Votre question

(Résolu) virus ou autres...!

Tags :
  • Sécurité
Dernière réponse : dans Sécurité et virus
11 Novembre 2007 15:02:07

Bonjour à tous,
j'ai plusieurs problèmes sur mon pc, je sais pas si c'est lié mais tous sont arrivé plus ou moin en même temps.

j'ai pas mal de fenetres de pub quand je navigue sur le net.
Notament erreur chasseur dont j ai vu que je n'était pas le premier.
J'ai fait plusieurs scan avec Avast, adware, CCleaner mais pas spybot car quand je le lance mon pc s'éteint de suite avec un écran bleu ou il était afficher Bad-pool-caller mais je suis pas sure que ca affiche la meme chose à chaque fois car ca va fort vite.
J'ai aussi un autre problème, par moment mes icones et ma barre des taches disparaissent totalement et plus aucunes fonctions disponnibles (ni click droit).

Si quelqu'un peut m'aider, je le remercie par avance, Merci.

Autres pages sur : resolu virus

11 Novembre 2007 16:27:55

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:27:27, on 11/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trust\MI-2500X OPTICAL MOUSE\Mouse32a.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\NotifyPhoneBook.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [InstantOn] "C:\Program Files\CyberLink\PowerCinema Linux\ion_install.exe" /c
O4 - HKLM\..\Run: [AME_CSA] rundll32 csa.cpl,RUN_DLL
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Trust\MI-2500X OPTICAL MOUSE\Mouse32a.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls...
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--
End of file - 7251 bytes
Contenus similaires
a b 8 Sécurité
11 Novembre 2007 16:31:28

Re,

Tu as des pubs partout ?

Télécharge Gmer.
Dézippe le dans un dossier ou sur ton bureau.

Déconnecte toi d'Internet puis et ferme tous les programmes.
Double-clique sur Gmer.exe.

IMPORTANT: Si une alerte de ton antivirus apparaît pour le fichier gmer.sys ou gmer.exe, laisse le s'executer.

Clique sur l'onglet rootkit.
A droite, coche Files et Services.
Clique maintenant sur Scan.

Lorsque le scan est terminé, clique sur Copy.

Ouvre le Bloc-notes puis clique sur le Menu Edition / Coller.
Le rapport doit alors apparaître.
Enregistre le fichier sur ton bureau et copie/colle le contenu ici.
11 Novembre 2007 17:07:35

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-11-11 17:00:47
Windows 5.1.2600 Service Pack 2


---- Files - GMER 1.0.13 ----

ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\corsica_bella@hotmail.com\DFSR\Staging\CS{CF670B35-42EE-910C-D00D-EAC7AF7B33D5}\01\358-{CF670B35-42EE-910C-D00D-EAC7AF7B33D5}-v1-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v358-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\gentillekenote@hotmail.com\DFSR\Staging\CS{9E952257-70D4-0E1D-8B2A-B49443CA2937}\01\354-{9E952257-70D4-0E1D-8B2A-B49443CA2937}-v1-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v354-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\gentillekenote@hotmail.com\DFSR\Staging\CS{9E952257-70D4-0E1D-8B2A-B49443CA2937}\18\1201-{DAA461AF-FF09-4EF9-ABCC-EEA5297769A8}-v18-{8E361E60-7353-4936-BAE8-7AA375DF61D5}-v1201-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\gentillekenote@hotmail.com\DFSR\Staging\CS{9E952257-70D4-0E1D-8B2A-B49443CA2937}\18\1201-{DAA461AF-FF09-4EF9-ABCC-EEA5297769A8}-v18-{8E361E60-7353-4936-BAE8-7AA375DF61D5}-v1201-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\gentillekenote@hotmail.com\DFSR\Staging\CS{9E952257-70D4-0E1D-8B2A-B49443CA2937}\41\64-{8E361E60-7353-4936-BAE8-7AA375DF61D5}-v1141-{DAA461AF-FF09-4EF9-ABCC-EEA5297769A8}-v64-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\miss-mel-08@hotmail.com\DFSR\Staging\CS{6C0113BF-CD40-2F73-5639-0024ACF1D190}\01\82-{6C0113BF-CD40-2F73-5639-0024ACF1D190}-v1-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v82-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\10\359-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5110-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v359-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\10\359-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5110-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v359-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\14\360-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5114-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v360-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\14\360-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5114-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v360-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\16\427-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5116-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v427-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\16\427-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5116-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v427-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\17\361-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5117-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v361-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\17\361-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5117-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v361-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\18\411-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5218-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v411-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\18\411-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5218-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v411-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\19\412-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5219-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v412-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\19\412-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5219-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v412-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\20\5232-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5220-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5232-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\21\414-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5221-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v414-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\21\414-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5221-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v414-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\22\5238-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5222-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5238-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\23\362-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5123-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v362-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\23\362-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5123-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v362-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\23\5227-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5223-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5227-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\24\5228-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5224-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5228-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\25\410-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5225-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v410-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\25\410-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5225-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v410-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\27\5172-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5127-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\28\364-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5128-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v364-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\28\364-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5128-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v364-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\29\365-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5129-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v365-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\29\365-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5129-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v365-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\30\366-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5130-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v366-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\30\366-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5130-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v366-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\31\5176-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5131-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5176-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\32\368-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5132-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v368-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\32\368-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5132-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v368-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\33\369-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5133-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v369-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\33\369-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5133-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v369-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\33\416-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5233-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v416-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\33\416-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5233-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v416-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\34\370-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5134-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v370-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\34\370-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5134-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v370-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\35\371-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5135-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v371-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\35\371-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5135-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v371-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\36\372-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5136-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v372-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\36\372-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5136-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v372-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\37\373-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5137-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v373-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\37\373-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5137-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v373-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\38\374-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5138-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v374-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\38\374-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5138-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v374-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\39\375-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5139-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v375-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\39\375-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5139-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v375-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\40\376-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5140-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v376-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\40\376-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5140-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v376-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\40\420-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5240-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v420-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\40\420-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5240-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v420-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\41\5186-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5141-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5186-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\42\419-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5242-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v419-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\42\419-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5242-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v419-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\42\419-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5242-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v419-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\42\5187-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5142-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5187-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\43\379-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5143-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v379-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\43\379-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5143-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v379-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\44\380-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5144-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v380-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\44\380-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5144-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v380-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\45\152-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3245-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v152-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\45\152-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3245-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v152-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\45\224-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3345-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v224-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\45\224-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3345-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v224-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\45\428-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5245-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v428-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\45\428-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5245-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v428-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\45\5190-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5145-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5190-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\46\153-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3246-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\46\153-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3246-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\46\225-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3346-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v225-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\46\225-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3346-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v225-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\46\382-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5146-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v382-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\46\382-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5146-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v382-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\46\421-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5246-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v421-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\46\421-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5246-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v421-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\47\154-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3247-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v154-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\47\154-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3247-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v154-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\47\226-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3347-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v226-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\47\226-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3347-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v226-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\47\249-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v247-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v249-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\47\249-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v247-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v249-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\47\249-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v247-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v249-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\47\429-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5247-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v429-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\47\429-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5247-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v429-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\47\5192-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5147-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5192-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\48\155-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3248-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\48\155-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3248-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\48\351-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v348-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v351-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\48\351-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v348-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v351-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\48\351-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v348-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v351-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\48\5193-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5148-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5193-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\49\164-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3249-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v164-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\49\164-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3249-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v164-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\49\352-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v349-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v352-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\49\352-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v349-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v352-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\49\352-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v349-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v352-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\49\5194-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5149-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5194-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\50\165-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3250-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v165-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\50\165-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3250-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v165-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\50\353-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v350-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v353-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\50\353-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v350-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v353-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\50\353-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v350-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v353-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\50\386-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5150-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v386-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\50\386-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5150-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v386-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\51\229-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v2651-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v229-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\51\229-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v2651-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v229-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\51\253-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v251-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v253-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\51\253-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v251-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v253-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\51\253-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v251-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v253-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\51\5258-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5151-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5258-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\52\387-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5152-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v387-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\52\387-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5152-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v387-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\52\441-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5252-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v441-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\52\441-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5252-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v441-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\53\173-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3253-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\53\173-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3253-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\53\388-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5153-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v388-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\53\388-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5153-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v388-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\54\258-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v254-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v258-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\54\258-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v254-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v258-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\54\258-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v254-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v258-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\54\389-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5154-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v389-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\54\389-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5154-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v389-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\55\357-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v355-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v357-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\55\357-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v355-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v357-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\55\357-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v355-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v357-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\55\390-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5155-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v390-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\55\390-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5155-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v390-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\56\5201-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5156-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5201-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\57\4625-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3157-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v4625-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\57\5202-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5157-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5202-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\58\174-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3258-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v174-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\58\174-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3258-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v174-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\58\5203-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5158-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5203-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\59\175-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3259-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v175-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\59\175-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3259-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v175-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\59\261-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v259-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v261-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\59\261-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v259-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v261-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\59\261-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v259-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v261-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\59\397-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5159-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v397-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\59\397-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5159-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v397-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\59\430-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5259-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v430-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\59\430-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5259-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v430-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\60\172-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3260-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\60\172-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3260-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\60\172-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3260-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\60\398-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5160-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v398-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\60\398-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5160-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v398-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\61\194-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3261-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v194-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\61\194-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3261-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v194-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\61\206-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v1761-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v206-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\61\206-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v1761-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v206-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\61\399-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5161-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v399-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\61\399-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5161-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v399-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\61\439-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5261-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v439-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\61\439-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5261-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v439-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\62\176-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3262-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v176-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\62\176-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3262-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v176-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\62\228-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v1762-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v228-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\62\228-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v1762-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v228-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\62\263-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v262-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v263-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\62\263-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v262-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v263-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\62\263-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v262-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v263-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\62\423-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5162-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v423-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\62\423-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5162-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v423-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\63\177-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3263-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v177-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\63\177-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3263-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v177-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\63\400-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5163-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v400-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\63\400-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v5163-{999CD58D-320C-4BCC-BDDA-C06D16D7320C}-v400-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\moi\Local Settings\Application Data\Microsoft\Messenger\cassisetmanon@hotmail.com\SharingMetadata\mollymaurice@hotmail.com\DFSR\Staging\CS{9EFFC945-E7D8-DB2F-B62C-B6E180F7A2BF}\64\178-{B59A27FD-E5E7-4AC5-9BFF-D3F508101819}-v3264-{999CD58D-
a b 8 Sécurité
11 Novembre 2007 19:09:54

Tu peux pas répondre à ma question ?
11 Novembre 2007 19:20:33

Sorry,
je croyais que tu fesais une constatation en voyans le résultat!

J'en ai quelques une et surtout erreur chasseur qui me demande d'installer un logiciel fortement conseillé avec des pop up et ensuite des pages de pub quand je ferme les pop up.
a b 8 Sécurité
11 Novembre 2007 19:26:15

oK.

Télécharge Navilog1.exe (IL-MAFIOSO)
Enregistre-le sur ton Bureau.
Lance l'installation en double cliquant sur navilog.exe.
Une fois l'installation terminée, l'utilitaire s'exécutera automatiquement.
(Si ce n'est pas le cas, double clique sur le raccourci présent sur le Bureau)

Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
[#ff0000]! N'utilise pas l'option 2, 3 et 4 sans notre accord ![/#f]
Patiente jusqu'à l'apparition de ce message :
"*** Analyse Termine le ..... ***"
Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste-nous son contenu de cette manière :

-> Edition / Sélectionner tout
-> Edition / Copier
-> Clique-Droit / Coller dans ta réponse


NOTE : Le rapport se trouve également ici : C:\fixnavi.txt
11 Novembre 2007 20:22:45

Search Navipromo version 3.3.5 commencé le dim. 11/11/2007 à 20:19:46,14

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 08.11.2007 à 18h00 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2900.2180


*** Recherche Programmes installés ***




*** Recherche dossiers dans C:\WINDOWS ***



*** Recherche dossiers dans C:\Program Files ***



*** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***




*** Recherche dossiers dans C:\Documents and Settings\moi\Application Data ***


*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Aucun fichier trouvé dans :

- C:\WINDOWS\system32
- C:\DOCUME~1\MOI\LOCALS~1\APPLIC~1



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans C:\WINDOWS\system32 *

* Recherche dans C:\DOCUME~1\MOI\LOCALS~1\APPLIC~1 *



*** Recherche fichiers ***




*** Recherche clés spécifiques dans le Registre ***

a b 8 Sécurité
11 Novembre 2007 20:24:20

Le rapport n'est pas complet.
11 Novembre 2007 20:46:17

Search Navipromo version 3.3.5 commencé le dim. 11/11/2007 à 20:43:47,75

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 08.11.2007 à 18h00 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2900.2180


*** Recherche Programmes installés ***




*** Recherche dossiers dans C:\WINDOWS ***



*** Recherche dossiers dans C:\Program Files ***



*** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***




*** Recherche dossiers dans C:\Documents and Settings\moi\Application Data ***


*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Aucun fichier trouvé dans :

- C:\WINDOWS\system32
- C:\DOCUME~1\MOI\LOCALS~1\APPLIC~1



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans C:\WINDOWS\system32 *

* Recherche dans C:\DOCUME~1\MOI\LOCALS~1\APPLIC~1 *



*** Recherche fichiers ***




*** Recherche clés spécifiques dans le Registre ***


*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche fichiers connus:
C:\WINDOWS\system32\jjkkj.ini2 trouvé ! infection Vundo possible non traitée par cet outil !

2)Recherche Heuristique :



3)Recherche Certificats :

Certificat Egroup absent !


*** Analyse terminée le dim. 11/11/2007 à 20:44:39,10 ***
a b 8 Sécurité
11 Novembre 2007 21:30:26

Re,

  • Télécharge combofix.exe (par sUBs) sur ton Bureau.
  • Double clique combofix.exe.
  • Tape sur la touche 1 (Yes) pour démarrer le scan.
  • Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt
    11 Novembre 2007 22:32:39

    Je ne sais pas si c'est normal mais pendant le scan le pc s'est éteind et ralumé tout seul.


    ComboFix 07-11-08.1 - moi 2007-11-11 22:18:16.1 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.578 [GMT 1:00]
    Running from: C:\Documents and Settings\moi\Local Settings\Temporary Internet Files\Content.IE5\Q9ATUVWX\ComboFix[1].exe
    * Created a new restore point
    .

    Incapable d'obtenir les privilèges Système

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\moi.\aria.txt
    C:\WINDOWS\system32\~.exe
    C:\WINDOWS\system32\jjkkj.ini
    C:\WINDOWS\system32\jjkkj.ini2
    C:\WINDOWS\system32\jkkjj.dll
    C:\WINDOWS\system32\ssqqnlm.dll
    C:\WINDOWS\system32\sysdl132.exe

    .
    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-10-11 to 2007-11-11 ))))))))))))))))))))))))))))))))))))
    .

    2007-11-11 22:16 51,200 --a------ C:\WINDOWS\NirCmd.exe
    2007-11-11 14:46 <REP> d-------- C:\Program Files\Trend Micro
    2007-11-11 14:41 <REP> d-------- C:\Program Files\Navilog1
    2007-11-11 12:47 <REP> d-------- C:\WINDOWS\system32\ActiveScan
    2007-11-11 12:47 <REP> d-------- C:\WINDOWS\LastGood.Tmp
    2007-11-09 16:33 <REP> d-------- C:\Program Files\Yahoo!
    2007-11-09 16:33 <REP> d-------- C:\Program Files\CCleaner
    2007-11-07 11:09 <REP> d-------- C:\Documents and Settings\moi\Application Data\HP
    2007-11-06 11:05 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\HP
    2007-11-06 11:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\HP
    2007-11-06 11:04 <REP> d-------- C:\Program Files\Fichiers communs\HP
    2007-11-06 11:02 <REP> d-------- C:\Program Files\Hewlett-Packard
    2007-11-06 11:02 <REP> d-------- C:\Program Files\Fichiers communs\Hewlett-Packard
    2007-11-06 11:00 306,688 --a------ C:\WINDOWS\IsUninst.exe
    2007-11-06 11:00 282,680 --a------ C:\WINDOWS\system32\HPZidr12.dll
    2007-11-06 11:00 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
    2007-11-06 11:00 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
    2007-11-06 11:00 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe
    2007-11-06 11:00 65,536 --a------ C:\WINDOWS\system32\HPZinw12.exe
    2007-11-06 11:00 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
    2007-11-06 10:59 <REP> d-------- C:\Program Files\HP
    2007-11-06 10:58 49,664 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
    2007-11-06 10:58 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
    2007-11-06 10:57 128,615 --a------ C:\WINDOWS\hpoins11.dat
    2007-11-06 10:57 77,824 -ra------ C:\WINDOWS\system32\HPZIDS01.dll
    2007-11-06 10:57 38,400 --a------ C:\WINDOWS\system32\hpz3l054.dll
    2007-11-06 10:47 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
    2007-11-06 10:47 31,616 --a------ C:\WINDOWS\system32\dllcache\usbccgp.sys
    2007-11-05 12:31 1,901 --a------ C:\WINDOWS\panose.bin
    2007-11-04 11:35 <REP> d-------- C:\Program Files\Data++
    2007-10-27 20:41 <REP> d-------- C:\Documents and Settings\moi\Application Data\OpenOffice.org2
    2007-10-27 20:38 <REP> d-------- C:\Program Files\OpenOffice.org 2.3
    2007-10-26 21:41 1,386,496 --a------ C:\WINDOWS\system32\MSVBVM60.DLL
    2007-10-26 18:01 <REP> d-------- C:\Program Files\PDF Editeur 2
    2007-10-26 18:01 73,216 --a------ C:\WINDOWS\cadkasdeinst01f.exe

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-11-11 15:20 3,842 ----a-w C:\Documents and Settings\moi\Application Data\wklnhst.dat
    2007-11-11 12:53 --------- d-----w C:\Program Files\QuickTime
    2007-11-11 12:50 --------- d-----w C:\Program Files\MSN Messenger
    2007-11-11 12:49 --------- d-----w C:\Program Files\Microsoft Works
    2007-11-11 12:49 --------- d-----w C:\Program Files\Lexmark X1100 Series
    2007-11-10 13:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2007-11-09 11:50 --------- d-----w C:\Program Files\Google
    2007-11-09 09:38 --------- d-----w C:\Program Files\Java
    2007-11-08 22:54 --------- d-----w C:\Documents and Settings\moi\Application Data\uTorrent
    2007-11-08 18:49 --------- d-----w C:\Program Files\Free Monitor for Google
    2007-11-08 18:46 --------- d-----w C:\Program Files\Fichiers communs\Adobe
    2007-11-08 09:52 --------- d-----w C:\Documents and Settings\moi\Application Data\Skype
    2007-11-04 10:11 --------- d-----w C:\Program Files\MailingBuilder
    2007-10-27 19:29 --------- d-----w C:\Documents and Settings\moi\Application Data\SecondLife
    2007-10-25 17:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
    2007-10-25 17:05 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
    2007-10-25 17:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
    2007-10-25 17:01 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
    2007-10-25 16:58 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
    2007-10-09 12:40 --------- d-----w C:\Documents and Settings\moi\Application Data\ABBYY
    2007-09-27 11:45 --------- d-----w C:\Program Files\EasyPHP1-8
    2007-09-21 10:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
    2007-09-21 09:57 --------- d-----w C:\Program Files\Fichiers communs\Macrovision Shared
    2007-09-11 21:00 --------- d-----w C:\Program Files\Pilot Group Ltd
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7D01700F-9031-47B7-AF93-CAFADC85D0B7}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 13:00 C:\WINDOWS\system32\bthprops.cpl]
    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:34]
    "Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 16:07 C:\WINDOWS\system32\HdAShCut.exe]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-03 18:21]
    "nwiz"="nwiz.exe" [2006-05-03 18:21 C:\WINDOWS\system32\nwiz.exe]
    "RTHDCPL"="RTHDCPL.EXE" [2006-02-27 16:28 C:\WINDOWS\RTHDCPL.EXE]
    "SMSERIAL"="sm56hlpr.exe" [2005-09-16 13:01 C:\WINDOWS\sm56hlpr.exe]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-08-25 15:25]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50]
    "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-04-15 15:13]
    "InstantOn"="C:\Program Files\CyberLink\PowerCinema Linux\ion_install.exe" [2006-03-16 16:07]
    "AME_CSA"="csa.cpl" [2003-06-12 11:42 C:\WINDOWS\system32\CSA.cpl]
    "FLMOFFICE4DMOUSE"="C:\Program Files\Trust\MI-2500X OPTICAL MOUSE\Mouse32a.exe" [2006-08-31 13:25]
    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-10-25 17:20]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58]
    "Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 15:48]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41]
    "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 18:19]
    "UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 13:00]
    "RssReader"="C:\Program Files\RssReader\RssReader.exe" []
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"= msv1_0 C:\WINDOWS\system32\jkkjj.dll

    R0 SiSRaid2;SiSRaid2;C:\WINDOWS\system32\drivers\SiSRaid2.sys
    R0 viamraid;viamraid;C:\WINDOWS\system32\drivers\viamraid.sys
    S3 AmeAtmPc;AmeAtmPc;C:\WINDOWS\system32\DRIVERS\AmeAtmPc.sys
    S3 AtmElan;Réseau émulant ATM;C:\WINDOWS\system32\DRIVERS\atmlane.sys
    S3 AtmLane;Émulation réseau ATM;C:\WINDOWS\system32\DRIVERS\atmlane.sys
    S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys
    S3 Usblink;Usblink Driver;C:\WINDOWS\system32\Drivers\ulink.sys
    S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
    S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

    .
    **************************************************************************

    catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-11-11 22:27:00
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-11-11 22:30:12 - machine was rebooted
    .
    --- E O F ---
    a b 8 Sécurité
    12 Novembre 2007 16:36:06

    Reposte un rapport Hijackthis.
    12 Novembre 2007 17:43:09

    Ca a l'air d'aller bcp mieux, depuis hier plus rien.
    Je vais essayer de voir si spybot plante encore...


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:41:33, on 12/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\sm56hlpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Trust\MI-2500X OPTICAL MOUSE\Mouse32a.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\NotifyPhoneBook.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Notepad++\notepad++.exe
    C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\FileZilla\FileZilla.exe
    C:\Program Files\Adobe\Photoshop 7.0\ImageReady.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7D01700F-9031-47B7-AF93-CAFADC85D0B7} - (no file)
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [InstantOn] "C:\Program Files\CyberLink\PowerCinema Linux\ion_install.exe" /c
    O4 - HKLM\..\Run: [AME_CSA] rundll32 csa.cpl,RUN_DLL
    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Trust\MI-2500X OPTICAL MOUSE\Mouse32a.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls...
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

    --
    End of file - 7447 bytes
    12 Novembre 2007 20:58:32



    AntiVir PersonalEdition Classic
    Report file date: lundi 12 novembre 2007 19:53

    Scanning for 927083 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: SYSTEM
    Computer name: PORTABLE

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 18:52:12
    ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 18:52:13
    ANTIVIR2.VDF : 7.0.0.198 1206272 Bytes 11/11/2007 18:52:13
    ANTIVIR3.VDF : 7.0.0.206 29696 Bytes 12/11/2007 18:52:13
    AVEWIN32.DLL : 7.6.0.34 3125760 Bytes 12/11/2007 18:52:14
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
    AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: C:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: lundi 12 novembre 2007 19:53

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
    Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
    Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'StarWindService.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'HPZipm12.exe' - '1' Module(s) have been scanned
    Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
    Scan process 'ehSched.exe' - '1' Module(s) have been scanned
    Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'UnlockerAssistant.exe' - '1' Module(s) have been scanned
    Scan process 'lxbkbmon.exe' - '1' Module(s) have been scanned
    Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
    Scan process 'lxbkbmgr.exe' - '1' Module(s) have been scanned
    Scan process 'qttask.exe' - '1' Module(s) have been scanned
    Scan process 'jusched.exe' - '1' Module(s) have been scanned
    Scan process 'NotifyPhoneBook.exe' - '1' Module(s) have been scanned
    Scan process 'mouse32a.exe' - '1' Module(s) have been scanned
    Scan process 'rundll32.exe' - '1' Module(s) have been scanned
    Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
    Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
    Scan process 'sm56hlpr.exe' - '1' Module(s) have been scanned
    Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned
    Scan process 'ehtray.exe' - '1' Module(s) have been scanned
    Scan process 'rundll32.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'LEXPPS.EXE' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'LEXBCES.EXE' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    49 processes with 49 modules were scanned

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '30' files ).


    Starting the file scan:

    Begin scan in 'C:\' <459662>
    C:\hiberfil.sys
    [WARNING] The file could not be opened!
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\Documents and Settings\moi\Mes documents\Downloads\Adobe_Flash_CS3_v9__(with_crack_full_version).zip
    [0] Archive type: ZIP
    --> _crack_/Keygen.exe
    [DETECTION] Is the Trojan horse TR/Proxy.Horst.aae.14
    [INFO] The file was deleted!
    C:\Documents and Settings\moi\Mes documents\Downloads\_crack_\Keygen.exe
    [DETECTION] Is the Trojan horse TR/Proxy.Horst.aae.14
    [INFO] The file was deleted!
    C:\qoobox\Quarantine\catchme2007-11-11_222606.20.zip
    [0] Archive type: ZIP
    --> ssqqnlm.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was deleted!
    C:\qoobox\Quarantine\C\WINDOWS\system32\jkkjj.dll.vir
    [DETECTION] Is the Trojan horse TR/Trash.Gen
    [INFO] The file was deleted!
    C:\qoobox\Quarantine\C\WINDOWS\system32\ssqqnlm.dll.vir
    [DETECTION] Is the Trojan horse TR/Trash.Gen
    [INFO] The file was deleted!
    C:\qoobox\Quarantine\C\WINDOWS\system32\sysdl132.exe.vir
    [DETECTION] Is the Trojan horse TR/Drop.BHO.A.1
    [INFO] The file was deleted!
    C:\qoobox\Quarantine\C\WINDOWS\system32\~.exe.vir
    [DETECTION] Is the Trojan horse TR/Dldr.Brosys
    [INFO] The file was deleted!
    C:\System Volume Information\_restore{03468A8C-8EB4-49E1-A2E1-534B5119005A}\RP501\A0115610.exe
    [DETECTION] Is the Trojan horse TR/Delphi.Downloader.Gen
    [INFO] The file was deleted!
    C:\System Volume Information\_restore{03468A8C-8EB4-49E1-A2E1-534B5119005A}\RP501\A0115618.exe
    [DETECTION] Contains suspicious code HEUR/Crypted
    [INFO] The file was moved to '4769ac83.qua'!
    C:\System Volume Information\_restore{03468A8C-8EB4-49E1-A2E1-534B5119005A}\RP503\A0117626.exe
    [DETECTION] Contains suspicious code HEUR/Crypted
    [INFO] The file was moved to '4769ac89.qua'!
    C:\System Volume Information\_restore{03468A8C-8EB4-49E1-A2E1-534B5119005A}\RP516\A0146632.exe
    [DETECTION] Is the Trojan horse TR/Dldr.Brosys
    [INFO] The file was deleted!
    C:\System Volume Information\_restore{03468A8C-8EB4-49E1-A2E1-534B5119005A}\RP516\A0146633.exe
    [DETECTION] Is the Trojan horse TR/Drop.BHO.A.1
    [INFO] The file was deleted!
    C:\System Volume Information\_restore{03468A8C-8EB4-49E1-A2E1-534B5119005A}\RP516\A0146642.dll
    [DETECTION] Is the Trojan horse TR/Trash.Gen
    [INFO] The file was deleted!
    C:\System Volume Information\_restore{03468A8C-8EB4-49E1-A2E1-534B5119005A}\RP516\A0146643.dll
    [DETECTION] Is the Trojan horse TR/Trash.Gen
    [INFO] The file was deleted!
    C:\WINDOWS\system32\ActiveScan\pskavs.dll
    [DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
    [INFO] The file was deleted!
    C:\WINDOWS\system32\drivers\sptd.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\system32\drivers\sptd0973.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\system32\drivers\vaxscsi.sys
    [WARNING] The file could not be opened!


    End of the scan: lundi 12 novembre 2007 20:55
    Used time: 1:02:19 min

    The scan has been done completely.

    7756 Scanning directories
    505641 Files were scanned
    13 viruses and/or unwanted programs were found
    2 Files were classified as suspicious:
    13 files were deleted
    0 files were repaired
    2 files were moved to quarantine
    0 files were renamed
    5 Files cannot be scanned
    505628 Files not concerned
    8342 Archives were scanned
    5 Warnings
    10 Notes

    a b 8 Sécurité
    12 Novembre 2007 21:06:43

    Reposte un rapport Hijackthis.
    12 Novembre 2007 21:09:20

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:09:00, on 12/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\sm56hlpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Trust\MI-2500X OPTICAL MOUSE\Mouse32a.exe
    C:\WINDOWS\system32\NotifyPhoneBook.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7D01700F-9031-47B7-AF93-CAFADC85D0B7} - (no file)
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [InstantOn] "C:\Program Files\CyberLink\PowerCinema Linux\ion_install.exe" /c
    O4 - HKLM\..\Run: [AME_CSA] rundll32 csa.cpl,RUN_DLL
    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Trust\MI-2500X OPTICAL MOUSE\Mouse32a.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls...
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

    --
    End of file - 6852 bytes
    a b 8 Sécurité
    12 Novembre 2007 21:43:30

    C'est mieux ?
    12 Novembre 2007 21:51:31

    oui je ne vois plus de problèmes,
    j'attend juste encore ton accord pour lancer Spybot.
    Car avant dès que je le lançais mon pc buguait sur un écran bleu.
    a b 8 Sécurité
    13 Novembre 2007 11:59:38

    Re,

    Fix les lignes dans le cadre ci-dessous avec Hijackthis : AIDE EN IMAGES

    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {7D01700F-9031-47B7-AF93-CAFADC85D0B7} - (no file)
    13 Novembre 2007 14:48:01

    Voilà j'ai fais ce que tu as demandé...
    Je te repost un rapport:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:46:16, on 13/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\sm56hlpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Trust\MI-2500X OPTICAL MOUSE\Mouse32a.exe
    C:\WINDOWS\system32\NotifyPhoneBook.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [InstantOn] "C:\Program Files\CyberLink\PowerCinema Linux\ion_install.exe" /c
    O4 - HKLM\..\Run: [AME_CSA] rundll32 csa.cpl,RUN_DLL
    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Trust\MI-2500X OPTICAL MOUSE\Mouse32a.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls...
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

    --
    End of file - 6694 bytes
    a b 8 Sécurité
    13 Novembre 2007 16:23:43

    D'autres soucis ?
    13 Novembre 2007 19:54:55

    Non y a pas l'air, j'ai fait un scan avec spybot il a encore trouvé des spywear... Mais tout à l'heure de rouler maintenant...
    a b 8 Sécurité
    13 Novembre 2007 21:37:21

    Il en retrouve ?
    14 Novembre 2007 20:34:27

    Oui il en a trouvé 5-6...
    a b 8 Sécurité
    15 Novembre 2007 13:49:12

    Tu peux donner leur emplacement ?
    15 Novembre 2007 17:06:57

    Comment je m y prend pour te donner ca?
    a b 8 Sécurité
    15 Novembre 2007 17:10:43

    Tu clique sur le + devant le nom des infections.
    18 Novembre 2007 22:36:29

    Apparement je n'ai plus rien et tant mieux!

    Merci en tous cas d'avoir pris la peine de m'aider et surtout d'avoir résolu mes problèmes...
    a b 8 Sécurité
    19 Novembre 2007 18:22:23

    Bonne continuation ;) 
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS