Votre question

[Résolu] - Trojan.Vundo ErrorSafe Infostealer

Tags :
  • Internet Explorer
  • Sécurité
Dernière réponse : dans Sécurité et virus
25 Janvier 2007 15:22:27

Au secour , si une ame charitable voulais bien m'aider ce serai bien !!! je met la mon hijack (puis mon SDFix , puis mon VundoFix , puis mon ComboFix ...) :


Logfile of HijackThis v1.99.1
Scan saved at 18:36:08, on 25/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Myk\Bureau\Bureau\hijackthis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
O2 - BHO: PimpFish Toolbar Opcode Handler - {29C88E20-4234-41B9-A9DB-982958C95FB1} - C:\Program Files\PimpFish\PimpFish.dll
O2 - BHO: (no name) - {317BFEF3-B0B4-435B-91B8-AE9E4361B89A} - C:\WINDOWS\system32\geebb.dll (file missing)
O2 - BHO: (no name) - {4A023C6D-7C1C-42F8-8FCF-B252FB1DFDF6} - C:\WINDOWS\system32\ddccy.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: FloatBar Class - {75B1A646-CDCE-4C06-B52F-84F4463B4FC8} - C:\Program Files\PimpFish\FloatBar.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {B7BC5CCE-E6CE-43DB-B3E3-DA47DDDD4A5E} - C:\WINDOWS\system32\awtssst.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: PimpFish - {D593DE91-7B41-45C2-830E-E9A99AB142AA} - C:\Program Files\PimpFish\PimpFish.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
O8 - Extra context menu item: PimpFish - Saisir cette image - C:\Program Files\PimpFish\GRABPIC.HTM
O8 - Extra context menu item: PimpFish - Saisir le fichier cible - C:\Program Files\PimpFish\GRABLINK.HTM
O8 - Extra context menu item: PimpFish - Saisir les images auxquelles cette page est reliée - C:\Program Files\PimpFish\GRABPAGELINKS.HTM
O8 - Extra context menu item: PimpFish - Saisir les images sur cette page - C:\Program Files\PimpFish\GRABPAGEPICS.HTM
O8 - Extra context menu item: PimpFish - Saisir les vidéos sur cette page - C:\Program Files\PimpFish\GRABPAGEMOVIES.HTM
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet3_88.dll' missing
O16 - DPF: Interface Chat Wanadoo - http://chat10.x-echo.com/version8/Applet/wchatsign.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavweb...
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: awtssst - C:\WINDOWS\SYSTEM32\awtssst.dll
O20 - Winlogon Notify: ddccy - C:\WINDOWS\system32\ddccy.dll
O20 - Winlogon Notify: geebb - C:\WINDOWS\system32\geebb.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winjgf32 - winjgf32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\System32\UAService7.exe

Autres pages sur : resolu trojan vundo errorsafe infostealer

25 Janvier 2007 16:44:05

Voila mon rapport SDfix



SDFix: Version 1.62

25/01/2007 - 18:59:18,78

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:

Path:


Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting...

Normal Mode:
Checking Files:

Files will be copied to Backups folder and removed:

C:\DOCUME~1\Myk\LOCALS~1\Temp\ubi8.tmp.exe - Deleted
C:\DOCUME~1\Myk\LOCALS~1\Temp\winC.tmp.exe - Deleted
C:\WINDOWS\system32\TFTP172 - Deleted
C:\WINDOWS\system32\winsys.exe - Deleted
C:\WINDOWS\Temp\win1.tmp - Deleted
C:\WINDOWS\Temp\win10.tmp - Deleted
C:\WINDOWS\Temp\win100.tmp - Deleted
C:\WINDOWS\Temp\win101.tmp - Deleted
C:\WINDOWS\Temp\win102.tmp - Deleted
C:\WINDOWS\Temp\win103.tmp - Deleted
C:\WINDOWS\Temp\win104.tmp - Deleted
C:\WINDOWS\Temp\win105.tmp - Deleted
C:\WINDOWS\Temp\win106.tmp - Deleted
C:\WINDOWS\Temp\win107.tmp - Deleted
C:\WINDOWS\Temp\win108.tmp - Deleted
C:\WINDOWS\Temp\win109.tmp - Deleted
C:\WINDOWS\Temp\win10A.tmp - Deleted
C:\WINDOWS\Temp\win10B.tmp - Deleted
C:\WINDOWS\Temp\win10C.tmp - Deleted
C:\WINDOWS\Temp\win10D.tmp - Deleted
C:\WINDOWS\Temp\win10E.tmp - Deleted
C:\WINDOWS\Temp\win10F.tmp - Deleted
C:\WINDOWS\Temp\win11.tmp - Deleted
C:\WINDOWS\Temp\win110.tmp - Deleted
C:\WINDOWS\Temp\win111.tmp - Deleted
C:\WINDOWS\Temp\win112.tmp - Deleted
C:\WINDOWS\Temp\win113.tmp - Deleted
C:\WINDOWS\Temp\win114.tmp - Deleted
C:\WINDOWS\Temp\win115.tmp - Deleted
C:\WINDOWS\Temp\win116.tmp - Deleted
C:\WINDOWS\Temp\win117.tmp - Deleted
C:\WINDOWS\Temp\win118.tmp - Deleted
C:\WINDOWS\Temp\win119.tmp - Deleted
C:\WINDOWS\Temp\win11A.tmp - Deleted
C:\WINDOWS\Temp\win11B.tmp - Deleted
C:\WINDOWS\Temp\win11C.tmp - Deleted
C:\WINDOWS\Temp\win11D.tmp - Deleted
C:\WINDOWS\Temp\win11E.tmp - Deleted
C:\WINDOWS\Temp\win11F.tmp - Deleted
C:\WINDOWS\Temp\win12.tmp - Deleted
C:\WINDOWS\Temp\win120.tmp - Deleted
C:\WINDOWS\Temp\win121.tmp - Deleted
C:\WINDOWS\Temp\win122.tmp - Deleted
C:\WINDOWS\Temp\win123.tmp - Deleted
C:\WINDOWS\Temp\win124.tmp - Deleted
C:\WINDOWS\Temp\win125.tmp - Deleted
C:\WINDOWS\Temp\win126.tmp - Deleted
C:\WINDOWS\Temp\win127.tmp - Deleted
C:\WINDOWS\Temp\win128.tmp - Deleted
C:\WINDOWS\Temp\win129.tmp - Deleted
C:\WINDOWS\Temp\win12A.tmp - Deleted
C:\WINDOWS\Temp\win12B.tmp - Deleted
C:\WINDOWS\Temp\win12C.tmp - Deleted
C:\WINDOWS\Temp\win12D.tmp - Deleted
C:\WINDOWS\Temp\win12E.tmp - Deleted
C:\WINDOWS\Temp\win12F.tmp - Deleted
C:\WINDOWS\Temp\win13.tmp - Deleted
C:\WINDOWS\Temp\win130.tmp - Deleted
C:\WINDOWS\Temp\win131.tmp - Deleted
C:\WINDOWS\Temp\win132.tmp - Deleted
C:\WINDOWS\Temp\win133.tmp - Deleted
C:\WINDOWS\Temp\win134.tmp - Deleted
C:\WINDOWS\Temp\win135.tmp - Deleted
C:\WINDOWS\Temp\win136.tmp - Deleted
C:\WINDOWS\Temp\win137.tmp - Deleted
C:\WINDOWS\Temp\win138.tmp - Deleted
C:\WINDOWS\Temp\win139.tmp - Deleted
C:\WINDOWS\Temp\win13A.tmp - Deleted
C:\WINDOWS\Temp\win13B.tmp - Deleted
C:\WINDOWS\Temp\win13C.tmp - Deleted
C:\WINDOWS\Temp\win13D.tmp - Deleted
C:\WINDOWS\Temp\win13E.tmp - Deleted
C:\WINDOWS\Temp\win13F.tmp - Deleted
C:\WINDOWS\Temp\win14.tmp - Deleted
C:\WINDOWS\Temp\win140.tmp - Deleted
C:\WINDOWS\Temp\win141.tmp - Deleted
C:\WINDOWS\Temp\win142.tmp - Deleted
C:\WINDOWS\Temp\win143.tmp - Deleted
C:\WINDOWS\Temp\win144.tmp - Deleted
C:\WINDOWS\Temp\win145.tmp - Deleted
C:\WINDOWS\Temp\win146.tmp - Deleted
C:\WINDOWS\Temp\win147.tmp - Deleted
C:\WINDOWS\Temp\win148.tmp - Deleted
C:\WINDOWS\Temp\win149.tmp - Deleted
C:\WINDOWS\Temp\win14A.tmp - Deleted
C:\WINDOWS\Temp\win14B.tmp - Deleted
C:\WINDOWS\Temp\win14C.tmp - Deleted
C:\WINDOWS\Temp\win14D.tmp - Deleted
C:\WINDOWS\Temp\win14E.tmp - Deleted
C:\WINDOWS\Temp\win14F.tmp - Deleted
C:\WINDOWS\Temp\win15.tmp - Deleted
C:\WINDOWS\Temp\win150.tmp - Deleted
C:\WINDOWS\Temp\win151.tmp - Deleted
C:\WINDOWS\Temp\win152.tmp - Deleted
C:\WINDOWS\Temp\win153.tmp - Deleted
C:\WINDOWS\Temp\win154.tmp - Deleted
C:\WINDOWS\Temp\win155.tmp - Deleted
C:\WINDOWS\Temp\win156.tmp - Deleted
C:\WINDOWS\Temp\win157.tmp - Deleted
C:\WINDOWS\Temp\win158.tmp - Deleted
C:\WINDOWS\Temp\win159.tmp - Deleted
C:\WINDOWS\Temp\win15A.tmp - Deleted
C:\WINDOWS\Temp\win15B.tmp - Deleted
C:\WINDOWS\Temp\win15C.tmp - Deleted
C:\WINDOWS\Temp\win15D.tmp - Deleted
C:\WINDOWS\Temp\win15E.tmp - Deleted
C:\WINDOWS\Temp\win15F.tmp - Deleted
C:\WINDOWS\Temp\win16.tmp - Deleted
C:\WINDOWS\Temp\win160.tmp - Deleted
C:\WINDOWS\Temp\win161.tmp - Deleted
C:\WINDOWS\Temp\win162.tmp - Deleted
C:\WINDOWS\Temp\win163.tmp - Deleted
C:\WINDOWS\Temp\win164.tmp - Deleted
C:\WINDOWS\Temp\win165.tmp - Deleted
C:\WINDOWS\Temp\win166.tmp - Deleted
C:\WINDOWS\Temp\win167.tmp - Deleted
C:\WINDOWS\Temp\win168.tmp - Deleted
C:\WINDOWS\Temp\win169.tmp - Deleted
C:\WINDOWS\Temp\win16A.tmp - Deleted
C:\WINDOWS\Temp\win16B.tmp - Deleted
C:\WINDOWS\Temp\win16C.tmp - Deleted
C:\WINDOWS\Temp\win16D.tmp - Deleted
C:\WINDOWS\Temp\win16E.tmp - Deleted
C:\WINDOWS\Temp\win16F.tmp - Deleted
C:\WINDOWS\Temp\win17.tmp - Deleted
C:\WINDOWS\Temp\win170.tmp - Deleted
C:\WINDOWS\Temp\win171.tmp - Deleted
C:\WINDOWS\Temp\win172.tmp - Deleted
C:\WINDOWS\Temp\win173.tmp - Deleted
C:\WINDOWS\Temp\win174.tmp - Deleted
C:\WINDOWS\Temp\win175.tmp - Deleted
C:\WINDOWS\Temp\win176.tmp - Deleted
C:\WINDOWS\Temp\win177.tmp - Deleted
C:\WINDOWS\Temp\win178.tmp - Deleted
C:\WINDOWS\Temp\win179.tmp - Deleted
C:\WINDOWS\Temp\win17A.tmp - Deleted
C:\WINDOWS\Temp\win17B.tmp - Deleted
C:\WINDOWS\Temp\win17C.tmp - Deleted
C:\WINDOWS\Temp\win17D.tmp - Deleted
C:\WINDOWS\Temp\win17E.tmp - Deleted
C:\WINDOWS\Temp\win17F.tmp - Deleted
C:\WINDOWS\Temp\win18.tmp - Deleted
C:\WINDOWS\Temp\win180.tmp - Deleted
C:\WINDOWS\Temp\win181.tmp - Deleted
C:\WINDOWS\Temp\win182.tmp - Deleted
C:\WINDOWS\Temp\win183.tmp - Deleted
C:\WINDOWS\Temp\win184.tmp - Deleted
C:\WINDOWS\Temp\win185.tmp - Deleted
C:\WINDOWS\Temp\win186.tmp - Deleted
C:\WINDOWS\Temp\win187.tmp - Deleted
C:\WINDOWS\Temp\win188.tmp - Deleted
C:\WINDOWS\Temp\win189.tmp - Deleted
C:\WINDOWS\Temp\win18A.tmp - Deleted
C:\WINDOWS\Temp\win18B.tmp - Deleted
C:\WINDOWS\Temp\win18C.tmp - Deleted
C:\WINDOWS\Temp\win18D.tmp - Deleted
C:\WINDOWS\Temp\win18E.tmp - Deleted
C:\WINDOWS\Temp\win18F.tmp - Deleted
C:\WINDOWS\Temp\win19.tmp - Deleted
C:\WINDOWS\Temp\win190.tmp - Deleted
C:\WINDOWS\Temp\win191.tmp - Deleted
C:\WINDOWS\Temp\win192.tmp - Deleted
C:\WINDOWS\Temp\win193.tmp - Deleted
C:\WINDOWS\Temp\win194.tmp - Deleted
C:\WINDOWS\Temp\win195.tmp - Deleted
C:\WINDOWS\Temp\win196.tmp - Deleted
C:\WINDOWS\Temp\win197.tmp - Deleted
C:\WINDOWS\Temp\win198.tmp - Deleted
C:\WINDOWS\Temp\win199.tmp - Deleted
C:\WINDOWS\Temp\win19A.tmp - Deleted
C:\WINDOWS\Temp\win19B.tmp - Deleted
C:\WINDOWS\Temp\win19C.tmp - Deleted
C:\WINDOWS\Temp\win19D.tmp - Deleted
C:\WINDOWS\Temp\win19E.tmp - Deleted
C:\WINDOWS\Temp\win19F.tmp - Deleted
C:\WINDOWS\Temp\win1A.tmp - Deleted
C:\WINDOWS\Temp\win1A0.tmp - Deleted
C:\WINDOWS\Temp\win1A1.tmp - Deleted
C:\WINDOWS\Temp\win1A2.tmp - Deleted
C:\WINDOWS\Temp\win1A3.tmp - Deleted
C:\WINDOWS\Temp\win1A5.tmp - Deleted
C:\WINDOWS\Temp\win1A6.tmp - Deleted
C:\WINDOWS\Temp\win1A7.tmp - Deleted
C:\WINDOWS\Temp\win1A8.tmp - Deleted
C:\WINDOWS\Temp\win1A9.tmp - Deleted
C:\WINDOWS\Temp\win1AA.tmp - Deleted
C:\WINDOWS\Temp\win1AB.tmp - Deleted
C:\WINDOWS\Temp\win1AC.tmp - Deleted
C:\WINDOWS\Temp\win1AD.tmp - Deleted
C:\WINDOWS\Temp\win1AE.tmp - Deleted
C:\WINDOWS\Temp\win1AF.tmp - Deleted
C:\WINDOWS\Temp\win1B.tmp - Deleted
C:\WINDOWS\Temp\win1B0.tmp - Deleted
C:\WINDOWS\Temp\win1B1.tmp - Deleted
C:\WINDOWS\Temp\win1B2.tmp - Deleted
C:\WINDOWS\Temp\win1B3.tmp - Deleted
C:\WINDOWS\Temp\win1B4.tmp - Deleted
C:\WINDOWS\Temp\win1B5.tmp - Deleted
C:\WINDOWS\Temp\win1B6.tmp - Deleted
C:\WINDOWS\Temp\win1B7.tmp - Deleted
C:\WINDOWS\Temp\win1B8.tmp - Deleted
C:\WINDOWS\Temp\win1B9.tmp - Deleted
C:\WINDOWS\Temp\win1BA.tmp - Deleted
C:\WINDOWS\Temp\win1BB.tmp - Deleted
C:\WINDOWS\Temp\win1BC.tmp - Deleted
C:\WINDOWS\Temp\win1BD.tmp - Deleted
C:\WINDOWS\Temp\win1BE.tmp - Deleted
C:\WINDOWS\Temp\win1BF.tmp - Deleted
C:\WINDOWS\Temp\win1C.tmp - Deleted
C:\WINDOWS\Temp\win1C0.tmp - Deleted
C:\WINDOWS\Temp\win1C1.tmp - Deleted
C:\WINDOWS\Temp\win1C2.tmp - Deleted
C:\WINDOWS\Temp\win1C3.tmp - Deleted
C:\WINDOWS\Temp\win1C4.tmp - Deleted
C:\WINDOWS\Temp\win1C5.tmp - Deleted
C:\WINDOWS\Temp\win1C6.tmp - Deleted
C:\WINDOWS\Temp\win1C7.tmp - Deleted
C:\WINDOWS\Temp\win1C8.tmp - Deleted
C:\WINDOWS\Temp\win1C9.tmp - Deleted
C:\WINDOWS\Temp\win1CA.tmp - Deleted
C:\WINDOWS\Temp\win1CB.tmp - Deleted
C:\WINDOWS\Temp\win1CC.tmp - Deleted
C:\WINDOWS\Temp\win1CD.tmp - Deleted
C:\WINDOWS\Temp\win1CE.tmp - Deleted
C:\WINDOWS\Temp\win1CF.tmp - Deleted
C:\WINDOWS\Temp\win1D.tmp - Deleted
C:\WINDOWS\Temp\win1D0.tmp - Deleted
C:\WINDOWS\Temp\win1D1.tmp - Deleted
C:\WINDOWS\Temp\win1D2.tmp - Deleted
C:\WINDOWS\Temp\win1D3.tmp - Deleted
C:\WINDOWS\Temp\win1D4.tmp - Deleted
C:\WINDOWS\Temp\win1D5.tmp - Deleted
C:\WINDOWS\Temp\win1D6.tmp - Deleted
C:\WINDOWS\Temp\win1D7.tmp - Deleted
C:\WINDOWS\Temp\win1D8.tmp - Deleted
C:\WINDOWS\Temp\win1D9.tmp - Deleted
C:\WINDOWS\Temp\win1DA.tmp - Deleted
C:\WINDOWS\Temp\win1DB.tmp - Deleted
C:\WINDOWS\Temp\win1DC.tmp - Deleted
C:\WINDOWS\Temp\win1DD.tmp - Deleted
C:\WINDOWS\Temp\win1DE.tmp - Deleted
C:\WINDOWS\Temp\win1DF.tmp - Deleted
C:\WINDOWS\Temp\win1E.tmp - Deleted
C:\WINDOWS\Temp\win1E0.tmp - Deleted
C:\WINDOWS\Temp\win1E1.tmp - Deleted
C:\WINDOWS\Temp\win1E2.tmp - Deleted
C:\WINDOWS\Temp\win1E3.tmp - Deleted
C:\WINDOWS\Temp\win1E4.tmp - Deleted
C:\WINDOWS\Temp\win1E5.tmp - Deleted
C:\WINDOWS\Temp\win1E6.tmp - Deleted
C:\WINDOWS\Temp\win1E7.tmp - Deleted
C:\WINDOWS\Temp\win1E8.tmp - Deleted
C:\WINDOWS\Temp\win1E9.tmp - Deleted
C:\WINDOWS\Temp\win1EA.tmp - Deleted
C:\WINDOWS\Temp\win1EB.tmp - Deleted
C:\WINDOWS\Temp\win1EC.tmp - Deleted
C:\WINDOWS\Temp\win1ED.tmp - Deleted
C:\WINDOWS\Temp\win1EE.tmp - Deleted
C:\WINDOWS\Temp\win1EF.tmp - Deleted
C:\WINDOWS\Temp\win1F.tmp - Deleted
C:\WINDOWS\Temp\win1F0.tmp - Deleted
C:\WINDOWS\Temp\win1F1.tmp - Deleted
C:\WINDOWS\Temp\win1F2.tmp - Deleted
C:\WINDOWS\Temp\win1F3.tmp - Deleted
C:\WINDOWS\Temp\win1F4.tmp - Deleted
C:\WINDOWS\Temp\win1F5.tmp - Deleted
C:\WINDOWS\Temp\win1F6.tmp - Deleted
C:\WINDOWS\Temp\win1F7.tmp - Deleted
C:\WINDOWS\Temp\win1F8.tmp - Deleted
C:\WINDOWS\Temp\win1F9.tmp - Deleted
C:\WINDOWS\Temp\win1FA.tmp - Deleted
C:\WINDOWS\Temp\win1FB.tmp - Deleted
C:\WINDOWS\Temp\win1FC.tmp - Deleted
C:\WINDOWS\Temp\win1FD.tmp - Deleted
C:\WINDOWS\Temp\win1FE.tmp - Deleted
C:\WINDOWS\Temp\win1FF.tmp - Deleted
C:\WINDOWS\Temp\win2.tmp - Deleted
C:\WINDOWS\Temp\win20.tmp - Deleted
C:\WINDOWS\Temp\win200.tmp - Deleted
C:\WINDOWS\Temp\win201.tmp - Deleted
C:\WINDOWS\Temp\win202.tmp - Deleted
C:\WINDOWS\Temp\win203.tmp - Deleted
C:\WINDOWS\Temp\win204.tmp - Deleted
C:\WINDOWS\Temp\win205.tmp - Deleted
C:\WINDOWS\Temp\win206.tmp - Deleted
C:\WINDOWS\Temp\win207.tmp - Deleted
C:\WINDOWS\Temp\win208.tmp - Deleted
C:\WINDOWS\Temp\win209.tmp - Deleted
C:\WINDOWS\Temp\win20A.tmp - Deleted
C:\WINDOWS\Temp\win20B.tmp - Deleted
C:\WINDOWS\Temp\win20C.tmp - Deleted
C:\WINDOWS\Temp\win20D.tmp - Deleted
C:\WINDOWS\Temp\win20E.tmp - Deleted
C:\WINDOWS\Temp\win20F.tmp - Deleted
C:\WINDOWS\Temp\win21.tmp - Deleted
C:\WINDOWS\Temp\win210.tmp - Deleted
C:\WINDOWS\Temp\win211.tmp - Deleted
C:\WINDOWS\Temp\win212.tmp - Deleted
C:\WINDOWS\Temp\win213.tmp - Deleted
C:\WINDOWS\Temp\win214.tmp - Deleted
C:\WINDOWS\Temp\win215.tmp - Deleted
C:\WINDOWS\Temp\win216.tmp - Deleted
C:\WINDOWS\Temp\win217.tmp - Deleted
C:\WINDOWS\Temp\win218.tmp - Deleted
C:\WINDOWS\Temp\win219.tmp - Deleted
C:\WINDOWS\Temp\win21A.tmp - Deleted
C:\WINDOWS\Temp\win21B.tmp - Deleted
C:\WINDOWS\Temp\win21C.tmp - Deleted
C:\WINDOWS\Temp\win21D.tmp - Deleted
C:\WINDOWS\Temp\win21E.tmp - Deleted
C:\WINDOWS\Temp\win21F.tmp - Deleted
C:\WINDOWS\Temp\win22.tmp - Deleted
C:\WINDOWS\Temp\win220.tmp - Deleted
C:\WINDOWS\Temp\win221.tmp - Deleted
C:\WINDOWS\Temp\win222.tmp - Deleted
C:\WINDOWS\Temp\win224.tmp - Deleted
C:\WINDOWS\Temp\win225.tmp - Deleted
C:\WINDOWS\Temp\win226.tmp - Deleted
C:\WINDOWS\Temp\win227.tmp - Deleted
C:\WINDOWS\Temp\win228.tmp - Deleted
C:\WINDOWS\Temp\win22D.tmp - Deleted
C:\WINDOWS\Temp\win22F.tmp - Deleted
C:\WINDOWS\Temp\win23.tmp - Deleted
C:\WINDOWS\Temp\win230.tmp - Deleted
C:\WINDOWS\Temp\win232.tmp - Deleted
C:\WINDOWS\Temp\win234.tmp - Deleted
C:\WINDOWS\Temp\win23D.tmp - Deleted
C:\WINDOWS\Temp\win24.tmp - Deleted
C:\WINDOWS\Temp\win25.tmp - Deleted
C:\WINDOWS\Temp\win26.tmp - Deleted
C:\WINDOWS\Temp\win27.tmp - Deleted
C:\WINDOWS\Temp\win28.tmp - Deleted
C:\WINDOWS\Temp\win288.tmp - Deleted
C:\WINDOWS\Temp\win29.tmp - Deleted
C:\WINDOWS\Temp\win2A.tmp - Deleted
C:\WINDOWS\Temp\win2A9.tmp - Deleted
C:\WINDOWS\Temp\win2B.tmp - Deleted
C:\WINDOWS\Temp\win2C.tmp - Deleted
C:\WINDOWS\Temp\win2D.tmp - Deleted
C:\WINDOWS\Temp\win2D6.tmp - Deleted
C:\WINDOWS\Temp\win2E.tmp - Deleted
C:\WINDOWS\Temp\win2F.tmp - Deleted
C:\WINDOWS\Temp\win3.tmp - Deleted
C:\WINDOWS\Temp\win30.tmp - Deleted
C:\WINDOWS\Temp\win31.tmp - Deleted
C:\WINDOWS\Temp\win32.tmp - Deleted
C:\WINDOWS\Temp\win33.tmp - Deleted
C:\WINDOWS\Temp\win34.tmp - Deleted
C:\WINDOWS\Temp\win35.tmp - Deleted
C:\WINDOWS\Temp\win36.tmp - Deleted
C:\WINDOWS\Temp\win37.tmp - Deleted
C:\WINDOWS\Temp\win38.tmp - Deleted
C:\WINDOWS\Temp\win39.tmp - Deleted
C:\WINDOWS\Temp\win3A.tmp - Deleted
C:\WINDOWS\Temp\win3B.tmp - Deleted
C:\WINDOWS\Temp\win3C.tmp - Deleted
C:\WINDOWS\Temp\win3D.tmp - Deleted
C:\WINDOWS\Temp\win3E.tmp - Deleted
C:\WINDOWS\Temp\win3F.tmp - Deleted
C:\WINDOWS\Temp\win4.tmp - Deleted
C:\WINDOWS\Temp\win40.tmp - Deleted
C:\WINDOWS\Temp\win41.tmp - Deleted
C:\WINDOWS\Temp\win42.tmp - Deleted
C:\WINDOWS\Temp\win43.tmp - Deleted
C:\WINDOWS\Temp\win44.tmp - Deleted
C:\WINDOWS\Temp\win44B.tmp - Deleted
C:\WINDOWS\Temp\win45.tmp - Deleted
C:\WINDOWS\Temp\win459.tmp - Deleted
C:\WINDOWS\Temp\win45E.tmp - Deleted
C:\WINDOWS\Temp\win46.tmp - Deleted
C:\WINDOWS\Temp\win463.tmp - Deleted
C:\WINDOWS\Temp\win464.tmp - Deleted
C:\WINDOWS\Temp\win465.tmp - Deleted
C:\WINDOWS\Temp\win466.tmp - Deleted
C:\WINDOWS\Temp\win46C.tmp - Deleted
C:\WINDOWS\Temp\win46D.tmp - Deleted
C:\WINDOWS\Temp\win46E.tmp - Deleted
C:\WINDOWS\Temp\win46F.tmp - Deleted
C:\WINDOWS\Temp\win47.tmp - Deleted
C:\WINDOWS\Temp\win470.tmp - Deleted
C:\WINDOWS\Temp\win471.tmp - Deleted
C:\WINDOWS\Temp\win472.tmp - Deleted
C:\WINDOWS\Temp\win473.tmp - Deleted
C:\WINDOWS\Temp\win475.tmp - Deleted
C:\WINDOWS\Temp\win476.tmp - Deleted
C:\WINDOWS\Temp\win477.tmp - Deleted
C:\WINDOWS\Temp\win478.tmp - Deleted
C:\WINDOWS\Temp\win479.tmp - Deleted
C:\WINDOWS\Temp\win47A.tmp - Deleted
C:\WINDOWS\Temp\win47B.tmp - Deleted
C:\WINDOWS\Temp\win47C.tmp - Deleted
C:\WINDOWS\Temp\win48.tmp - Deleted
C:\WINDOWS\Temp\win49.tmp - Deleted
C:\WINDOWS\Temp\win4A.tmp - Deleted
C:\WINDOWS\Temp\win4A9.tmp - Deleted
C:\WINDOWS\Temp\win4AA.tmp - Deleted
C:\WINDOWS\Temp\win4AB.tmp - Deleted
C:\WINDOWS\Temp\win4AC.tmp - Deleted
C:\WINDOWS\Temp\win4AD.tmp - Deleted
C:\WINDOWS\Temp\win4AE.tmp - Deleted
C:\WINDOWS\Temp\win4AF.tmp - Deleted
C:\WINDOWS\Temp\win4B.tmp - Deleted
C:\WINDOWS\Temp\win4B0.tmp - Deleted
C:\WINDOWS\Temp\win4B2.tmp - Deleted
C:\WINDOWS\Temp\win4B3.tmp - Deleted
C:\WINDOWS\Temp\win4B4.tmp - Deleted
C:\WINDOWS\Temp\win4B5.tmp - Deleted
C:\WINDOWS\Temp\win4C.tmp - Deleted
C:\WINDOWS\Temp\win4C9.tmp - Deleted
C:\WINDOWS\Temp\win4CA.tmp - Deleted
C:\WINDOWS\Temp\win4CB.tmp - Deleted
C:\WINDOWS\Temp\win4CC.tmp - Deleted
C:\WINDOWS\Temp\win4CD.tmp - Deleted
C:\WINDOWS\Temp\win4CF.tmp - Deleted
C:\WINDOWS\Temp\win4D.tmp - Deleted
C:\WINDOWS\Temp\win4D0.tmp - Deleted
C:\WINDOWS\Temp\win4D1.tmp - Deleted
C:\WINDOWS\Temp\win4D2.tmp - Deleted
C:\WINDOWS\Temp\win4D3.tmp - Deleted
C:\WINDOWS\Temp\win4D7.tmp - Deleted
C:\WINDOWS\Temp\win4D8.tmp - Deleted
C:\WINDOWS\Temp\win4D9.tmp - Deleted
C:\WINDOWS\Temp\win4DA.tmp - Deleted
C:\WINDOWS\Temp\win4DF.tmp - Deleted
C:\WINDOWS\Temp\win4E.tmp - Deleted
C:\WINDOWS\Temp\win4E0.tmp - Deleted
C:\WINDOWS\Temp\win4E1.tmp - Deleted
C:\WINDOWS\Temp\win4E2.tmp - Deleted
C:\WINDOWS\Temp\win4E3.tmp - Deleted
C:\WINDOWS\Temp\win4ED.tmp - Deleted
C:\WINDOWS\Temp\win4EE.tmp - Deleted
C:\WINDOWS\Temp\win4EF.tmp - Deleted
C:\WINDOWS\Temp\win4F.tmp - Deleted
C:\WINDOWS\Temp\win4F0.tmp - Deleted
C:\WINDOWS\Temp\win4F8.tmp - Deleted
C:\WINDOWS\Temp\win4F9.tmp - Deleted
C:\WINDOWS\Temp\win4FA.tmp - Deleted
C:\WINDOWS\Temp\win4FB.tmp - Deleted
C:\WINDOWS\Temp\win4FF.tmp - Deleted
C:\WINDOWS\Temp\win5.tmp - Deleted
C:\WINDOWS\Temp\win50.tmp - Deleted
C:\WINDOWS\Temp\win500.tmp - Deleted
C:\WINDOWS\Temp\win501.tmp - Deleted
C:\WINDOWS\Temp\win502.tmp - Deleted
C:\WINDOWS\Temp\win505.tmp - Deleted
C:\WINDOWS\Temp\win506.tmp - Deleted
C:\WINDOWS\Temp\win507.tmp - Deleted
C:\WINDOWS\Temp\win508.tmp - Deleted
C:\WINDOWS\Temp\win509.tmp - Deleted
C:\WINDOWS\Temp\win50A.tmp - Deleted
C:\WINDOWS\Temp\win50B.tmp - Deleted
C:\WINDOWS\Temp\win50C.tmp - Deleted
C:\WINDOWS\Temp\win51.tmp - Deleted
C:\WINDOWS\Temp\win512.tmp - Deleted
C:\WINDOWS\Temp\win513.tmp - Deleted
C:\WINDOWS\Temp\win514.tmp - Deleted
C:\WINDOWS\Temp\win515.tmp - Deleted
C:\WINDOWS\Temp\win51E.tmp - Deleted
C:\WINDOWS\Temp\win51F.tmp - Deleted
C:\WINDOWS\Temp\win52.tmp - Deleted
C:\WINDOWS\Temp\win520.tmp - Deleted
C:\WINDOWS\Temp\win521.tmp - Deleted
C:\WINDOWS\Temp\win524.tmp - Deleted
C:\WINDOWS\Temp\win525.tmp - Deleted
C:\WINDOWS\Temp\win526.tmp - Deleted
C:\WINDOWS\Temp\win527.tmp - Deleted
C:\WINDOWS\Temp\win53.tmp - Deleted
C:\WINDOWS\Temp\win54.tmp - Deleted
C:\WINDOWS\Temp\win55.tmp - Deleted
C:\WINDOWS\Temp\win558.tmp - Deleted
C:\WINDOWS\Temp\win56.tmp - Deleted
C:\WINDOWS\Temp\win57.tmp - Deleted
C:\WINDOWS\Temp\win58.tmp - Deleted
C:\WINDOWS\Temp\win59.tmp - Deleted
C:\WINDOWS\Temp\win598.tmp - Deleted
C:\WINDOWS\Temp\win599.tmp - Deleted
C:\WINDOWS\Temp\win59A.tmp - Deleted
C:\WINDOWS\Temp\win59B.tmp - Deleted
C:\WINDOWS\Temp\win5A.tmp - Deleted
C:\WINDOWS\Temp\win5A6.tmp - Deleted
C:\WINDOWS\Temp\win5A7.tmp - Deleted
C:\WINDOWS\Temp\win5A8.tmp - Deleted
C:\WINDOWS\Temp\win5A9.tmp - Deleted
C:\WINDOWS\Temp\win5AB.tmp - Deleted
C:\WINDOWS\Temp\win5AC.tmp - Deleted
C:\WINDOWS\Temp\win5AD.tmp - Deleted
C:\WINDOWS\Temp\win5AE.tmp - Deleted
C:\WINDOWS\Temp\win5AF.tmp - Deleted
C:\WINDOWS\Temp\win5B.tmp - Deleted
C:\WINDOWS\Temp\win5C.tmp - Deleted
C:\WINDOWS\Temp\win5CF.tmp - Deleted
C:\WINDOWS\Temp\win5D.tmp - Deleted
C:\WINDOWS\Temp\win5D0.tmp - Deleted
C:\WINDOWS\Temp\win5D1.tmp - Deleted
C:\WINDOWS\Temp\win5D2.tmp - Deleted
C:\WINDOWS\Temp\win5D3.tmp - Deleted
C:\WINDOWS\Temp\win5D4.tmp - Deleted
C:\WINDOWS\Temp\win5D5.tmp - Deleted
C:\WINDOWS\Temp\win5D6.tmp - Deleted
C:\WINDOWS\Temp\win5D7.tmp - Deleted
C:\WINDOWS\Temp\win5E.tmp - Deleted
C:\WINDOWS\Temp\win5E0.tmp - Deleted
C:\WINDOWS\Temp\win5E5.tmp - Deleted
C:\WINDOWS\Temp\win5F.tmp - Deleted
C:\WINDOWS\Temp\win6.tmp - Deleted
C:\WINDOWS\Temp\win60.tmp - Deleted
C:\WINDOWS\Temp\win61.tmp - Deleted
C:\WINDOWS\Temp\win62.tmp - Deleted
C:\WINDOWS\Temp\win63.tmp - Deleted
C:\WINDOWS\Temp\win64.tmp - Deleted
C:\WINDOWS\Temp\win65.tmp - Deleted
C:\WINDOWS\Temp\win66.tmp - Deleted
C:\WINDOWS\Temp\win67.tmp - Deleted
C:\WINDOWS\Temp\win68.tmp - Deleted
C:\WINDOWS\Temp\win69.tmp - Deleted
C:\WINDOWS\Temp\win6A.tmp - Deleted
C:\WINDOWS\Temp\win6B.tmp - Deleted
C:\WINDOWS\Temp\win6C.tmp - Deleted
C:\WINDOWS\Temp\win6D.tmp - Deleted
C:\WINDOWS\Temp\win6E.tmp - Deleted
C:\WINDOWS\Temp\win6F.tmp - Deleted
C:\WINDOWS\Temp\win7.tmp - Deleted
C:\WINDOWS\Temp\win70.tmp - Deleted
C:\WINDOWS\Temp\win71.tmp - Deleted
C:\WINDOWS\Temp\win72.tmp - Deleted
C:\WINDOWS\Temp\win73.tmp - Deleted
C:\WINDOWS\Temp\win74.tmp - Deleted
C:\WINDOWS\Temp\win75.tmp - Deleted
C:\WINDOWS\Temp\win76.tmp - Deleted
C:\WINDOWS\Temp\win77.tmp - Deleted
C:\WINDOWS\Temp\win78.tmp - Deleted
C:\WINDOWS\Temp\win79.tmp - Deleted
C:\WINDOWS\Temp\win7A.tmp - Deleted
C:\WINDOWS\Temp\win7B.tmp - Deleted
C:\WINDOWS\Temp\win7C.tmp - Deleted
C:\WINDOWS\Temp\win7D.tmp - Deleted
C:\WINDOWS\Temp\win7E.tmp - Deleted
C:\WINDOWS\Temp\win7F.tmp - Deleted
C:\WINDOWS\Temp\win8.tmp - Deleted
C:\WINDOWS\Temp\win80.tmp - Deleted
C:\WINDOWS\Temp\win81.tmp - Deleted
C:\WINDOWS\Temp\win82.tmp - Deleted
C:\WINDOWS\Temp\win83.tmp - Deleted
C:\WINDOWS\Temp\win84.tmp - Deleted
C:\WINDOWS\Temp\win85.tmp - Deleted
C:\WINDOWS\Temp\win86.tmp - Deleted
C:\WINDOWS\Temp\win87.tmp - Deleted
C:\WINDOWS\Temp\win88.tmp - Deleted
C:\WINDOWS\Temp\win89.tmp - Deleted
C:\WINDOWS\Temp\win8A.tmp - Deleted
C:\WINDOWS\Temp\win8B.tmp - Deleted
C:\WINDOWS\Temp\win8C.tmp - Deleted
C:\WINDOWS\Temp\win8D.tmp - Deleted
C:\WINDOWS\Temp\win8E.tmp - Deleted
C:\WINDOWS\Temp\win8F.tmp - Deleted
C:\WINDOWS\Temp\win9.tmp - Deleted
C:\WINDOWS\Temp\win90.tmp - Deleted
C:\WINDOWS\Temp\win91.tmp - Deleted
C:\WINDOWS\Temp\win92.tmp - Deleted
C:\WINDOWS\Temp\win93.tmp - Deleted
C:\WINDOWS\Temp\win94.tmp - Deleted
C:\WINDOWS\Temp\win95.tmp - Deleted
C:\WINDOWS\Temp\win96.tmp - Deleted
C:\WINDOWS\Temp\win97.tmp - Deleted
C:\WINDOWS\Temp\win98.tmp - Deleted
C:\WINDOWS\Temp\win99.tmp - Deleted
C:\WINDOWS\Temp\win9A.tmp - Deleted
C:\WINDOWS\Temp\win9B.tmp - Deleted
C:\WINDOWS\Temp\win9C.tmp - Deleted
C:\WINDOWS\Temp\win9D.tmp - Deleted
C:\WINDOWS\Temp\win9E.tmp - Deleted
C:\WINDOWS\Temp\win9F.tmp - Deleted
C:\WINDOWS\Temp\winA.tmp - Deleted
C:\WINDOWS\Temp\winA0.tmp - Deleted
C:\WINDOWS\Temp\winA1.tmp - Deleted
C:\WINDOWS\Temp\winA2.tmp - Deleted
C:\WINDOWS\Temp\winA3.tmp - Deleted
C:\WINDOWS\Temp\winA4.tmp - Deleted
C:\WINDOWS\Temp\winA5.tmp - Deleted
C:\WINDOWS\Temp\winA6.tmp - Deleted
C:\WINDOWS\Temp\winA7.tmp - Deleted
C:\WINDOWS\Temp\winA8.tmp - Deleted
C:\WINDOWS\Temp\winA9.tmp - Deleted
C:\WINDOWS\Temp\winAA.tmp - Deleted
C:\WINDOWS\Temp\winAB.tmp - Deleted
C:\WINDOWS\Temp\winAC.tmp - Deleted
C:\WINDOWS\Temp\winAD.tmp - Deleted
C:\WINDOWS\Temp\winAE.tmp - Deleted
C:\WINDOWS\Temp\winAF.tmp - Deleted
C:\WINDOWS\Temp\winB.tmp - Deleted
C:\WINDOWS\Temp\winB0.tmp - Deleted
C:\WINDOWS\Temp\winB1.tmp - Deleted
C:\WINDOWS\Temp\winB2.tmp - Deleted
C:\WINDOWS\Temp\winB3.tmp - Deleted
C:\WINDOWS\Temp\winB4.tmp - Deleted
C:\WINDOWS\Temp\winB5.tmp - Deleted
C:\WINDOWS\Temp\winB6.tmp - Deleted
C:\WINDOWS\Temp\winB7.tmp - Deleted
C:\WINDOWS\Temp\winB8.tmp - Deleted
C:\WINDOWS\Temp\winB9.tmp - Deleted
C:\WINDOWS\Temp\winBA.tmp - Deleted
C:\WINDOWS\Temp\winBB.tmp - Deleted
C:\WINDOWS\Temp\winBC.tmp - Deleted
C:\WINDOWS\Temp\winBD.tmp - Deleted
C:\WINDOWS\Temp\winBE.tmp - Deleted
C:\WINDOWS\Temp\winBF.tmp - Deleted
C:\WINDOWS\Temp\winC.tmp - Deleted
C:\WINDOWS\Temp\winC0.tmp - Deleted
C:\WINDOWS\Temp\winC1.tmp - Deleted
C:\WINDOWS\Temp\winC2.tmp - Deleted
C:\WINDOWS\Temp\winC3.tmp - Deleted
C:\WINDOWS\Temp\winC4.tmp - Deleted
C:\WINDOWS\Temp\winC5.tmp - Deleted
C:\WINDOWS\Temp\winC6.tmp - Deleted
C:\WINDOWS\Temp\winC7.tmp - Deleted
C:\WINDOWS\Temp\winC8.tmp - Deleted
C:\WINDOWS\Temp\winC9.tmp - Deleted
C:\WINDOWS\Temp\winCA.tmp - Deleted
C:\WINDOWS\Temp\winCB.tmp - Deleted
C:\WINDOWS\Temp\winCC.tmp - Deleted
C:\WINDOWS\Temp\winCD.tmp - Deleted
C:\WINDOWS\Temp\winCE.tmp - Deleted
C:\WINDOWS\Temp\winCF.tmp - Deleted
C:\WINDOWS\Temp\winD.tmp - Deleted
C:\WINDOWS\Temp\winD0.tmp - Deleted
C:\WINDOWS\Temp\winD1.tmp - Deleted
C:\WINDOWS\Temp\winD2.tmp - Deleted
C:\WINDOWS\Temp\winD3.tmp - Deleted
C:\WINDOWS\Temp\winD4.tmp - Deleted
C:\WINDOWS\Temp\winD5.tmp - Deleted
C:\WINDOWS\Temp\winD6.tmp - Deleted
C:\WINDOWS\Temp\winD7.tmp - Deleted
C:\WINDOWS\Temp\winD8.tmp - Deleted
C:\WINDOWS\Temp\winD9.tmp - Deleted
C:\WINDOWS\Temp\winDA.tmp - Deleted
C:\WINDOWS\Temp\winDB.tmp - Deleted
C:\WINDOWS\Temp\winDC.tmp - Deleted
C:\WINDOWS\Temp\winDD.tmp - Deleted
C:\WINDOWS\Temp\winDE.tmp - Deleted
C:\WINDOWS\Temp\winDF.tmp - Deleted
C:\WINDOWS\Temp\winE.tmp - Deleted
C:\WINDOWS\Temp\winE0.tmp - Deleted
C:\WINDOWS\Temp\winE1.tmp - Deleted
C:\WINDOWS\Temp\winE2.tmp - Deleted
C:\WINDOWS\Temp\winE3.tmp - Deleted
C:\WINDOWS\Temp\winE4.tmp - Deleted
C:\WINDOWS\Temp\winE5.tmp - Deleted
C:\WINDOWS\Temp\winE6.tmp - Deleted
C:\WINDOWS\Temp\winE7.tmp - Deleted
C:\WINDOWS\Temp\winE8.tmp - Deleted
C:\WINDOWS\Temp\winE9.tmp - Deleted
C:\WINDOWS\Temp\winEA.tmp - Deleted
C:\WINDOWS\Temp\winEB.tmp - Deleted
C:\WINDOWS\Temp\winEC.tmp - Deleted
C:\WINDOWS\Temp\winED.tmp - Deleted
C:\WINDOWS\Temp\winEE.tmp - Deleted
C:\WINDOWS\Temp\winEF.tmp - Deleted
C:\WINDOWS\Temp\winF.tmp - Deleted
C:\WINDOWS\Temp\winF0.tmp - Deleted
C:\WINDOWS\Temp\winF1.tmp - Deleted
C:\WINDOWS\Temp\winF2.tmp - Deleted
C:\WINDOWS\Temp\winF3.tmp - Deleted
C:\WINDOWS\Temp\winF4.tmp - Deleted
C:\WINDOWS\Temp\winF5.tmp - Deleted
C:\WINDOWS\Temp\winF6.tmp - Deleted
C:\WINDOWS\Temp\winF7.tmp - Deleted
C:\WINDOWS\Temp\winF8.tmp - Deleted
C:\WINDOWS\Temp\winF9.tmp - Deleted
C:\WINDOWS\Temp\winFA.tmp - Deleted
C:\WINDOWS\Temp\winFB.tmp - Deleted
C:\WINDOWS\Temp\winFC.tmp - Deleted
C:\WINDOWS\Temp\winFD.tmp - Deleted
C:\WINDOWS\Temp\winFE.tmp - Deleted
C:\WINDOWS\Temp\winFF.tmp - Deleted



Alternate Streams Check:

C:\WINDOWS\system32
No streams found.

Final Check:

Remaining Services:
------------------


Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Kazaa Lite K++\\KazaaLite.kpp"="C:\\Program Files\\Kazaa Lite K++\\KazaaLite.kpp:*:Enabled:KazaaLite"
"C:\\Valve\\Steam\\SteamApps\\m0rpheus974\\counter-strike source\\hl2.exe"="C:\\Valve\\Steam\\SteamApps\\m0rpheus974\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\Valve\\Steam\\SteamApps\\m0rpheus974\\half-life 2 deathmatch\\hl2.exe"="C:\\Valve\\Steam\\SteamApps\\m0rpheus974\\half-life 2 deathmatch\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\LTCDA Pro\\ltcda.exe"="C:\\Program Files\\LTCDA Pro\\ltcda.exe:*:Enabled:Compteur pour Cyber-cafés"
"C:\\Program Files\\Rockstar Games\\GTA Vice City\\Myk\\Plus\\Downalds\\WoW-1.9.4-frFR-Installer-downloader.exe"="C:\\Program Files\\Rockstar Games\\GTA Vice City\\Myk\\Plus\\Downalds\\WoW-1.9.4-frFR-Installer-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Controle Parental\\bin\\optproxy.exe"="C:\\Program Files\\Controle Parental\\bin\\optproxy.exe:*:Enabled:Contrôle Parental"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Giganology\\Gigaget\\Gigaget.exe"="C:\\Program Files\\Giganology\\Gigaget\\Gigaget.exe:*:Enabled:Gigaget"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:µTorrent"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"


Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip


Checking For Files with Hidden Attributes :

C:\NTDETECT.COM
C:\Documents and Settings\Myk\Local Settings\Application Data\Microsoft\Messenger\m0rpheus974@hotmail.fr\Sharing Folders\aurore-boreale@hotmail.com\Thumbs.db
C:\Documents and Settings\Propri‚taire\Local Settings\Application Data\Microsoft\Messenger\myk_the_killer974@hotmail.fr\Sharing Folders\babylovedu974@hotmail.com\Thumbs.db
C:\WINDOWS\system32\awtssst.dll
C:\WINDOWS\system32\ddccy.dll
C:\WINDOWS\system32\wxmmin.dll
C:\Program Files\RamBoost XP\StopRam.exe
C:\WINDOWS\system32\cdplayer.exe.manifest
C:\WINDOWS\system32\logonui.exe.manifest
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\WINDOWS\system32\KGyGaAvL.sys
C:\Documents and Settings\Myk\Local Settings\Temp\~17.tmp
C:\Documents and Settings\Myk\Local Settings\Temp\~19.tmp
C:\Documents and Settings\Myk\Local Settings\Temp\~B.tmp
C:\Documents and Settings\Myk\Local Settings\Temp\~C.tmp
C:\Documents and Settings\Propri‚taire\Application Data\Microsoft\Word\~WRL0004.tmp
C:\Documents and Settings\Propri‚taire\Local Settings\Temp\~19.tmp
C:\Documents and Settings\Propri‚taire\Local Settings\Temp\~28.tmp
C:\Documents and Settings\Propri‚taire\Local Settings\Temp\~5.tmp
C:\Documents and Settings\Propri‚taire\Local Settings\Temp\~6.tmp
C:\Documents and Settings\Propri‚taire\Local Settings\Temp\~7.tmp
C:\Documents and Settings\Propri‚taire\Local Settings\Temp\~8.tmp
C:\Documents and Settings\Propri‚taire\Local Settings\Temp\~B.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\f8da354fef804e89ae2e375e9026fb3b\BIT9.tmp
C:\WINDOWS\system32\bbeeg.tmp
C:\WINDOWS\system32\yccdd.tmp

Finished
25 Janvier 2007 16:45:49

... Voila mon rapport VundoFix :
(mais je crois quil manque une suite)


VundoFix V6.3.2

Checking Java version...

Sun Java not detected
Scan started at 19:30:49 25/01/2007

Listing files found while scanning....

C:\WINDOWS\system32\awtssst.dll
C:\WINDOWS\system32\bbeeg.bak1
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\bbeeg.tmp
C:\WINDOWS\system32\ddccy.dll
C:\WINDOWS\system32\geebb.dll
C:\WINDOWS\system32\yccdd.bak1
C:\WINDOWS\system32\yccdd.bak2
C:\WINDOWS\system32\yccdd.ini
C:\WINDOWS\system32\yccdd.ini2
C:\WINDOWS\system32\yccdd.tmp

Beginning removal...

Attempting to delete C:\WINDOWS\system32\awtssst.dll
C:\WINDOWS\system32\awtssst.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bbeeg.bak1
C:\WINDOWS\system32\bbeeg.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\bbeeg.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\bbeeg.tmp
C:\WINDOWS\system32\bbeeg.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddccy.dll
C:\WINDOWS\system32\ddccy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yccdd.bak1
C:\WINDOWS\system32\yccdd.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\yccdd.bak2
C:\WINDOWS\system32\yccdd.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\yccdd.ini
C:\WINDOWS\system32\yccdd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\yccdd.ini2
C:\WINDOWS\system32\yccdd.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\yccdd.tmp
C:\WINDOWS\system32\yccdd.tmp Has been deleted!

Performing Repairs to the registry.
Done!
Contenus similaires
25 Janvier 2007 16:46:51

Et voila mon rapport ComboFix :
(pour la suite je ne sais pas quoi faire ...)


"Myk" - 07-01-25 19:49:20 Service Pack 2
ComboFix 07-01-25 - Running from: "C:\Program Files\Rockstar Games\GTA Vice City\Myk\Plus\Downalds"

((((((((((((((((((((((((((((((( Files Created from 2006-12-25 to 2007-01-25 ))))))))))))))))))))))))))))))))))


2007-01-25 19:30 <REP> d-------- C:\VundoFix Backups
2007-01-25 18:51 <REP> dr------- C:\DOCUME~1\ADMINI~1\Menu D‚marrer
2007-01-25 18:51 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisinage r‚seau
2007-01-25 18:51 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisinage d'impression
2007-01-25 18:51 <REP> d--h----- C:\DOCUME~1\ADMINI~1\ModŠles
2007-01-25 18:51 <REP> d-------- C:\DOCUME~1\ADMINI~1\Mes documents
2007-01-25 18:51 <REP> d-------- C:\DOCUME~1\ADMINI~1\Favoris
2007-01-25 18:51 <REP> d-------- C:\DOCUME~1\ADMINI~1\Bureau
2007-01-25 18:42 <REP> d-------- C:\SDFix
2007-01-25 18:02 <REP> d-------- C:\Program Files\uTorrent
2007-01-25 18:02 <REP> d-------- C:\DOCUME~1\Myk\Application Data\uTorrent
2007-01-24 22:39 <REP> d---s---- C:\Program Files\Xfire
2007-01-24 22:39 <REP> d-------- C:\DOCUME~1\Myk\Application Data\Xfire
2007-01-22 11:33 197,120 --a------ C:\WINDOWS\patchw32.dll
2007-01-22 11:33 <REP> d-------- C:\Program Files\Fichiers communs\PocketSoft
2007-01-21 12:13 <REP> d-------- C:\WINDOWS\system32\ActiveScan
2007-01-21 12:09 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-01-20 19:00 <REP> d-------- C:\Program Files\GameShadow
2007-01-20 18:47 <REP> d-------- C:\Program Files\Eidos
2007-01-20 15:21 37,376 --a------ C:\WINDOWS\system32\udial.exe
2007-01-11 19:26 <REP> d-------- C:\Program Files\GStudio6
2007-01-11 18:56 <REP> d-------- C:\Program Files\Microsoft.NET
2007-01-11 18:56 <REP> d-------- C:\Program Files\Microsoft Visual Studio 8
2007-01-11 18:56 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Microsoft Help
2007-01-11 18:43 <REP> d-------- C:\WINDOWS\Downloaded Installations
2007-01-11 18:16 <REP> d-------- C:\Program Files\Compil Games
2007-01-09 13:35 <REP> d-------- C:\DOCUME~1\LOCALS~1\Application Data\MEGAUPLOADTOOLBAR
2007-01-07 19:30 <REP> d-------- C:\DOCUME~1\Myk\Application Data\dvdcss
2007-01-05 20:41 <REP> d-------- C:\Program Files\Copie de VirtualDJ
2007-01-05 20:35 <REP> d-------- C:\DOCUME~1\PROPRI~1\Application Data\MegauploadToolbar
2007-01-05 15:11 <REP> d-------- C:\Program Files\Controle Parental
2007-01-05 15:07 126,976 --a------ C:\WINDOWS\system32\coclassfast.dll
2007-01-05 15:07 <REP> d-------- C:\Program Files\SAGEM
2007-01-04 12:52 121,856 --------- C:\WINDOWS\system32\xmllite.dll
2007-01-04 12:51 <REP> d-------- C:\WINDOWS\network diagnostic
2006-12-31 23:05 9 --ah----- C:\WINDOWS\system32\wxmmin.dll
2006-12-31 23:04 <REP> d-------- C:\Program Files\VirtualDJ
2006-12-31 20:05 <REP> d-------- C:\Program Files\DJ Mix Pro
2006-12-27 12:53 <REP> d-------- C:\Ubisoft
2006-12-25 11:29 <REP> d-------- C:\Program Files\Ubisoft


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-25 18:36 9879 --ahs---- C:\WINDOWS\system32\kgygaavl.sys
2007-01-25 18:02 -------- d-------- C:\Program Files\Fichiers communs\symantec shared
2007-01-25 12:02 -------- d--h----- C:\Program Files\installshield installation information
2007-01-24 22:35 -------- d-------- C:\Program Files\gamespy arcade
2007-01-24 22:17 -------- d-------- C:\Program Files\wanadoo
2007-01-22 18:31 -------- d-------- C:\Program Files\pimpfish
2007-01-22 11:27 -------- d-------- C:\Program Files\atari
2007-01-21 13:31 -------- d-------- C:\Program Files\symantec
2007-01-21 13:00 -------- d-------- C:\Program Files\messenger
2007-01-21 12:53 -------- d-------- C:\Program Files\google
2007-01-21 12:20 -------- d-------- C:\DOCUME~1\Myk\Application Data\symantec
2007-01-20 19:00 98304 --a------ C:\WINDOWS\system32\cmdlineext.dll
2007-01-18 22:04 -------- d-------- C:\Program Files\ramboost xp
2007-01-17 16:02 -------- d-------- C:\DOCUME~1\Myk\Application Data\hamachi
2007-01-11 19:42 -------- d-------- C:\Program Files\ea sports
2007-01-11 19:08 -------- d---s---- C:\DOCUME~1\Myk\Application Data\microsoft
2007-01-09 20:16 -------- d-------- C:\Program Files\warcraft iii
2007-01-09 12:23 -------- d-------- C:\Program Files\quicktime
2007-01-07 18:36 -------- d-------- C:\Program Files\wc3banlist
2007-01-05 15:01 -------- d-------- C:\Program Files\controle parental 2 not use
2006-12-25 13:13 -------- d-------- C:\Program Files\ea games
2006-12-24 13:45 -------- d-------- C:\Program Files\winpcap
2006-12-15 07:57 -------- d-------- C:\Program Files\daemon tools
2006-12-15 07:53 639224 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2006-12-14 19:15 2829 --a------ C:\WINDOWS\war3unin.pif
2006-12-14 19:15 139264 --a------ C:\WINDOWS\war3unin.exe
2006-12-13 19:50 -------- d-------- C:\Program Files\newdotnet
2006-12-08 15:08 -------- d-------- C:\Program Files\messenger plus! live
2006-11-08 08:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-11-02 19:16 48824 --a------ C:\WINDOWS\system32\s32evnt1.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"nForce Tray Options"="sstray.exe /r"
"snpstd"="C:\\WINDOWS\\vsnpstd.exe"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvMcTray.dll,NvTaskbarInit"
"EoEngine"=""
"EoSudoku"=""
"ccApp"="\"C:\\Program Files\\Fichiers communs\\Symantec Shared\\ccApp.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Bluetooth Manager.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\Bluetooth Manager.lnk"
"backup"="C:\\WINDOWS\\pss\\Bluetooth Manager.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Toshiba\\BLUETO~1\\TOSBTM~1.EXE "
"item"="Bluetooth Manager"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^hp psc 1000 series.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\hp psc 1000 series.lnk"
"backup"="C:\\WINDOWS\\pss\\hp psc 1000 series.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HEWLET~1\\DIGITA~1\\bin\\hpohmr08.exe "
"item"="hp psc 1000 series"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^hpoddt01.exe.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\hpoddt01.exe.lnk"
"backup"="C:\\WINDOWS\\pss\\hpoddt01.exe.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HEWLET~1\\DIGITA~1\\bin\\hpotdd01.exe "
"item"="hpoddt01.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\InterVideo WinCinema Manager.lnk"
"backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\INTERV~1\\Common\\Bin\\WINCIN~1.EXE "
"item"="InterVideo WinCinema Manager"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Picture Package Menu.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\Picture Package Menu.lnk"
"backup"="C:\\WINDOWS\\pss\\Picture Package Menu.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\SONYCO~1\\PICTUR~1\\PICTUR~3\\SonyTray.exe "
"item"="Picture Package Menu"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Picture Package VCD Maker.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\Picture Package VCD Maker.lnk"
"backup"="C:\\WINDOWS\\pss\\Picture Package VCD Maker.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\SONYCO~1\\PICTUR~1\\PICTUR~1\\RESIDE~1.EXE -h"
"item"="Picture Package VCD Maker"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Myk^Menu Démarrer^Programmes^Démarrage^Registration Prince of Persia T2T.LNK]
"path"="C:\\Documents and Settings\\Myk\\Menu Démarrer\\Programmes\\Démarrage\\Registration Prince of Persia T2T.LNK"
"backup"="C:\\WINDOWS\\pss\\Registration Prince of Persia T2T.LNKStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\Ubisoft\\PRINCE~1\\Support\\Register\\REGIST~1.EXE -d 802968 -l french -r 7 -g Prince of Persia T2T -c fr -i 2430"
"item"="Registration Prince of Persia T2T"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTCDA_Pro]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ltcda"
"hkey"="HKLM"
"command"="C:\\Program Files\\LTCDA Pro\\ltcda.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RssReader]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RssReader"
"hkey"="HKCU"
"command"="C:\\Program Files\\RssReader\\RssReader.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Steam"
"hkey"="HKCU"
"command"="\"C:\\Valve\\Steam\\Steam.exe\" -silent"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webHancer Survey Companion]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="whSurvey"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\webHancer\\Programs\\whSurvey.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOKIT]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Shell"
"hkey"="HKCU"
"command"="C:\\PROGRA~1\\Wanadoo\\Shell.exe appLaunchClientZone.shl|PARAM= cnx"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Watch"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Wanadoo\\Watch.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{B7BC5CCE-E6CE-43DB-B3E3-DA47DDDD4A5E}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geebb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winjgf32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1100 series#1087935391.job
C:\WINDOWS\tasks\Norton AntiVirus - Effectuer une analyse complŠte du systŠme - Myk.job
C:\WINDOWS\tasks\Norton AntiVirus - Effectuer une analyse complŠte du systŠme - Propri‚taire.job

Completion time: 07-01-25 19:55:50
25 Janvier 2007 16:54:17

Ah si !!! Je sais quoi faire !!! Un petit rapport Hijackthis !!!



Logfile of HijackThis v1.99.1
Scan saved at 20:08:09, on 25/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Myk\Bureau\Bureau\hijackthis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
O2 - BHO: PimpFish Toolbar Opcode Handler - {29C88E20-4234-41B9-A9DB-982958C95FB1} - C:\Program Files\PimpFish\PimpFish.dll
O2 - BHO: (no name) - {317BFEF3-B0B4-435B-91B8-AE9E4361B89A} - C:\WINDOWS\system32\geebb.dll (file missing)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: FloatBar Class - {75B1A646-CDCE-4C06-B52F-84F4463B4FC8} - C:\Program Files\PimpFish\FloatBar.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {B7BC5CCE-E6CE-43DB-B3E3-DA47DDDD4A5E} - C:\WINDOWS\system32\awtssst.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: (no name) - {FC80FBC8-6B25-4278-B54D-910407409B5A} - C:\WINDOWS\system32\ddccy.dll (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: PimpFish - {D593DE91-7B41-45C2-830E-E9A99AB142AA} - C:\Program Files\PimpFish\PimpFish.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
O8 - Extra context menu item: PimpFish - Saisir cette image - C:\Program Files\PimpFish\GRABPIC.HTM
O8 - Extra context menu item: PimpFish - Saisir le fichier cible - C:\Program Files\PimpFish\GRABLINK.HTM
O8 - Extra context menu item: PimpFish - Saisir les images auxquelles cette page est reliée - C:\Program Files\PimpFish\GRABPAGELINKS.HTM
O8 - Extra context menu item: PimpFish - Saisir les images sur cette page - C:\Program Files\PimpFish\GRABPAGEPICS.HTM
O8 - Extra context menu item: PimpFish - Saisir les vidéos sur cette page - C:\Program Files\PimpFish\GRABPAGEMOVIES.HTM
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet3_88.dll' missing
O16 - DPF: Interface Chat Wanadoo - http://chat10.x-echo.com/version8/Applet/wchatsign.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavweb...
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: geebb - C:\WINDOWS\system32\geebb.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winjgf32 - winjgf32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\System32\UAService7.exe

25 Janvier 2007 17:20:23

lol allez silvou plaieuh
25 Janvier 2007 17:43:40

Angeldark plz je t'attend !!!
a b 8 Sécurité
25 Janvier 2007 17:46:46

Bonjour,

On se calme !
Qui t'a demandé d'utiliser ces utilitaires ?

Repose un rapport Hijackthis.
25 Janvier 2007 17:48:29

ok le voila !!!




Logfile of HijackThis v1.99.1
Scan saved at 21:02:53, on 25/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Myk\Bureau\Bureau\hijackthis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
O2 - BHO: PimpFish Toolbar Opcode Handler - {29C88E20-4234-41B9-A9DB-982958C95FB1} - C:\Program Files\PimpFish\PimpFish.dll
O2 - BHO: (no name) - {317BFEF3-B0B4-435B-91B8-AE9E4361B89A} - C:\WINDOWS\system32\geebb.dll (file missing)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: FloatBar Class - {75B1A646-CDCE-4C06-B52F-84F4463B4FC8} - C:\Program Files\PimpFish\FloatBar.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {B7BC5CCE-E6CE-43DB-B3E3-DA47DDDD4A5E} - C:\WINDOWS\system32\awtssst.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: (no name) - {FC80FBC8-6B25-4278-B54D-910407409B5A} - C:\WINDOWS\system32\ddccy.dll (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: PimpFish - {D593DE91-7B41-45C2-830E-E9A99AB142AA} - C:\Program Files\PimpFish\PimpFish.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
O8 - Extra context menu item: PimpFish - Saisir cette image - C:\Program Files\PimpFish\GRABPIC.HTM
O8 - Extra context menu item: PimpFish - Saisir le fichier cible - C:\Program Files\PimpFish\GRABLINK.HTM
O8 - Extra context menu item: PimpFish - Saisir les images auxquelles cette page est reliée - C:\Program Files\PimpFish\GRABPAGELINKS.HTM
O8 - Extra context menu item: PimpFish - Saisir les images sur cette page - C:\Program Files\PimpFish\GRABPAGEPICS.HTM
O8 - Extra context menu item: PimpFish - Saisir les vidéos sur cette page - C:\Program Files\PimpFish\GRABPAGEMOVIES.HTM
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet3_88.dll' missing
O16 - DPF: Interface Chat Wanadoo - http://chat10.x-echo.com/version8/Applet/wchatsign.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavweb...
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: geebb - C:\WINDOWS\system32\geebb.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winjgf32 - winjgf32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\System32\UAService7.exe


25 Janvier 2007 17:53:56

Tu est infecté par ErrorSafe ? Tu as du sûrement installé ce FAUX logiciel de sécurité , si c'est le cas , Spybot-Search & Destroy le supprime facilement : http://www.clubic.com/telecharger-fiche10965-spybot-sea... !
Va dans l'onglet mises à jours , télécharge toutes les mises à jours dispo , va ensuite dans l'onglet Vaccination et vaccine tout tes fichiers , va ensuite dans l'onglet Search & Destroy et fait l'analyse patiente et supprime tout ce qu'il trouve ... Voila @+ !
25 Janvier 2007 17:55:03

Au fait . Je voudrais savoir comment tu fais pour reconnaitre quels virus sont dans ma machine juste en lookant un rapport hijack ???
25 Janvier 2007 17:58:44

C'est impossible pour un débutant il faut des connaissances des virus qui existent , des façons de les supprimer , des faux logiciel ainsi que l'emplacement , le VRAI nom d'un fichier caché etc ... (moi je ne sais pas décrypter un rapport HijackThis mais les rapport AVG et SmitFraudFix si ... Mais fait ce que je t'ai dit ca devrait surement marcher !!!
25 Janvier 2007 18:01:41

ok c'est ce ke je fai ^_^ ! en tout cas merci pour tous et ... RESPECT MAN !!!
a b 8 Sécurité
25 Janvier 2007 18:04:08

Poste moi ton rapport Combofix stp.
25 Janvier 2007 18:11:24

ahhh ateen !! combofix ??? ok mais je viens de lancer spybot destroy ...
25 Janvier 2007 18:12:07

c'est le meme que tout a l'heure



"Myk" - 07-01-25 19:49:20 Service Pack 2
ComboFix 07-01-25 - Running from: "C:\Program Files\Rockstar Games\GTA Vice City\Myk\Plus\Downalds"

((((((((((((((((((((((((((((((( Files Created from 2006-12-25 to 2007-01-25 ))))))))))))))))))))))))))))))))))


2007-01-25 19:30 <REP> d-------- C:\VundoFix Backups
2007-01-25 18:51 <REP> dr------- C:\DOCUME~1\ADMINI~1\Menu D‚marrer
2007-01-25 18:51 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisinage r‚seau
2007-01-25 18:51 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisinage d'impression
2007-01-25 18:51 <REP> d--h----- C:\DOCUME~1\ADMINI~1\ModŠles
2007-01-25 18:51 <REP> d-------- C:\DOCUME~1\ADMINI~1\Mes documents
2007-01-25 18:51 <REP> d-------- C:\DOCUME~1\ADMINI~1\Favoris
2007-01-25 18:51 <REP> d-------- C:\DOCUME~1\ADMINI~1\Bureau
2007-01-25 18:42 <REP> d-------- C:\SDFix
2007-01-25 18:02 <REP> d-------- C:\Program Files\uTorrent
2007-01-25 18:02 <REP> d-------- C:\DOCUME~1\Myk\Application Data\uTorrent
2007-01-24 22:39 <REP> d---s---- C:\Program Files\Xfire
2007-01-24 22:39 <REP> d-------- C:\DOCUME~1\Myk\Application Data\Xfire
2007-01-22 11:33 197,120 --a------ C:\WINDOWS\patchw32.dll
2007-01-22 11:33 <REP> d-------- C:\Program Files\Fichiers communs\PocketSoft
2007-01-21 12:13 <REP> d-------- C:\WINDOWS\system32\ActiveScan
2007-01-21 12:09 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-01-20 19:00 <REP> d-------- C:\Program Files\GameShadow
2007-01-20 18:47 <REP> d-------- C:\Program Files\Eidos
2007-01-20 15:21 37,376 --a------ C:\WINDOWS\system32\udial.exe
2007-01-11 19:26 <REP> d-------- C:\Program Files\GStudio6
2007-01-11 18:56 <REP> d-------- C:\Program Files\Microsoft.NET
2007-01-11 18:56 <REP> d-------- C:\Program Files\Microsoft Visual Studio 8
2007-01-11 18:56 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Microsoft Help
2007-01-11 18:43 <REP> d-------- C:\WINDOWS\Downloaded Installations
2007-01-11 18:16 <REP> d-------- C:\Program Files\Compil Games
2007-01-09 13:35 <REP> d-------- C:\DOCUME~1\LOCALS~1\Application Data\MEGAUPLOADTOOLBAR
2007-01-07 19:30 <REP> d-------- C:\DOCUME~1\Myk\Application Data\dvdcss
2007-01-05 20:41 <REP> d-------- C:\Program Files\Copie de VirtualDJ
2007-01-05 20:35 <REP> d-------- C:\DOCUME~1\PROPRI~1\Application Data\MegauploadToolbar
2007-01-05 15:11 <REP> d-------- C:\Program Files\Controle Parental
2007-01-05 15:07 126,976 --a------ C:\WINDOWS\system32\coclassfast.dll
2007-01-05 15:07 <REP> d-------- C:\Program Files\SAGEM
2007-01-04 12:52 121,856 --------- C:\WINDOWS\system32\xmllite.dll
2007-01-04 12:51 <REP> d-------- C:\WINDOWS\network diagnostic
2006-12-31 23:05 9 --ah----- C:\WINDOWS\system32\wxmmin.dll
2006-12-31 23:04 <REP> d-------- C:\Program Files\VirtualDJ
2006-12-31 20:05 <REP> d-------- C:\Program Files\DJ Mix Pro
2006-12-27 12:53 <REP> d-------- C:\Ubisoft
2006-12-25 11:29 <REP> d-------- C:\Program Files\Ubisoft


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-25 18:36 9879 --ahs---- C:\WINDOWS\system32\kgygaavl.sys
2007-01-25 18:02 -------- d-------- C:\Program Files\Fichiers communs\symantec shared
2007-01-25 12:02 -------- d--h----- C:\Program Files\installshield installation information
2007-01-24 22:35 -------- d-------- C:\Program Files\gamespy arcade
2007-01-24 22:17 -------- d-------- C:\Program Files\wanadoo
2007-01-22 18:31 -------- d-------- C:\Program Files\pimpfish
2007-01-22 11:27 -------- d-------- C:\Program Files\atari
2007-01-21 13:31 -------- d-------- C:\Program Files\symantec
2007-01-21 13:00 -------- d-------- C:\Program Files\messenger
2007-01-21 12:53 -------- d-------- C:\Program Files\google
2007-01-21 12:20 -------- d-------- C:\DOCUME~1\Myk\Application Data\symantec
2007-01-20 19:00 98304 --a------ C:\WINDOWS\system32\cmdlineext.dll
2007-01-18 22:04 -------- d-------- C:\Program Files\ramboost xp
2007-01-17 16:02 -------- d-------- C:\DOCUME~1\Myk\Application Data\hamachi
2007-01-11 19:42 -------- d-------- C:\Program Files\ea sports
2007-01-11 19:08 -------- d---s---- C:\DOCUME~1\Myk\Application Data\microsoft
2007-01-09 20:16 -------- d-------- C:\Program Files\warcraft iii
2007-01-09 12:23 -------- d-------- C:\Program Files\quicktime
2007-01-07 18:36 -------- d-------- C:\Program Files\wc3banlist
2007-01-05 15:01 -------- d-------- C:\Program Files\controle parental 2 not use
2006-12-25 13:13 -------- d-------- C:\Program Files\ea games
2006-12-24 13:45 -------- d-------- C:\Program Files\winpcap
2006-12-15 07:57 -------- d-------- C:\Program Files\daemon tools
2006-12-15 07:53 639224 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2006-12-14 19:15 2829 --a------ C:\WINDOWS\war3unin.pif
2006-12-14 19:15 139264 --a------ C:\WINDOWS\war3unin.exe
2006-12-13 19:50 -------- d-------- C:\Program Files\newdotnet
2006-12-08 15:08 -------- d-------- C:\Program Files\messenger plus! live
2006-11-08 08:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-11-02 19:16 48824 --a------ C:\WINDOWS\system32\s32evnt1.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"nForce Tray Options"="sstray.exe /r"
"snpstd"="C:\\WINDOWS\\vsnpstd.exe"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvMcTray.dll,NvTaskbarInit"
"EoEngine"=""
"EoSudoku"=""
"ccApp"="\"C:\\Program Files\\Fichiers communs\\Symantec Shared\\ccApp.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Bluetooth Manager.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\Bluetooth Manager.lnk"
"backup"="C:\\WINDOWS\\pss\\Bluetooth Manager.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Toshiba\\BLUETO~1\\TOSBTM~1.EXE "
"item"="Bluetooth Manager"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^hp psc 1000 series.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\hp psc 1000 series.lnk"
"backup"="C:\\WINDOWS\\pss\\hp psc 1000 series.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HEWLET~1\\DIGITA~1\\bin\\hpohmr08.exe "
"item"="hp psc 1000 series"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^hpoddt01.exe.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\hpoddt01.exe.lnk"
"backup"="C:\\WINDOWS\\pss\\hpoddt01.exe.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HEWLET~1\\DIGITA~1\\bin\\hpotdd01.exe "
"item"="hpoddt01.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\InterVideo WinCinema Manager.lnk"
"backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\INTERV~1\\Common\\Bin\\WINCIN~1.EXE "
"item"="InterVideo WinCinema Manager"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Picture Package Menu.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\Picture Package Menu.lnk"
"backup"="C:\\WINDOWS\\pss\\Picture Package Menu.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\SONYCO~1\\PICTUR~1\\PICTUR~3\\SonyTray.exe "
"item"="Picture Package Menu"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Picture Package VCD Maker.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\Picture Package VCD Maker.lnk"
"backup"="C:\\WINDOWS\\pss\\Picture Package VCD Maker.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\SONYCO~1\\PICTUR~1\\PICTUR~1\\RESIDE~1.EXE -h"
"item"="Picture Package VCD Maker"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Myk^Menu Démarrer^Programmes^Démarrage^Registration Prince of Persia T2T.LNK]
"path"="C:\\Documents and Settings\\Myk\\Menu Démarrer\\Programmes\\Démarrage\\Registration Prince of Persia T2T.LNK"
"backup"="C:\\WINDOWS\\pss\\Registration Prince of Persia T2T.LNKStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\Ubisoft\\PRINCE~1\\Support\\Register\\REGIST~1.EXE -d 802968 -l french -r 7 -g Prince of Persia T2T -c fr -i 2430"
"item"="Registration Prince of Persia T2T"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTCDA_Pro]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ltcda"
"hkey"="HKLM"
"command"="C:\\Program Files\\LTCDA Pro\\ltcda.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RssReader]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RssReader"
"hkey"="HKCU"
"command"="C:\\Program Files\\RssReader\\RssReader.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Steam"
"hkey"="HKCU"
"command"="\"C:\\Valve\\Steam\\Steam.exe\" -silent"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webHancer Survey Companion]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="whSurvey"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\webHancer\\Programs\\whSurvey.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOKIT]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Shell"
"hkey"="HKCU"
"command"="C:\\PROGRA~1\\Wanadoo\\Shell.exe appLaunchClientZone.shl|PARAM= cnx"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Watch"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Wanadoo\\Watch.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{B7BC5CCE-E6CE-43DB-B3E3-DA47DDDD4A5E}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geebb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winjgf32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1100 series#1087935391.job
C:\WINDOWS\tasks\Norton AntiVirus - Effectuer une analyse complŠte du systŠme - Myk.job
C:\WINDOWS\tasks\Norton AntiVirus - Effectuer une analyse complŠte du systŠme - Propri‚taire.job

Completion time: 07-01-25 19:55:50
a b 8 Sécurité
25 Janvier 2007 18:15:49

Re,

Télécharge Clean.zip (de Malekal),
Décompresse-le sur ton bureau (Clique-Droit/Extraire tout), tu dois obtenir un dossier Clean.
Ouvre le dossier clean, double-clique sur clean.cmd.
Choisis l'option 1 puis patiente. Poste ensuite le contenu du rapport.
25 Janvier 2007 18:15:53

Houla !!! 26 élément WildTangent !!! Pourtant il m'avais l'air innocent WildTangent ...
25 Janvier 2007 18:18:25

Tu as fait les manip que je t'ai indiqué avec Spybot ? Si oui supprime tout comme je t'ai dit et si tu as toujours l'alerte pour ErrorSafe suis la procédure de AngelDark c'est un pro ... !
Si tu ne l'a plus je pense que c'est bon (et garde Spybot il te re-servira surement hein Angel ?) !
25 Janvier 2007 18:20:02

Voila c'est lancé ... Je wait ...
25 Janvier 2007 18:20:32

sa y est


Rapport clean par Malekal_morte - http://www.malekal.com
Option 1, executee le 25/01/2007 a 21:34:23,00

*** Recherche de fichiers sur C:

*** Recherche des fichiers dans C:\WINDOWS\

*** Recherche des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system32\ide21201.vxd FOUND
C:\WINDOWS\system32\msiuins.exe FOUND
C:\WINDOWS\system32\SpoonUninstall.exe FOUND
C:\WINDOWS\system32\udial.exe FOUND

*** Fin du rapport !
a b 8 Sécurité
25 Janvier 2007 18:21:38

Re,

Redémarre en mode sans échec

Ouvre le dossier clean, double-clique sur clean.cmd.
Choisis l'option 2 puis patiente.

Redémarre normalement

- Le rapport clean : Poste de travail / double clic sur disque C / double-clic sur rapport_clean.txt et copier/coller le contenu ici C:\rapport_clean.txt
25 Janvier 2007 18:22:35

Merci a toi testeur01^^
25 Janvier 2007 18:24:14

Derien , mais ca n'a pas marché avec Spybot tu as toujours l'alerte et t'a supprimé quoi avec spybot ?
25 Janvier 2007 18:48:21

voila le rapport (dsl si sa a pris du temps)


Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Option 2, executee le 25/01/2007 a 21:42:24,62

Microsoft Windows XP [version 5.1.2600]

*** Suppression de fichiers sur C:

*** Suppression des fichiers dans C:\WINDOWS\

*** Suppression des fichiers dans C:\WINDOWS\system32
tentative de suppression de C:\WINDOWS\system32\ide21201.vxd
tentative de suppression de C:\WINDOWS\system32\msiuins.exe
tentative de suppression de C:\WINDOWS\system32\SpoonUninstall.exe
tentative de suppression de C:\WINDOWS\system32\udial.exe


*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
25 Janvier 2007 19:05:44

Euh Darkangel ? Désolé pour l'écriture en texto ! Mais je pensais que ce mode d'expressionétais plus éfficace mais je préfère quand même le mode d'écriture normal (ajouté a de petits smileys ^_^)

Et je suis totalement d'accord avec toi sur le fait que c'est une abération aux bénévoles (j'aurais ajouté super sympas , vraiment redevable , super utiles a la sociétée , QUI DEVRAIENT ETRE PAYES !!! ect ect ...) ^_^
a b 8 Sécurité
26 Janvier 2007 18:31:42

Citation :
Pas d'impatience :Les gens sont bénévoles et prennent sur leur temps libre pour répondre. Si vous voulez un service rapide, payez-vous un professionnel !

:sarcastic: 

Reposte un rapport Hijackthis.
28 Janvier 2007 12:08:49

ok !

Logfile of HijackThis v1.99.1
Scan saved at 15:23:16, on 28/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SoftwareDistribution\Download\Install\IE7-WindowsXP-x86-fra.exe
c:\262c83c8903b4d14c12520a8280372\update\iesetup.exe
C:\WINDOWS\system32\mrt.exe
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Documents and Settings\Myk\Bureau\Bureau\hijackthis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
O2 - BHO: PimpFish Toolbar Opcode Handler - {29C88E20-4234-41B9-A9DB-982958C95FB1} - C:\Program Files\PimpFish\PimpFish.dll
O2 - BHO: (no name) - {317BFEF3-B0B4-435B-91B8-AE9E4361B89A} - C:\WINDOWS\system32\geebb.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: FloatBar Class - {75B1A646-CDCE-4C06-B52F-84F4463B4FC8} - C:\Program Files\PimpFish\FloatBar.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {B7BC5CCE-E6CE-43DB-B3E3-DA47DDDD4A5E} - C:\WINDOWS\system32\awtssst.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: (no name) - {FC80FBC8-6B25-4278-B54D-910407409B5A} - C:\WINDOWS\system32\ddccy.dll (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: PimpFish - {D593DE91-7B41-45C2-830E-E9A99AB142AA} - C:\Program Files\PimpFish\PimpFish.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
O8 - Extra context menu item: PimpFish - Saisir cette image - C:\Program Files\PimpFish\GRABPIC.HTM
O8 - Extra context menu item: PimpFish - Saisir le fichier cible - C:\Program Files\PimpFish\GRABLINK.HTM
O8 - Extra context menu item: PimpFish - Saisir les images auxquelles cette page est reliée - C:\Program Files\PimpFish\GRABPAGELINKS.HTM
O8 - Extra context menu item: PimpFish - Saisir les images sur cette page - C:\Program Files\PimpFish\GRABPAGEPICS.HTM
O8 - Extra context menu item: PimpFish - Saisir les vidéos sur cette page - C:\Program Files\PimpFish\GRABPAGEMOVIES.HTM
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O10 - Broken Internet access because of LSP provider 'xfire_lsp_9028.dll' missing
O16 - DPF: Interface Chat Wanadoo - http://chat10.x-echo.com/version8/Applet/wchatsign.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavweb...
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: geebb - C:\WINDOWS\system32\geebb.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winjgf32 - winjgf32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\System32\UAService7.exe

a b 8 Sécurité
28 Janvier 2007 22:46:43

Re,

  • Fais un scan en ligne Kaspersky avec Internet Explorer :
  • Clique sur
  • Clique maintenant sur J'accepte.
  • Valide l'installation d'un ou de plusieurs ActiveX si c'est nécessaire.
  • Patiente pendant l'installation des Mises à jour.
  • Choisis par la suite l'analyse du Poste de travail
  • Sauvegarde puis colle le rapport généré en fin d'analyse.

    AIDE : Configurer le contrôle des ActiveX

    NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte toi sur le site de Kaspersky pour retenter le scan en ligne.
    31 Janvier 2007 15:48:09

    Euh ?? tu a vu le temps que sa prend ??? 15 Minutes pour 1 % ...
    a b 8 Sécurité
    31 Janvier 2007 16:14:26

    Cela va s'accélérer.
    31 Janvier 2007 16:18:41

    KASPERSKY ON-LINE SCANNER REPORT
    Wednesday, January 31, 2007 7:30:17 PM
    Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky On-line Scanner version : 5.0.83.0
    Dernière mise à jour de la base antivirus Kaspersky : 31/01/2007
    Enregistrements dans la base antivirus Kaspersky : 248961


    Paramètres d'analyse
    Analyser avec la base antivirus suivante standard
    Analyser les archives vrai
    Analyser les bases de messagerie vrai

    Cible de l'analyse Poste de travail
    A:\
    C:\
    D:\
    E:\

    Statistiques de l'analyse
    Total d'objets analysés 39312
    Nombre de virus trouvés 14
    Nombre d'objets infectés 26 / 0
    Nombre d'objets suspects 1
    Durée de l'analyse 00:28:59

    Nom de l'objet infecté Nom du virus Dernière action
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\b9ba5289a232191811f12df87b532d6c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0016b311f08d56d052439dd47d44e924_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\010707c18cef78b494ed2b2c6e68534d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\019c489f9f67ec29c4528d59797faf0c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\022c52f45c74607336aba484da49919d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0239ed4f98e0b883829873188c36d63a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\02af33bcf5b9f44f49f1ce2e6867dfaf_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\02f116b6d869065cfdbcb0fc6411a600_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0312fbdbad8216e3dedd3dd35629aa69_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\032338d4972e540ccacfa567faf72d3f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\048eee5e466422f36aa62bec15dc8d12_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\051ba51aad07dd405766ca3790df992d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0546082f39847b53b92ca8c9c6eed57a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\07d71c283385d388356392d9eac67d5b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\08614a8a2ba90ab54f19a0f8610801eb_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\087492d80c0531e63e720555f5abb747_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\08c4be365fe3b90b146ebc584fe7c44f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\096cba0019961b817928a3309231de90_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b1988e0469f7e501268f7ae1911b6a8_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0c13e6710d3aeaf5f728735d04f65edc_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0ce44dc6812f772f89ecff1d9a07a43d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f6ae31369e110c5a4f4d5dae7ec1d83_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1005fbfa1dc4b11c5f511a495d8633fe_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1017d4a74adfacf0d37dce3e4c4aaecf_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\11a289d7c22cea1af5b48cdb3ed1e73f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\13667d6fa4324881985a4f6bdb3fe984_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1687e8cc1cf1db03abba64ccb9238fdf_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\17aea3583e10f6e529521994f9c3b22a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1831f1d1e5a459ab26d43e4acc906a12_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\19623fba0447f755a53265ee61fd452a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\19a9c8edecc5e11bd8d9776bbb518060_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\19f55fec9e4de637cb25553fc495768f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1a7b6e962fb445d09b22dc8befc890dd_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1da0725bf2e1471bcdc116754fd72321_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1e540d833ec3d87e37273ced8d90084d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1e8ba60257c3f1504b4c4d4806356907_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1ec2cbb7eb1ddff356f21c3d05d41a06_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f3145c3bdddb49f2a6290ffc8cc884a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f527eaf25c538adb2642582830b4580_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f736cdf9dc0fd1e21b3e5a5556bc9b4_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f8c0db0d57a22527c194bb65ec4497e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\202e6e0b8c89a7e56e517dc4b9cc1898_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\206ecc59077d1d07850ee35e95b62238_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20bd76b0a5e970fc7b18440a2cce60f4_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2150f39b4f6a62128f60f4f3e2589560_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\215482a664727563be5daf86fff21417_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\21c93e9268bb54dd1b393eb79c970b0d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\23fd4e061a9d521bc24613da57710981_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\24b8d6949b2a265206d7e40aac482589_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\24e780546321e96925bf6a2d8d7169ea_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\25b3ced9aa2d374152e24e8f038c70b8_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\27da6a3c303468f315c34d5dc5a076c2_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\28ba57aedec1281d90819308c65fab75_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2956b590c9e091f44406b4e019498783_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\29e78621bd4ddf17e17db2b116acbf42_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\29ede7b40133066e3dfb4c11cd26aee1_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a156cb54e638b0dff68aa38311feb27_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c5350071a9be16335b91a26b9907350_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e45db960c5c3789df7a3bb829f0244c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f9c588b6396bd5c42e903500ba07425_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3061900a8ce349aa5ef35b9354875275_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\306617a84dd5a57ee821f9452d1c1a42_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3165abe1266ef11b720653d1bef1f455_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\319f06dbf06f46ce0c114efb0b2b0a69_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\322954cb887a138a212a74e4296f26de_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3484d4e245a7083787b96c28df9f410e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\35b77158da504336d6816dbe76570cc9_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3778b172db5cdf56f4937ed1c8b72fbc_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3818ae7d668bfbd158a952d10119c646_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\38a3b690270b880ca1580bb634e1e2c6_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3c8be4cad34f5ccb08cbb1f88d1dd5a6_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3d049842fddab9d5e6899ce861a28d5d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3dfd8a4ad4e3351f8cae38ae2b0e2239_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e720193ea0514473449fc38457d7257_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3eed100ebe3973a7c82b6e13c572ff5c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\40996ab7e9afbab2d0996a2dc7607cb8_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\40bed8e97b18ab33d4e4ef176c088b55_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\413210058c6aa6a691a6f6ade4d51107_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\41e06784ed05b187649da0df3d0c0fd4_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\422e7b3f0506a99000cfda770a1ba543_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\42ce262665480bbf8876d423d519f090_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\43e4663cc832fb1bd8d77c22e5d0c8bb_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\44952897911b45428b38d79daa218e25_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\46e0c4ba5fc151556f2b237a9067741b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\491338b551e1fde2ed7c430e607540cc_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\49f592d8cd8f8f3a53737f26d1a7e9a8_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4d4bdea992152860c6dae2409fb2cd4d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4f521263a62ddf18467d13c9aea7221c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5055ca1b6162ce1e83c791a59c197ce6_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5102378e61c1ab8aeff97d57985133c9_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5111b4e90fad6e0db715a526e87827a3_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\516a438802dbcf08ce85f8104a4f9281_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\51b994995f4aeab494eeb15ed436d470_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\54938e95bf88bb37ada1243230c1e6b1_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\551bc008c87fd6285918401037f78d48_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\560531e1a01f0d0d91f10b09607fd037_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5643a186322d0c4aae0e2f161a0a740e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5666a8854d9861da6c0a4539effca8b1_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5693955235035f382020520588e2b6ef_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\56b834853bb9b971cde3f68079db377c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5754ed72fe7c8c259a134df92bdd9fc0_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58c841ae5c27fff89ef993a23ed5d97b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c20788da4af68b62d44237e8984934a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\603ec825ba89e747d605323ec7e2f149_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\61b001b882ac23721dc5ce1fed7b843e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6235770cd9fd539e48ec95cd5ab6a064_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63114208aa70d066323325b86e4187ab_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6335d8125db8ff18d524f4e16df162e1_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\633f4785fc017092740da1c85f71738c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6382d156ac799c7f8513d2199dc37f1c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\639cfa406a2f8625818097b55db91982_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63e116859f1d2182ff9f27791aa14603_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\64bff5df41204a41ffb047a9eec4a4c2_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\662964c0fdf782e7b77fb65066672a34_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\68c0732ce45e48064d8b64fe0c70a79d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\69a73f1450e78a0b4a6b37720cef3932_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\69c345653dc45dae786e6c526b7f103c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6a087615732c0a8d803cd8d797fd832a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6b5a6071393c1a4ad70acb5b40499045_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6beb6cdb3de13705c0dbdc16fbe9e752_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6c0ffc74b84733a01f9f07c0a307be11_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6c16bef403e7f035c1af9e991c3f70e9_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d34bba50e23c8e1bdf99987cf0fa22c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6e13f70c0fdb45510fd0f45e25b5f54d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6e20d3e0bac1918a62a12666070bbc71_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6fba9995c7cf97ea9a5c0ef9cff61c4b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6fc2553ee1e36c3b42ea833da2828bd2_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\71dbc91b415ad8c37c42258cb5e08260_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\72a480eeacfb0c1f457343868f16140b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\72c0561ac12df86b4f547230a72400f3_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\72eba2d2b56d0c342c86e021ad136b04_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73a9f37f7b042c41f6819c6f4061a409_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\74e1ff59ffd6f03788e624b086bdfd6d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\75ba65f28f3e0a8c12c5e8ce31fe0cb8_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7686546361928a614bd69c64c76f29de_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\76b11f6b5c0473497f375d3698fed38d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\79fada1235fda696d40ff7a699c3ef05_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a05f253d0137c4506d9912db1fe9900_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b0d06a249ab98dd8e8e5acadd0b994b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b3783114354f8ef5a3e34931620fc15_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7bc549fc9191267d954b805dc02db201_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7bd344931d9a52510dfe5b09cedca25a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7c674e21adb7f39111c0a4360bc54b15_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7ceac770ac1f074124553d73887bbad5_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d13cd13a07a11d6b471febc2e136319_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d78c885464dd6940139d0c8baeea4b9_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7dca96c68bd83226da1a38bacf12e351_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7e4cfe58c18c22ecc814b55f82501476_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7fc73dc8dfcb893da18b770535d8e8fb_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\800a65907dc86fc459569c883d4476e2_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8011a5da420484adaae40b39b711c194_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8025fd668eef319a6dc5cb3ee355bebe_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8033e11a85e134b2c38b241777ad815c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\81a69f4bc1f4ab61b216d86dfc69b5b8_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\825e66102dbccaf4b6db4c83b628fa60_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\82e6095829b26a642fa2f7e206337f13_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\83419687c732b20d3c2077a0d56f581a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\83b053ee9475a950f3f6b781bb907ae2_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8473eb75cb4aa75241de3996a50d240b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\84bb8e7ed42123178642b239d6a9b016_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\84e97daa12fb186f396215a8fc5cde8f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8622863924f66ed4964cf1522182ad2f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\87c5f9ccb02b1f761238a380ad1c37cb_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\87c63e6585b5d9922a487c0f0254ffea_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\87eb0a9af711152925c861a66fcfbb8e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8946282def1e8349f49bb5104c798b82_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89fa07c355277f276ce5400ad223795c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a031a76335dfac7bc8331a7601ecc46_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a1d6244352ef3feaad29de7ea6f339a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a336992ec3a17172e2b79272996024e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a7cf8aa2d2930ef50515ab050e55036_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8addb8dae88f6d92618c872856b3c341_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8b0febd831ff291d6499b0ebbfd0ab89_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8be46af7cea3b879efa85848880741cb_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8fde72f631a93fa56202b3269e6e5a40_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\90a87e3f1ba6efd767c55b25319326db_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9197eb7f5f655c62c629bee95529d374_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\925837d292fc53279d6f50eddea6876d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\929363806e32b0dd6650a1d7ebc44d2f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\92bc95c32d8e0426cadf946ff9d26f51_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\92c030c9d0fd71dd21490dcc798f5514_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9364eb2b52f3f61128ead20fd369a261_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\93c3df0706a523de48e037ae178c560f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\942c34c77d9cc11104d2e432bd220bed_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\948917adaff37b08024d7c7c6d4425ab_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94c34734192a29a946ce852023e1ae7b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\95524a285400e408ee7af228f0d793be_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9554ce2dc57d6db231d00441d85997ec_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9556a82642fa7bbf54a1f2df7815cce7_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\958b3ef18590685cd50dc604ebc40c15_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\960ae297febf6c9e3a63deebe6d0e541_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\96a3dd62eb8d9354769defb9d6c5e4c8_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\977b524411c9acc9c22d467b4d49c8f7_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\981f0b1d1119eda454127cfffc75576a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\992a1994f3864b7a338eb90c4d90b0d3_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a18017cdf783f501253e606ed737604_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9b5bea1f41f20dfae7101684921b3665_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9bf2daac7fa6ca7fc77192f5a64a264d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9d53d4bf709e6f66e516d45af5c9d918_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9f37e45457b1eb1ad144f216bcee9006_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a00fe746b7ada43ccd4f8773df3fde32_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a01f5028e94cfaa1b5ab11755d98712b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a0a922b3a9ffb32c6d1db0e3229b8314_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1082909f272727041b5bdbab8873f9e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a396e4bd5a137d88c5e34048f09defad_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a3c9e269bf9053508b6594cb9e4b878c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a45d939990b90a755d535d548ff22695_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4f0daf8c288d622476533506c75e75e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a646db12ebee9e3ebc983f2ab60de797_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a706d956e021717cd4b5d29cc4334b5e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a943cb0992d9be03254788613fde7f21_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a953943ad250198f3084ce5faaedce1e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab276efc0c384258888b37faaf85bc7e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ac04960d56f15aaf0383a9bd475e2632_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aca4d7591268d4b677d851831c04ef76_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b1184a6e0d440c3175fafe4bafd800d5_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b1b6c9b23450407aa55d59b55257e1ce_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b1eb88c9bc7addacb3e2aa47622299d9_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b247ecea688580f1fc2297d01ccaeb59_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b2c136af039d0b110c7d54d456ad6641_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b312df87afe61b1353ee38d2e267ae93_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b3ae76cb005830fdc3d0f373ed2c4718_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b417e392e4e50054e170b09a2d5d77a2_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b53993a6a4fca80cd753ebb38088e060_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b6b7076f06d20f55e54ab1e78ffe7aca_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b6e01eba7755533461f4cc9de29d42d9_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b72af321df5fa71a44e3bd6e647b8cb0_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b7774e286ea2400a03652829d7257aaf_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b812c2f15276c8b2d27a8f8f4af5e9cd_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b850f717b9f668b0e1022a14a1072455_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ba194b1eb9df4ed12d06a8796f8f385b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bb66ad27ea526d2e5d4a4c8b89e59e6a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bc3bd4f07fa582111387af308223200c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bcab7e216b99147b647110df8768ca5a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bcd0cb46d8f3076c90cf87c72060562e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bcd1f27f059622c809f2b5851a3ebf76_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bcf093e950cd75c1f404d29533c5ea15_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be731f4f7878757eab8ab724c8096d4d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c02b0a12dca5e1661f300d002a6cd785_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c0db6524e567ebe3954cef3b7613e192_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c16b24185caf21023826efeffe8bf486_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c240d399081a38ec70bd733f5a8e87de_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c25d1177be27bf84a38514a9f3ac09fc_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c706c6541790101477c6fec24346177b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c74bf4068a2890962d5029df97ed0906_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c79feeb9e4b09f52115173e60698e0f3_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c80742ada33aa10c03f1922c48051876_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c8b530b9d508f2105c8e800cad84440f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c8cd7f827362fdf897c5c29af513ab64_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c90930cd53d14842837cf3cc723e2d95_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c9e46609a0d1a27397e4b2af82e57bdd_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ca832d8258866824bb0b31900afc0928_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\caa885bcb489c0f2495b47f7d4c418d4_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cb9c7b02054714d5a1c9f1434b20d67b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cbfbffccbcbfd48b297380ba4f1353c5_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cdbec3a6647152074cec65916c70044b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce343eda1df0513bce2c1fa72c61988d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cf969753e8e518528bd7a3a482208e2b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d02eee58e9e00f7e15ba6404c9c023a2_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d0ca2b815a2787e59c301852f5d905f7_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d105c400b11f062812032115b5c63f9a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d16ec2a1d11799e49c5756741124876c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1f7bb08f680765f799f152d4f6c3c59_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3737d62010de85c6642ba49f5262fcf_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3782c626eac1bf045b5686c657e42ba_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3aeadb1404accdfa57b0c3469fdf46e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d54d7424a54c7894d1ece2a6aadb7ed9_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d55dc9d8c817cda049328441787ffca4_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d56feb3795f88fd2c9b98989c8b688f9_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d574b911dc475269af0bbbfb3dfd2473_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d6fe8d1f1de2da19e5ce575f985fc752_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d73eb742a4e5fd71c9d6f94cfce638ab_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d84a9ccf80e3b45b28ab45169be375f2_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d98ba30d16da2edfba70c4b445ab3f5f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d9dc122ee345fe937c412f327c7c321b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd735c5f2c4aed56fe688daa8bfb7db5_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd8b28a5474a800f5c48057fbdd2914a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ddc0e23ff429e40261958a3949f20b0d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dde34fe18cc9ad3961c3968a537a7986_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\de1de8dce917487ea0a22d1fa1b4743f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dea3182bf55680d165a451c73040710b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df0b7f673f12c0e9031acd6f95948ca8_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df46f895bc3bd3b39d4208c96236e822_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e11c78a2fe23d4ae19025047a8bf76a8_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e16326c64df4e61bb482c16d8ad2eab5_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e24370cb88ac788115d6729fb051200b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3a3492e8c944fb1cd4cd4c2bb2d85ac_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3d424736bb8db6181285b7efbd89d57_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e62249c5e5b1232022efd8b27c620d89_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e6aeedab56451b0e6d17404a1d7f586f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e6b5dac55da0467dc077d6c858046167_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e7c57de6beb8fbb38ce3e80b34065041_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e862c3b3d1ad5837a5ba6f454840ba17_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea2864f17d0f276e8d93d462d5f8fead_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec3d8ec7ec7126cc7bb449eb055fbb8e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ecc91981a42201b27b1fe04bcc6d995b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ecd9f1683f9a2dfcde6e4346dd2d023e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eeee6c4b643c4614a3c503be319dcd8e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ef19127bd40a8fe5448f093f518b0caa_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ef8091f31c5180c0f2e5aad115902562_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f09eae08823d43d477694a92eb0b435c_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f247ec485139c9f45154d74d95183842_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f6d5124d90daa1b251f1dbfe5b4a4377_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8eb4ddbf6a718655fed124426436e77_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f9edc7fb6f0675942901ebf10aa15e2f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fa83898e8bd3a08ad7bd6fd0c5d4ece0_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fb2fbacf4964e256e094f19ac750134d_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fb58288c9d0076527782d885f7d4428b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fbadf64ac01437bbcab056c47404c12b_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd025dbe356b8bf9267af69d833b743e_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd7a24d7c803165d2957f171a14e6ed9_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fdaa55d312942df785e654664852b16f_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fe36cdbd7d6b92cb56d87ee3ef23625a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fe6e132696c8a11e986cbab1111998ef_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff78bd0a1a1e0627c7f7701cbd5ab218_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ffa375a1b3f676e3f1f82f622d78dd3a_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ffaaaa6223af37c500ed31fe14b1b757_67f6fc3c-610d-483e-b822-a541b2579588 L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\HPPAppActivity.log L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\HPPHomePageActivity.log L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-01-31_Log.ALUSchedulerSvc.LiveUpdate L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00B70949.wma Infecté : Trojan-Downloader.WMA.Wimad.d ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01F77F80 Infecté : Trojan-Downloader.BAT.Ftp.c ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0A3D518E.dat Infecté : P2P-Worm.Win32.Delf.ad ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0FE65317 Infecté : not-virus:BadJoke.Win32.KnijpMe ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11264FA5.exe Infecté : Trojan-Downloader.Win32.Delf.aeu ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\281E6DCF Infecté : not-virus:BadJoke.Win32.KnijpMe ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2A523743.dll Infecté : Trojan.Win32.BHO.g ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2EC05E64.htm Suspect : Exploit.HTML.Mht ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2EDE5843.htm Infecté : Trojan-Downloader.JS.Small.d ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2FCF3CA1/Splinter Cell NOCD.exe Infecté : P2P-Worm.Win32.Doep.a ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2FCF3CA1 ZIP: infecté - 1 ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2FCF3CA1 Cryp
    31 Janvier 2007 16:22:54

    la suite n'arrivera pas ... (J'ai interrompue l'anlyse ! cause : anlyse de disque dur externe (jugé inutile))
    31 Janvier 2007 16:23:40

    oups il manque un morceau :


    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\HPPAppActivity.log L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\HPPHomePageActivity.log L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-01-31_Log.ALUSchedulerSvc.LiveUpdate L'objet est verrouillé ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00B70949.wma Infecté : Trojan-Downloader.WMA.Wimad.d ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01F77F80 Infecté : Trojan-Downloader.BAT.Ftp.c ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0A3D518E.dat Infecté : P2P-Worm.Win32.Delf.ad ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0FE65317 Infecté : not-virus:BadJoke.Win32.KnijpMe ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11264FA5.exe Infecté : Trojan-Downloader.Win32.Delf.aeu ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\281E6DCF Infecté : not-virus:BadJoke.Win32.KnijpMe ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2A523743.dll Infecté : Trojan.Win32.BHO.g ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2EC05E64.htm Suspect : Exploit.HTML.Mht ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2EDE5843.htm Infecté : Trojan-Downloader.JS.Small.d ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2FCF3CA1/Splinter Cell NOCD.exe Infecté : P2P-Worm.Win32.Doep.a ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2FCF3CA1 ZIP: infecté - 1 ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2FCF3CA1 CryptFF: infecté - 1 ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2FD73C67 Infecté : Trojan-Downloader.Win32.Small.or ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\33496046.dll Infecté : Trojan-Spy.Win32.VBStat.h ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\344D59BF.exe Infecté : Trojan-Dropper.Win32.Agent.azn ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\414A28CF.exe Infecté : Trojan-Downloader.Win32.Delf.aeu ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4C2036A2.dll Infecté : Trojan.Win32.BHO.g ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4D0E7C7E.exe Infecté : Trojan.Win32.Dialer.hh ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\54455A91.dll Infecté : Trojan.Win32.BHO.g ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\54AF62A4.dll Infecté : Trojan.Win32.BHO.g ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5F081E56 Infecté : not-virus:BadJoke.Win32.KnijpMe ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6BE003D5 Infecté : Trojan-Downloader.BAT.Ftp.c ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73590D7D.exe Infecté : not-virus:Hoax.Win32.Renos.az ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73D66596.tmp Infecté : Trojan.Win32.Dialer.hh ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7AB62B5E.dll Infecté : Trojan.Win32.BHO.g ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7D3D464E.dll Infecté : Trojan-Spy.Win32.VBStat.h ignoré

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7D643E23.dll Infecté : Trojan.Win32.BHO.g ignoré

    C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

    C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré

    C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Application Data\Symantec\PendingAlertsQueue.log L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Cookies\index.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Application Data\Microsoft\Messenger\m0rpheus974@hotmail.fr\SharingMetadata\Logs\Dfsr.log L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Application Data\Microsoft\Messenger\m0rpheus974@hotmail.fr\SharingMetadata\pending.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Application Data\Microsoft\Messenger\m0rpheus974@hotmail.fr\SharingMetadata\Working\database_608C_28B8_8C28_8A9C\dfsr.db L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Application Data\Microsoft\Messenger\m0rpheus974@hotmail.fr\SharingMetadata\Working\database_608C_28B8_8C28_8A9C\fsr.log L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Application Data\Microsoft\Messenger\m0rpheus974@hotmail.fr\SharingMetadata\Working\database_608C_28B8_8C28_8A9C\fsrtmp.log L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Application Data\Microsoft\Messenger\m0rpheus974@hotmail.fr\SharingMetadata\Working\database_608C_28B8_8C28_8A9C\tmp.edb L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Application Data\Microsoft\Windows Live Contacts\M0rPheUs974@hotmail.fr\real\members.stg L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Application Data\Microsoft\Windows Live Contacts\M0rPheUs974@hotmail.fr\shadow\members.stg L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Historique\History.IE5\MSHist012007013120070201\index.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Temp\~DF862F.tmp L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Temp\~DF8ACB.tmp L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Temp\~DF940A.tmp L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Temp\~DF946F.tmp L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\Mes documents\Mes Historiques de Conversation\janvier 2007\aurore-boreale@hotmail.com.html L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\NTUSER.DAT L'objet est verrouillé ignoré

    C:\Documents and Settings\Myk\ntuser.dat.LOG L'objet est verrouillé ignoré

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

    C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré

    C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
    18 Février 2007 09:20:18

    EDIT :
    Mes débuts en tant qu'IDnaute sont pitoyables x)
    Tss j'arrive même pas à croire que j'ai été aussi impatient que sa !
    Contenus similaires
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS