voici le rapport :
-----------------------[ Lop S&D 4.2.2-0 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Charlotte ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 08/07/2008 | 22:58:01,26 ] [ PC : GUYANE ]
[ MAJ : 06-07-2008 | 10:55 ]
-------------[ Listing des dossiers dans Application Data ]------------
[07/12/2006|19:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[12/03/2008|12:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[01/06/2008|18:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bags Plus Online Chin
[16/03/2006|18:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BVRP Software
[26/05/2007|13:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[12/07/2005|03:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[14/05/2008|10:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ENJOY Plus!
[23/10/2006|18:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[04/07/2007|18:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[28/06/2007|22:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[20/05/2008|21:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[07/05/2008|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[16/03/2006|21:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[27/09/2005|23:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[23/02/2008|19:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[12/03/2008|12:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[11/07/2006|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[15/07/2007|21:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[14/05/2008|18:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[26/05/2008|17:12] C:\DOCUME~1\CHARLO~1\APPLIC~1\AccurateRip
[27/04/2008|11:02] C:\DOCUME~1\CHARLO~1\APPLIC~1\Adobe
[10/06/2007|11:48] C:\DOCUME~1\CHARLO~1\APPLIC~1\AdobeUM
[12/03/2008|12:22] C:\DOCUME~1\CHARLO~1\APPLIC~1\Apple Computer
[24/02/2007|19:35] C:\DOCUME~1\CHARLO~1\APPLIC~1\Creative
[12/07/2005|03:09] C:\DOCUME~1\CHARLO~1\APPLIC~1\desktop.ini
[30/03/2008|16:43] C:\DOCUME~1\CHARLO~1\APPLIC~1\dvdcss
[14/05/2008|10:25] C:\DOCUME~1\CHARLO~1\APPLIC~1\ENJOY Plus!
[07/02/2007|13:43] C:\DOCUME~1\CHARLO~1\APPLIC~1\Google
[05/07/2007|16:26] C:\DOCUME~1\CHARLO~1\APPLIC~1\Grisoft
[04/02/2007|18:31] C:\DOCUME~1\CHARLO~1\APPLIC~1\Help
[07/01/2007|13:16] C:\DOCUME~1\CHARLO~1\APPLIC~1\Identities
[03/05/2008|18:37] C:\DOCUME~1\CHARLO~1\APPLIC~1\InstallShield
[22/06/2008|14:15] C:\DOCUME~1\CHARLO~1\APPLIC~1\LimeWire
[31/03/2007|12:21] C:\DOCUME~1\CHARLO~1\APPLIC~1\Macromedia
[22/06/2008|17:32] C:\DOCUME~1\CHARLO~1\APPLIC~1\Microsoft
[30/03/2008|14:54] C:\DOCUME~1\CHARLO~1\APPLIC~1\Mozilla
[14/05/2008|10:27] C:\DOCUME~1\CHARLO~1\APPLIC~1\MSN Pictures Displayer
[25/06/2008|18:49] C:\DOCUME~1\CHARLO~1\APPLIC~1\Online gram
[21/05/2008|11:40] C:\DOCUME~1\CHARLO~1\APPLIC~1\SecuROM
[08/06/2007|19:28] C:\DOCUME~1\CHARLO~1\APPLIC~1\Sun
[12/03/2008|12:04] C:\DOCUME~1\CHARLO~1\APPLIC~1\Ulead Systems
[02/06/2008|19:12] C:\DOCUME~1\CHARLO~1\APPLIC~1\vlc
[12/07/2005|03:09] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[11/07/2005|15:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[07/12/2006|22:30] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[15/08/2007|18:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[24/09/2005|22:23] C:\DOCUME~1\Sylvie\APPLIC~1\Adobe
[12/07/2005|03:09] C:\DOCUME~1\Sylvie\APPLIC~1\desktop.ini
[11/09/2005|15:30] C:\DOCUME~1\Sylvie\APPLIC~1\Help
[16/07/2005|00:04] C:\DOCUME~1\Sylvie\APPLIC~1\Identities
[10/10/2005|23:16] C:\DOCUME~1\Sylvie\APPLIC~1\Macromedia
[08/10/2005|14:08] C:\DOCUME~1\Sylvie\APPLIC~1\Microsoft
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[08/07/2008 22:00][--ah-----] C:\WINDOWS\tasks\AF28E768907B98A0.job
[08/07/2008 22:43][--a------] C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1183063346.job
[08/07/2008 22:36][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
AF28E768907B98A0.job <--> c:\docume~1\charlo~1\applic~1\online~1\DVDMEALBODY.exe
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[10/09/2005|23:07] C:\Program Files\Adobe
[19/05/2007|10:36] C:\Program Files\Ahead
[02/05/2006|20:07] C:\Program Files\Alwil Software
[24/12/2006|14:33] C:\Program Files\Audible
[19/11/2007|21:58] C:\Program Files\CDex_150
[22/07/2005|21:26] C:\Program Files\C-Media 3D Audio
[26/05/2007|13:29] C:\Program Files\Creative
[24/12/2006|14:30] C:\Program Files\Creative Installation Information
[03/11/2006|21:32] C:\Program Files\DivX
[21/05/2008|11:34] C:\Program Files\EA GAMES
[07/04/2008|22:47] C:\Program Files\Fichiers communs
[07/02/2007|13:04] C:\Program Files\Google
[04/07/2007|18:31] C:\Program Files\Grisoft
[22/07/2005|21:35] C:\Program Files\Hewlett-Packard
[17/06/2008|19:07] C:\Program Files\InstallShield Installation Information
[10/06/2008|20:43] C:\Program Files\InterActual
[19/04/2008|09:55] C:\Program Files\Internet Explorer
[09/05/2007|14:58] C:\Program Files\Java
[04/10/2006|09:06] C:\Program Files\Messenger
[12/05/2008|14:42] C:\Program Files\Messenger Plus! Live
[11/07/2005|15:22] C:\Program Files\microsoft frontpage
[15/07/2005|20:31] C:\Program Files\Microsoft Office
[15/07/2005|20:32] C:\Program Files\Microsoft Visual Studio
[04/10/2006|09:06] C:\Program Files\Movie Maker
[11/07/2005|15:18] C:\Program Files\MSN
[24/07/2005|23:54] C:\Program Files\MSN Apps
[11/07/2005|15:18] C:\Program Files\MSN Gaming Zone
[19/08/2007|12:30] C:\Program Files\MSXML 4.0
[04/10/2006|09:06] C:\Program Files\NetMeeting
[19/03/2007|19:57] C:\Program Files\NoteWorthy Composer
[01/06/2008|18:56] C:\Program Files\Online gram
[16/06/2007|21:41] C:\Program Files\Outlook Express
[16/07/2005|21:10] C:\Program Files\RegClean32
[11/07/2005|15:20] C:\Program Files\Services en ligne
[22/07/2005|21:27] C:\Program Files\SiSLan
[15/07/2005|20:29] C:\Program Files\Snapshot Viewer
[12/03/2008|11:46] C:\Program Files\Ulead Systems
[11/07/2005|15:31] C:\Program Files\Uninstall Information
[15/07/2007|21:53] C:\Program Files\Windows Live
[12/03/2008|11:48] C:\Program Files\Windows Media Components
[07/12/2006|22:29] C:\Program Files\Windows Media Connect 2
[07/12/2006|22:14] C:\Program Files\Windows Media Player
[28/09/2005|22:30] C:\Program Files\Windows NT
[16/07/2005|20:58] C:\Program Files\WindowsUpdate
[11/07/2005|15:22] C:\Program Files\xerox
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[04/01/2007|22:43] C:\Program Files\Fichiers communs\Adobe
[24/12/2006|14:30] C:\Program Files\Fichiers communs\Creative
[15/07/2005|20:32] C:\Program Files\Fichiers communs\Designer
[22/07/2005|21:32] C:\Program Files\Fichiers communs\Hewlett-Packard
[12/03/2008|11:47] C:\Program Files\Fichiers communs\InstallShield
[09/05/2007|14:11] C:\Program Files\Fichiers communs\Java
[03/05/2008|18:39] C:\Program Files\Fichiers communs\Microsoft Shared
[11/07/2005|15:19] C:\Program Files\Fichiers communs\MSSoap
[12/07/2005|03:10] C:\Program Files\Fichiers communs\ODBC
[12/07/2005|03:10] C:\Program Files\Fichiers communs\SpeechEngines
[16/06/2007|21:41] C:\Program Files\Fichiers communs\System
[12/03/2008|11:47] C:\Program Files\Fichiers communs\Ulead Systems
[07/04/2008|22:47] C:\Program Files\Fichiers communs\WindowsLiveInstaller
---------------------------[ Process ]--------------------------
... 49
iexplore.exe ~ [172]
iexplore.exe ~ [328]
iexplore.exe ~ [2504]
iexplore.exe ~ [296]
----------------------[ Recherche avec S_Lop ]---------------------
C:\DOCUME~1\CHARLO~1\LOCALS~1\Temp\bisA.exe
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bags Plus Online Chin
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bags Plus Online Chin\Plan Mapi.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bags Plus Online Chin\slow style.exe
C:\DOCUME~1\CHARLO~1\APPLIC~1\online~1
C:\DOCUME~1\CHARLO~1\APPLIC~1\online~1\drive dupe wma ante.exe
C:\DOCUME~1\CHARLO~1\APPLIC~1\online~1\DVD MEAL BODY.exe
C:\DOCUME~1\CHARLO~1\APPLIC~1\online~1\niujptnc.exe
C:\DOCUME~1\CHARLO~1\APPLIC~1\online~1\oauasttc.exe
C:\DOCUME~1\CHARLO~1\APPLIC~1\online~1\Thunkabout.exe
C:\DOCUME~1\CHARLO~1\APPLIC~1\online~1\umkxprdl.exe
C:\Program Files\online~1
C:\WINDOWS\Prefetch\SLOW STYLE.EXE-026B7F14.pf
C:\WINDOWS\Prefetch\DVD MEAL BODY.EXE-099768F6.pf
C:\WINDOWS\Prefetch\THUNKABOUT.EXE-13959164.pf
C:\DOCUME~1\CHARLO~1\Cookies\charlotte@banner.casinoking[2].txt
C:\DOCUME~1\CHARLO~1\Cookies\charlotte@casinoking[1].txt
C:\DOCUME~1\CHARLO~1\Cookies\charlotte@adopt.euroclick[2].txt
C:\DOCUME~1\CHARLO~1\Cookies\charlotte@32vegas[2].txt
C:\DOCUME~1\CHARLO~1\Cookies\charlotte@banner.32vegas[2].txt
C:\DOCUME~1\CHARLO~1\Cookies\charlotte@banner.32vegas[3].txt
C:\WINDOWS\Tasks\AF28E768907B98A0.job
----------------------[ Verification du Registre ]----------------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Heckbuild"="C:\\DOCUME~1\\CHARLO~1\\APPLIC~1\\ONLINE~1\\Thunkabout.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Online chin internet bolt"="C:\\Documents and Settings\\All Users\\Application Data\\Bags Plus Online Chin\\slow style.exe"
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts MODIFIE
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww
/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww
/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww
/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww
/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww
/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww
/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww
/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww
/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww
/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww
/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww
/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww
/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww
/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww
/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww
/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww
/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww
/iw.winsoftware.com ## added by CiD
-> 72 ( 70 ## added by CiD )
/!\ 1 Not 127.0.0.1 !!
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-08 23:01:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
C:\documents and settings\charlotte\local settings\application data\gucociw.exe [228]
scanning hidden files ...
scan completed successfully
hidden processes: 1
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
C:\WINDOWS\Pack.epk
C:\WINDOWS\System32\nvs2.inf
C:\DOCUME~1\CHARLO~1\LOCALS~1\APPLIC~1\gucociw.dat
C:\DOCUME~1\CHARLO~1\LOCALS~1\APPLIC~1\gucociw.exe
C:\DOCUME~1\CHARLO~1\LOCALS~1\APPLIC~1\gucociw_nav.dat
C:\DOCUME~1\CHARLO~1\LOCALS~1\APPLIC~1\gucociw_navps.dat
C:\WINDOWS\Prefetch\GUCOCIW.EXE-2DB7AE4A.pf
C:\DOCUME~1\CHARLO~1\LOCALS~1\APPLIC~1\piralu.dat
C:\DOCUME~1\CHARLO~1\LOCALS~1\APPLIC~1\piralu_nav.dat
C:\DOCUME~1\CHARLO~1\LOCALS~1\APPLIC~1\piralu_navps.dat
C:\WINDOWS\System32\qlbaqkxa.dat
C:\WINDOWS\System32\qlbaqkxa_navup.dat
C:\WINDOWS\System32\vrrweg.dat
C:\WINDOWS\System32\vrrweg_navup.dat
C:\WINDOWS\System32\ycwxvqu.dat
C:\WINDOWS\System32\ycwxvqu_nav.dat
C:\WINDOWS\System32\ycwxvqu_navps.dat
C:\WINDOWS\System32\ycwxvqu_navup.dat
[b]! EGDACCESS !
/b
C:\WINDOWS\system32\aHiilUvw.ini2
C:\WINDOWS\system32\aHiilUvw.ini
C:\WINDOWS\system32\fLUFNqss.ini2
C:\WINDOWS\system32\fLUFNqss.ini
C:\WINDOWS\system32\GQprCJlm.ini2
C:\WINDOWS\system32\GQprCJlm.ini
C:\WINDOWS\system32\MVwHQXyb.ini2
C:\WINDOWS\system32\MVwHQXyb.ini
C:\WINDOWS\system32\sAceOqru.ini2
C:\WINDOWS\system32\sAceOqru.ini
C:\WINDOWS\system32\TAIPqqss.ini2
C:\WINDOWS\system32\TAIPqqss.ini
[b]! VUNDO Possible !
/b
[F:2006][D:119]-> C:\DOCUME~1\CHARLO~1\LOCALS~1\Temp
[F:73][D:0]-> C:\DOCUME~1\CHARLO~1\Cookies
[F:1202][D:73]-> C:\DOCUME~1\CHARLO~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 23:04:24,70 ]----------------------