Bonsoir, merci à vous pour ces conseils.
Il y avais deux choix de suppresion de fichier lop. Choix 1 : suppression +host et suppression -host, et bien j'ai commencé par le premier.
Voici le premier rapport (+host)
-----------------------[ Lop S&D 4.2.0-7 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : utilisateur ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 04/10/2008 | 20:20:41,59 ] [ PC : SY4PPTM34 ]
[ MAJ : 06-05-2008 | 21:45 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
Supprimé! - C:\DOCUME~1\UTILIS~1\APPLIC~1\32user~1\mcnknbiv.exe
Supprimé! - C:\DOCUME~1\UTILIS~1\APPLIC~1\32user~1\qalptqvy.exe
Supprimé! - C:\DOCUME~1\UTILIS~1\APPLIC~1\32user~1\rfszpefc.exe
Supprimé! - C:\DOCUME~1\UTILIS~1\APPLIC~1\32user~1\ryqrdpqs.exe
Supprimé! - C:\WINDOWS\Tasks\A5D61720919191BC.job
Supprimé! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Loud spam else tool
Supprimé! - C:\DOCUME~1\LOCALS~1\APPLIC~1\32user~1
Supprimé! - C:\DOCUME~1\UTILIS~1\APPLIC~1\32user~1
Supprimé! - C:\Program Files\32user~1
Restauré! - Fichier Hosts
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans Application Data ]------------
[18/11/2004|16:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[18/11/2004|15:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[18/11/2004|17:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/06/2008|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[06/04/2008|16:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[26/06/2008|07:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bin Wait Ante Cast
[07/05/2008|11:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[05/04/2008|15:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Brother
[19/11/2004|12:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[18/11/2004|16:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[06/04/2008|17:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[06/04/2008|17:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InterVideo
[05/04/2008|19:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[24/08/2008|21:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[22/12/2007|17:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Prism
[12/05/2008|18:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[05/04/2008|15:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
[28/08/2008|17:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\services
[19/08/2008|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SoftLand Ltd
[03/10/2008|19:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[06/04/2008|18:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[08/09/2007|15:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[15/04/2008|20:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[18/11/2004|19:10] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Adobe
[18/11/2004|16:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[18/11/2004|15:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[18/11/2004|19:10] C:\DOCUME~1\DEFAUL~1\APPLIC~1\InterTrust
[18/11/2004|17:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[10/08/2008|12:41] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[24/08/2008|21:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[18/11/2004|15:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[15/05/2008|10:57] C:\DOCUME~1\UTILIS~1\APPLIC~1\AccurateRip
[21/06/2008|16:40] C:\DOCUME~1\UTILIS~1\APPLIC~1\Adobe
[06/04/2008|18:19] C:\DOCUME~1\UTILIS~1\APPLIC~1\Apple Computer
[07/05/2008|11:20] C:\DOCUME~1\UTILIS~1\APPLIC~1\BitDefender
[28/07/2008|19:48] C:\DOCUME~1\UTILIS~1\APPLIC~1\Brother
[13/12/2004|11:44] C:\DOCUME~1\UTILIS~1\APPLIC~1\CyberLink
[18/11/2004|16:16] C:\DOCUME~1\UTILIS~1\APPLIC~1\desktop.ini
[10/06/2008|19:46] C:\DOCUME~1\UTILIS~1\APPLIC~1\Desktopicon
[19/12/2004|18:11] C:\DOCUME~1\UTILIS~1\APPLIC~1\Help
[04/10/2008|17:05] C:\DOCUME~1\UTILIS~1\APPLIC~1\Icone
[18/11/2004|15:27] C:\DOCUME~1\UTILIS~1\APPLIC~1\Identities
[04/09/2008|18:15] C:\DOCUME~1\UTILIS~1\APPLIC~1\IGN2K5
[18/11/2004|19:10] C:\DOCUME~1\UTILIS~1\APPLIC~1\InterTrust
[09/04/2008|16:08] C:\DOCUME~1\UTILIS~1\APPLIC~1\ma-config.com
[06/06/2007|18:57] C:\DOCUME~1\UTILIS~1\APPLIC~1\Macromedia
[03/09/2008|17:50] C:\DOCUME~1\UTILIS~1\APPLIC~1\Microsoft
[06/04/2008|11:48] C:\DOCUME~1\UTILIS~1\APPLIC~1\ScanSoft
[06/04/2008|19:01] C:\DOCUME~1\UTILIS~1\APPLIC~1\Ulead Systems
[14/04/2008|16:48] C:\DOCUME~1\UTILIS~1\APPLIC~1\vlc
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[04/10/2008 18:51][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUser.job
[10/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
[04/10/2008 14:05][--ah-----] C:\WINDOWS\tasks\SA.DAT
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[09/06/2008|19:41] C:\Program Files\Adobe
[18/11/2004|18:56] C:\Program Files\Ahead
[28/06/2008|23:14] C:\Program Files\AlerteGPS
[04/09/2008|18:59] C:\Program Files\Anuman Interactive
[18/11/2004|17:11] C:\Program Files\ATI Technologies
[07/05/2008|11:19] C:\Program Files\BitDefender
[05/04/2008|15:29] C:\Program Files\Brother
[05/05/2008|12:56] C:\Program Files\CCleaner
[05/04/2008|15:28] C:\Program Files\Common Files
[18/11/2004|15:23] C:\Program Files\ComPlus Applications
[25/11/2004|14:16] C:\Program Files\Cr‚ez votre site Web
[19/11/2004|12:51] C:\Program Files\CyberLink
[06/06/2007|16:39] C:\Program Files\Ediser
[18/11/2004|18:04] C:\Program Files\FIC
[15/04/2008|20:16] C:\Program Files\Fichiers communs
[18/11/2004|15:34] C:\Program Files\HighMAT CD Writing Wizard
[04/09/2008|18:04] C:\Program Files\IGN France
[15/05/2008|10:57] C:\Program Files\Illustrate
[04/09/2008|18:27] C:\Program Files\InstallShield Installation Information
[18/11/2004|16:01] C:\Program Files\Intel
[04/10/2008|17:05] C:\Program Files\Internet Explorer
[06/04/2008|17:00] C:\Program Files\InterVideo
[06/06/2007|18:46] C:\Program Files\Inventel
[11/03/2005|18:14] C:\Program Files\K-Lite Codec Pack
[08/05/2008|18:08] C:\Program Files\Lavalys
[04/04/2008|17:43] C:\Program Files\ma-config.com
[30/04/2008|19:35] C:\Program Files\Maxis
[14/08/2008|23:35] C:\Program Files\Messenger
[12/08/2008|19:02] C:\Program Files\Metin2_France
[18/11/2004|15:27] C:\Program Files\microsoft frontpage
[08/09/2007|17:53] C:\Program Files\Microsoft Office
[03/10/2008|20:24] C:\Program Files\Microsoft Windows OneCare Live
[08/09/2007|17:52] C:\Program Files\Microsoft.NET
[18/11/2004|15:24] C:\Program Files\Movie Maker
[15/05/2008|11:18] C:\Program Files\MSN
[18/11/2004|15:22] C:\Program Files\MSN Gaming Zone
[18/11/2004|15:25] C:\Program Files\NetMeeting
[18/11/2004|15:23] C:\Program Files\Online Services
[16/06/2007|13:43] C:\Program Files\Outlook Express
[05/04/2008|14:12] C:\Program Files\PacificPoker4
[28/09/2008|17:39] C:\Program Files\PDF…Word
[18/11/2004|15:34] C:\Program Files\Phoenix Technologies Ltd
[06/04/2008|16:57] C:\Program Files\QuickTime
[18/11/2004|17:18] C:\Program Files\Realtek
[05/04/2008|15:26] C:\Program Files\ScanSoft
[18/11/2004|15:25] C:\Program Files\Services en ligne
[19/12/2004|20:16] C:\Program Files\ShowTime
[03/10/2008|19:09] C:\Program Files\Spybot - Search & Destroy
[06/04/2008|18:57] C:\Program Files\Ulead Systems
[18/11/2004|15:31] C:\Program Files\Uninstall Information
[07/06/2008|19:47] C:\Program Files\Unlocker
[04/10/2008|17:39] C:\Program Files\Wanadoo
[05/04/2008|16:16] C:\Program Files\Wanadoo Messager
[18/11/2004|15:35] C:\Program Files\Windows Journal Viewer
[15/04/2008|20:17] C:\Program Files\Windows Live
[06/04/2008|16:55] C:\Program Files\Windows Media Components
[18/11/2004|15:34] C:\Program Files\Windows Media Connect
[18/11/2004|15:34] C:\Program Files\Windows Media Player
[18/11/2004|15:22] C:\Program Files\Windows NT
[18/11/2004|15:22] C:\Program Files\Windows Plus
[18/11/2004|15:25] C:\Program Files\WindowsUpdate
[11/03/2005|18:13] C:\Program Files\WinRAR
[03/10/2008|22:30] C:\Program Files\WinTV
[18/11/2004|15:27] C:\Program Files\xerox
[08/05/2008|21:53] C:\Program Files\Yahoo!
[05/04/2008|16:30] C:\Program Files\ZebHelpProcess 2
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[09/06/2008|19:41] C:\Program Files\Fichiers communs\Adobe
[18/11/2004|18:55] C:\Program Files\Fichiers communs\Ahead
[07/05/2008|11:19] C:\Program Files\Fichiers communs\BitDefender
[05/04/2008|16:30] C:\Program Files\Fichiers communs\Borland Shared
[08/09/2007|17:53] C:\Program Files\Fichiers communs\DESIGNER
[05/04/2008|16:13] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[05/04/2008|15:28] C:\Program Files\Fichiers communs\InstallShield
[14/06/2008|23:05] C:\Program Files\Fichiers communs\Microsoft Shared
[18/11/2004|15:25] C:\Program Files\Fichiers communs\MSSoap
[18/11/2004|16:16] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|15:26] C:\Program Files\Fichiers communs\ScanSoft Shared
[18/11/2004|15:25] C:\Program Files\Fichiers communs\Services
[18/11/2004|16:16] C:\Program Files\Fichiers communs\SpeechEngines
[08/09/2007|17:53] C:\Program Files\Fichiers communs\System
[06/04/2008|19:02] C:\Program Files\Fichiers communs\Ulead Systems
[15/04/2008|20:16] C:\Program Files\Fichiers communs\WindowsLiveInstaller
---------------------------[ Process ]--------------------------
... 56
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 20:22:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
/!\ [Fich:252][Doss:8] C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp
/!\ [Fich:29][Doss:0] C:\DOCUME~1\UTILIS~1\Cookies
/!\ [Fich:528][Doss:6] C:\DOCUME~1\UTILIS~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 20:22:41,59 ]----------------------
Rapport 2 (-host)
-----------------------[ Lop S&D 4.2.0-7 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : utilisateur ] [ "C:\Lop SD" ] [ Selection : 3 ]
[ 04/10/2008 | 20:24:19,64 ] [ PC : SY4PPTM34 ]
[ MAJ : 06-05-2008 | 21:45 ]
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans Application Data ]------------
[18/11/2004|16:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[18/11/2004|15:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[18/11/2004|17:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/06/2008|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[06/04/2008|16:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[26/06/2008|07:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bin Wait Ante Cast
[07/05/2008|11:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[05/04/2008|15:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Brother
[19/11/2004|12:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[18/11/2004|16:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[06/04/2008|17:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[06/04/2008|17:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InterVideo
[05/04/2008|19:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[24/08/2008|21:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[22/12/2007|17:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Prism
[12/05/2008|18:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[05/04/2008|15:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
[28/08/2008|17:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\services
[19/08/2008|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SoftLand Ltd
[03/10/2008|19:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[06/04/2008|18:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[08/09/2007|15:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[15/04/2008|20:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[18/11/2004|19:10] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Adobe
[18/11/2004|16:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[18/11/2004|15:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[18/11/2004|19:10] C:\DOCUME~1\DEFAUL~1\APPLIC~1\InterTrust
[18/11/2004|17:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[10/08/2008|12:41] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[24/08/2008|21:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[18/11/2004|15:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[15/05/2008|10:57] C:\DOCUME~1\UTILIS~1\APPLIC~1\AccurateRip
[21/06/2008|16:40] C:\DOCUME~1\UTILIS~1\APPLIC~1\Adobe
[06/04/2008|18:19] C:\DOCUME~1\UTILIS~1\APPLIC~1\Apple Computer
[07/05/2008|11:20] C:\DOCUME~1\UTILIS~1\APPLIC~1\BitDefender
[28/07/2008|19:48] C:\DOCUME~1\UTILIS~1\APPLIC~1\Brother
[13/12/2004|11:44] C:\DOCUME~1\UTILIS~1\APPLIC~1\CyberLink
[18/11/2004|16:16] C:\DOCUME~1\UTILIS~1\APPLIC~1\desktop.ini
[10/06/2008|19:46] C:\DOCUME~1\UTILIS~1\APPLIC~1\Desktopicon
[19/12/2004|18:11] C:\DOCUME~1\UTILIS~1\APPLIC~1\Help
[04/10/2008|17:05] C:\DOCUME~1\UTILIS~1\APPLIC~1\Icone
[18/11/2004|15:27] C:\DOCUME~1\UTILIS~1\APPLIC~1\Identities
[04/09/2008|18:15] C:\DOCUME~1\UTILIS~1\APPLIC~1\IGN2K5
[18/11/2004|19:10] C:\DOCUME~1\UTILIS~1\APPLIC~1\InterTrust
[09/04/2008|16:08] C:\DOCUME~1\UTILIS~1\APPLIC~1\ma-config.com
[06/06/2007|18:57] C:\DOCUME~1\UTILIS~1\APPLIC~1\Macromedia
[03/09/2008|17:50] C:\DOCUME~1\UTILIS~1\APPLIC~1\Microsoft
[06/04/2008|11:48] C:\DOCUME~1\UTILIS~1\APPLIC~1\ScanSoft
[06/04/2008|19:01] C:\DOCUME~1\UTILIS~1\APPLIC~1\Ulead Systems
[14/04/2008|16:48] C:\DOCUME~1\UTILIS~1\APPLIC~1\vlc
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[04/10/2008 18:51][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUser.job
[10/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
[04/10/2008 14:05][--ah-----] C:\WINDOWS\tasks\SA.DAT
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[09/06/2008|19:41] C:\Program Files\Adobe
[18/11/2004|18:56] C:\Program Files\Ahead
[28/06/2008|23:14] C:\Program Files\AlerteGPS
[04/09/2008|18:59] C:\Program Files\Anuman Interactive
[18/11/2004|17:11] C:\Program Files\ATI Technologies
[07/05/2008|11:19] C:\Program Files\BitDefender
[05/04/2008|15:29] C:\Program Files\Brother
[05/05/2008|12:56] C:\Program Files\CCleaner
[05/04/2008|15:28] C:\Program Files\Common Files
[18/11/2004|15:23] C:\Program Files\ComPlus Applications
[25/11/2004|14:16] C:\Program Files\Cr‚ez votre site Web
[19/11/2004|12:51] C:\Program Files\CyberLink
[06/06/2007|16:39] C:\Program Files\Ediser
[18/11/2004|18:04] C:\Program Files\FIC
[15/04/2008|20:16] C:\Program Files\Fichiers communs
[18/11/2004|15:34] C:\Program Files\HighMAT CD Writing Wizard
[04/09/2008|18:04] C:\Program Files\IGN France
[15/05/2008|10:57] C:\Program Files\Illustrate
[04/09/2008|18:27] C:\Program Files\InstallShield Installation Information
[18/11/2004|16:01] C:\Program Files\Intel
[04/10/2008|17:05] C:\Program Files\Internet Explorer
[06/04/2008|17:00] C:\Program Files\InterVideo
[06/06/2007|18:46] C:\Program Files\Inventel
[11/03/2005|18:14] C:\Program Files\K-Lite Codec Pack
[08/05/2008|18:08] C:\Program Files\Lavalys
[04/04/2008|17:43] C:\Program Files\ma-config.com
[30/04/2008|19:35] C:\Program Files\Maxis
[14/08/2008|23:35] C:\Program Files\Messenger
[12/08/2008|19:02] C:\Program Files\Metin2_France
[18/11/2004|15:27] C:\Program Files\microsoft frontpage
[08/09/2007|17:53] C:\Program Files\Microsoft Office
[03/10/2008|20:24] C:\Program Files\Microsoft Windows OneCare Live
[08/09/2007|17:52] C:\Program Files\Microsoft.NET
[18/11/2004|15:24] C:\Program Files\Movie Maker
[15/05/2008|11:18] C:\Program Files\MSN
[18/11/2004|15:22] C:\Program Files\MSN Gaming Zone
[18/11/2004|15:25] C:\Program Files\NetMeeting
[18/11/2004|15:23] C:\Program Files\Online Services
[16/06/2007|13:43] C:\Program Files\Outlook Express
[05/04/2008|14:12] C:\Program Files\PacificPoker4
[28/09/2008|17:39] C:\Program Files\PDF…Word
[18/11/2004|15:34] C:\Program Files\Phoenix Technologies Ltd
[06/04/2008|16:57] C:\Program Files\QuickTime
[18/11/2004|17:18] C:\Program Files\Realtek
[05/04/2008|15:26] C:\Program Files\ScanSoft
[18/11/2004|15:25] C:\Program Files\Services en ligne
[19/12/2004|20:16] C:\Program Files\ShowTime
[03/10/2008|19:09] C:\Program Files\Spybot - Search & Destroy
[06/04/2008|18:57] C:\Program Files\Ulead Systems
[18/11/2004|15:31] C:\Program Files\Uninstall Information
[07/06/2008|19:47] C:\Program Files\Unlocker
[04/10/2008|17:39] C:\Program Files\Wanadoo
[05/04/2008|16:16] C:\Program Files\Wanadoo Messager
[18/11/2004|15:35] C:\Program Files\Windows Journal Viewer
[15/04/2008|20:17] C:\Program Files\Windows Live
[06/04/2008|16:55] C:\Program Files\Windows Media Components
[18/11/2004|15:34] C:\Program Files\Windows Media Connect
[18/11/2004|15:34] C:\Program Files\Windows Media Player
[18/11/2004|15:22] C:\Program Files\Windows NT
[18/11/2004|15:22] C:\Program Files\Windows Plus
[18/11/2004|15:25] C:\Program Files\WindowsUpdate
[11/03/2005|18:13] C:\Program Files\WinRAR
[03/10/2008|22:30] C:\Program Files\WinTV
[18/11/2004|15:27] C:\Program Files\xerox
[08/05/2008|21:53] C:\Program Files\Yahoo!
[05/04/2008|16:30] C:\Program Files\ZebHelpProcess 2
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[09/06/2008|19:41] C:\Program Files\Fichiers communs\Adobe
[18/11/2004|18:55] C:\Program Files\Fichiers communs\Ahead
[07/05/2008|11:19] C:\Program Files\Fichiers communs\BitDefender
[05/04/2008|16:30] C:\Program Files\Fichiers communs\Borland Shared
[08/09/2007|17:53] C:\Program Files\Fichiers communs\DESIGNER
[05/04/2008|16:13] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[05/04/2008|15:28] C:\Program Files\Fichiers communs\InstallShield
[14/06/2008|23:05] C:\Program Files\Fichiers communs\Microsoft Shared
[18/11/2004|15:25] C:\Program Files\Fichiers communs\MSSoap
[18/11/2004|16:16] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|15:26] C:\Program Files\Fichiers communs\ScanSoft Shared
[18/11/2004|15:25] C:\Program Files\Fichiers communs\Services
[18/11/2004|16:16] C:\Program Files\Fichiers communs\SpeechEngines
[08/09/2007|17:53] C:\Program Files\Fichiers communs\System
[06/04/2008|19:02] C:\Program Files\Fichiers communs\Ulead Systems
[15/04/2008|20:16] C:\Program Files\Fichiers communs\WindowsLiveInstaller
---------------------------[ Process ]--------------------------
... 56
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 20:26:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
/!\ [Fich:253][Doss:8] C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp
/!\ [Fich:29][Doss:0] C:\DOCUME~1\UTILIS~1\Cookies
/!\ [Fich:530][Doss:6] C:\DOCUME~1\UTILIS~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 20:26:57,20 ]----------------------
Rapport hijack
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:29:34, on 04/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SDDetect.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\utilisateur\Bureau\Nettoyage\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Windows module - {2756BAD7-2F9F-47ef-AE6D-8D39CCEB396F} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" VBStart
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [setDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [ante cast ooze tray] C:\Documents and Settings\All Users\Application Data\Bin Wait Ante Cast\Play New.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\utilisateur\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: LED Display Driver.lnk = C:\WINDOWS\SDDetect.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/fichier...on_2_0_4_13.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\PROGRA~1\WinTV\HCWTVS~1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 8358 bytes
Merci