"


▶Clic sur Run Scan.

A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

▶▶▶ NE LE POSTE PAS SUR LE FORUM

Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

▶ Clique sur Parcourir et cherche le fichier ci-dessus.

▶ Clique sur Ouvrir.

▶ Clique sur "Cliquez ici pour déposer le fichier".

Un lien de cette forme :

http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

est ajouté dans la page.

▶ Copie ce lien dans ta réponse.

▶▶ Tu feras la meme chose avec le "Extra.txt".
0
re,

je n'ai pas astoolbar, ni ask.com donc pas de désinstallation je te poste rapport OTL txt :

http://www.cijoint.fr/cjlink.php?file=cj201001/cijoaD1xc3.txt

Par contre je n'ai pas de fichier Extra.txt comme tu me le demande.

Merci d'avance.
0
Salut gen-hackman, excuse moi j'avais chercher dans les programmes. Effectivement j'avais bien Ask.com dans programme files. Je l'ai supprimé et j'ai refais la manip avec OTL voilà le nouveau rapport :

http://www.cijoint.fr/cjlink.php?file=cj201001/cij7b5uK1A.txt

Merci beaucoup
0
Salut gen hackman, voilà le rapport :

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{14f0d511-36a2-41ca-ae01-ba4f87282c97} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14f0d511-36a2-41ca-ae01-ba4f87282c97}\ deleted successfully.
C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll moved successfully.
Unable to set value : HKU\S-1-5-21-2328322012-3734155301-851506153-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page_bak| /E!
Prefs.js: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15 removed from extensions.enabledItems
Prefs.js: "Ask" removed from browser.search.order.1
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B56A7D7D-6927-48C8-A975-17DF180C71AC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B56A7D7D-6927-48C8-A975-17DF180C71AC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_USERS\S-1-5-21-2328322012-3734155301-851506153-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8}\ deleted successfully.
File C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll not found.
Registry value HKEY_USERS\S-1-5-21-2328322012-3734155301-851506153-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Recherche avec cherche.us\ deleted successfully.
C:\Documents and Settings\Laurent\scriptjava.html moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}\ not found.
Starting removal of ActiveX control {00000055-9980-0010-8000-00AA00389B71}
C:\WINDOWS\Downloaded Program Files\fhg.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000055-9980-0010-8000-00AA00389B71}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000055-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{00000055-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000055-9980-0010-8000-00AA00389B71}\ not found.
Starting removal of ActiveX control {09CC593B-E8A9-4491-927D-A3E33534DDD4}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\ not found.
Starting removal of ActiveX control {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)\ not found.
Starting removal of ActiveX control {BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
C:\WINDOWS\Downloaded Program Files\McGDMgr.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\ not found.
Starting removal of ActiveX control {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}
C:\WINDOWS\Downloaded Program Files\ZylomGamesPlayer.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
Starting removal of ActiveX control Microsoft XML Parser for Java
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:C3759076 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:8FF81EB0 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:981884E7 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:20FFCF0B deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:82C50600 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:0656FCD2 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:59846E5E deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:00F7B10F deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:33DB8278 deleted successfully.
========== FILES ==========
C:\Documents and Settings\Laurent\Local Settings\Application Data\AskToolbar folder moved successfully.
C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}\x86\x86 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}\x86 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} folder moved successfully.
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job moved successfully.
C:\WINDOWS\System32\scvhost.ini moved successfully.
C:\Documents and Settings\Administrator\Application Data\21cnPPS folder moved successfully.
C:\Documents and Settings\All Users\Application Data\BOONTY\Licenses folder moved successfully.
C:\Documents and Settings\All Users\Application Data\BOONTY folder moved successfully.
C:\Documents and Settings\All Users\Application Data\humyo.com\humyo\logs folder moved successfully.
C:\Documents and Settings\All Users\Application Data\humyo.com\humyo folder moved successfully.
C:\Documents and Settings\All Users\Application Data\humyo.com folder moved successfully.
C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357} folder moved successfully.
C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} folder moved successfully.
C:\Documents and Settings\David\Application Data\app folder moved successfully.
C:\Documents and Settings\David\Application Data\AskToolbar folder moved successfully.
C:\Documents and Settings\David\Application Data\www.TheXSoft.com\Radio Stream Player\1.5.0.10\FastTranslations folder moved successfully.
C:\Documents and Settings\David\Application Data\www.TheXSoft.com\Radio Stream Player\1.5.0.10 folder moved successfully.
C:\Documents and Settings\David\Application Data\www.TheXSoft.com\Radio Stream Player folder moved successfully.
C:\Documents and Settings\David\Application Data\www.TheXSoft.com folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\resources-processed.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\resources-loadingwindow.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\numerics.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\highscoregems.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\gems.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\gem-fragments.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\fonts.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\bonusfonts.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\boardfonts.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\board-red-processed.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\board-processed.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\board-particles.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\board-empty-processed.frc folder moved successfully.
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrateur
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Administrator

User: All Users

User: David
->Temp folder emptied: 224912 bytes
->Temporary Internet Files folder emptied: 1656522 bytes
->Java cache emptied: 71069584 bytes
->FireFox cache emptied: 17386060 bytes
->Google Chrome cache emptied: 6769710 bytes
->Apple Safari cache emptied: 68411074 bytes
->Opera cache emptied: 5197465 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: Invité
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Opera cache emptied: 358515 bytes

User: Laurent
->Temp folder emptied: 19696409 bytes
->Temporary Internet Files folder emptied: 1593250 bytes
->Java cache emptied: 75075871 bytes
->FireFox cache emptied: 151067741 bytes
->Google Chrome cache emptied: 394176837 bytes
->Apple Safari cache emptied: 750534 bytes
->Opera cache emptied: 85444599 bytes

User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->FireFox cache emptied: 4095466 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 65670 bytes

User: Propriétaire
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 664 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 281556 bytes

Total Files Cleaned = 862,00 mb


OTL by OldTimer - Version 3.1.20.1 log created on 01062010_222622

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


D'après toi y aura t'il encore beaucoup de manip à faire ? Merci de ton aide.
0
Utilisateur anonyme
5 janv. 2010 à 23:03
tu n'as pas ceci ?

c:\program files\Ask.com
0
Utilisateur anonyme
6 janv. 2010 à 20:55
▶ Télécharge Zeb-Restoreet enregistre ce fichier sur le bureau.

▶-Clic droit Zeb-Restore.zip ==> Extraire tout choisis comme lieu d'enregistrement le bureau.

▶-Ouvre le dossier ZR_1.0.0.37 ==> double clic sur Zeb-Restore.exe

▶- Coche la case devant : sites de confiance

▶- Ne coche aucune autre case

▶-Clique sur Restaurer

▶-Redémarre ton PC

ensuite :

▶ Double clic sur OTL.exe pour le lancer.


▶Copie la liste qui se trouve en gras ci-dessous,

▶ colle-la dans la zone sous Customs Scans/Fixes :

:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe

:OTL
IE - HKLM\..\URLSearchHook: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC)
IE - HKU\S-1-5-21-2328322012-3734155301-851506153-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..browser.search.order.1: "Ask"
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - No CLSID value found.
O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKU\S-1-5-21-2328322012-3734155301-851506153-1006\..\Toolbar\WebBrowser: (SHOUTcast Radio Toolbar) - {0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC)
O3 - HKU\S-1-5-21-2328322012-3734155301-851506153-1006\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Recherche avec cherche.us - C:\Documents and Settings\Laurent\scriptjava.html ()
O9 - Extra Button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - Reg Error: Key error. File not found
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} http://m6video.m6.fr/1click/install/files/installer2.cab (Reg Error: Key error.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://game08.zylom.com/activex/zylomgamesplayer.cab (Zylom Games Player)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} https://www.oracle.com/java/technologies/ (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
@Alternate Data Stream - 279 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C3759076
@Alternate Data Stream - 229 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8FF81EB0
@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:981884E7
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:20FFCF0B
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:82C50600
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0656FCD2
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59846E5E
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:00F7B10F
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:33DB8278

:files
C:\Documents and Settings\Laurent\Local Settings\Application Data\AskToolbar
C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\System32\scvhost.ini
C:\Documents and Settings\Administrator\Application Data\21cnPPS
C:\Documents and Settings\All Users\Application Data\BOONTY
C:\Documents and Settings\All Users\Application Data\humyo.com
C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
C:\Documents and Settings\David\Application Data\app
C:\Documents and Settings\David\Application Data\AskToolbar
C:\Documents and Settings\David\Application Data\www.TheXSoft.com
C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx

:commands
[emptytemp]
[start explorer]
[reboot]


▶ Clique sur RunFix pour lancer la suppression.


▶ Poste le rapport.
0
Utilisateur anonyme
6 janv. 2010 à 23:18
quels soucis persistent ?
0
Salut gen hackman, voilà ce matin j'ai passé spybot. Au début du scan il détecte 850000 lignes à scaner. De la ligne 150000 à la ligne 760000 il me lit (en bas à gauche) des lignes qui s'intitulent virtumonde, virtumonde dll, et virtumonde dll. Est ce normal, ou est ce encore le virus qui traine ?
A la fin du scan il m'a donné les problèmes suivant à corriger : Adviva, bluestreak, doubleclick, fastclick, Mediaplex et tradedoubler que j'ai corrigé.

Merci beaucoup, bonne journée.
0