Votre question

svp pouvez vous m'aider a supprimer nokia 19

Tags :
  • Nokia
  • Sécurité
Dernière réponse : dans Sécurité et virus
11 Novembre 2007 12:32:52

Bonjour, mon ordi est infecteté par ce virus.
je vous joint le rapport msnfix que j'ai executé 2 fois et également hijackthisMSNFix 1.571

C:\MSNFix
Fix exécuté le 10/11/2007 - 11:37:05,62 By jean-claude delpech
mode normal

************************ Recherche les fichiers présents

... C:\DOCUME~1\ALLUSE~1\MENUDM~1\carlton
... C:\Program Files\Fichiers communs\Carlson\carlton
... C:\3d3t4t8n7l.exe
... C:\or-1-1148.exe
... C:\WINDOWS\17PHolmes1148.exe
... C:\WINDOWS\ccSvcHst.exe
... C:\WINDOWS\Dance_dec_jpg.zip
... C:\WINDOWS\LBTWiz.exe
... C:\WINDOWS\mrofinu*.exe
... C:\WINDOWS\Nokia_19_jpg.zip
... C:\WINDOWS\Nokia_19_jpg.zip
... C:\WINDOWS\system32\microsoft\backup.ftp
... C:\WINDOWS\system32\microsoft\backup.tftp
... C:\WINDOWS\Dance_dec_jpg.zip
... C:\WINDOWS\Nokia_19_jpg.zip

************************ MSNCHK ***** /!\ beta test /!\

[!] C:\WINDOWS\Dance_dec_jpg.zip is INFECTED
[!] C:\WINDOWS\Nokia_19_jpg.zip is INFECTED


************************ Recherche les dossiers présents

... C:\Program Files\Fichiers communs\Carlson\




************************ Suppression des fichiers

.. OK ... C:\DOCUME~1\ALLUSE~1\MENUDM~1\carlton
.. OK ... C:\Program Files\Fichiers communs\Carlson\carlton
.. OK ... C:\3d3t4t8n7l.exe
.. OK ... C:\or-1-1148.exe
.. OK ... C:\WINDOWS\17PHolmes1148.exe
/!\ ... C:\WINDOWS\ccSvcHst.exe
.. OK ... C:\WINDOWS\Dance_dec_jpg.zip
.. OK ... C:\WINDOWS\LBTWiz.exe
/!\ ... C:\WINDOWS\mrofinu*.exe
.. OK ... C:\WINDOWS\Nokia_19_jpg.zip
.. OK ... C:\WINDOWS\Nokia_19_jpg.zip
.. OK ... C:\WINDOWS\system32\microsoft\backup.ftp
.. OK ... C:\WINDOWS\system32\microsoft\backup.tftp
.. OK ... C:\or-1-1148.exe
.. OK ... C:\3d3t4t8n7l.exe
.. OK ... C:\3d3t4t8n7l.exe
.. OK ... C:\3d3t4t8n7l.exe
.. OK ... C:\3d3t4t8n7l.exe
.. OK ... C:\WINDOWS\Dance_dec_jpg.zip
.. OK ... C:\WINDOWS\Nokia_19_jpg.zip


************************ Suppression des dossiers

.. OK ... C:\Program Files\Fichiers communs\Carlson\


************************ Nettoyage du registre



Les fichiers encore présents seront supprimés au prochain redémarrage


************************ Suppression des fichiers

.. OK ... C:\WINDOWS\ccSvcHst.exe
.. OK ... C:\WINDOWS\mrofinu*.exe



************************ Fichiers suspects

Aucun Fichier trouvé


Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 10112007_11463368.zip


------------------------------------------------------------------------
Auteur : !aur3n7 Contact: http://changelog.fr
------------------------------------------------------------------------

--------------------------------------------- END ---------------------------------------------

le second...
MSNFix 1.571

C:\MSNFix
Fix exécuté le 10/11/2007 - 12:27:43,78 By jean-claude delpech
mode normal

************************ Recherche les fichiers présents

Aucun Fichier trouvé

************************ Recherche les dossiers présents

Aucun dossier trouvé


************************ Fichiers suspects

Aucun Fichier trouvé



------------------------------------------------------------------------
Auteur : !aur3n7 Contact: http://changelog.fr
------------------------------------------------------------------------

--------------------------------------------- END ---------------------------------------------

le rapport hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:08:37, on 11/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Symantec\DelFax\WFXMOD32.EXE
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Symantec\DelFax\WFXCTL32.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\QuickZip4\QuickZip.exe
C:\Documents and Settings\jean-claude delpech\Bureau\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [Instant Access] rundll32.exe p2esocks_1049.dll,InstantAccess
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\RunOnce: [ypagerps] cmd.exe /C del "C:\Program Files\Yahoo!\Messenger\ypagerps.dll"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Contrôleur.LNK = C:\Program Files\Symantec\DelFax\WFXCTL32.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader....
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5AA580AE-A3E9-4A9C-9C49-7EC814C8E2ED} (CamTraceViewer Class) - http://213.41.245.7/lib/download/CamTraceViewer.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.ca...
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab50997.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: DelrinaFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe

--
End of file - 12022 bytes
Merci d'avance pour votre aide

Autres pages sur : svp pouvez aider supprimer nokia

11 Novembre 2007 13:01:13

Bonjour,

Pour MSNFix, c'est bon.

Tu as une autre infection apparemment, dûe à l'installation d'Instant Access.


Télécharge Navilog (de Il-Mafioso)

Enregistre-le sur ton Bureau.
Installe-le en double cliquant sur navilog.exe.
Une fois l'installation terminée, l'utilitaire s'exécutera automatiquement.
(Si ce n'est pas le cas, double clique sur le raccourci présent sur le Bureau)

Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
! N'utilise pas l'option 2,3 et 4 sans notre accord !
Patiente jusqu'à l'apparition de ce message :
"*** Analyse Termine le ..... ***"
Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste le rapport ici.

Le rapport se trouve ici :C:\fixnavi.txt
14 Novembre 2007 21:15:34

Tout d'abord merci pour votre aide.
Voici le rapport que que vous m'avez demandé.
Cordialement
Jean Claude
Search Navipromo version 3.3.6 commencé le 14/11/2007 à 17:10:34,15

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2900.2180


*** Recherche Programmes installés ***


Instant Access


*** Recherche dossiers dans C:\WINDOWS ***

C:\WINDOWS\msskinner trouvé !


*** Recherche dossiers dans C:\Program Files ***

C:\Program Files\MailSkinner trouvé !


*** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***




*** Recherche dossiers dans C:\Documents and Settings\jean-claude delpech\Application Data ***


*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Aucun fichier trouvé dans :

- C:\WINDOWS\system32
- C:\DOCUME~1\JEAN-C~1\LOCALS~1\APPLIC~1



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans C:\WINDOWS\system32 *

* Recherche dans C:\DOCUME~1\JEAN-C~1\LOCALS~1\APPLIC~1 *



*** Recherche fichiers ***


C:\WINDOWS\tmlpcert2007 trouvé !
C:\WINDOWS\system32\sysiasvc32.dll trouvé !


*** Recherche clés spécifiques dans le Registre ***

HKEY_CURRENT_USER\Software\Lanconfig trouvé !
HKEY_CURRENT_USER\Software\mc trouvé !

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche fichiers connus:

2)Recherche Heuristique :

C:\WINDOWS\system32\kgwaqzrpd.dat trouvé !
C:\WINDOWS\system32\kgwaqzrpd_nav.dat trouvé !
C:\WINDOWS\system32\kgwaqzrpd.exe trouvé !


3)Recherche Certificats :

Certificat Egroup trouvé !


*** Analyse terminée le 14/11/2007 à 17:11:49,56 ***


Contenus similaires
14 Novembre 2007 22:14:10

Re,

Double clique sur le raccourci de navilog1.
Option 2 puis valide. (entrée)
Laisse toi guider.
Ton ordinateur va redémarrer, sinon fais le manuellement.

Ton bureau va disparaître.

Patiente jusqu'à l'apparition de ce message :
"*** Nettoyage Termine le ..... ***"

Appuie sur une touche comme demandé, le Bloc-notes va s'ouvrir.
Sauvegarde le rapport.
Referme le Bloc-notes. Ton bureau va maintenant réapparaître.

Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
Tapes explorer et valides. Cela te fera apparaitre ton bureau


Démarrer -> panneau de configuration -> options internet
Clique sur l'onglet "Contenu" puis onglet "Certificats" et si tu trouves ceci, en particulier dans "éditeurs approuvés" :

electronic-group ; egroup ; Montorgueil ; VIP ; "Sunny Day Design Ltd"

~~> Supprime-les tous <~~

Poste le rapport sauvegardé auparavant (C:\cleannavi.txt)
Ainsi qu'un nouveau rapport Hijackthis.
15 Novembre 2007 00:25:24

Voila le nouveau rapport cleannavi + hijackthis . Par contre j'ai toujours un fichier du nom de "Carlton" dans mes connexions!!! avant d'attraper ce virus il n'y etait pas.
Clean Navipromo version 3.3.6 commencé le 14/11/2007 à 19:53:30,31

Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2900.2180

Mode suppression automatique



*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)


*** Suppression avec sauvegardes résultats GenericNaviSearch ***

* Suppression dans C:\WINDOWS\System32 *


* Suppression dans C:\DOCUME~1\JEAN-C~1\LOCALS~1\APPLIC~1 *



*** Suppression dossiers dans C:\WINDOWS ***

C:\WINDOWS\msskinner ...suppression...
C:\WINDOWS\msskinner supprimé !


*** Suppression dossiers dans C:\Program Files ***

C:\Program Files\MailSkinner ...suppression...
C:\Program Files\MailSkinner supprimé !


*** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***


*** Suppression dossiers dans C:\Documents and Settings\jean-claude delpech\Application Data ***


*** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***



*** Suppression fichiers ***

C:\WINDOWS\tmlpcert2007 supprimé !
C:\WINDOWS\system32\sysiasvc32.dll supprimé !

*** Suppression fichiers temporaires ***

Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\jean-claude delpech\Local Settings\Temp effectué !

*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche fichiers connus:


2)Recherche, création sauvegardes et suppression Heuristique :

C:\WINDOWS\System32\kgwaqzrpd.dat trouvé !
Copie C:\WINDOWS\system32\kgwaqzrpd.dat réalisé avec succès !
C:\WINDOWS\system32\kgwaqzrpd.dat supprimé !

C:\WINDOWS\System32\kgwaqzrpd_nav.dat trouvé !
Copie C:\WINDOWS\system32\kgwaqzrpd_nav.dat réalisé avec succès !
C:\WINDOWS\system32\kgwaqzrpd_nav.dat supprimé !

C:\WINDOWS\System32\kgwaqzrpd_navps.dat trouvé !
Copie C:\WINDOWS\system32\kgwaqzrpd_navps.dat réalisé avec succès !
C:\WINDOWS\system32\kgwaqzrpd_navps.dat supprimé !

C:\WINDOWS\system32\kgwaqzrpd.exe trouvé !
Copie C:\WINDOWS\system32\kgwaqzrpd.exe réalisé avec succès !
C:\WINDOWS\system32\kgwaqzrpd.exe supprimé !


*** Sauvegarde du Registre vers dossier Backupnavi ***

sauvegarde du Registre réalisé avec succès !

*** Nettoyage Registre ***

Nettoyage Registre Ok


*** Certificats ***

Certificat Egroup supprimé !

*** Nettoyage terminé le 14/11/2007 à 20:04:19,70 ***
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:24:09, on 14/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Symantec\DelFax\WFXMOD32.EXE
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Symantec\DelFax\WFXCTL32.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Documents and Settings\jean-claude delpech\Bureau\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\RunOnce: [ypagerps] cmd.exe /C del "C:\Program Files\Yahoo!\Messenger\ypagerps.dll"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Contrôleur.LNK = C:\Program Files\Symantec\DelFax\WFXCTL32.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader....
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5AA580AE-A3E9-4A9C-9C49-7EC814C8E2ED} (CamTraceViewer Class) - http://213.41.245.7/lib/download/CamTraceViewer.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.ca...
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab50997.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: DelrinaFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe

--
End of file - 11860 bytes



15 Novembre 2007 19:04:12

Bien.

Télécharge sur ton bureau : Clean (de Malekal)
Dézippe le sur ton bureau. Double-clic sur ce dossier clean.
Double-clic sur clean.cmd. Cela va ouvrir une fenêtre noire.
Un menu va apparaître, choisis l'option 1 puis entrée. Ensuite appuies sur une touche comme il te sera demandé et poste le rapport ici.
Le rapport se trouve ici : C:\rapport_clean.txt
Tuto
16 Novembre 2007 10:21:37

16/11/2007 a 6:10:21,87

*** Recherche des fichiers dans C:

*** Recherche des fichiers dans C:\WINDOWS\

Voici le rapport de clean.

*** Recherche des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system32\winspool.dll FOUND
"C:\WINDOWS\Downloaded Program Files\CONFLICT.1" FOUND

*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\SystemDoctor 2006 Free\" FOUND
16 Novembre 2007 19:34:56

Re,

Télécharge AVG Anti-Spyware Installes-le.
Lance AVG et fais une mise à jour.
Clique sur le bouton Analyse (de la barre d'outils)
Puis sur l'onglet comment réagir, clique sur Actions recommandées. Choisis Quarantaine.
Ne fais pas d’analyse pour le moment.
Redémarre en mode sans échec
/!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\
Relance Avg.
Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas.
Clique sur "Enregistrer le rapport". Ceci génère un rapport qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.
Poste le ici.
&
Toujours en mode sans échec, relance clean et fais l'option 2, poste le rapport.
18 Novembre 2007 11:49:57

re,ci joint le rapport AVG mais je dois te dire que j'ai fait une analyse avant de redemarrer (j'espere que ce n'est pas grave!!) et j'en ai fait une en mode sans echec.

AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 20:39:37 17/11/2007

+ Résultat de l'analyse:



HKLM\SOFTWARE\Classes\WR -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP486\A0113984.dll -> Adware.NaviPromo : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP486\A0113985.dll -> Adware.NaviPromo : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\jean-claude delpech\Mes documents\Mes fichiers reçus\Nokia_19_jpg.zip/www.Nokia_19_jpg-msn.com -> Backdoor.SdBot.bzy : Nettoyé et sauvegardé (mise en quarantaine).
C:\MSNFix\10112007_11463368.zip/backup/LBTWiz.exe -> Backdoor.SdBot.bzy : Nettoyé et sauvegardé (mise en quarantaine).
C:\MSNFix\10112007_11463368.zip/backup/Nokia_19_jpg.zip/www.Nokia_19_jpg-msn.com -> Backdoor.SdBot.bzy : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP542\A0122636.com -> Backdoor.SdBot.bzy : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP543\A0122737.exe -> Backdoor.SdBot.bzy : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP543\A0122766.exe -> Backdoor.SdBot.bzy : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP541\A0122623.exe -> Backdoor.SdBot.cgz : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP542\A0122659.exe -> Backdoor.SdBot.cgz : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\jean-claude delpech\Local Settings\Temporary Internet Files\Content.IE5\VZH3JTK8\dance[1].jpg -> Backdoor.SdBot.cha : Nettoyé et sauvegardé (mise en quarantaine).
C:\MSNFix\10112007_11463368.zip/backup/Dance_dec_jpg.zip/www.Dance_dec_jpg_Msn.com -> Backdoor.SdBot.cha : Nettoyé et sauvegardé (mise en quarantaine).
C:\MSNFix\10112007_11463368.zip/backup/ccSvcHst.exe -> Backdoor.SdBot.cha : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP542\A0122690.exe -> Backdoor.SdBot.cha : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP543\A0122753.exe -> Backdoor.SdBot.cha : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP543\A0122758.exe -> Backdoor.SdBot.cha : Nettoyé et sauvegardé (mise en quarantaine).
C:\MSNFix\10112007_11463368.zip/backup/3d3t4t8n7l.exe -> Dialer.Agent.z : Nettoyé et sauvegardé (mise en quarantaine).
C:\MSNFix\10112007_11463368.zip/backup/carlton -> Dialer.Agent.z : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP542\A0122639.exe -> Dialer.Agent.z : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP542\A0122664.exe -> Dialer.Agent.z : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP542\A0122693.exe -> Dialer.Agent.z : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP543\A0122702.exe -> Dialer.Agent.z : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP543\A0122756.exe -> Dialer.Agent.z : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP486\A0113986.exe -> Dialer.EGroup.1061 : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP546\A0123036.dll -> Dialer.EGroup.u : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP486\A0113993.dll -> Dialer.EgroupDial.v : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP486\A0113987.exe -> Dialer.InstantAccess.m : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP486\A0113989.dll -> Dialer.InstantAccess.m : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP486\A0113990.dll -> Dialer.InstantAccess.m : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP486\A0113991.dll -> Dialer.InstantAccess.m : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP486\A0113992.dll -> Dialer.InstantAccess.r : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP486\A0113994.dll -> Dialer.InstantAccess.r : Nettoyé et sauvegardé (mise en quarantaine).
C:\MSNFix\10112007_11463368.zip/backup/17PHolmes1148.exe -> Downloader.Agent.emo : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP541\A0122596.exe -> Downloader.Agent.emo : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP541\A0122625.exe -> Downloader.Agent.emo : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP543\A0122704.exe -> Downloader.Agent.emo : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP543\A0122736.exe -> Downloader.Agent.emo : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP543\A0122755.exe -> Downloader.Agent.emo : Nettoyé et sauvegardé (mise en quarantaine).
C:\MSNFix\10112007_11463368.zip/backup/mrofinu1148.exe -> Downloader.Agent.fak : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP543\A0122754.exe -> Downloader.Agent.fak : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP543\A0122767.exe -> Downloader.Agent.fak : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@2o7[2].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@adbrite[1].txt -> TrackingCookie.Adbrite : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@ads.adbrite[2].txt -> TrackingCookie.Adbrite : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@estat[1].txt -> TrackingCookie.Estat : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@perf.overture[1].txt -> TrackingCookie.Overture : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\WINDOWS\system32\config\systemprofile\Cookies\system@skype[1].txt -> TrackingCookie.Skype : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@smartadserver[2].txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\jean-claude delpech\Cookies\jean-claude delpech@m.webtrends[2].txt -> TrackingCookie.Webtrends : Nettoyé.


Fin du rapport

6:46 18/11/2007C:\WINDOWS\System32\ftp.exe -->09/11/2007 06:21:14
C:\WINDOWS\System32\MRT.exe -->02/11/2007 04:12:57
C:\WINDOWS\System32\xpsp3res.dll -->29/10/2007 16:35:14
C:\WINDOWS\System32\shell32.dll -->25/10/2007 13:56:24
C:\WINDOWS\System32\portal.dll -->09/09/2007 11:27:48
C:\WINDOWS\System32\coface.dll -->09/09/2007 11:27:48
C:\WINDOWS\System32\ifsrel.dll -->09/09/2007 11:27:47
C:\WINDOWS\System32\wininet.dll -->22/08/2007 10:13:08
C:\WINDOWS\System32\urlmon.dll -->22/08/2007 10:13:08
C:\WINDOWS\System32\shlwapi.dll -->22/08/2007 10:13:08
C:\WINDOWS\System32\shdocvw.dll -->22/08/2007 10:13:08
C:\WINDOWS\System32\pngfilt.dll -->22/08/2007 10:13:07
C:\WINDOWS\System32\mstime.dll -->22/08/2007 10:13:07
C:\WINDOWS\System32\msrating.dll -->22/08/2007 10:13:07
C:\WINDOWS\System32\mshtmled.dll -->22/08/2007 10:13:07
C:\WINDOWS\System32\mshtml.dll -->22/08/2007 10:13:07
C:\WINDOWS\System32\jsproxy.dll -->22/08/2007 10:13:06


J'ai toujour "Carlton" dans mes connexions
18 Novembre 2007 11:54:33

Carlton ? OK..

Tu peux vider la quarantaine d'avg.

Télécharge SDFix (d’Andy Manchesta)

Enregistre le sur ton le bureau.

Lance le.
Fais install afin qu’il puisse s’extraire.

Redémarre en mode sans échec
/!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

Lance SDFix.
Double clique sur RunThis.bat .
Appuie sur Y pour le lancer.

Il te sera demandé d'appuyer sur une touche pour redemarrer , fais le
Il est probable que le redémarrage soit un peu plus long que d’habitude.
Une fois l’apparition de ton Bureau, il affichera Finished

Appuie sur une touche.

Un rapport est généré , poste le dans ta réponse.
Il se trouve également. dans le dossier SDFix >Report.txt<

Ët poste un nouvel Hijackthis.
18 Novembre 2007 13:10:53

re,

SDFix: Version 1.114

Run by jean-claude delpech on 18/11/2007 at 07:39

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

No Trojan Files Found




Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-18 07:50:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000c55062574]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000c55062574]

scanning hidden registry entries ...

scanning hidden files ...

C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\37\143-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v137-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v143-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 37848 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\37\143-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v137-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v143-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2766 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\37\143-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v137-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v143-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4312 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\37\37-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v37-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 120 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\00\1700-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1700-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1700-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2080 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\00\400-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v400-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v400-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1506 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\00\400-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v400-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v400-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 160 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\01\10-{C84A1D92-46E3-9638-3EDC-BD5447567328}-v1-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\01\1701-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1701-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1701-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1776 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\01\470-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14201-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v470-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5448 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\01\470-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14201-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v470-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 624 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\02\1702-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1702-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1702-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1792 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\03\14211-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14203-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14211-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 116994 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\03\14211-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14203-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14211-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 8166 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\03\14211-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14203-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14211-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 13464 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\03\1703-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1703-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1703-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1784 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\03\204-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v203-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v204-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4314 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\03\204-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v203-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v204-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 480 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\03\477-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14203-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v477-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 116994 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\03\477-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14203-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v477-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 13464 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\04\1704-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1704-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1704-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1752 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\05\106-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v105-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v106-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\05\1705-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1705-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1705-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2416 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\06\1706-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1706-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1706-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2232 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\07\104-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v207-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v104-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4314 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\07\104-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v207-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v104-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 480 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\07\1707-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1707-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1707-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2448 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\08\1708-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1708-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1708-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2128 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\09\1709-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1709-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1709-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2168 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\09\709-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v709-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v709-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2064 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\10\110-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v110-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v110-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\10\212-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v210-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v212-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4332 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\10\212-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v210-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v212-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 480 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\10\410-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v410-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v410-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\10\710-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v710-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v710-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4696 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\11\711-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v711-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v711-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 680 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\12\239-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v112-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v239-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 44562 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\12\239-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v112-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v239-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3288 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\12\239-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v112-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v239-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5056 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\12\412-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v412-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v412-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 17832 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\12\412-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v412-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v412-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1326 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\12\412-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v412-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v412-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2000 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\12\481-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14212-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v481-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4854 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\12\481-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v14212-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v481-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 632 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\12\712-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v712-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v712-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 128 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\13\713-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v713-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v713-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5416 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\14\414-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v414-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v414-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 948 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\14\414-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v414-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v414-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 112 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\14\714-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v714-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v714-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 11622 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\14\714-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v714-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v714-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\15\415-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v415-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v415-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 930 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\15\415-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v415-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v415-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 112 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\16\116-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v116-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v116-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1056 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\16\116-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v116-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v116-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 120 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\16\416-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v416-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v416-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 876 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\16\416-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v416-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v416-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 104 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\17\117-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v117-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v117-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\17\417-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v417-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v417-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 966 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\17\417-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v417-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v417-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 104 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\20\494-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v320-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v494-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 14988 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\20\494-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v320-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v494-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1696 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\20\497-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v220-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v497-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4314 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\20\497-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v220-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v497-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 480 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\22\22-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v22-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 136 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\23\123-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v123-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v123-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1976 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\24\124-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v124-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v124-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1896 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\25\125-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v125-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v125-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2648 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\26\126-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v126-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v126-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2728 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\27\127-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v127-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v127-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2800 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\28\128-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v128-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v128-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2680 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\29\129-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v129-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v129-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2768 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\29\135-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v129-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v135-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 37974 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\29\135-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v129-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v135-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2730 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\29\135-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v129-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v135-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4312 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\30\101-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v30-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v101-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 38262 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\30\101-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v30-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v101-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2802 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\30\101-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v30-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v101-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\30\130-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v130-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v130-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2696 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\30\5731-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v5730-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v5731-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2456 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\31\131-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v131-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v131-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2616 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\31\234-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v231-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v234-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 37830 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\31\234-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v231-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v234-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2802 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\31\234-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v231-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v234-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\31\236-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v231-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v236-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 37830 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\31\236-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v231-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v236-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\31\333-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v331-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v333-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2406 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\31\333-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v331-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v333-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\32\132-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v132-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v132-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2744 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\35\137-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v135-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v137-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\35\338-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v335-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v338-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2496 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\35\338-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v335-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v338-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\35\436-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v435-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v436-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1578 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\35\436-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v435-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v436-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 168 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\36\136-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v136-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v136-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1088 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\36\36-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v36-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 112 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\38\38-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v38-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 120 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\39\376-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v339-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v376-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2496 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\39\376-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v339-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v376-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\42\5743-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v5742-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v5743-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 72 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\44\118-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v244-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v118-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 44418 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\44\118-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v244-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v118-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3180 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\44\118-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v244-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v118-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5048 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\45\151-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v145-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 37938 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\45\151-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v145-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2802 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\45\151-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v145-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4320 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\45\432-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v5545-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v432-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 696 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\45\432-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v5545-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v432-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 96 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\46\367-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v346-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v367-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\51\58-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v51-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 38172 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\51\58-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v51-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2748 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\51\58-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v51-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4320 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\53\68-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v153-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v68-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 37938 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\53\68-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v153-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v68-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2802 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\53\68-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v153-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v68-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4320 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\54\258-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v254-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v258-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 44472 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\54\258-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v254-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v258-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3180 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\54\258-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v254-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v258-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5048 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\58\366-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v358-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v366-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\60\260-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v260-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v260-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\61\463-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v461-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v463-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2766 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\61\463-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v461-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v463-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\63\166-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v163-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v166-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 38046 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\63\166-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v163-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v166-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2838 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\63\166-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v163-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v166-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4320 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\68\189-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v168-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v189-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 37956 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\68\189-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v168-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v189-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2802 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\68\189-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v168-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v189-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4320 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\69\160-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v69-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 38226 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\69\160-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v69-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2838 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\69\160-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v69-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\72\172-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v172-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\72\272-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v272-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v272-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\73\73-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v73-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v73-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\73\76-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v73-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v76-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5056 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\77\1711-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v377-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1711-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2496 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\77\1711-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v377-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1711-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\77\177-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v177-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v177-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\77\381-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v377-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v381-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2496 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\77\381-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v377-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v381-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\79\879-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v879-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v879-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 280 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\80\280-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v280-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v280-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\80\880-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v880-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v880-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 288 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\81\881-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v881-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v881-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 304 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\81\94-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v81-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v94-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4314 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\81\94-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v81-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v94-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 480 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\82\882-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v882-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v882-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 248 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\83\387-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v383-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v387-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2334 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\83\387-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v383-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v387-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 320 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\83\485-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v283-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v485-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\83\883-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v883-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v883-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 288 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\84\187-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v184-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v187-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 38046 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\84\187-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v184-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v187-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2784 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\84\187-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v184-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v187-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4328 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\84\884-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v884-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v884-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 272 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\85\343-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1485-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v343-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3558 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\85\343-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1485-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v343-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 488 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\90\1715-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v390-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1715-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3594 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\90\1715-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v390-{7975C535-CC6D-456F-83C5-58C0CD74C2D3}-v1715-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 488 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\91\126-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v91-{93315258-C4B5-40EB-BE71-DDC356B67BD3}-v126-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 38010 bytes hidden from API
C:\Documents and Settings\jean-claude delpech\Local Settings\Application Data\Microsoft\Messenger\jeanclaudedelpech@hotmail.com\SharingMetadata\phil44115@hotmail.com\DFSR\Staging\CS{C84A1D92-46E3-9638-3EDC-BD5447567328}\91\126-{93315258-C4B5-40EB-BE71-DDC356B67
18 Novembre 2007 14:01:23

Re,

Tu n'as plsu le dossier Carlton.

Tu peux supprimer ces clefs via démarrer>exécuter>regedit>ok :
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000c55062574]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000c55062574]


Tu peux faire une sauvegarde du registre avant au cas où : http://www.commentcamarche.net/faq/sujet-363-sauvegarde...

Reposte un HIjackthis.
18 Novembre 2007 17:36:11

Re ,
Si j'ai toujours "Carlton"
18 Novembre 2007 17:40:26

Localisation ?
18 Novembre 2007 18:11:18

Je ne le vois que dans mes connexions.
Quand je met le courseur dessus , il me marque "AC 97 DATA FAX soft modem with smart CP" mais ca c'est mon logiciel de fax
Je n'ai pas de localisation précise ou alors je ne sais pas ou la trouver!
18 Novembre 2007 18:33:52

Pourtant il a été supprimé .. ^^

Aller dans poste de travail>outils>option des dossiers>affichage>afficher les fichiers et dossiers cachés. - - > Appliquer - - > OK

Aller dans poste de travail>outils>option des dossiers>affichage>décocher masquer les fichiers protégés du système d’exploitation. - - > Appliquer - - > OK
(Tu recoches après)

Démarrer>rechercher>tous les fichiers et dossiers : tape Carlton.
Donne moi les résultats s'il y en a.
18 Novembre 2007 19:15:12

ci joint rapport HIjackthis apres "regedit"
Je n'ai aucun résultat quand je recherche "Carlton"
Mais l'icone est toujours la!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:12:43, on 18/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Symantec\DelFax\WFXMOD32.EXE
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Symantec\DelFax\WFXCTL32.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\jean-claude delpech\Bureau\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Contrôleur.LNK = C:\Program Files\Symantec\DelFax\WFXCTL32.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader....
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5AA580AE-A3E9-4A9C-9C49-7EC814C8E2ED} (CamTraceViewer Class) - http://213.41.245.7/lib/download/CamTraceViewer.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.ca...
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab50997.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: DelrinaFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe

--
End of file - 11888 bytes
18 Novembre 2007 19:45:32

Tu peux faire un screenshot de l'îcone ?

++++++++++++

Désinstalle avast, redémarre et supprime ~~>C:\Program Files\Alwil Software

Télécharge ccleaner (>>tuto à lire !<<), tu download «the latest version » puis installe le en décochant - Ajouter la Barre d'Outils Yahoo! CCleaner
Puis lance le nettoyage, puis fais chercher des erreurs et sauvegardes si tu le souhaites.

Télécharge et installe Antivir. (tuto)
Pourquoi changer ? Avast vs Antivir
Vérifie qu’il soit bien à jour ! Fais une analyse complète, poste le rapport.
18 Novembre 2007 20:10:58

comment je fait un screenshot!!! j'ai hyper snap
18 Novembre 2007 20:42:04

Tuto

Pour héberger l'image, va sur Hiboox ou ImageShack, mezimages ne marche plus il me semble.
18 Novembre 2007 23:36:22

AntiVir PersonalEdition Classic
Report file date: dimanche 18 novembre 2007 18:21

Scanning for 933576 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: jean-claude delpech
Computer name: PC302132836219

Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 17:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 16:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 19:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 16:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 18:27:15
ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 18:26:55
ANTIVIR2.VDF : 7.0.0.198 1206272 Bytes 11/11/2007 21:17:04
ANTIVIR3.VDF : 7.0.0.227 112128 Bytes 18/11/2007 21:17:04
AVEWIN32.DLL : 7.6.0.34 3125760 Bytes 18/11/2007 21:17:04
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 14:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 11:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 17:16:24
AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 12:46:00
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 11:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 16:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 11:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 15:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 16:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 16:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 13:37:21

Configuration settings for the scan:
Jobname..........................: ShlExt
Configuration file...............: C:\DOCUME~1\JEAN-C~1\LOCALS~1\Temp\bd5eadb4.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: off
Scan registry....................: off
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: dimanche 18 novembre 2007 18:21

Starting the file scan:

Begin scan in 'C:\Documents and Settings\jean-claude delpech\Bureau\antivir_workstation_win7u_en_h.exe'


End of the scan: dimanche 18 novembre 2007 18:21
Used time: 00:14 min

The scan has been done completely.

0 Scanning directories
317 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
317 Files not concerned
3 Archives were scanned
0 Warnings
0 Notes

19 Novembre 2007 18:58:27

Et tu n'avais pas cette icône avant?
Reposte un Hijackthis
22 Novembre 2007 02:49:56

non je n'avais pas cette icone du nom de carlton !
Voici le rapport.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:47:24, on 21/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\Symantec\DelFax\WFXMOD32.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Symantec\DelFax\WFXCTL32.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
c:\progra~1\fichie~1\instal~1\update~1\isuspm.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\agent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\jean-claude delpech\Bureau\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Contrôleur.LNK = C:\Program Files\Symantec\DelFax\WFXCTL32.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader....
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5AA580AE-A3E9-4A9C-9C49-7EC814C8E2ED} (CamTraceViewer Class) - http://213.41.245.7/lib/download/CamTraceViewer.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.ca...
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab50997.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: DelrinaFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe

--
End of file - 11860 bytes

22 Novembre 2007 21:42:08

Re,

Aller dans poste de travail>outils>option des dossiers>affichage>afficher les fichiers et dossiers cachés. - - > Appliquer - - > OK

Aller dans poste de travail>outils>option des dossiers>affichage>décocher masquer les fichiers protégés du système d’exploitation. - - > Appliquer - - > OK
(Tu recoches après)

Fais analyser ces fichier sur ce site >> Virustotal <<

Clique sur Parcourir en haut, choisis Poste de travail et cherche ce fichier : C:\Program Files\Symantec\DelFax\WFXCTL32.EXE
Clique maintenant sur envoyer le fichier.
Poste le rapport
Tom's guide dans le monde
  • Allemagne
  • Italie
  • Irlande
  • Royaume Uni
  • Etats Unis
Suivre Tom's Guide
Inscrivez-vous à la Newsletter
  • ajouter à twitter
  • ajouter à facebook
  • ajouter un flux RSS