merci our une reponse aussi rapide laddy . voila les trois rapports demander :
Rapport DSS:
Deckard's System Scanner v20071014.68
Run by MARC on 2008-07-02 14:54:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-07-02 12:54:50 UTC - RP1 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 504 MiB (512 MiB recommended).
-- HijackThis (run as MARC.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:58:43, on 02/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\MARC\Local Settings\Temporary Internet Files\Content.IE5\Q129SHUJ\dss[1].exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\MARC.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.hp.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
R3 - URLSearchHook: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsec1.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\^^ %%%% ^ ^ %%^^^ %^%%%^^% %%^%^ ^^^%%^ .exe
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsec1.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsec1.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [VadeRetro Outlook] C:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
O4 - HKLM\..\Run: [VadeRetro Desktop] C:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [kqsgeuygs] c:\documents and settings\marc\local settings\application data\kqsgeuygs.exe kqsgeuygs
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\Hp\digital imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 9404 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S3 SE2Ebus (Sony Ericsson Device 046 Driver driver (WDM)) - c:\windows\system32\drivers\se2ebus.sys <Not Verified; MCCI; Sony Ericsson Device 046 Driver>
S3 SE2Emdfl (Sony Ericsson Device 046 USB WMC Modem Filter) - c:\windows\system32\drivers\se2emdfl.sys <Not Verified; MCCI; Sony Ericsson Device 046 USB WMC Modem Filter Driver>
S3 SE2Emdm (Sony Ericsson Device 046 USB WMC Modem Driver) - c:\windows\system32\drivers\se2emdm.sys <Not Verified; MCCI; Sony Ericsson Device 046 USB WMC Data Modem>
S3 SYMIDSCO - c:\progra~1\fichie~1\symant~1\symcdata\idsdefs\20050901.036\symidsco.sys (file missing)
S3 tifm21 - c:\windows\system32\drivers\tifm21.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S2 PCA (PC Angel) - c:\windows\sminst\pcangel.exe <Not Verified; SoftThinks; PCAngel Application>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-05-30 15:00:23 406 --a------ C:\WINDOWS\Tasks\Norton Security Scan.job
-- Files created between 2008-06-02 and 2008-07-02 -----------------------------
2008-07-02 14:58:23 0 d-------- C:\Program Files\Trend Micro
2008-07-02 14:47:05 0 d-------- C:\Program Files\Navilog1
2008-07-02 14:17:12 0 d-------- C:\Lop SD
2008-06-14 19:10:47 0 d-------- C:\Program Files\Pvm
2008-06-07 19:59:06 0 d-------- C:\Documents and Settings\MARC\Start Menu
2008-06-07 19:58:16 0 d-------- C:\Program Files\PacificPoker4
2008-06-02 00:34:06 0 d-------- C:\Program Files\Fichiers communs\xing shared
2008-06-02 00:31:13 0 d-------- C:\Program Files\Real
2008-06-02 00:30:51 0 d-------- C:\Program Files\Fichiers communs\Real
2008-06-02 00:30:19 0 d-------- C:\Documents and Settings\MARC\Application Data\Real
-- Find3M Report ---------------------------------------------------------------
2008-07-01 20:00:53 0 d-------- C:\Program Files\Windows Live Safety Center
2008-07-01 19:56:09 0 d-------- C:\Program Files\eMule
2008-06-02 00:34:06 0 d-------- C:\Program Files\Fichiers communs
2008-06-01 15:50:03 0 d-------- C:\Program Files\djDecks VirtualDJ Control Record Plug-In
2008-06-01 15:48:51 0 d-------- C:\Program Files\VirtualDJ
2008-05-30 15:00:01 0 d-------- C:\Program Files\Norton Security Scan
2008-05-18 19:08:12 0 d-------- C:\Program Files\Windows Live
2008-05-16 21:06:48 0 d-------- C:\Documents and Settings\MARC\Application Data\GetRightToGo
2008-05-10 14:48:14 0 d-------- C:\Documents and Settings\MARC\Application Data\WinRAR
2008-05-10 12:49:01 0 d-------- C:\Program Files\SweetIM
2008-05-09 23:24:13 0 d-------- C:\Program Files\HPQ
2008-05-09 22:48:36 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-09 22:40:39 0 d-------- C:\Program Files\Hewlett-Packard
2008-05-09 22:40:39 0 d-------- C:\Program Files\Google
2008-05-09 21:42:12 0 d-------- C:\Program Files\Fichiers communs\Adobe
2008-05-03 17:50:25 0 d-------- C:\Program Files\securedie
2008-04-25 03:15:44 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-24 04:27:31 486692 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-04-24 04:27:31 80948 --a------ C:\WINDOWS\system32\perfc00C.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd36797a-70f3-4acd-8825-623d3b896881}]
03/05/2008 17:50 1470488 --a------ C:\Program Files\securedie\tbsec1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
27/03/2008 14:12 1164600 --a------ C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [27/03/2008 14:12 1164600]
"{CD36797A-70F3-4ACD-8825-623D3B896881}"= C:\Program Files\securedie\tbsec1.dll [03/05/2008 17:50 1470488]
[-HKEY_CLASSES_ROOT\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[-HKEY_CLASSES_ROOT\CLSID\{CD36797A-70F3-4ACD-8825-623D3B896881}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"AGRSMMSG"="AGRSMMSG.exe" [30/01/2006 03:00 C:\WINDOWS\AGRSMMSG.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [20/05/2005 10:11]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [06/05/2005 14:06]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [16/02/2005 23:11]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [31/08/2005 05:20]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [03/03/2006 18:46]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [23/03/2006 14:17]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [23/03/2006 14:13]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [23/03/2006 14:17]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [14/02/2006 10:49]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [08/05/2006 09:56]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [26/01/2006 14:35]
"Recguard"="C:\WINDOWS\Sminst\Recguard.exe" [20/12/2005 16:51]
"Reminder"="C:\WINDOWS\Creator\Remind_XP.exe" [09/03/2006 17:38]
"Scheduler"="C:\WINDOWS\SMINST\Scheduler.exe" [15/02/2006 17:43]
"WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [08/11/2005 11:59]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe" [06/04/2004 12:28]
"HPHUPD06"="C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [07/06/2004 06:53]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [12/05/2004 16:18]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [07/06/2004 06:43]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [17/08/2007 14:41]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [16/05/2008 01:19]
"VadeRetro Outlook"="C:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe" [20/02/2008 18:48]
"VadeRetro Desktop"="C:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe" [10/04/2008 10:00]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 22:16]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [02/06/2008 00:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [05/08/2004 10:00]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [18/10/2007 11:34]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [03/11/2006 09:59]
"kqsgeuygs"="c:\documents and settings\marc\local settings\application data\kqsgeuygs.exe" []
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DVD Check.lnk - C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [29/09/2006 16:08:51]
D‚marrage rapide du logiciel HP Image Zone.lnk - C:\Program Files\Hp\digital imaging\bin\hpqthb08.exe [29/05/2004 00:06:36]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hp\digital imaging\bin\hpqtra08.exe [28/05/2004 23:31:38]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [13/02/2001 09:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\^^ %%%% ^ ^ %%^^^ %^%%%^^% %%^%^ ^^^%%^ .exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03781b1c-e287-11dc-bcde-806d6172696f}]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0b11fc9a-786a-11db-9f6c-0014a5bcc3e5}]
AutoRun\command- G:\
explore\Command- WScript.exe .\autorun.vbs
open\Command- WScript.exe .\autorun.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{58cec526-dfad-11db-9fd4-0014a5bcc3e5}]
AutoRun\command- F:\
explore\Command- WScript.exe .\autorun.vbs
open\Command- WScript.exe .\autorun.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b2c457b2-e039-11db-9fd7-0014a5bcc3e5}]
AutoRun\command- F:\
explore\Command- WScript.exe .\autorun.vbs
open\Command- WScript.exe .\autorun.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2e19518-4fc2-11db-9f54-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
*Newly Created Service* - CATCHME
-- Hosts -----------------------------------------------------------------------
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
60 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-07-02 15:00:10 ------------
Rapport lop s d :
-----------------------[ Lop S&D 4.2.1-9 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : MARC ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 02/07/2008 | 14:18:34,78 ] [ PC : PC270171002195 ]
[ MAJ : 01-07-2008 | 00:25 ]
-------------[ Listing des dossiers dans Application Data ]------------
[17/08/2004|11:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[30/09/2006|00:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[30/09/2006|00:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[30/09/2006|00:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
[05/05/2008|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[17/08/2007|14:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[24/04/2008|18:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BufferZone
[17/08/2004|11:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[09/05/2008|21:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[29/10/2006|18:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard
[30/09/2006|00:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpqLog
[29/10/2006|18:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[30/09/2006|00:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[30/03/2008|23:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[19/04/2008|21:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NCH Swift Sound
[19/04/2008|22:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[30/09/2006|00:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[05/04/2008|02:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM
[15/04/2008|19:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[10/05/2008|12:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[02/07/2008|14:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tick Find Close Surf
[24/04/2008|03:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\VadeRetro
[14/04/2008|03:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[30/03/2008|23:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[17/08/2004|11:58] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[30/09/2006|00:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[30/09/2006|00:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[30/09/2006|00:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\SampleView
[11/12/2006|12:34] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[25/04/2008|15:06] C:\DOCUME~1\MARC\APPLIC~1\Adobe
[11/04/2008|14:44] C:\DOCUME~1\MARC\APPLIC~1\AdobeUM
[17/08/2007|14:56] C:\DOCUME~1\MARC\APPLIC~1\Apple Computer
[17/08/2004|11:58] C:\DOCUME~1\MARC\APPLIC~1\desktop.ini
[29/03/2008|19:59] C:\DOCUME~1\MARC\APPLIC~1\GDIPFONTCACHEV1.DAT
[16/05/2008|21:06] C:\DOCUME~1\MARC\APPLIC~1\GetRightToGo
[23/02/2008|20:45] C:\DOCUME~1\MARC\APPLIC~1\Google
[30/09/2006|00:46] C:\DOCUME~1\MARC\APPLIC~1\Identities
[17/08/2007|14:34] C:\DOCUME~1\MARC\APPLIC~1\Leadertech
[24/02/2008|19:09] C:\DOCUME~1\MARC\APPLIC~1\Macromedia
[30/03/2008|23:58] C:\DOCUME~1\MARC\APPLIC~1\Microsoft
[25/04/2008|03:15] C:\DOCUME~1\MARC\APPLIC~1\Mozilla
[09/03/2008|00:36] C:\DOCUME~1\MARC\APPLIC~1\MSNInstaller
[19/04/2008|21:34] C:\DOCUME~1\MARC\APPLIC~1\NCH Swift Sound
[02/06/2008|00:40] C:\DOCUME~1\MARC\APPLIC~1\Real
[30/09/2006|00:46] C:\DOCUME~1\MARC\APPLIC~1\SampleView
[24/04/2008|18:44] C:\DOCUME~1\MARC\APPLIC~1\ShoppingReport
[08/03/2008|20:07] C:\DOCUME~1\MARC\APPLIC~1\Sports Interactive
[22/03/2008|21:12] C:\DOCUME~1\MARC\APPLIC~1\Sun
[25/04/2008|03:17] C:\DOCUME~1\MARC\APPLIC~1\Talkback
[24/04/2008|03:45] C:\DOCUME~1\MARC\APPLIC~1\VadeRetro
[23/02/2008|20:49] C:\DOCUME~1\MARC\APPLIC~1\vlc
[10/05/2008|14:48] C:\DOCUME~1\MARC\APPLIC~1\WinRAR
[11/12/2006|12:34] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[05/06/2007|12:01] C:\DOCUME~1\saur\APPLIC~1\Adobe
[05/06/2007|12:01] C:\DOCUME~1\saur\APPLIC~1\AdobeUM
[17/08/2004|11:58] C:\DOCUME~1\saur\APPLIC~1\desktop.ini
[30/09/2006|00:46] C:\DOCUME~1\saur\APPLIC~1\Identities
[05/06/2007|11:56] C:\DOCUME~1\saur\APPLIC~1\Microsoft
[30/09/2006|00:46] C:\DOCUME~1\saur\APPLIC~1\SampleView
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[30/05/2008 15:00][--a------] C:\WINDOWS\tasks\Norton Security Scan.job
[02/07/2008 13:34][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 10:00][-rah-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[09/05/2008|21:42] C:\Program Files\Adobe
[23/02/2008|20:14] C:\Program Files\Alwil Software
[30/09/2006|00:47] C:\Program Files\Analog Devices
[17/03/2008|14:04] C:\Program Files\Audacity
[05/04/2008|02:36] C:\Program Files\BitDownload
[05/04/2008|02:33] C:\Program Files\BitTorrent Fastest Tool
[29/10/2006|18:26] C:\Program Files\Canon
[30/09/2006|00:47] C:\Program Files\ComPlus Applications
[01/06/2008|15:50] C:\Program Files\djDecks VirtualDJ Control Record Plug-In
[01/07/2008|19:56] C:\Program Files\eMule
[02/06/2008|00:34] C:\Program Files\Fichiers communs
[30/09/2006|00:47] C:\Program Files\Fingerprint Sensor
[09/05/2008|22:40] C:\Program Files\Google
[24/04/2008|03:45] C:\Program Files\Goto Software
[09/05/2008|22:40] C:\Program Files\Hewlett-Packard
[29/10/2006|18:14] C:\Program Files\Hp
[09/05/2008|23:24] C:\Program Files\HPQ
[09/05/2008|22:48] C:\Program Files\InstallShield Installation Information
[16/06/2008|14:00] C:\Program Files\Internet Explorer
[29/09/2006|16:09] C:\Program Files\InterVideo
[30/09/2006|00:47] C:\Program Files\Java
[30/09/2006|00:47] C:\Program Files\Messenger
[31/03/2008|21:00] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[30/09/2006|00:47] C:\Program Files\microsoft frontpage
[29/09/2006|20:26] C:\Program Files\Microsoft Office
[30/03/2008|23:59] C:\Program Files\Microsoft SQL Server Compact Edition
[30/09/2006|00:47] C:\Program Files\Movie Maker
[02/07/2008|13:43] C:\Program Files\Mozilla Firefox
[09/05/2008|22:49] C:\Program Files\MSN
[30/09/2006|00:47] C:\Program Files\MSN Gaming Zone
[05/06/2007|11:47] C:\Program Files\MSXML 4.0
[19/04/2008|21:35] C:\Program Files\NCH Swift Sound
[30/09/2006|00:47] C:\Program Files\NetMeeting
[30/05/2008|15:00] C:\Program Files\Norton Security Scan
[30/09/2006|00:47] C:\Program Files\Online Services
[24/02/2008|06:54] C:\Program Files\Outlook Express
[07/06/2008|19:59] C:\Program Files\PacificPoker4
[16/06/2008|01:03] C:\Program Files\Pvm
[17/08/2007|14:41] C:\Program Files\QuickTime
[29/09/2006|15:54] C:\Program Files\Raccourcis de programmes
[02/06/2008|00:31] C:\Program Files\Real
[24/04/2008|18:44] C:\Program Files\Secured IE
[03/05/2008|17:50] C:\Program Files\securedie
[30/09/2006|00:47] C:\Program Files\Services en ligne
[24/04/2008|18:44] C:\Program Files\ShoppingReport
[05/06/2007|11:46] C:\Program Files\Sofrel
[10/03/2008|00:16] C:\Program Files\SOFTOOLS
[30/09/2006|00:47] C:\Program Files\Sonic
[10/05/2008|12:49] C:\Program Files\SweetIM
[15/04/2008|19:58] C:\Program Files\Symantec
[30/09/2006|00:47] C:\Program Files\Synaptics
[30/09/2006|00:47] C:\Program Files\Uninstall Information
[23/02/2008|20:48] C:\Program Files\VideoLAN
[01/06/2008|15:48] C:\Program Files\VirtualDJ
[18/05/2008|19:08] C:\Program Files\Windows Live
[01/07/2008|20:00] C:\Program Files\Windows Live Safety Center
[13/04/2008|20:58] C:\Program Files\Windows Media Connect
[13/04/2008|21:02] C:\Program Files\Windows Media Connect 2
[13/04/2008|21:02] C:\Program Files\Windows Media Player
[30/09/2006|00:47] C:\Program Files\Windows NT
[30/09/2006|00:47] C:\Program Files\WindowsUpdate
[11/05/2008|12:03] C:\Program Files\WinRAR
[30/09/2006|00:47] C:\Program Files\xerox
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[09/05/2008|21:42] C:\Program Files\Fichiers communs\Adobe
[29/09/2006|20:26] C:\Program Files\Fichiers communs\Designer
[29/10/2006|18:13] C:\Program Files\Fichiers communs\HP
[30/09/2006|00:47] C:\Program Files\Fichiers communs\InstallShield
[30/09/2006|00:47] C:\Program Files\Fichiers communs\LightScribe
[30/03/2008|23:53] C:\Program Files\Fichiers communs\Microsoft Shared
[30/09/2006|00:47] C:\Program Files\Fichiers communs\MSSoap
[30/09/2006|00:47] C:\Program Files\Fichiers communs\ODBC
[02/06/2008|00:33] C:\Program Files\Fichiers communs\Real
[30/09/2006|00:47] C:\Program Files\Fichiers communs\Services
[26/10/2006|08:48] C:\Program Files\Fichiers communs\SOFREL
[30/09/2006|00:47] C:\Program Files\Fichiers communs\Sonic Shared
[30/09/2006|00:47] C:\Program Files\Fichiers communs\SpeechEngines
[30/09/2006|00:47] C:\Program Files\Fichiers communs\SureThing Shared
[15/04/2008|19:58] C:\Program Files\Fichiers communs\Symantec Shared
[24/02/2008|06:54] C:\Program Files\Fichiers communs\System
[30/09/2006|00:47] C:\Program Files\Fichiers communs\TiVo Shared
[30/03/2008|23:53] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[02/06/2008|00:34] C:\Program Files\Fichiers communs\xing shared
---------------------------[ Process ]--------------------------
... 60
IEXPLORE.EXE ~ [808]
----------------------[ Recherche avec S_Lop ]---------------------
C:\DOCUME~1\MARC\LOCALS~1\Temp\bis3F.exe
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tick Find Close Surf
C:\Program Files\Bitdownload
C:\Program Files\Bitdownload\session.store
C:\Program Files\BitTorrent Fastest Tool
C:\Program Files\BitTorrent Fastest Tool\BitDownload-4.5-setup.exe
C:\Program Files\BitTorrent Fastest Tool\BitP.exe
C:\Program Files\BitTorrent Fastest Tool\INSTALL.LOG
C:\DOCUME~1\MARC\Cookies\marc@adultfriendfinder[1].txt
C:\DOCUME~1\MARC\Cookies\marc@adin.bigpoint[2].txt
C:\DOCUME~1\MARC\Cookies\marc@bigpoint[2].txt
C:\DOCUME~1\MARC\Cookies\marc@fr1.seafight.bigpoint[1].txt
C:\DOCUME~1\MARC\Cookies\marc@banner.cotedazurpalace[2].txt
C:\DOCUME~1\MARC\Cookies\marc@cotedazurpalace[1].txt
C:\DOCUME~1\MARC\Cookies\marc@adopt.euroclick[2].txt
C:\DOCUME~1\MARC\Cookies\marc@pacificpoker[2].txt
C:\DOCUME~1\MARC\Cookies\marc@fr1.seafight.bigpoint[1].txt
C:\DOCUME~1\MARC\Cookies\marc@32vegas[2].txt
C:\DOCUME~1\MARC\Cookies\marc@banner.32vegas[2].txt
----------------------[ Verification du Registre ]----------------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts MODIFIE
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1
www.drivecleaner.com ## added by CiD
127.0.0.1
www.errorprotector.com ## added by CiD
127.0.0.1
www.errorsafe.com ## added by CiD
127.0.0.1
www.systemdoctor.com ## added by CiD
127.0.0.1
www.utils.winfixer.com ## added by CiD
127.0.0.1
www.win-anti-virus-pro.com ## added by CiD
127.0.0.1
www.win-virus-pro.com ## added by CiD
127.0.0.1
www.winantispam.com ## added by CiD
127.0.0.1
www.winantispy.com ## added by CiD
127.0.0.1
www.winantispyware.com ## added by CiD
127.0.0.1
www.winantivirus.com ## added by CiD
127.0.0.1
www.winantiviruspro.com ## added by CiD
127.0.0.1
www.windrivecleaner.com ## added by CiD
127.0.0.1
www.windrivesafe.com ## added by CiD
127.0.0.1
www.winfixer.com ## added by CiD
127.0.0.1
www.winfixer2006.com ## added by CiD
127.0.0.1
www.winsoftware.com ## added by CiD
-> 72 ( 70 ## added by CiD )
/!\ 1 Not 127.0.0.1 !!
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-02 14:20:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\nvs2.inf
C:\DOCUME~1\MARC\LOCALS~1\APPLIC~1\kqsgeuygs_navps.dat
C:\DOCUME~1\MARC\LOCALS~1\APPLIC~1\kqsgeuygs_nav.dat
C:\DOCUME~1\MARC\LOCALS~1\APPLIC~1\kqsgeuygs.dat
! EGDACCESS !
=> C:\Documents and Settings\MARC\Recent\Atomix Virtual DJ 3.2 + crack + 38 skins + 109 effects + 123 samples.lnk
=> C:\Documents and Settings\MARC\Recent\Virtual Dj 4 0 Full Crack Skins Samples Plugins Effects Vdjtimecode Fr French Francais.lnk
[F:920][D:40]-> C:\DOCUME~1\MARC\LOCALS~1\Temp
[F:112][D:0]-> C:\DOCUME~1\MARC\Cookies
[F:2593][D:4]-> C:\DOCUME~1\MARC\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 14:21:13,79 ]----------------------
Rapport navilogfix:
Search Navipromo version 3.6.0 commencé le 02/07/2008 à 14:49:12,56
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "MARC"
Mise à jour le 27.06.2008 à 23h00 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2900.2180
Système de fichiers : NTFS
Recherche executé en mode normal
*** Recherche Programmes installés ***
Favorit
*** Recherche dossiers dans "C:\WINDOWS" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Recherche dossiers dans "c:\docume~1\alluse~1\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\MARC\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\saur\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\MARC\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\saur\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\MARC\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\saur\menudm~1\progra~1" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos :
http://www.gmer.net
Aucun Fichier trouvé
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\WINDOWS\system32" *
* Recherche dans "C:\Documents and Settings\MARC\locals~1\applic~1" *
* Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *
* Recherche dans "C:\DOCUME~1\saur\locals~1\applic~1" *
*** Recherche fichiers ***
C:\WINDOWS\pack.epk trouvé !
C:\WINDOWS\system32\nvs2.inf trouvé !
*** Recherche clés spécifiques dans le Registre ***
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\WINDOWS\system32" :
* Dans "C:\Documents and Settings\MARC\locals~1\applic~1" :
kqsgeuygs.dat trouvé !
kqsgeuygs_nav.dat trouvé !
kqsgeuygs_navps.dat trouvé !
* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :
* Dans "C:\DOCUME~1\saur\locals~1\applic~1" :
3)Recherche Certificats :
Certificat Egroup trouvé !
Certificat Electronic-Group trouvé !
Certificat OOO-Favorit trouvé !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche fichiers connus :
*** Analyse terminée le 02/07/2008 à 14:53:15,12 ***
voila ...