netsvcs
msconfig
activex
drivers32
/md5start
explorer.exe
wininit.exe
winlogon.exe
userinit.exe
svchost.exe
services.exe
/md5stop
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\Tasks\*.* /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
nslookup http://www.google.fr /c
CREATERESTOREPOINT
:OTL
MOD - [2012/08/09 10:30:20 | 002,046,496 | ---- | M] () -- c:\ProgramData\PC Performer Manager\2.2.558.177\{16cdff19-861d-48e3-a751-d99a27784753}\%Protector Process Name%.dll
MOD - [2012/08/09 10:30:20 | 001,695,776 | ---- | M] () -- C:\ProgramData\PC Performer Manager\2.2.558.177\{16cdff19-861d-48e3-a751-d99a27784753}\%Protector Process Name%.exe
SRV - [2012/08/09 10:30:20 | 001,695,776 | ---- | M] () [Auto | Running] -- C:\ProgramData\PC Performer Manager\2.2.558.177\{16cdff19-861d-48e3-a751-d99a27784753}\%Protector Process Name%.exe -- (PC Performer Manager)
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2849852
IE - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\URLSearchHook: {0cc09160-108c-4759-bab1-5c12c216e005} - No CLSID value found
IE - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\URLSearchHook: {ef79f67a-6ad7-4715-a0f8-932fca442023} - No CLSID value found
IE - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\SearchScopes,bProtectorDefaultScope = {12BA3640-E7C8-405A-B723-5B02229C54B0}
IE - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\SearchScopes,DefaultScope = {12BA3640-E7C8-405A-B723-5B02229C54B0}
IE - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=108988&tt=010712_2&babsrc=SP_ss&mntrId=301737a500000000000000262d664655
IE - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\SearchScopes\{12BA3640-E7C8-405A-B723-5B02229C54B0}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3227980
IE - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={4010B16D-997A-4138-9443-B549CD1AF615}&mid=4b3cc2fe44c74484b60986354251b190-1d56a0139df94ea0406d7bbb0f3131df3da900e7&lang=fr&ds=hk011&pr=sa&d=2012-07-22 12:34:16&v=12.1.0.20&sap=dsp&q={searchTerms}
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\PC Performer Manager\2.2.558.177\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012/08/09 10:30:21 | 000,000,000 | ---D | M]
[2012/06/14 12:59:45 | 000,000,000 | ---D | M] (BittorrentBar_FR Community Toolbar) -- C:\Users\sandee\AppData\Roaming\mozilla\Firefox\extensions\{ef79f67a-6ad7-4715-a0f8-932fca442023}
CHR - homepage: http://search.conduit.com/?ctid=CT3227980&SearchSource=48
CHR - homepage: http://search.conduit.com/?ctid=CT3227982&SearchSource=48
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll File not found
O3 - HKLM\..\Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\Toolbar\WebBrowser: (no name) - {0CC09160-108C-4759-BAB1-5C12C216E005} - No CLSID value found.
O3 - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\Toolbar\WebBrowser: (no name) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No CLSID value found.
O3 - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O3 - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\Toolbar\WebBrowser: (no name) - {EF79F67A-6AD7-4715-A0F8-932FCA442023} - No CLSID value found.
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O20 - AppInit_DLLs: (c:\progra~3\pcperf~1\22558~1.177\{16cdf~1\%prote~1.dll) - c:\ProgramData\PC Performer Manager\2.2.558.177\{16cdff19-861d-48e3-a751-d99a27784753}\%Protector Process Name%.dll ()
[2012/08/26 10:21:08 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{A3851D8D-B9A3-41BE-8667-AD2FFFC3DC5D}
[2012/08/25 21:44:32 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{48A28FA6-E909-43AA-A834-07476C6A4F8C}
[2012/08/25 09:44:06 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{2F0FD80E-EE5C-40D0-AC5A-81BF6CC69664}
[2012/08/24 15:34:26 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{C685BC6E-86F0-4E34-B10E-864016CD534A}
[2012/08/23 22:34:04 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{F161F84A-B5A1-46AB-9DE9-34BFF0ADC489}
[2012/08/23 09:06:46 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{9DAA7D1D-D637-46AA-BF38-05D881DBC196}
[2012/08/22 11:18:26 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{08CC6CF9-44AD-4629-83B8-9BE6457CEC6E}
[2012/08/21 18:06:13 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{8924027D-FBEF-40B1-B6B4-9FFA51708062}
[2012/08/21 06:05:47 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{29411FF9-D9B9-4F6A-AED8-CAFAF0E7F5BC}
[2012/08/20 13:19:52 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{C268A27B-676B-41E0-978A-7E6C937C77F4}
[2012/08/20 01:19:27 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{A265B37B-8308-4CC4-AADC-C3C0BC3F4601}
[2012/08/19 13:19:01 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{9D4F3ED9-145F-4FD2-92FC-64CF0DD9F81A}
[2012/08/18 10:36:24 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{068BBA6D-68AE-48FB-88FC-F36D6B52317A}
[2012/08/18 10:36:10 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{7D6207A5-9DDF-48BA-90D0-59AC45BF3336}
[2012/08/17 11:42:10 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{076EBC1F-D4AA-4A24-8882-017B568D763A}
[2012/08/17 11:41:59 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{C8CE25DC-58F1-4829-80F2-C77DD56F91AA}
[2012/08/15 22:22:17 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{359A5C1F-E735-4C2C-A7D9-8DD7E0BFB1D2}
[2012/08/15 22:22:05 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{EB825550-9D8B-44ED-A38C-4C356A85053B}
[2012/08/15 10:21:36 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{F947ACC7-B73A-4649-8399-A68C21445D4A}
[2012/08/15 10:21:24 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{4E4E1268-7CDB-43E6-B1D2-C740780A880E}
[2012/08/14 16:01:25 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{40C2EE3C-2044-4ADC-B271-57AC30234D7A}
[2012/08/14 16:01:13 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{EAE80E82-78BB-426A-85C5-C3B696F06C1B}
[2012/08/14 10:01:32 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{319C71EC-D570-4DA5-9739-BBC7EEB55C07}
[2012/08/14 10:01:21 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{0024EEBF-0525-41F9-B2E7-1D8E263EEFE4}
[2012/08/12 11:33:51 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{75814303-09C8-4FBD-9984-BED3E676764D}
[2012/08/12 11:33:40 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{CC6F01E0-3B1C-423E-BFB7-B01F25C428CD}
[2012/08/11 14:57:32 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{C4750707-CFFE-444B-BCF9-F3B09B9BF0D5}
[2012/08/11 14:57:19 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{A03F4518-FDE8-4E74-A15C-A70C5C303C92}
[2012/08/11 02:20:16 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{9818B425-9C8D-4F97-ABA2-AFDCECB24434}
[2012/08/11 02:20:04 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{45DE5561-EADC-4F21-8394-9CC983AE8511}
[2012/08/10 12:18:50 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{4E5B4B70-B00B-48ED-8726-032766DEE965}
[2012/08/10 12:18:38 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{0DE8D778-109E-4B22-A6A4-5F3CA6606B37}
[2012/08/09 10:31:32 | 000,000,000 | ---D | C] -- C:\ProgramData\IBUpdaterService
[2012/08/09 10:30:21 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\searchplugins
[2012/08/09 10:30:21 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Extensions
[2012/08/09 10:30:20 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Performer Manager
[2012/08/09 10:16:23 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{8EF329DC-8E09-4DF8-9632-FEB0A80E4457}
[2012/08/09 10:16:11 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{9DA8D92C-A30C-4EE2-9904-464BE311F26F}
[2012/08/08 19:56:34 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{F3429B19-4A40-4B96-A9B6-AE70E608BA57}
[2012/08/08 19:56:23 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{64DC1950-99C2-418A-9393-51AB2E67344F}
[2012/08/07 11:11:58 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{E49B4886-8C51-47CA-A44E-4363DD0E59AD}
[2012/08/07 11:11:45 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{1480A477-5D57-47C1-B3E4-496D8BA8A75E}
[2012/08/06 19:54:47 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{3D153B4E-4FE2-41E9-BC14-E3C8B97F36FA}
[2012/08/06 19:54:35 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{23F60C02-FD64-407F-8DEF-05B9BBF3BF2C}
[2012/08/05 11:59:28 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{084F2B45-A1BE-4A34-8290-909AF5A87675}
[2012/08/05 11:59:16 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{A782B33D-769D-469A-8FC9-9D4E432021B7}
[2012/08/04 11:21:39 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{03FD7BE9-A34A-4695-8A35-490D323C9055}
[2012/08/04 11:21:28 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{E883C7B2-25EC-49FD-98D5-6FA5645EF28B}
[2012/08/03 22:48:44 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{42FF0574-070D-4758-9143-1C96FA3F03AA}
[2012/08/03 22:48:32 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{41BC2B66-F959-4E7C-8916-5439A1DFC07E}
[2012/08/03 10:48:03 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{825EC809-3108-439D-9E91-6F4E9608E769}
[2012/08/03 10:47:49 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{1EC67ADB-5EC1-4FC6-AC3D-8CB201C13515}
[2012/08/02 14:08:09 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{083143DC-96C9-47DE-B247-2448FCD6620F}
[2012/08/02 14:07:58 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{C206A4BA-BCDC-435D-B7B9-0914C16B9711}
[2012/08/01 22:25:07 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{921AF5F7-359A-4A02-B729-9CC278EC9A38}
[2012/08/01 22:24:55 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{EC8F21D1-03E6-448B-A46C-CCF573D0397D}
[2012/08/01 10:24:28 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{AC61ADF8-7A3D-43DF-B5AB-1FFEF93B1E7E}
[2012/07/31 20:23:01 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{EED5A44A-D749-4ED9-87C1-84EEF6AD073E}
[2012/07/31 20:22:49 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{9D89A8E5-1029-4895-B9A1-4BD517B28B91}
[2012/07/31 08:09:02 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{F9261B8A-B419-406E-8B87-CF7ABFE67552}
[2012/07/31 08:08:50 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{3973A475-8E54-4523-B8DC-26C408757A63}
[2012/07/30 11:35:12 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{9F5E51BC-FF2D-444C-97F5-91D70BD6DAE1}
[2012/07/30 11:34:59 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{9339785E-8899-4BA8-9181-E22F54E427C6}
[2012/07/29 16:55:56 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{F58FDC3A-184C-47F1-B777-0E8B5CED1B76}
[2012/07/29 16:55:40 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{2E1B3952-F015-4BC6-B9F8-516F2E42C82A}
[2012/07/29 04:54:16 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{B3EA7B93-031B-442D-AAAB-50583304BE52}
[2012/07/29 04:54:05 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{7235CF56-D543-4872-B964-C24D45EF3FA5}
[2012/07/28 00:21:23 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{1D765112-F767-4725-B600-88F5F3ED2C1F}
[2012/07/28 00:21:09 | 000,000,000 | ---D | C] -- C:\Users\sandee\AppData\Local\{0C8CB6EB-12A4-4C2E-AF30-8EFC96194B77}
[2012/08/05 16:05:50 | 000,232,960 | ---- | C] () -- C:\Windows\Installer\{5db9a795-ee48-0838-da62-3307677b2cbd}\U\00000008.@
[2012/08/05 16:05:48 | 000,093,184 | ---- | C] () -- C:\Windows\Installer\{5db9a795-ee48-0838-da62-3307677b2cbd}\U\80000032.@
[2012/08/05 16:05:48 | 000,080,896 | ---- | C] () -- C:\Windows\Installer\{5db9a795-ee48-0838-da62-3307677b2cbd}\U\80000064.@
[2012/08/05 16:05:48 | 000,000,804 | ---- | C] () -- C:\Windows\Installer\{5db9a795-ee48-0838-da62-3307677b2cbd}\L\00000004.@
[2012/08/05 16:05:46 | 000,016,896 | ---- | C] () -- C:\Windows\Installer\{5db9a795-ee48-0838-da62-3307677b2cbd}\U\80000000.@
[2012/08/05 16:05:46 | 000,002,048 | ---- | C] () -- C:\Windows\Installer\{5db9a795-ee48-0838-da62-3307677b2cbd}\U\00000004.@
[2012/08/05 16:05:46 | 000,001,632 | ---- | C] () -- C:\Windows\Installer\{5db9a795-ee48-0838-da62-3307677b2cbd}\U\000000cb.@
[2012/06/13 11:23:06 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{5db9a795-ee48-0838-da62-3307677b2cbd}\@
[2012/07/04 22:43:09 | 000,000,000 | ---D | M] -- C:\Users\sandee\AppData\Roaming\Babylon
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:7631EA83
:files
C:\Windows\Installer\{5db9a795-ee48-0838-da62-3307677b2cbd}
C:\Windows\SysNative\services.exe|C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe /replace
ipconfig /flushdns /c
:Commands
[EMPTYTEMP]
[CREATERESTOREPOINT]
Je ne pense pas avoir d'antivirusBen oui .... et le résultat ne s'est pas fait attendre, une bonne infection :III
netsvcs
msconfig
activex
drivers32
/md5start
explorer.exe
wininit.exe
winlogon.exe
userinit.exe
svchost.exe
services.exe
/md5stop
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\Tasks\*.* /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
nslookup http://www.google.fr /c
je ne vois pas la case Reboot computer ?
C:\Windows\assembly\GAC_32\Desktop.ini
Replace: C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe C:\Windows\System32\services.exe
netsvcs
msconfig
activex
drivers32
/md5start
explorer.exe
wininit.exe
winlogon.exe
userinit.exe
svchost.exe
services.exe
/md5stop
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\Tasks\*.* /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
nslookup http://www.google.fr /c
:OTL
IE - HKU\S-1-5-21-2449440193-2042137118-2482735012-1000\..\SearchScopes,bProtectorDefaultScope = {12BA3640-E7C8-405A-B723-5B02229C54B0}
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox
CHR - homepage: http://search.conduit.com/?ctid=CT3227980&SearchSource=48
CHR - homepage: http://search.conduit.com/?ctid=CT3227982&SearchSource=48
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0cc09160-108c-4759-bab1-5c12c216e005} - No CLSID value found.
[2012/08/05 16:48:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Trymedia
[2012/08/05 15:01:56 | 000,000,000 | ---D | C] -- C:\Program Files\Cracked Steam
[2012/07/04 22:45:04 | 000,230,547 | R--- | M] () -- C:\Users\sandee\AppData\Roaming\Microsoft\Installer\{77236F9C-987C-40EC-832B-5BD6181E4846}\_05C54B1BA48220C27C65AA.exe
[2012/07/04 22:45:04 | 000,230,547 | R--- | M] () -- C:\Users\sandee\AppData\Roaming\Microsoft\Installer\{77236F9C-987C-40EC-832B-5BD6181E4846}\_112D608FD02CD87FDC7735.exe
[2012/07/04 22:45:04 | 000,230,547 | R--- | M] () -- C:\Users\sandee\AppData\Roaming\Microsoft\Installer\{77236F9C-987C-40EC-832B-5BD6181E4846}\_748810A0065ABBFCE0FA2E.exe
[2012/07/04 22:45:04 | 000,230,547 | R--- | M] () -- C:\Users\sandee\AppData\Roaming\Microsoft\Installer\{77236F9C-987C-40EC-832B-5BD6181E4846}\_853F67D554F05449430E7E.exe
:files
C:\Users\sandee\Downloads\SoftonicDownloader_pour_softkey-revealer.exe
ipconfig /flushdns /c
:Commands
[EMPTYTEMP]
[CREATERESTOREPOINT]
j'ai choisi l'antivirus AVG
:Commands
[CLEARALLRESTOREPOINTS]
[EMPTYTEMP]
Windows seven me le refuse