--------------------\\ Lop S&D 4.2.4-2 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 4000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : lulu ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 080908-0] 4.8.1229 (Activated)
"C:\Lop SD" ( MAJ : 08-09-2008|21:40 )
Option : [1] ( 08/09/2008|21:29 )
--------------------\\ Listing des dossiers dans APPLIC~1
[30/06/2008|20:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[25/06/2008|21:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ATI
[30/06/2008|18:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[01/07/2008|16:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[25/06/2008|18:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[01/09/2008|16:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tool Eggs Less City
[25/06/2008|18:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[24/06/2008|23:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[24/06/2008|23:33] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[24/07/2008|17:49] C:\DOCUME~1\lulu\APPLIC~1\Adobe
[25/06/2008|21:16] C:\DOCUME~1\lulu\APPLIC~1\ATI
[21/07/2008|11:34] C:\DOCUME~1\lulu\APPLIC~1\DAEMON Tools
[30/08/2008|18:03] C:\DOCUME~1\lulu\APPLIC~1\EoRezo
[01/07/2008|16:38] C:\DOCUME~1\lulu\APPLIC~1\Google
[24/06/2008|23:39] C:\DOCUME~1\lulu\APPLIC~1\Identities
[30/08/2008|18:01] C:\DOCUME~1\lulu\APPLIC~1\ItsLabel
[25/06/2008|18:38] C:\DOCUME~1\lulu\APPLIC~1\Macromedia
[30/08/2008|19:03] C:\DOCUME~1\lulu\APPLIC~1\Microsoft
[25/08/2008|12:12] C:\DOCUME~1\lulu\APPLIC~1\Sun
[25/06/2008|20:10] C:\DOCUME~1\lulu\APPLIC~1\TMP
[01/09/2008|16:10] C:\DOCUME~1\lulu\APPLIC~1\WEB THUNK JUGS
[21/07/2008|11:51] C:\DOCUME~1\lulu\APPLIC~1\WinRAR
[24/06/2008|23:33] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WIN-LNA\tasks
[08/09/2008 19:56][--a------] C:\WIN-LNA\tasks\GoogleUpdateTaskUser.job
[08/09/2008 21:00][--ah-----] C:\WIN-LNA\tasks\AD176F569194E30A.job
[08/09/2008 20:55][--ah-----] C:\WIN-LNA\tasks\SA.DAT
[28/08/2001 12:00][-r-h-----] C:\WIN-LNA\tasks\desktop.ini
( AD176F569194E30A.job )=( c:\docume~1\lulu\applic~1\webthu~1\activebibtest.exe )
--------------------\\ Listing des dossiers dans C:\Program LNA
[30/06/2008|20:31] C:\Program LNA\Adobe
[30/08/2008|17:45] C:\Program LNA\Alwil Software
[01/09/2008|23:17] C:\Program LNA\Antipub
[25/06/2008|21:10] C:\Program LNA\ATI Technologies
[25/08/2008|12:13] C:\Program LNA\Common
[24/06/2008|23:30] C:\Program LNA\ComPlus Applications
[30/08/2008|17:37] C:\Program LNA\DAEMON Tools Toolbar
[30/08/2008|19:52] C:\Program LNA\Dofus
[25/08/2008|17:47] C:\Program LNA\DofusArena2
[01/09/2008|16:39] C:\Program LNA\DofusBeta
[30/08/2008|17:39] C:\Program LNA\EA GAME
[30/08/2008|18:03] C:\Program LNA\EoRezo
[30/06/2008|18:11] C:\Program LNA\Google
[30/08/2008|17:41] C:\Program LNA\Gpotato.eu
[25/06/2008|21:18] C:\Program LNA\InstallShield Installation Information
[24/08/2008|20:08] C:\Program LNA\Internet Explorer
[25/08/2008|12:13] C:\Program LNA\Java
[30/06/2008|18:06] C:\Program LNA\Lexmark 3400 Series
[30/06/2008|18:06] C:\Program LNA\Lexmark Toolbar
[30/08/2008|17:34] C:\Program LNA\lx_cats
[01/07/2008|16:42] C:\Program LNA\ma-config.com
[25/06/2008|20:10] C:\Program LNA\Marvell
[14/08/2008|17:03] C:\Program LNA\Messenger
[03/09/2008|22:01] C:\Program LNA\Metin2_France
[24/06/2008|23:34] C:\Program LNA\microsoft frontpage
[24/06/2008|23:31] C:\Program LNA\Movie Maker
[24/06/2008|23:29] C:\Program LNA\MSN
[24/06/2008|23:30] C:\Program LNA\MSN Gaming Zone
[25/08/2008|14:04] C:\Program LNA\Mu Intensity S3
[24/06/2008|23:31] C:\Program LNA\NetMeeting
[24/06/2008|23:30] C:\Program LNA\Online Services
[25/06/2008|23:58] C:\Program LNA\Outlook Express
[25/06/2008|21:18] C:\Program LNA\Realtek
[24/06/2008|23:32] C:\Program LNA\Services en ligne
[24/06/2008|23:39] C:\Program LNA\Uninstall Information
[01/09/2008|16:09] C:\Program LNA\WEB THUNK JUGS
[30/08/2008|17:38] C:\Program LNA\Windows Live
[25/06/2008|21:42] C:\Program LNA\Windows Media Player
[24/06/2008|23:30] C:\Program LNA\Windows NT
[24/06/2008|23:32] C:\Program LNA\WindowsUpdate
[21/07/2008|11:48] C:\Program LNA\WinRAR
[24/06/2008|23:34] C:\Program LNA\xerox
--------------------\\ Listing des dossiers dans C:\Program LNA\Common
[30/06/2008|20:31] C:\Program LNA\Common\Adobe
[25/06/2008|21:07] C:\Program LNA\Common\InstallShield
[25/08/2008|12:13] C:\Program LNA\Common\Java
[02/07/2008|14:43] C:\Program LNA\Common\logishrd
[25/06/2008|18:38] C:\Program LNA\Common\Microsoft Shared
[24/06/2008|23:31] C:\Program LNA\Common\MSSoap
[24/06/2008|23:24] C:\Program LNA\Common\ODBC
[24/06/2008|23:31] C:\Program LNA\Common\Services
[24/06/2008|23:24] C:\Program LNA\Common\SpeechEngines
[25/06/2008|23:58] C:\Program LNA\Common\System
[25/06/2008|18:38] C:\Program LNA\Common\WindowsLiveInstaller
--------------------\\ Process
( 26 Processes )
iexplore.exe ~ [PID:528]
IEXPLORE.EXE ~ [PID:512]
--------------------\\ Recherche avec S_Lop
C:\DOCUME~1\lulu\LOCALS~1\Temp\bis3.exe
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tool Eggs Less City
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tool Eggs Less City\dog meta.exe
C:\DOCUME~1\lulu\APPLIC~1\webthu~1
C:\DOCUME~1\lulu\APPLIC~1\webthu~1\activebibtest.exe
C:\DOCUME~1\lulu\APPLIC~1\webthu~1\close fast.exe
C:\DOCUME~1\lulu\APPLIC~1\webthu~1\NewJunkAnteCopy.exe
C:\DOCUME~1\lulu\APPLIC~1\webthu~1\ucbdvuae.exe
C:\Program LNA\webthu~1
C:\DOCUME~1\lulu\LOCALS~1\Temp\nsc5.tmp
C:\DOCUME~1\lulu\LOCALS~1\Temp\nsd7.tmp
C:\DOCUME~1\lulu\LOCALS~1\Temp\nse8.tmp
C:\DOCUME~1\lulu\Cookies\lulu@adultfriendfinder[1].txt
C:\DOCUME~1\lulu\Cookies\lulu@advertising[2].txt
C:\DOCUME~1\lulu\Cookies\lulu@adin.bigpoint[1].txt
C:\DOCUME~1\lulu\Cookies\lulu@bigpoint[1].txt
C:\DOCUME~1\lulu\Cookies\lulu@fr.thepimps.bigpoint[1].txt
C:\DOCUME~1\lulu\Cookies\lulu@fr1.seafight.bigpoint[2].txt
C:\DOCUME~1\lulu\Cookies\lulu@banner.casinoking[2].txt
C:\DOCUME~1\lulu\Cookies\lulu@casinoking[1].txt
C:\DOCUME~1\lulu\Cookies\lulu@banner.cotedazurpalace[2].txt
C:\DOCUME~1\lulu\Cookies\lulu@cotedazurpalace[1].txt
C:\DOCUME~1\lulu\Cookies\lulu@www.cotedazurpalace[1].txt
C:\DOCUME~1\lulu\Cookies\lulu@adopt.euroclick[1].txt
C:\DOCUME~1\lulu\Cookies\lulu@pacificpoker[1].txt
C:\DOCUME~1\lulu\Cookies\lulu@partypoker[2].txt
C:\DOCUME~1\lulu\Cookies\lulu@fr1.seafight.bigpoint[2].txt
C:\DOCUME~1\lulu\Cookies\lulu@32vegas[1].txt
C:\DOCUME~1\lulu\Cookies\lulu@banner.32vegas[2].txt
C:\DOCUME~1\lulu\Cookies\lulu@888[1].txt
C:\DOCUME~1\lulu\Cookies\lulu@888[2].txt
C:\WIN-LNA\Tasks\AD176F569194E30A.job
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LESS CITY AMEN SETUP"="C:\\Documents and Settings\\All Users\\Application Data\\Tool Eggs Less City\\dog meta.exe"
"Findacid"="C:\\DOCUME~1\\lulu\\APPLIC~1\\WEBTHU~1\\close fast.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-08 21:30:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 1
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:977][D:73]-> C:\DOCUME~1\lulu\LOCALS~1\Temp
[F:321][D:0]-> C:\DOCUME~1\lulu\Cookies
[F:4170][D:8]-> C:\DOCUME~1\lulu\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 08/09/2008|21:30 - Option : [1]
--------------------\\ Fin du rapport a 21:30:51