Voilà pour le premier rapport que j'avais oublié.
Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1876
Windows 5.1.2600 Service Pack 3
20/03/2009 15:49:12
mbam-log-2009-03-20 (15-49-12).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 112482
Temps écoulé: 31 minute(s), 8 second(s)
Processus mémoire infecté(s): 3
Module(s) mémoire infecté(s): 8
Clé(s) du Registre infectée(s): 29
Valeur(s) du Registre infectée(s): 10
Elément(s) de données du Registre infecté(s): 8
Dossier(s) infecté(s): 12
Fichier(s) infecté(s): 71
Processus mémoire infecté(s):
C:\Documents and Settings\lolly\Application Data\nidle\nidle.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\system32\wcenter.exe (Trojan.FakeAlert) -> Unloaded process successfully.
C:\Program Files\Malware Defender 2009\malwaredef.exe (Rogue.MalwareDefender) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\ruhefife.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\yijukidi.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\yizimife.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\zizesabo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\mozulavo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll (Trojan.Fakealert) -> Delete on reboot.
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\ecepgmldzw.dll (Trojan.Fakealert) -> Delete on reboot.
C:\Program Files\Mozilla Firefox\components\srff.dll (Trojan.Agent) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b645ee8f-1139-4054-8fa8-000a4de468d4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{b645ee8f-1139-4054-8fa8-000a4de468d4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b645ee8f-1139-4054-8fa8-000a4de468d4} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d25bcd5e-8295-4462-a81d-64eda68b62c4} (Trojan.Fakealert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4d244c91-9dc9-4267-a9d1-c0a02e2803c7} (Trojan.Fakealert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_cpv.workhorse (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{63334394-3da3-4b29-a041-03535909d361} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_cpv.workhorse.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d88e1558-7c2d-407a-953a-c044f5607cea} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d88e1558-7c2d-407a-953a-c044f5607cea} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d88e1558-7c2d-407a-953a-c044f5607cea} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Adware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ExtSecurityCenter (Rogue.ExtSecurityCenter) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TSA (Adware.TargetSaver) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defender 2009 (Rogue.MalwareDefender2009) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4c55e43b (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yuforojabi (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm4f66d7a7 (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\hardwaredrivers (Trojan.Fakealert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\driversload (Trojan.Fakealert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nidle (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\malwaredef (Rogue.MalwareDefender) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows logon applicationedc (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\yijukidi.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\yijukidi.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\yijukidi.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\yizimife.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\yizimife.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
C:\Program Files\InetGet2 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Application Data\nidle (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\WWShow (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Application Data\speedrunner (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\Program Files\iCheck (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\VnrPack (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\VirusRemover2009 (Rogue.VirusRemove) -> Quarantined and deleted successfully.
C:\Program Files\Jcore (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aNI15 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Malware Defender 2009 (Rogue.MalwareDefender2009) -> Quarantined and deleted successfully.
C:\Program Files\Malware Defender 2009\quarantine (Rogue.MalwareDefender2009) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers (Rogue.MalwareDefender2009) -> Delete on reboot.
Fichier(s) infecté(s):
C:\WINDOWS\system32\refurepo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\operufer.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ruhefife.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\efifehur.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mozulavo.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\yizimife.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\zizesabo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\yijukidi.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll (Trojan.Fakealert) -> Delete on reboot.
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\ecepgmldzw.dll (Trojan.Fakealert) -> Delete on reboot.
C:\Documents and Settings\lolly\Application Data\nidle\nidle.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wcenter.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\Malware Defender 2009\malwaredef.exe (Rogue.MalwareDefender) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\components\srff.dll (Trojan.Agent) -> Delete on reboot.
C:\Program Files\WWShow\WWShow.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Program Files\Jcore\Jcore2.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\win.exe (Rogue.MalwareDefender) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\svchos.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Application Data\SpeedRunner\SpeedRunner.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Application Data\Twain\Twain.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Local Settings\Temp\tsinstall_4_0_4_0_b4.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Local Settings\Temp\tsupdate_4_0_4_1_b3.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Local Settings\Temp\__14.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Local Settings\Temp\__15.tmp (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Local Settings\Temp\__18.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Local Settings\Temp\__1C.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Local Settings\Temporary Internet Files\Content.IE5\X7K3SQIS\virusremover2009_setup_free_rezer_en[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Program Files\Fichiers communs\mqir\mqira.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Fichiers communs\mqir\mqirl.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Fichiers communs\mqir\mqirp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Fichiers communs\mqir\mqird\mqirc.dll (Adware.TargetServer) -> Quarantined and deleted successfully.
C:\Program Files\iCheck\Uninstall.exe (Adware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\VnrPack\VnrPack28.exe (Adware.SpeedMonitor) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP136\A0049322.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP137\A0049340.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP137\A0049383.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP137\A0050383.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP137\A0051382.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP138\A0051400.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP138\A0051425.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP138\A0051440.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP138\A0052433.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP138\A0052443.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP138\A0053440.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03C3FDF4-B10A-4684-A5DC-3B39F16CBF81}\RP138\A0053454.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ravuhavu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MSINET.oca (Rogue.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rijavuza.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tsuninst.exe (Spyware.TargetSaver) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hodisuto.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kawolumi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aNI02\aNI022328.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aNI15\aNI151080.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Application Data\speedrunner\config.cfg (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\Program Files\VnrPack\trgts.gz (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\VirusRemover2009\ExtSecurityCenter.exe (Rogue.VirusRemove) -> Quarantined and deleted successfully.
C:\Program Files\Malware Defender 2009\conf.cfg (Rogue.MalwareDefender2009) -> Quarantined and deleted successfully.
C:\Program Files\Malware Defender 2009\mbase.vdb (Rogue.MalwareDefender2009) -> Quarantined and deleted successfully.
C:\Program Files\Malware Defender 2009\quarantine.vdb (Rogue.MalwareDefender2009) -> Quarantined and deleted successfully.
C:\Program Files\Malware Defender 2009\queue.vdb (Rogue.MalwareDefender2009) -> Quarantined and deleted successfully.
C:\Program Files\Malware Defender 2009\uninstall.exe (Rogue.MalwareDefender2009) -> Quarantined and deleted successfully.
C:\Program Files\Malware Defender 2009\vbase.vdb (Rogue.MalwareDefender2009) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\c.cgm (Rogue.MalwareDefender2009) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\Bureau\Malware Defender 2009.lnk (Rogue.Link) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\~.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\sysexplorer.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\reged.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\sys.com (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\syscert.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\lolly\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
Et le second rapport avec Lop
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor LE-1150 )
BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
USER : lolly ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:149 Go (Free:133 Go)
D:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 20/03/2009|16:16 )
--------------------\\ Listing des dossiers dans APPLIC~1
[24/10/2008|16:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[06/02/2009|21:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\aim rect help creative
[13/02/2009|18:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[27/10/2008|22:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[04/03/2009|12:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CDTEST
[25/10/2008|22:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[27/10/2008|22:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[20/03/2009|15:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[25/10/2008|09:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[20/03/2009|15:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[23/10/2008|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Corporation
[27/10/2008|22:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[24/10/2008|17:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[22/10/2008|20:26] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[22/10/2008|20:26] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[24/10/2008|16:24] C:\DOCUME~1\lolly\APPLIC~1\Adobe
[27/10/2008|23:38] C:\DOCUME~1\lolly\APPLIC~1\Creative
[20/03/2009|01:14] C:\DOCUME~1\lolly\APPLIC~1\FUJIFILM
[30/01/2009|18:50] C:\DOCUME~1\lolly\APPLIC~1\gtk-2.0
[22/10/2008|20:30] C:\DOCUME~1\lolly\APPLIC~1\Identities
[20/03/2009|01:07] C:\DOCUME~1\lolly\APPLIC~1\InstallShield
[27/10/2008|22:53] C:\DOCUME~1\lolly\APPLIC~1\LimeWire
[23/10/2008|14:55] C:\DOCUME~1\lolly\APPLIC~1\Macromedia
[20/03/2009|15:15] C:\DOCUME~1\lolly\APPLIC~1\Malwarebytes
[13/02/2009|18:04] C:\DOCUME~1\lolly\APPLIC~1\Microsoft
[05/12/2008|21:29] C:\DOCUME~1\lolly\APPLIC~1\Mozilla
[24/10/2008|14:41] C:\DOCUME~1\lolly\APPLIC~1\OpenOffice.org
[26/10/2008|11:14] C:\DOCUME~1\lolly\APPLIC~1\Real
[06/02/2009|21:31] C:\DOCUME~1\lolly\APPLIC~1\Real Itch Link
[17/12/2008|12:09] C:\DOCUME~1\lolly\APPLIC~1\Samsung
[23/10/2008|19:17] C:\DOCUME~1\lolly\APPLIC~1\Sun
[24/10/2008|14:39] C:\DOCUME~1\lolly\APPLIC~1\Talkback
[20/03/2009|15:49] C:\DOCUME~1\lolly\APPLIC~1\Twain
[23/10/2008|08:36] C:\DOCUME~1\lolly\APPLIC~1\vlc
[27/10/2008|17:53] C:\DOCUME~1\lolly\APPLIC~1\WinRAR
[22/10/2008|20:26] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[20/03/2009 16:00][--ah-----] C:\WINDOWS\tasks\ADDCA266911B5C16.job
[20/03/2009 15:50][--ah-----] C:\WINDOWS\tasks\SA.DAT
[02/03/2006 15:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
( ADDCA266911B5C16.job )=( c:\docume~1\lolly\applic~1\realit~1\Elsespamsixth.exe )
--------------------\\ Listing des dossiers dans C:\Program Files
[24/10/2008|16:28] C:\Program Files\Adobe
[13/02/2009|22:03] C:\Program Files\Alwil Software
[25/10/2008|22:36] C:\Program Files\Audible
[18/03/2009|13:15] C:\Program Files\AxBx
[06/02/2009|21:29] C:\Program Files\Circle Developeent
[22/10/2008|20:24] C:\Program Files\ComPlus Applications
[25/10/2008|22:37] C:\Program Files\Creative
[25/10/2008|22:35] C:\Program Files\Creative Installation Information
[20/03/2009|10:05] C:\Program Files\Enigma Software Group
[18/03/2009|12:59] C:\Program Files\Fichiers communs
[20/03/2009|12:16] C:\Program Files\FinePixViewer
[16/11/2008|19:29] C:\Program Files\GIMP-2.0
[20/03/2009|01:09] C:\Program Files\InstallShield Installation Information
[13/12/2008|11:39] C:\Program Files\Internet Explorer
[07/12/2008|11:12] C:\Program Files\Java
[23/10/2008|19:18] C:\Program Files\JRE
[26/10/2008|22:42] C:\Program Files\LimeWire
[20/03/2009|15:15] C:\Program Files\Malwarebytes' Anti-Malware
[13/12/2008|11:41] C:\Program Files\Messenger
[06/02/2009|21:29] C:\Program Files\Messenger Plus! Live
[22/10/2008|20:27] C:\Program Files\microsoft frontpage
[23/10/2008|13:44] C:\Program Files\Microsoft Windows Vista Upgrade Advisor
[13/12/2008|11:39] C:\Program Files\Movie Maker
[20/03/2009|15:51] C:\Program Files\Mozilla Firefox
[22/10/2008|20:23] C:\Program Files\MSN
[22/10/2008|20:24] C:\Program Files\MSN Gaming Zone
[18/12/2008|22:51] C:\Program Files\MSXML 4.0
[23/10/2008|19:19] C:\Program Files\MSXML 6.0
[13/12/2008|11:37] C:\Program Files\NetMeeting
[22/10/2008|20:24] C:\Program Files\Online Services
[23/10/2008|19:18] C:\Program Files\OpenOffice.org 3
[13/12/2008|11:37] C:\Program Files\Outlook Express
[26/10/2008|11:08] C:\Program Files\Real
[06/02/2009|21:30] C:\Program Files\Real Itch Link
[23/10/2008|13:11] C:\Program Files\Realtek
[17/12/2008|11:46] C:\Program Files\Samsung
[22/10/2008|20:25] C:\Program Files\Services en ligne
[20/03/2009|10:36] C:\Program Files\Trend Micro
[22/10/2008|20:30] C:\Program Files\Uninstall Information
[23/10/2008|08:32] C:\Program Files\VideoLAN
[27/10/2008|22:45] C:\Program Files\VirginMega
[24/10/2008|18:38] C:\Program Files\Windows Live
[27/10/2008|22:40] C:\Program Files\Windows Media Connect 2
[13/12/2008|11:37] C:\Program Files\Windows Media Player
[13/12/2008|11:37] C:\Program Files\Windows NT
[22/10/2008|20:25] C:\Program Files\WindowsUpdate
[27/10/2008|17:46] C:\Program Files\WinRAR
[22/10/2008|20:27] C:\Program Files\xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[24/10/2008|16:22] C:\Program Files\Fichiers communs\Adobe
[25/10/2008|22:34] C:\Program Files\Fichiers communs\Creative
[20/03/2009|01:09] C:\Program Files\Fichiers communs\InstallShield
[23/10/2008|19:17] C:\Program Files\Fichiers communs\Java
[24/10/2008|18:12] C:\Program Files\Fichiers communs\Microsoft Shared
[20/03/2009|15:49] C:\Program Files\Fichiers communs\mqir
[22/10/2008|20:25] C:\Program Files\Fichiers communs\MSSoap
[22/10/2008|23:16] C:\Program Files\Fichiers communs\ODBC
[26/10/2008|11:08] C:\Program Files\Fichiers communs\Real
[22/10/2008|20:25] C:\Program Files\Fichiers communs\Services
[22/10/2008|23:16] C:\Program Files\Fichiers communs\SpeechEngines
[13/12/2008|11:37] C:\Program Files\Fichiers communs\System
[24/10/2008|18:12] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[26/10/2008|11:08] C:\Program Files\Fichiers communs\xing shared
--------------------\\ Process
( 31 Processes )
iexplore.exe ~ [PID:576]
--------------------\\ Recherche avec S_Lop
C:\DOCUME~1\lolly\LOCALS~1\Temp\bis3B.exe
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\aim rect help creative
C:\DOCUME~1\ALLUSE~1\APPLIC~1\aim rect help creative\enc 01.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1\aim rect help creative\enc 01.exe
C:\DOCUME~1\lolly\APPLIC~1\realit~1
C:\DOCUME~1\lolly\APPLIC~1\realit~1\axvppwsh.exe
C:\DOCUME~1\lolly\APPLIC~1\realit~1\Else spam sixth.exe
C:\DOCUME~1\lolly\APPLIC~1\realit~1\test funk trans list.exe
C:\DOCUME~1\lolly\APPLIC~1\realit~1\VcWay.exe
C:\Program Files\realit~1
C:\DOCUME~1\lolly\LOCALS~1\Temp\msgpl_3720.tmp
C:\DOCUME~1\lolly\Cookies\lolly@advertising[1].txt
C:\WINDOWS\Tasks\ADDCA266911B5C16.job
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pure sect"="C:\\DOCUME~1\\lolly\\APPLIC~1\\REALIT~1\\VcWay.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Help Creative Meow City"="C:\\Documents and Settings\\All Users\\Application Data\\aim rect help creative\\enc 01.exe"
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-20 16:17:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 12
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:8626][D:217]-> C:\DOCUME~1\lolly\LOCALS~1\Temp
[F:119][D:0]-> C:\DOCUME~1\lolly\Cookies
[F:528][D:5]-> C:\DOCUME~1\lolly\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 20/03/2009|16:18 - Option : [1]
--------------------\\ Fin du rapport a 16:18:18