Alors Mb-AM ne trouve plus rien donc :
-----------\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Edition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3500+ )
BIOS : Award Modular BIOS v6.00PG
USER : Quentin ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition Classic 8.0.1.30 (Activated)
Firewall : NVIDIA Firewall 1.0 (Not Activated)
C: (Local Disk) - NTFS - Total:279 Go (Free:104 Go)
D: (CD or DVD)
E: (CD or DVD)
H: (USB)
I: (USB)
J: (USB)
K: (USB)
"C:ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 27/05/2009|17:22 )
-----------\ SUPPRESSION
Supprime! - C:Program FilesAskTBarar
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar1
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbara.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbaramazon.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbaran.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbararrow.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbararrowB.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbararrowT.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbararrow_down.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbararrow_up.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarautofill.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarg_pub.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarg_ttl.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarottom.png
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarottom_left.png
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarottom_right.png
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbartn_addstations.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbartn_delete.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarc.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarCAlogo.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarcanalblog.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarcn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarCOMBOSEARCH.list
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbard.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbardictionary2.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbardn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarDownloadCOM.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbardropdown.css
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbaremail_b.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarequalizer_loading.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarequalizer_off.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarequalizer_on.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarErrorPageTemplate.css
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarErrorPageTemplate_search.css
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarf.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarfn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarg.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargaming.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargraphred0.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargraphred0_5.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargraphred1.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargraphred1_5.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargraphred2.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargraphred2_5.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargraphred3.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargraphred3_5.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargraphred4.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargraphred4_5.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbargraphred5.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarhelp.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarhideremove.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarhighlight.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarhn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarhoroscope.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_aquarius.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_aries.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_cancer.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_capricorn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_gemini.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_leo.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_libra.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_pisces.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_sagittarius.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_scorpio.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_taurus.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarh_virgo.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbari.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarIEtab2_1.zip
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarimages01.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarin.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarj.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarjn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbark.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarkn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarl.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarleft.png
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarln.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarloading.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarlogo.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarlogo_facebook.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarminus.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarminus_on.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarmusic2.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt140289484
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt20095906
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt20493703
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt20910937
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt21126765
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt21477281
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt24847218
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt34538343
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt47008046
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt6606265
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt7108218
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNew York_NY_weather.txt9422171
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarNewCfg
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
ews.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
ews.html
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
ewsb.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
n.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbaro.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbaron.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarp.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarpixsy.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarplay.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarplay_on.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarplus.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarplus_on.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarpn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarpopup_off.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarpopup_on.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarpopup_ona.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarp_yahoo.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarp_yahoo_fr.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarq.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarqn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
adiocfgdlg.html
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarRadioStations.list
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
adio_bg.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
elatedlinks.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
eport.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
ight.png
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
n.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
ss.xsl
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
ss1.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
sslib.js
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
ssmenu1_7a.zip
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbars.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsearch.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsearch.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsearch_fr.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsettings.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarshop2.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt168601296
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt181055109
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt18317890
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt20092171
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt20095906
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt20493703
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt20910921
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt20961531
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt21477281
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt30408171
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt34538328
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt34978734
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt4744968
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt4905859
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt5334968
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt5482390
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt5528156
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt6151406
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt6348890
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt6485046
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt6543468
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt6547046
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt7771187
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsinfo.txt9422171
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsiteinfo.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarslider.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarsn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarspacer.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarstars-red1.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarstars-red2.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarstars-red3.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarstars-red4.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarstars-red5.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarstop.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarstop_on.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar .bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar abdataV3.js
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar abwelcome_en.html
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar abwelcome_fr.html
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar ab_icon.png
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar echnorati.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar n.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar ools.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar op.png
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar op_left.png
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar op_right.png
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar ranslate.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar tl_add.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbaru.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarun.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarUserStations.list
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarutf8.js
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarv.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarvmlib.js
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarvmntoolbartb1501.cfg
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarvn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarw.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarweb_en.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarweb_fr.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarwikipedia.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarwn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarx.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarxp_close_small.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbaryahoo_search.gif
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarYouTube.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarz.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarzn.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbarzoom.bmp
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar\__slider.bmp
Supprime! - C:Program FilesVMNToolbarinstall.ico
Supprime! - C:Program FilesVMNToolbar buninstall.exe
Supprime! - C:Program FilesVMNToolbar oolbar.ini
Supprime! - C:Program FilesVMNToolbaruninstall.exe
Supprime! - C:Program FilesVMNToolbarvmntoolbar.dll
Supprime! - C:WINDOWSsystem32
injaext-uninstall.exe
Supprime! - C:Program FilesAskTBar
Supprime! - C:DOCUME~1QuentinAPPLIC~1VMNToolbar
Supprime! - C:Program FilesVMNToolbar
-----------\ Recherche de Fichiers / Dossiers ...
-----------\ Extensions
(Quentin) - {5bf73a30-8317-404b-bb12-bb1d7aacb90d} => fr-FR
(Quentin) - {5bf73a30-8317-404b-bb12-bb1d7aacb90d} => frenchlocale
(Quentin) - {a7c6cf7f-112c-4500-a7ea-39801a327e5f} => fireftp
(Quentin) - {b66bc4c3-6d25-4a10-8c59-01daa9063051} => foxgame
(Quentin) - {db35fda8-77e3-4784-92c2-ee7345e91af4} => xplorer2
-----------\ [..Internet ExplorerMain]
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain]
"Local Page"="C:\WINDOWS\system32\blank.htm"
"Start Page"="http://www.google.com/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
[HKEY_LOCAL_MACHINESoftwareMicrosoftInternet ExplorerMain]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.msn.com/"
--------------------\ Recherche d'autres infections
--------------------\ Cracks & Keygens ..
C:DOCUME~1QuentinRecentThe.Sims.2.MULTILANGUE-Keygen.Shared.By.OCBTeam(CD3) (2).lnk
C:DOCUME~1QuentinRecentThe.Sims.2.MULTILANGUE-Keygen.Shared.By.OCBTeam(CD4) (4).lnk
1 - "C:ToolBar SDTB_1.txt" - 26/05/2009|17:28 - Option : [1]
2 - "C:ToolBar SDTB_2.txt" - 27/05/2009|13:42 - Option : [1]
3 - "C:ToolBar SDTB_3.txt" - 27/05/2009|17:26 - Option : [2]
-----------\ Fin du rapport a 17:26:07,65
puis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:27:49, on 27/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
C:Program FilesGoogleUpdateGoogleUpdate.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32
vraidservice.exe
C:Program FilesElaborate BytesVirtualCloneDriveVCDDaemon.exe
C:Program FilesSlySoftCloneCDCloneCDTray.exe
C:Program FilesLexmark 2300 Serieslxcgmon.exe
C:Program FilesLexmark 2300 Seriesezprint.exe
C:WINDOWSsystem32
undll32.exe
C:Program FilesCyberLinkPowerCinemaPCMService.exe
C:WINDOWSsystem32UMonit.exe
C:Program FilesFichiers communsInstallShieldUpdateServiceissch.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
C:Program FilesJavajre6injusched.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesOmniOmniMouse driver10.0GTGMouse.exe
C:Program FilesATI TechnologiesATI.ACECore-StaticMOM.EXE
C:Program FilesSony EricssonSony Ericsson PC SuiteSEPCSuite.exe
C:Program FilesTomTom HOME 2HOMERunner.exe
C:Program FilesSpybot - Search & DestroyTeaTimer.exe
C:Program FilesLG Soft IndiaforteManagerinMonitor.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
C:Program FilesFichiers communsAppleMobile Device SupportinAppleMobileDeviceService.exe
C:Program FilesATI TechnologiesATI.ACECore-Staticccc.exe
C:Program FilesCyberLinkPowerCinemaKernelTVCLCapSvc.exe
C:Program FilesCyberLinkShared FilesCLML_NTServiceCLMLServer.exe
C:Program FilesCyberLinkShared FilesCLML_NTServiceCLMLService.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2inapache.exe
C:Program FilesJavajre6injqs.exe
C:WINDOWSsystem32libusbd-nt.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerin
SvcIp.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2inapache.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerin
SvcLog.exe
C:WINDOWSsystem32PnkBstrA.exe
C:WINDOWSsystem32PSIService.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesCyberLinkPowerCinemaKernelTVCLSched.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerin
SvcAppFlt.exe
C:WINDOWSsystem32lxcgcoms.exe
C:WINDOWSsystem32wbemwmiapsrv.exe
C:WINDOWSsystem32wbemunsecapp.exe
C:Program FileseMuleemule.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
http://recherche.neuf.fr/ie/default.html
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = home:80
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Liens
R3 - URLSearchHook: xplorer2 Toolbar - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:Program Filesxplorer2 bxplo.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesFichiers communsAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesFichiers communsMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier3.1.807.1746swg.dll
O2 - BHO: xplorer2 Toolbar - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:Program Filesxplorer2 bxplo.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6injp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O3 - Toolbar: xplorer2 Toolbar - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:Program Filesxplorer2 bxplo.dll
O4 - HKLM..Run: [NVRaidService] C:WINDOWSsystem32
vraidservice.exe
O4 - HKLM..Run: [nTrayFw] C:Program FilesNVIDIA CorporationNetworkAccessManagerin
TrayFw.exe
O4 - HKLM..Run: [CARPService] carpserv.exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [VirtualCloneDrive] "C:Program FilesElaborate BytesVirtualCloneDriveVCDDaemon.exe" /s
O4 - HKLM..Run: [CloneCDTray] "C:Program FilesSlySoftCloneCDCloneCDTray.exe" /s
O4 - HKLM..Run: [LXCGCATS] rundll32 C:WINDOWSSystem32spoolDRIVERSW32X863LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM..Run: [lxcgmon.exe] "C:Program FilesLexmark 2300 Serieslxcgmon.exe"
O4 - HKLM..Run: [EzPrint] "C:Program FilesLexmark 2300 Seriesezprint.exe"
O4 - HKLM..Run: [FaxCenterServer] "C:Program FilesLexmark Fax Solutionsfm3032.exe" /s
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM..Run: [PCMService] "C:Program FilesCyberLinkPowerCinemaPCMService.exe"
O4 - HKLM..Run: [UMonit] C:WINDOWSsystem32UMonit.exe
O4 - HKLM..Run: [ISUSPM Startup] C:PROGRA~1FICHIE~1INSTAL~1UPDATE~1isuspm.exe -startup
O4 - HKLM..Run: [ISUSScheduler] "C:Program FilesFichiers communsInstallShieldUpdateServiceissch.exe" -start
O4 - HKLM..Run: [avgnt] "C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe" /min
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre6injusched.exe"
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesFichiers communsAheadlibNMBgMonitor.exe"
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [StartCCC] C:Program FilesATI TechnologiesATI.ACECore-StaticCLIStart.exe
O4 - HKCU..Run: [GTGMOUSE] "C:Program FilesOmniOmniMouse driver10.0GTGMouse.exe"
O4 - HKCU..Run: [Sony Ericsson PC Suite] "C:Program FilesSony EricssonSony Ericsson PC SuiteSEPCSuite.exe" /systray /nologon
O4 - HKCU..Run: [TomTomHOME.exe] "C:Program FilesTomTom HOME 2HOMERunner.exe"
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot - Search & DestroyTeaTimer.exe
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SERVICE RESEAU')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')
O4 - Global Startup: forteManager.lnk = C:Program FilesLG Soft IndiaforteManagerinMonitor.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:Program FilesFichiers communsMicrosoft SharedEncarta Search BarENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://a1540.g.akamai.net/7/1540/52/200 ... plugin.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/FR-FR/a-U ... E_UNO1.cab
O16 - DPF: {9DF1C00D-8426-4337-972C-DC042D19A916} (FTMediaPlayer Class) -
http://webtv.guidetv.orange.fr/resources/OCS_8884.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:Program FilesFichiers communsAppleMobile Device SupportinAppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:Program FilesCyberLinkPowerCinemaKernelTVCLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:Program FilesCyberLinkPowerCinemaKernelTVCLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:Program FilesCyberLinkShared FilesCLML_NTServiceCLMLServer.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:Program FilesNVIDIA CorporationNetworkAccessManagerin
SvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2inapache.exe
O23 - Service: Service Google Update (gupdate1c9d9f88585e512) (gupdate1c9d9f88585e512) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesFichiers communsInstallShieldDriver1050Intel 32IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:Program FilesiPodiniPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:Program FilesJavajre6injqs.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) -
http://libusb-win32.sourceforge.net - C:WINDOWSsystem32libusbd-nt.exe
O23 - Service: lxcg_device - Unknown owner - C:WINDOWSsystem32lxcgcoms.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:Program FilesNVIDIA CorporationNetworkAccessManagerin
SvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:Program FilesNVIDIA CorporationNetworkAccessManagerin
SvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32
vsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:WINDOWSsystem32PnkBstrA.exe
O23 - Service: DiRT Drivers Auto Removal (pr2ah4nc) (pr2ah4nc) - CODEMASTERS - C:WINDOWSsystem32pr2ah4nc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:WINDOWSsystem32PSIService.exe
--
End of file - 12485 bytes