--------------------\\ Lop S&D 4.2.4-5 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor TK-53 )
BIOS : A1632NMS Ver7.08
USER : Utilisateur ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081003-0] 4.8.1229 (Activated)
C:\ (Local Disk) - NTFS - Total : 34 Go Free : 8 Go
D:\ (Local Disk) - NTFS - Total : 109 Go Free : 96 Go
E:\ (CD or DVD)
F:\ (USB) - FAT32 - Total : 3709 Mo Free : 0 Go
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [2] ( 03/10/2008|17:55 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\ProgramData\That Face Camp Shim\aim 32.exe
Supprime! - C:\Users\UTILIS~1\AppData\Roaming\MICROS~1\Windows\Cookies\utilisateur@adopt.euroclick[2].txt
Supprime! - C:\ProgramData\Balm less less.sfpa5r
Supprime! - C:\ProgramData\active mags soft.cz5vrps
Supprime! - C:\ProgramData\Balm less less.03vqijm
Supprime! - C:\ProgramData\That Face Camp Shim
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[16/02/2008|08:06] C:\Users\UTILIS~1\AppData\Local\Adobe
[18/09/2007|16:48] C:\Users\UTILIS~1\AppData\Local\Application Data
[30/06/2008|20:19] C:\Users\UTILIS~1\AppData\Local\d3d9caps.dat
[12/09/2008|16:26] C:\Users\UTILIS~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[01/08/2008|15:07] C:\Users\UTILIS~1\AppData\Local\Electronic Arts
[23/06/2008|19:44] C:\Users\UTILIS~1\AppData\Local\GDIPFONTCACHEV1.DAT
[12/09/2008|16:24] C:\Users\UTILIS~1\AppData\Local\Google
[18/09/2007|16:48] C:\Users\UTILIS~1\AppData\Local\Historique
[03/10/2008|17:41] C:\Users\UTILIS~1\AppData\Local\IconCache.db
[02/09/2008|16:53] C:\Users\UTILIS~1\AppData\Local\Microsoft
[23/09/2007|20:28] C:\Users\UTILIS~1\AppData\Local\Microsoft Games
[30/10/2007|22:46] C:\Users\UTILIS~1\AppData\Local\Mozilla
[18/09/2007|17:30] C:\Users\UTILIS~1\AppData\Local\Seven Zip
[03/10/2008|17:55] C:\Users\UTILIS~1\AppData\Local\Temp
[18/09/2007|16:48] C:\Users\UTILIS~1\AppData\Local\Temporary Internet Files
[27/08/2008|13:42] C:\Users\UTILIS~1\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[03/10/2008 17:42][--ah-----] C:\Windows\tasks\SA.DAT
[03/10/2008 17:41][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[15/02/2008|20:20] C:\ProgramData\Adobe
[02/11/2006|15:02] C:\ProgramData\Application Data
[18/09/2007|16:44] C:\ProgramData\Bureau
[10/05/2008|00:38] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[18/09/2007|16:44] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[12/09/2008|16:29] C:\ProgramData\Google
[12/09/2008|22:58] C:\ProgramData\Grisoft
[10/09/2008|19:31] C:\ProgramData\Lavasoft
[18/09/2007|16:44] C:\ProgramData\Menu D‚marrer
[19/09/2008|18:40] C:\ProgramData\Messenger Plus!
[18/11/2007|19:38] C:\ProgramData\Microsoft
[18/09/2007|17:25] C:\ProgramData\Microsoft Help
[18/09/2007|16:44] C:\ProgramData\ModŠles
[23/06/2008|13:40] C:\ProgramData\ntuser.pol
[10/05/2008|13:37] C:\ProgramData\QuickTime
[18/09/2008|18:28] C:\ProgramData\ShimDebugTeam
[13/09/2008|13:09] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[12/09/2008|20:03] C:\ProgramData\Sunbelt
[12/09/2008|22:54] C:\ProgramData\SUPERAntiSpyware.com
[18/09/2007|17:11] C:\ProgramData\Symantec
[12/09/2008|16:39] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[20/04/2008|12:02] C:\ProgramData\WLInstaller
[11/09/2008|21:16] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[15/02/2008|20:20] C:\Program Files\Adobe
[19/09/2007|13:59] C:\Program Files\Alwil Software
[21/11/2007|22:53] C:\Program Files\Audacity
[11/09/2008|07:08] C:\Program Files\CCleaner
[12/09/2008|22:56] C:\Program Files\Common Files
[17/07/2007|14:10] C:\Program Files\CyberLink
[27/05/2008|14:24] C:\Program Files\DivX
[01/08/2008|14:35] C:\Program Files\Electronic Arts
[18/09/2007|16:44] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[29/10/2007|13:19] C:\Program Files\GIMP-2.0
[12/09/2008|19:28] C:\Program Files\Google
[27/05/2008|14:43] C:\Program Files\InstallShield Installation Information
[10/05/2008|12:17] C:\Program Files\Internet Explorer
[19/09/2007|14:11] C:\Program Files\Java
[02/12/2007|17:57] C:\Program Files\LimeWire
[19/09/2008|16:34] C:\Program Files\Messenger Plus! Live
[24/02/2008|12:23] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[24/04/2008|18:54] C:\Program Files\Movie Maker
[03/10/2008|17:43] C:\Program Files\Mozilla Firefox
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2007|19:04] C:\Program Files\MSI
[04/03/2008|19:44] C:\Program Files\MySpace
[23/06/2008|13:49] C:\Program Files\OpenOffice.org 2.2
[23/06/2008|14:13] C:\Program Files\OpenOffice.org 2.4
[12/04/2008|19:58] C:\Program Files\PhotoFiltre
[12/09/2008|16:24] C:\Program Files\Picasa2
[10/05/2008|12:17] C:\Program Files\QuickTime
[10/05/2008|14:51] C:\Program Files\Real
[17/07/2007|13:37] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[13/09/2008|13:04] C:\Program Files\Spybot - Search & Destroy
[17/07/2007|13:55] C:\Program Files\System Control Manager
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[24/04/2008|18:54] C:\Program Files\Windows Calendar
[24/04/2008|18:54] C:\Program Files\Windows Collaboration
[24/04/2008|18:54] C:\Program Files\Windows Defender
[24/04/2008|18:54] C:\Program Files\Windows Journal
[27/05/2008|15:12] C:\Program Files\Windows Live
[16/08/2008|11:53] C:\Program Files\Windows Mail
[24/04/2008|18:54] C:\Program Files\Windows Media Player
[18/09/2007|16:44] C:\Program Files\Windows NT
[24/04/2008|18:54] C:\Program Files\Windows Photo Gallery
[24/04/2008|18:54] C:\Program Files\Windows Sidebar
[03/10/2008|17:27] C:\Program Files\WinRAR
[17/07/2007|14:28] C:\Program Files\WinRAR 3.61 Multi
[11/09/2008|07:08] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[15/02/2008|20:20] C:\Program Files\Common Files\Adobe
[17/07/2007|14:06] C:\Program Files\Common Files\InstallShield
[19/09/2007|14:10] C:\Program Files\Common Files\Java
[27/05/2008|15:12] C:\Program Files\Common Files\microsoft shared
[10/05/2008|14:52] C:\Program Files\Common Files\Real
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[27/05/2008|14:43] C:\Program Files\Common Files\snp2std
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[18/09/2007|17:11] C:\Program Files\Common Files\Symantec Shared
[24/04/2008|18:54] C:\Program Files\Common Files\System
[16/02/2008|08:17] C:\Program Files\Common Files\WindowsLiveInstaller
[10/05/2008|14:52] C:\Program Files\Common Files\xing shared
--------------------\\ Process
( 63 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-03 17:55:22
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 957
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:126][D:33]-> C:\Users\UTILIS~1\AppData\Local\Temp
[F:104][D:1]-> C:\Users\UTILIS~1\AppData\Roaming\MICROS~1\Windows\Cookies
[F:209][D:5]-> C:\Users\UTILIS~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:6][D:3]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 03/10/2008|17:49 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 03/10/2008|17:56 - Option : [2]
--------------------\\ Fin du rapport a 17:56:59
[ UAC => 1 ]
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor TK-53 )
BIOS : A1632NMS Ver7.08
USER : Utilisateur ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081003-0] 4.8.1229 (Activated)
C:\ (Local Disk) - NTFS - Total : 34 Go Free : 8 Go
D:\ (Local Disk) - NTFS - Total : 109 Go Free : 96 Go
E:\ (CD or DVD)
F:\ (USB) - FAT32 - Total : 3709 Mo Free : 0 Go
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 03/10/2008|17:47 )
[ UAC => 0 ]
--------------------\\ Listing des dossiers dans Local
[16/02/2008|08:06] C:\Users\UTILIS~1\AppData\Local\Adobe
[18/09/2007|16:48] C:\Users\UTILIS~1\AppData\Local\Application Data
[30/06/2008|20:19] C:\Users\UTILIS~1\AppData\Local\d3d9caps.dat
[12/09/2008|16:26] C:\Users\UTILIS~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[01/08/2008|15:07] C:\Users\UTILIS~1\AppData\Local\Electronic Arts
[23/06/2008|19:44] C:\Users\UTILIS~1\AppData\Local\GDIPFONTCACHEV1.DAT
[12/09/2008|16:24] C:\Users\UTILIS~1\AppData\Local\Google
[18/09/2007|16:48] C:\Users\UTILIS~1\AppData\Local\Historique
[03/10/2008|17:41] C:\Users\UTILIS~1\AppData\Local\IconCache.db
[02/09/2008|16:53] C:\Users\UTILIS~1\AppData\Local\Microsoft
[23/09/2007|20:28] C:\Users\UTILIS~1\AppData\Local\Microsoft Games
[30/10/2007|22:46] C:\Users\UTILIS~1\AppData\Local\Mozilla
[18/09/2007|17:30] C:\Users\UTILIS~1\AppData\Local\Seven Zip
[03/10/2008|17:46] C:\Users\UTILIS~1\AppData\Local\Temp
[18/09/2007|16:48] C:\Users\UTILIS~1\AppData\Local\Temporary Internet Files
[27/08/2008|13:42] C:\Users\UTILIS~1\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[03/10/2008 17:42][--ah-----] C:\Windows\tasks\SA.DAT
[03/10/2008 17:41][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[31/08/2008|21:26] C:\ProgramData\active mags soft.cz5vrps
[15/02/2008|20:20] C:\ProgramData\Adobe
[02/11/2006|15:02] C:\ProgramData\Application Data
[31/08/2008|21:25] C:\ProgramData\Balm less less.03vqijm
[31/08/2008|21:25] C:\ProgramData\Balm less less.sfpa5r
[18/09/2007|16:44] C:\ProgramData\Bureau
[10/05/2008|00:38] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[18/09/2007|16:44] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[12/09/2008|16:29] C:\ProgramData\Google
[12/09/2008|22:58] C:\ProgramData\Grisoft
[10/09/2008|19:31] C:\ProgramData\Lavasoft
[18/09/2007|16:44] C:\ProgramData\Menu D‚marrer
[19/09/2008|18:40] C:\ProgramData\Messenger Plus!
[18/11/2007|19:38] C:\ProgramData\Microsoft
[18/09/2007|17:25] C:\ProgramData\Microsoft Help
[18/09/2007|16:44] C:\ProgramData\ModŠles
[23/06/2008|13:40] C:\ProgramData\ntuser.pol
[10/05/2008|13:37] C:\ProgramData\QuickTime
[18/09/2008|18:28] C:\ProgramData\ShimDebugTeam
[13/09/2008|13:09] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[12/09/2008|20:03] C:\ProgramData\Sunbelt
[12/09/2008|22:54] C:\ProgramData\SUPERAntiSpyware.com
[18/09/2007|17:11] C:\ProgramData\Symantec
[12/09/2008|16:39] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[31/08/2008|21:26] C:\ProgramData\That Face Camp Shim
[20/04/2008|12:02] C:\ProgramData\WLInstaller
[11/09/2008|21:16] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[15/02/2008|20:20] C:\Program Files\Adobe
[19/09/2007|13:59] C:\Program Files\Alwil Software
[21/11/2007|22:53] C:\Program Files\Audacity
[11/09/2008|07:08] C:\Program Files\CCleaner
[12/09/2008|22:56] C:\Program Files\Common Files
[17/07/2007|14:10] C:\Program Files\CyberLink
[27/05/2008|14:24] C:\Program Files\DivX
[01/08/2008|14:35] C:\Program Files\Electronic Arts
[18/09/2007|16:44] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[29/10/2007|13:19] C:\Program Files\GIMP-2.0
[12/09/2008|19:28] C:\Program Files\Google
[27/05/2008|14:43] C:\Program Files\InstallShield Installation Information
[10/05/2008|12:17] C:\Program Files\Internet Explorer
[19/09/2007|14:11] C:\Program Files\Java
[02/12/2007|17:57] C:\Program Files\LimeWire
[19/09/2008|16:34] C:\Program Files\Messenger Plus! Live
[24/02/2008|12:23] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[24/04/2008|18:54] C:\Program Files\Movie Maker
[03/10/2008|17:43] C:\Program Files\Mozilla Firefox
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2007|19:04] C:\Program Files\MSI
[04/03/2008|19:44] C:\Program Files\MySpace
[23/06/2008|13:49] C:\Program Files\OpenOffice.org 2.2
[23/06/2008|14:13] C:\Program Files\OpenOffice.org 2.4
[12/04/2008|19:58] C:\Program Files\PhotoFiltre
[12/09/2008|16:24] C:\Program Files\Picasa2
[10/05/2008|12:17] C:\Program Files\QuickTime
[10/05/2008|14:51] C:\Program Files\Real
[17/07/2007|13:37] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[13/09/2008|13:04] C:\Program Files\Spybot - Search & Destroy
[17/07/2007|13:55] C:\Program Files\System Control Manager
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[24/04/2008|18:54] C:\Program Files\Windows Calendar
[24/04/2008|18:54] C:\Program Files\Windows Collaboration
[24/04/2008|18:54] C:\Program Files\Windows Defender
[24/04/2008|18:54] C:\Program Files\Windows Journal
[27/05/2008|15:12] C:\Program Files\Windows Live
[16/08/2008|11:53] C:\Program Files\Windows Mail
[24/04/2008|18:54] C:\Program Files\Windows Media Player
[18/09/2007|16:44] C:\Program Files\Windows NT
[24/04/2008|18:54] C:\Program Files\Windows Photo Gallery
[24/04/2008|18:54] C:\Program Files\Windows Sidebar
[03/10/2008|17:27] C:\Program Files\WinRAR
[17/07/2007|14:28] C:\Program Files\WinRAR 3.61 Multi
[11/09/2008|07:08] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[15/02/2008|20:20] C:\Program Files\Common Files\Adobe
[17/07/2007|14:06] C:\Program Files\Common Files\InstallShield
[19/09/2007|14:10] C:\Program Files\Common Files\Java
[27/05/2008|15:12] C:\Program Files\Common Files\microsoft shared
[10/05/2008|14:52] C:\Program Files\Common Files\Real
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[27/05/2008|14:43] C:\Program Files\Common Files\snp2std
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[18/09/2007|17:11] C:\Program Files\Common Files\Symantec Shared
[24/04/2008|18:54] C:\Program Files\Common Files\System
[16/02/2008|08:17] C:\Program Files\Common Files\WindowsLiveInstaller
[10/05/2008|14:52] C:\Program Files\Common Files\xing shared
--------------------\\ Process
( 59 Processes )
iexplore.exe ~ [PID:2212]
--------------------\\ Recherche avec S_Lop
C:\ProgramData\Balm less less.sfpa5r
C:\ProgramData\active mags soft.cz5vrps
C:\ProgramData\Balm less less.03vqijm
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\ProgramData\That Face Camp Shim
C:\ProgramData\That Face Camp Shim\aim 32.exe
C:\Users\UTILIS~1\AppData\Roaming\MICROS~1\Windows\Cookies\utilisateur@adopt.euroclick[2].txt
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Batplay"="\"C:\\ProgramData\\Balm less less.sfpa5r\""
"CAMP SHIM EXIT HECK"="\"C:\\ProgramData\\active mags soft.cz5vrps\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-03 17:47:49
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 957
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:122][D:33]-> C:\Users\UTILIS~1\AppData\Local\Temp
[F:98][D:1]-> C:\Users\UTILIS~1\AppData\Roaming\MICROS~1\Windows\Cookies
[F:146][D:5]-> C:\Users\UTILIS~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:9][D:4]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 03/10/2008|17:49 - Option : [1]
--------------------\\ Fin du rapport a 17:49:49
[ UAC => 1 ]
Voila!