--------------------\\ Lop S&D 4.2.4-4 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 3000+ )
BIOS : Award Modular BIOS v6.00PG
USER : philippe rayot ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 080926-0] 4.8.1229 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 76 Go Free : 41 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (CD or DVD)
G:\ (CD or DVD)
H:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [1] ( 27/09/2008|22:09 )
--------------------\\ Listing des dossiers dans APPLIC~1
[16/10/2007|10:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[26/11/2007|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[18/11/2007|13:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[18/11/2007|13:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[22/11/2006|16:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[18/11/2007|13:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[22/09/2008|20:23] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Ahead
[22/09/2008|22:21] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Apple
[22/09/2008|22:24] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Apple Computer
[12/03/2008|10:36] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\DVD X Studios
[13/03/2008|22:29] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Google
[20/09/2008|14:27] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Grisoft
[18/09/2008|23:38] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\ma-config.com
[18/09/2008|19:37] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Microsoft
[18/09/2008|19:54] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Readme Live Axis Tons
[11/02/2008|16:32] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Windows Genuine Advantage
[18/09/2008|19:30] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\WLInstaller
[20/09/2008|12:21] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\yahoo!
[20/09/2008|14:33] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Yahoo! Companion
[01/12/2007|21:30] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[18/02/2008|12:01] C:\DOCUME~1\DEFAUL~1.WIN\APPLIC~1\Microsoft
[18/09/2006|04:03] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[18/09/2008|14:52] C:\DOCUME~1\LOCALS~1.AUT\APPLIC~1\Microsoft
[01/12/2007|21:29] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[17/01/2008|10:06] C:\DOCUME~1\NETWOR~1.AUT\APPLIC~1\Microsoft
[26/09/2006|17:51] C:\DOCUME~1\PHILIP~1\APPLIC~1\Adobe
[12/10/2006|10:01] C:\DOCUME~1\PHILIP~1\APPLIC~1\Ahead
[16/10/2007|10:24] C:\DOCUME~1\PHILIP~1\APPLIC~1\Apple Computer
[21/09/2006|11:02] C:\DOCUME~1\PHILIP~1\APPLIC~1\Brother
[11/09/2007|16:23] C:\DOCUME~1\PHILIP~1\APPLIC~1\DialMessenger
[21/09/2006|10:39] C:\DOCUME~1\PHILIP~1\APPLIC~1\Help
[18/09/2006|04:58] C:\DOCUME~1\PHILIP~1\APPLIC~1\Identities
[21/09/2006|10:49] C:\DOCUME~1\PHILIP~1\APPLIC~1\InterTrust
[15/01/2008|12:07] C:\DOCUME~1\PHILIP~1\APPLIC~1\LimeWire
[07/01/2008|23:59] C:\DOCUME~1\PHILIP~1\APPLIC~1\ma-config.com
[26/09/2006|17:39] C:\DOCUME~1\PHILIP~1\APPLIC~1\Macromedia
[26/11/2007|16:20] C:\DOCUME~1\PHILIP~1\APPLIC~1\Microsoft
[23/01/2008|09:49] C:\DOCUME~1\PHILIP~2\APPLIC~1\Adobe
[22/09/2008|20:32] C:\DOCUME~1\PHILIP~2\APPLIC~1\Ahead
[19/09/2008|20:26] C:\DOCUME~1\PHILIP~2\APPLIC~1\ATI
[18/09/2008|21:39] C:\DOCUME~1\PHILIP~2\APPLIC~1\DAEMON Tools
[22/01/2008|16:11] C:\DOCUME~1\PHILIP~2\APPLIC~1\Help
[21/01/2008|14:39] C:\DOCUME~1\PHILIP~2\APPLIC~1\Identities
[28/01/2008|09:55] C:\DOCUME~1\PHILIP~2\APPLIC~1\InterTrust
[18/09/2008|14:53] C:\DOCUME~1\PHILIP~2\APPLIC~1\LimeWire
[18/09/2008|14:50] C:\DOCUME~1\PHILIP~2\APPLIC~1\ma-config(2).com
[23/01/2008|09:49] C:\DOCUME~1\PHILIP~2\APPLIC~1\Macromedia
[18/09/2008|19:47] C:\DOCUME~1\PHILIP~2\APPLIC~1\Microsoft
[23/01/2008|12:15] C:\DOCUME~1\PHILIP~2\APPLIC~1\Mozilla
[18/09/2008|20:04] C:\DOCUME~1\PHILIP~2\APPLIC~1\MSN Pictures Displayer
[19/09/2008|11:05] C:\DOCUME~1\PHILIP~2\APPLIC~1\Proc vc
[25/09/2008|13:51] C:\DOCUME~1\PHILIP~2\APPLIC~1\SecuROM
[13/02/2008|16:12] C:\DOCUME~1\PHILIP~2\APPLIC~1\Sun
[23/01/2008|12:15] C:\DOCUME~1\PHILIP~2\APPLIC~1\Talkback
[21/09/2008|22:56] C:\DOCUME~1\PHILIP~2\APPLIC~1\vlc
[20/09/2008|12:21] C:\DOCUME~1\PHILIP~2\APPLIC~1\Yahoo!
[17/01/2008|13:08] C:\DOCUME~1\PROPRI~1\APPLIC~1\Adobe
[11/02/2008|16:14] C:\DOCUME~1\PROPRI~1\APPLIC~1\Bitdefender
[18/01/2008|13:24] C:\DOCUME~1\PROPRI~1\APPLIC~1\Help
[17/01/2008|10:06] C:\DOCUME~1\PROPRI~1\APPLIC~1\Identities
[17/01/2008|14:43] C:\DOCUME~1\PROPRI~1\APPLIC~1\LimeWire
[17/01/2008|10:24] C:\DOCUME~1\PROPRI~1\APPLIC~1\Macromedia
[17/01/2008|12:30] C:\DOCUME~1\PROPRI~1\APPLIC~1\Microsoft
[17/01/2008|13:05] C:\DOCUME~1\PROPRI~1\APPLIC~1\Mozilla
[17/01/2008|13:05] C:\DOCUME~1\PROPRI~1\APPLIC~1\Talkback
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[23/09/2008 16:25][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[27/09/2008 12:54][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][---------] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[21/09/2006|10:49] C:\Program Files\Adobe
[18/09/2006|05:14] C:\Program Files\Ahead
[25/09/2008|01:32] C:\Program Files\AIDA32 - Personal System Information
[21/09/2006|09:40] C:\Program Files\Alcatel
[22/09/2008|11:21] C:\Program Files\Alcohol Soft
[18/09/2008|18:58] C:\Program Files\Alwil Software
[22/09/2008|22:21] C:\Program Files\Apple Software Update
[19/09/2008|20:22] C:\Program Files\ATI Technologies
[22/09/2008|22:25] C:\Program Files\Bonjour
[27/09/2008|12:56] C:\Program Files\BPS Remover
[21/09/2006|10:48] C:\Program Files\Brother
[28/01/2008|10:03] C:\Program Files\Brownie
[29/12/2007|14:45] C:\Program Files\Canon
[18/09/2008|19:23] C:\Program Files\Common Files
[18/09/2006|04:00] C:\Program Files\ComPlus Applications
[17/11/2007|15:25] C:\Program Files\Controle Parental
[18/09/2008|22:11] C:\Program Files\DAEMON Tools Lite
[18/09/2008|22:11] C:\Program Files\DAEMON Tools Toolbar
[11/09/2007|16:23] C:\Program Files\DialMessenger
[23/09/2008|17:26] C:\Program Files\DVD X Player 4.1 Professionnel
[25/09/2008|13:50] C:\Program Files\EA GAMES
[23/09/2008|17:26] C:\Program Files\eMule
[25/09/2008|01:54] C:\Program Files\eToro
[27/09/2008|13:02] C:\Program Files\Everest Poker
[22/09/2008|22:24] C:\Program Files\Fichiers communs
[22/09/2008|11:21] C:\Program Files\free-downloads.net
[26/11/2007|21:23] C:\Program Files\Hewlett-Packard
[13/03/2008|22:30] C:\Program Files\InstallShield Installation Information
[19/09/2008|13:12] C:\Program Files\Internet Explorer
[11/02/2008|19:54] C:\Program Files\Java
[21/09/2006|09:40] C:\Program Files\JavaSoft
[18/09/2008|23:39] C:\Program Files\ma-config.com
[19/09/2008|13:13] C:\Program Files\Messenger
[23/09/2008|17:26] C:\Program Files\MessengerPlus! 3
[23/09/2008|17:26] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[18/09/2006|04:04] C:\Program Files\microsoft frontpage
[18/01/2008|13:23] C:\Program Files\Microsoft Office
[16/02/2008|11:26] C:\Program Files\Microsoft SQL Server Compact Edition
[11/02/2008|17:19] C:\Program Files\Movie Maker
[27/09/2008|22:06] C:\Program Files\Mozilla Firefox
[17/01/2008|00:41] C:\Program Files\MSN
[18/09/2006|03:59] C:\Program Files\MSN Gaming Zone
[18/09/2008|19:34] C:\Program Files\MSN Messenger
[18/09/2008|20:04] C:\Program Files\MSN Pictures Displayer
[26/11/2007|16:19] C:\Program Files\MSXML 4.0
[11/02/2008|20:05] C:\Program Files\MSXML 6.0
[20/09/2008|14:24] C:\Program Files\Navilog1
[22/09/2008|20:20] C:\Program Files\Nero
[11/02/2008|17:14] C:\Program Files\NetMeeting
[23/09/2008|17:02] C:\Program Files\NoAdware5.0
[18/09/2006|03:59] C:\Program Files\Online Services
[18/09/2008|15:44] C:\Program Files\OrangeHSS
[11/02/2008|19:23] C:\Program Files\Outlook Express
[23/09/2008|12:39] C:\Program Files\Panicware
[18/09/2008|19:54] C:\Program Files\Proc vc
[22/09/2008|22:25] C:\Program Files\QuickTime
[18/09/2008|23:44] C:\Program Files\Realtek AC97
[18/09/2008|14:47] C:\Program Files\Realtek AC97(2)
[18/09/2008|15:10] C:\Program Files\Securitoo
[22/09/2008|19:56] C:\Program Files\SharkMate
[22/09/2008|19:17] C:\Program Files\Smart Projects
[02/02/2008|00:12] C:\Program Files\SOFTWIN
[27/09/2008|20:52] C:\Program Files\Steam
[29/12/2007|10:51] C:\Program Files\Ulead Systems
[18/09/2006|04:58] C:\Program Files\Uninstall Information
[21/09/2008|22:54] C:\Program Files\VideoLAN
[03/10/2007|22:01] C:\Program Files\WebSubmit Manager
[19/09/2008|11:21] C:\Program Files\Windows Live
[23/09/2008|12:50] C:\Program Files\Windows Live Favorites
[23/09/2008|12:50] C:\Program Files\Windows Live Toolbar
[11/02/2008|19:10] C:\Program Files\Windows Media Connect 2
[18/09/2008|14:51] C:\Program Files\Windows Media Player
[18/01/2008|13:22] C:\Program Files\Windows Messaging
[11/02/2008|17:14] C:\Program Files\Windows NT
[11/02/2008|16:27] C:\Program Files\WindowsUpdate
[23/09/2008|17:26] C:\Program Files\WinRAR
[18/09/2006|04:04] C:\Program Files\xerox
[20/09/2008|12:21] C:\Program Files\Yahoo!
[23/09/2008|17:26] C:\Program Files\Zuma Deluxe
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[26/09/2006|17:51] C:\Program Files\Fichiers communs\Adobe
[22/09/2008|20:38] C:\Program Files\Fichiers communs\Ahead
[22/09/2008|22:24] C:\Program Files\Fichiers communs\Apple
[18/09/2008|15:08] C:\Program Files\Fichiers communs\France Telecom
[26/11/2007|11:02] C:\Program Files\Fichiers communs\Hewlett-Packard
[16/10/2007|10:17] C:\Program Files\Fichiers communs\InstallShield
[18/12/2007|11:10] C:\Program Files\Fichiers communs\Java
[18/01/2008|13:20] C:\Program Files\Fichiers communs\Microsoft Shared
[18/09/2006|04:01] C:\Program Files\Fichiers communs\MSSoap
[18/09/2006|05:18] C:\Program Files\Fichiers communs\ODBC
[18/09/2006|04:01] C:\Program Files\Fichiers communs\Services
[18/09/2008|15:01] C:\Program Files\Fichiers communs\Softwin
[18/09/2006|05:18] C:\Program Files\Fichiers communs\SpeechEngines
[11/02/2008|19:23] C:\Program Files\Fichiers communs\System
[18/09/2008|19:33] C:\Program Files\Fichiers communs\WindowsLiveInstaller
--------------------\\ Process
( 50 Processes )
IEXPLORE.EXE ~ [PID:2280]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Readme Live Axis Tons
C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Readme Live Axis Tons\proxy move.exe
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@www.adserver5[1].txt
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@advertising[1].txt
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@bigpoint[1].txt
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@fr1.darkorbit.bigpoint[1].txt
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@banner.cotedazurpalace[2].txt
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@cotedazurpalace[2].txt
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@www.cotedazurpalace[1].txt
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@adopt.euroclick[1].txt
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@pacificpoker[2].txt
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@partypoker[2].txt
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@32vegas[2].txt
C:\DOCUME~1\PHILIP~2\Cookies\philippe_rayot@banner.32vegas[2].txt
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AXIS TONS THE MP3"="C:\\Documents and Settings\\All Users.WINDOWS\\Application Data\\Readme Live Axis Tons\\proxy move.exe"
--------------------\\ Verification du fichier Hosts
Fichier Hosts MODIFIE
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww
/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww
/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww
/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww
/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww
/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww
/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww
/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww
/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww
/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww
/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww
/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww
/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww
/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww
/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww
/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww
/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww
/iw.winsoftware.com ## added by CiD
-> 71 [ 70 ## added by CiD ]
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-27 22:10:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
C:\DOCUME~1\PHILIP~2\LOCALS~1\APPLIC~1\Microsoft\Windows\GameExplorer\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}\PlayTasks\1\Les Sims™ 2 : Boit@Look.lnk 1087 bytes hidden from API
scan completed successfully
hidden processes: 0
hidden files: 1
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
[F:4792][D:206]-> C:\DOCUME~1\PHILIP~2\LOCALS~1\Temp
[F:105][D:0]-> C:\DOCUME~1\PHILIP~2\Cookies
[F:39969][D:52]-> C:\DOCUME~1\PHILIP~2\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 27/09/2008|22:16 - Option : [1]
--------------------\\ Fin du rapport a 22:16:27