Virus

carpat Messages postés 58 Statut Membre -  
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Bonjour,
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:49:53, on 2009-01-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\MICROS~3\GAMECO~1\Common\SWTrayV4.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdnserv.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\oneclick\oneclick.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\lxdncoms.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Lexmark 2600 Series\lxdnmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Lexmark 2600 Series\lxdnMsdMon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\NetMeeting\conf.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Hotbar\bin\10.0.368.0\Weather.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\PROGRA~1\Magentic\bin\MgApp.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.magentic.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Companion BHO - {02478D28-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_5.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Windows Live Toolbar Beta - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_5.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Windows Live Toolbar Beta - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~3\GAMECO~1\Common\SWTrayV4.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\TotRecSched.exe
O4 - HKLM\..\Run: [AQ3HelperStartUp] C:\PROGRA~1\AQUATI~1\AQ3HEL~1.EXE /partner AQ3
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [OneClick] "C:\Program Files\oneclick\oneclick.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HotbarOE] C:\Program Files\Hotbar\bin\10.0.368.0\OEAddOn.exe
O4 - HKLM\..\Run: [HotbarSA] "C:\Program Files\Hotbar\bin\10.0.368.0\HotbarSA.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [lxdnmon.exe] "C:\Program Files\Lexmark 2600 Series\lxdnmon.exe"
O4 - HKLM\..\Run: [lxdnamon] "C:\Program Files\Lexmark 2600 Series\lxdnamon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\system32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft NetMeeting] "C:\Program Files\NetMeeting\conf.exe" -Background
O4 - HKCU\..\Run: [SoniqueQuickStart] C:\Program Files\Sonique\sqstart.exe -nostick
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Hotbar\bin\10.0.368.0\Weather.exe" -auto
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-1844237615-308236825-1801674531-501\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Invité')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www2.sympatico.ca/
O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} - https://www.afternic.com/domains/downloadv3.com
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {4E7BD74F-2B8D-469E-CAF6-EF6DA692B53A} - http://toolbar.gograph.com/toolbar/install/GOgraphX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{37733992-8211-46A1-980C-01F20973C471}: NameServer = 142.217.192.9,142.217.192.8
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxdnCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdnserv.exe
O23 - Service: lxdn_device - - C:\WINDOWS\system32\lxdncoms.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Winkvn - Unknown owner - C:\WINDOWS\System32\Winkvn.exe (file missing)
A voir également:

15 réponses

E..T Messages postés 6565 Statut Contributeur 428
 
a analyser
svp


Tu étais déjà sur un autre topic >> la

Bye!
0
theking5910 Messages postés 97 Statut Membre 6
 
instale antivir je l'ai depuis 4 semaine il a detecté 13 virus que avst n'avait pas detecté
0
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Bonjour

C'est un peu "sec" !
La moindre des choses serait d'expliquer un peu les problèmes que tu rencontres...

Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
0
E..T Messages postés 6565 Statut Contributeur 428
 
Hello topti!
Meilleurs vieux à toi ;-)
++
0
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Merci, bonne année également.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
carpat Messages postés 58 Statut Membre
 
-----------\\ ToolBar S&D 1.2.8 XP/Vista

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 2009-01-01|14:09 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\Program Files\AltNet
C:\Program Files\AltNet\My Altnet Shares
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\cevakrnl.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\cevakrnl.ivd.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\cevakrnl.rvd.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\cevakrnl.xmd.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\cran.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\cran.cvd.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\emalware.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\emalware.ivd.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\iso.xmd.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\java.cvd.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\mbox.xmd.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\mdx_97.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\mdx_97.ivd.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\plugins.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\plugins.cab.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\plugins.cab.cab (incomplete)
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\plugins.cab.cab (incomplete-1)
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\sdx.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\sdx.ivd.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\update.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\update.txt.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\ve.xmd.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\zip.cab
C:\Program Files\AltNet\My Altnet Shares\Bullguard Protection\zip.xmd.cab
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\Installr
C:\Program Files\FunWebProducts\PopSwatr
C:\Program Files\FunWebProducts\Shared
C:\Program Files\FunWebProducts\Installr\1.bin
C:\Program Files\FunWebProducts\Installr\Cache
C:\Program Files\FunWebProducts\Installr\setups
C:\Program Files\FunWebProducts\Installr\1.bin\F3EZSETP.DLL
C:\Program Files\FunWebProducts\Installr\Cache\0018898E
C:\Program Files\FunWebProducts\Installr\Cache\0018D50E
C:\Program Files\FunWebProducts\Installr\Cache\001900B2
C:\Program Files\FunWebProducts\Installr\Cache\001913AD
C:\Program Files\FunWebProducts\Installr\Cache\001927C2
C:\Program Files\FunWebProducts\Installr\Cache\files.ini
C:\Program Files\FunWebProducts\PopSwatr\History
C:\Program Files\FunWebProducts\PopSwatr\History\allowed
C:\Program Files\FunWebProducts\PopSwatr\History\notallow
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\HbTools.log
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0\hbtools
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0\hbtools\static
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0\hbtools\static\DownLoad
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0\hbtools\static\DownLoad\BtnTrans.idx
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0\hbtools\static\DownLoad\BtnTrans.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0\hbtools\static\DownLoad\BtnTrans1.dat
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0\hbtools\static\DownLoad\BtnTrans1.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0\hbtools\static\DownLoad\components.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0\hbtools\static\DownLoad\email-t1-bg.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0\hbtools\static\DownLoad\email-t1-bg.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0\hbtools\static\DownLoad\keywords1.dat
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\HbTools.log
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\IESkins
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\HostOI
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\HostOL
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\HostOI\dynamic
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\HostOI\static
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\HostOL\dynamic
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\HostOL\static
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\1.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\1056045.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\1192161.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\1383771.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\1386871.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\1390845.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\1402020.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\1402657.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\2363825.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\2523250.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\2561292.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\2883915.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\2884801.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\3251993.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\3340762.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\344stat
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\3893181.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\3893236.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\3893245.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\3893642.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\600583.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\626504.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\803618.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\805478.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\953694.sdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\domains.txt
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\ustat
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\1000023946
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\1000029251
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\1000030301
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\1000030669
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\1000030882
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\1000031840
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\1000047588
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\11213
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\11390
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\115541
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\11940
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\12457
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\12581
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\13562
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\139965
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\14184
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\14575
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\14633
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\159294
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\16087
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\16204
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\17025
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\17040
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\17147
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\180320
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\186757
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\194120
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\19475
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\19597
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\20156
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\20266
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\20517
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\20570
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\20935
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\21158
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\211854
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\213217
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\213558
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\21595
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\218682
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\21887
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\22254
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\223385
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\22657
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\237756
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\242233
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\246310
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\25043
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\25466
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\25708
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\25818
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\259766
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\26340
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\26664
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\27503
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\275654
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\277907
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\28437
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\290893
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\29115
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\29642
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\30200
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\31537
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\32024
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\32122
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\32883
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\33233
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\3405
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\34123
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\34174
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\34186
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\34237
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\35120
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\36079
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\361427
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\362710
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\37135
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\372500
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\37673
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\38733
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\398397
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\4142
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\42208
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\4226
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\427075
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\42915
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\43377
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\4382
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44228
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44306
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44458
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44492
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44878
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\45510
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\46169
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\481176
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\490133
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\49821
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\51374
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\52335
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\526389
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\52902
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\531510
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\533670
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\53501
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\54473
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\5464
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\549635
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\56445
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\56815
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\57137
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\572023
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\576702
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\578081
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\578150
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\58197
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\583049
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\583749
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\58804
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\591975
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\59243
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\59844
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\61779
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\61837
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\628146
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\6292
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\64444
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\64446
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\64495
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\64564
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\64737
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\65770
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\66264
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\6635
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\66493
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\6658
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\670462
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\67469
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\68040
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\68094
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\6873
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\68748
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\688368
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\69325
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\705140
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\708497
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\712427
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\71383
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\71822
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\72123
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\72477
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\72748
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\73576
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\73625
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\737840
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\74398
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\744260
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\744603
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\744775
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\744857
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\744993
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\745024
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\745037
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\745220
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\745857
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\748957
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\751445
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\753276
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\753306
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\753309
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\753328
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\753334
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\753335
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\753340
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\77787
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\78918
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\79079
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\79257
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\79806
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\79824
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\8111
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\82292
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\86379
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\86587
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\868
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\87215
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\87385
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\87995
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\89235
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\93384
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\94407
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\94512
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95645
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95726
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95777
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\97499
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\98493
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\99008
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\9974
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\ustat\3650.dat
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\dynamic\ustat\3651.dat
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\ads.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\btntrans.idx
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\btntrans1.dat
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\business_promo.htm
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\buttondir.txt
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\components.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\cursors.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\default.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_511745-514279.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz1.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz10.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz11.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz12.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz13.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz14.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz15.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz16.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz17.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz18.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz19.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz2.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz20.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz3.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz4.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz5.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz6.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz7.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz8.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_bidz9.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_categorize.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_comparison.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_em_PROFL_CA_flow_b_IEB.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_explorer-Mails.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_explorer-people.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_favorites.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_Games.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_Hide.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_hotbarcom.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_Hotmail.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_hsskin.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_jemster.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_jemsterie.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_jemsteruk.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_jobsearch.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_Mails.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_new.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_premium.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_reun.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_ringtones.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_SearchBoxTrapper.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_searchfor.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_searchgo.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_weather.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Default_yellowpages.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_1000.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_2000.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_3000.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bar.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar1.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_logos.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_other.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\d_icons_weather.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\email-def-511724-548964.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\email-def-511724-9595.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\email-t1-bg.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\gamesmenu.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\gamesMenu.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\hb_ie_menu.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\hotbar-premium-hotbar-premium.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\hotbar-premium.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\hotbar_promo.htm
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\icons2.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\ie_games_icon.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\ie_video.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\keywords.idx
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\keywords1.dat
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\layout.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\linkpathlegal.txt
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\more.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\new_games.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\progress.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\sales_buttons.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\s_icons_buttons.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\t2_bg.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\theweb.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\top7.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\Top7_theweb.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\tsd_bg.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\1\weathericon.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\ads.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\btntrans.idx
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\btntrans1.dat
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\business_promo.htm
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\buttondir.txt
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\components.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\cursors.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\default.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_511745-514279.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz1.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz10.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz11.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz12.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz13.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz14.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz15.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz16.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz17.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz18.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz19.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz2.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz20.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz3.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz4.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz5.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz6.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz7.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz8.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_bidz9.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_categorize.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_comparison.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_em_PROFL_CA_flow_b_IEB.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_explorer-Mails.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_explorer-people.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_favorites.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_Games.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_Hide.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_hotbarcom.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_Hotmail.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_hsskin.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_jemster.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_jemsterie.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_jemsteruk.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_jobsearch.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_Mails.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_new.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_premium.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_reun.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_ringtones.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_SearchBoxTrapper.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_searchfor.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_searchgo.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_weather.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Default_yellowpages.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_1000.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_2000.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_3000.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bar.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar1.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_logos.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_other.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\d_icons_weather.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\email-def-511724-548964.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\email-def-511724-9595.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\email-t1-bg.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\gamesmenu.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\gamesMenu.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\hb_ie_menu.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\hotbar-premium-hotbar-premium.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\hotbar-premium.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\hotbar_promo.htm
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\icons2.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\ie_games_icon.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\ie_video.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\keywords.idx
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\keywords1.dat
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\layout.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\linkpathlegal.txt
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\more.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\new_games.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\progress.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\sales_buttons.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\s_icons_buttons.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\t2_bg.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\theweb.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\top7.cdf
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\Top7_theweb.mnu
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\tsd_bg.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\2\weathericon.res
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\ads.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\BtnTrans.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\BtnTrans1.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\business_promo.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\buttondir.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\cursors.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\default.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_1000.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_2000.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_3000.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bar.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar1.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_logos.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_other.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_weather.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\email-t1-bg.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\gamesmenu.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\hb_ie_menu.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\hotbar-premium.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\hotbar_promo.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\icons2.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\ie_games_icon.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\ie_video.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\keywords.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\keywords1.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\layout.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\linkpathlegal.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\more.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\progress.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\sales_buttons.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\samplegroups2.txt
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\samplegroups2.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\s_icons_buttons.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\t2_bg.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\top7.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\tsd_bg.xip
C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0\Hotbar\static\DownLoad\weathericon.xip
C:\Program Files\Hotbar
C:\Program Files\Hotbar\bin
C:\Program Files\Hotbar\bin\10.0.368.0
C:\Program Files\Hotbar\bin\10.0.368.0\HostOE.dll
C:\Program Files\Hotbar\bin\10.0.368.0\HotbarSA.exe
C:\Program Files\Hotbar\bin\10.0.368.0\HotbarSAAX.dll
C:\Program Files\Hotbar\bin\10.0.368.0\HotbarSAHook.dll
C:\Program Files\Hotbar\bin\10.0.368.0\Weather.exe
C:\Program Files\Hotbar\bin\10.0.368.0\WeSkin.dll
C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\Hotbar
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@hotbar[2].txt
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@www.hotbar[2].txt
C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA
C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSA.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSAAbout.mht
C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSAau.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSAEula.mht
C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSA_gdf.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSA_kyf.dat
C:\Program Files\KaZaA
C:\Program Files\KaZaA\Db
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA\plugins
C:\Program Files\KaZaA\plugins.htm
C:\Program Files\KaZaA\versions.dat
C:\Program Files\KaZaA\Db\data1024.dbb
C:\Program Files\KaZaA\Db\data256.dbb
C:\Program Files\KaZaA\Db\np.tmp
C:\Program Files\KaZaA\Db\str4-040318.cab
C:\Program Files\KaZaA\Db\tss4.cab
C:\Program Files\KaZaA\Db\tssv124.dat
C:\Program Files\KaZaA\My Shared Folder\(Patrick Normand) Perce Les Nuages.mp3
C:\Program Files\KaZaA\My Shared Folder\Alain Morisod & Sweet People - CALIFORNIA BLUE.MP3
C:\Program Files\KaZaA\My Shared Folder\Alain Morisod & Sweet People - Pardon.mp3
C:\Program Files\KaZaA\My Shared Folder\Alain Morisod & Sweet People - River Blue.mp3
C:\Program Files\KaZaA\My Shared Folder\Alain Morisod & Sweet People - T'envoler (1).mp3
C:\Program Files\KaZaA\My Shared Folder\Alain Morisod Sweet Peoples - Au Revoir.mp3
C:\Program Files\KaZaA\My Shared Folder\AlbumArtSmall.jpg
C:\Program Files\KaZaA\My Shared Folder\AlbumArt_{9E82F6B3-9B4F-40FD-8877-418B07D86875}_Large.jpg
C:\Program Files\KaZaA\My Shared Folder\AlbumArt_{9E82F6B3-9B4F-40FD-8877-418B07D86875}_Small.jpg
C:\Program Files\KaZaA\My Shared Folder\AlbumArt_{D8BD50E7-7E58-4D6F-910B-BCA1760FE420}_Large.jpg
C:\Program Files\KaZaA\My Shared Folder\AlbumArt_{D8BD50E7-7E58-4D6F-910B-BCA1760FE420}_Small.jpg
C:\Program Files\KaZaA\My Shared Folder\Claude Valade - Au bout du monde.mp3
C:\Program Files\KaZaA\My Shared Folder\Claude Valade - Une vague bleue (1).mp3
C:\Program Files\KaZaA\My Shared Folder\Copy of Claude Valade - Reste avec lui.mp3
C:\Program Files\KaZaA\My Shared Folder\desktop.ini
C:\Program Files\KaZaA\My Shared Folder\download10804993497888140.dat
C:\Program Files\KaZaA\My Shared Folder\download10804993837921906.dat
C:\Program Files\KaZaA\My Shared Folder\Folder.jpg
C:\Program Files\KaZaA\My Shared Folder\Francis Cabrel - Petite marie.mp3
C:\Program Files\KaZaA\My Shared Folder\George Hamel - Roses des bois.mp3
C:\Program Files\KaZaA\My Shared Folder\Je T'ATTENDRAI MY LOVE.mp3
C:\Program Files\KaZaA\My Shared Folder\Joe Dassin - Ga va pas changer le monde.mp3
C:\Program Files\KaZaA\My Shared Folder\Julie Daraiche - On a pas le droit.mp3
C:\Program Files\KaZaA\My Shared Folder\Kenny Rogers - Lucille.mp3
C:\Program Files\KaZaA\My Shared Folder\kmd260_en.exe
C:\Program Files\KaZaA\My Shared Folder\La chanson d'Evita.mp3
C:\Program Files\KaZaA\My Shared Folder\Morisod Alain-Sweet People - Chansons d'amour.mp3
C:\Program Files\KaZaA\My Shared Folder\Patrick Norman - Mon Coeur est a toi.mp3
C:\Program Files\KaZaA\My Shared Folder\Petula Clark - Charriot.mp3
C:\Program Files\KaZaA\My Shared Folder\Renee Martel - Cadeau.mp3
C:\Program Files\KaZaA\My Shared Folder\Renée martel - Cowgirl Dorée.mp3
C:\Program Files\KaZaA\My Shared Folder\Renée Martel - D.I.V.O.R.C.E.mp3
C:\Program Files\KaZaA\My Shared Folder\Richard Desjardin - J'aurais du don du ben du....wpk
C:\Program Files\KaZaA\My Shared Folder\Sweet People -Les violons d'acadie -.mp3
C:\Program Files\KaZaA\My Shared Folder\T._Hatch_-_Downtown[1].mid
C:\Program Files\KaZaA\plugins\ace.xmd
C:\Program Files\KaZaA\plugins\arc.xmd
C:\Program Files\KaZaA\plugins\arj.xmd
C:\Program Files\KaZaA\plugins\bach.xmd
C:\Program Files\KaZaA\plugins\bzip2.xmd
C:\Program Files\KaZaA\plugins\cab.xmd
C:\Program Files\KaZaA\plugins\cevakrnl.cvd
C:\Program Files\KaZaA\plugins\cevakrnl.ivd
C:\Program Files\KaZaA\plugins\cevakrnl.rvd
C:\Program Files\KaZaA\plugins\cevakrnl.xmd
C:\Program Files\KaZaA\plugins\ceva_vfs.cvd
C:\Program Files\KaZaA\plugins\chm.xmd
C:\Program Files\KaZaA\plugins\cpio.xmd
C:\Program Files\KaZaA\plugins\cran.cvd
C:\Program Files\KaZaA\plugins\cran.xmd
C:\Program Files\KaZaA\plugins\dbx.xmd
C:\Program Files\KaZaA\plugins\docfile.xmd
C:\Program Files\KaZaA\plugins\emalware.cvd
C:\Program Files\KaZaA\plugins\emalware.ivd
C:\Program Files\KaZaA\plugins\emalware.xmd
C:\Program Files\KaZaA\plugins\gzip.xmd
C:\Program Files\KaZaA\plugins\ha.xmd
C:\Program Files\KaZaA\plugins\hlp.xmd
C:\Program Files\KaZaA\plugins\hpe.cvd
C:\Program Files\KaZaA\plugins\hpe.xmd
C:\Program Files\KaZaA\plugins\hqx.xmd
C:\Program Files\KaZaA\plugins\html.xmd
C:\Program Files\KaZaA\plugins\imp.xmd
C:\Program Files\KaZaA\plugins\inno.xmd
C:\Program Files\KaZaA\plugins\instyler.xmd
C:\Program Files\KaZaA\plugins\iso.xmd
C:\Program Files\KaZaA\plugins\java.cvd
C:\Program Files\KaZaA\plugins\java.xmd
C:\Program Files\KaZaA\plugins\lha.xmd
C:\Program Files\KaZaA\plugins\lnk.xmd
C:\Program Files\KaZaA\plugins\mbox.xmd
C:\Program Files\KaZaA\plugins\mbx.xmd
C:\Program Files\KaZaA\plugins\mdx.xmd
C:\Program Files\KaZaA\plugins\mdx_97.cvd
C:\Program Files\KaZaA\plugins\mdx_97.ivd
C:\Program Files\KaZaA\plugins\mdx_w95.cvd
C:\Program Files\KaZaA\plugins\mdx_x95.cvd
C:\Program Files\KaZaA\plugins\mdx_xf.cvd
C:\Program Files\KaZaA\plugins\mime.xmd
C:\Program Files\KaZaA\plugins\mso.xmd
C:\Program Files\KaZaA\plugins\na.cvd
C:\Program Files\KaZaA\plugins\na.xmd
C:\Program Files\KaZaA\plugins\nelf.cvd
C:\Program Files\KaZaA\plugins\nelf.xmd
C:\Program Files\KaZaA\plugins\objd.xmd
C:\Program Files\KaZaA\plugins\pdf.xmd
C:\Program Files\KaZaA\plugins\pst.xmd
C:\Program Files\KaZaA\plugins\rar.xmd
C:\Program Files\KaZaA\plugins\rpm.xmd
C:\Program Files\KaZaA\plugins\rtf.xmd
C:\Program Files\KaZaA\plugins\rup.cvd
C:\Program Files\KaZaA\plugins\rup.xmd
C:\Program Files\KaZaA\plugins\sdx.cvd
C:\Program Files\KaZaA\plugins\sdx.ivd
C:\Program Files\KaZaA\plugins\sdx.xmd
C:\Program Files\KaZaA\plugins\sfx.xmd
C:\Program Files\KaZaA\plugins\swf.xmd
C:\Program Files\KaZaA\plugins\tar.xmd
C:\Program Files\KaZaA\plugins\td0.xmd
C:\Program Files\KaZaA\plugins\thebat.xmd
C:\Program Files\KaZaA\plugins\tnef.xmd
C:\Program Files\KaZaA\plugins\unpack.cvd
C:\Program Files\KaZaA\plugins\unpack.ivd
C:\Program Files\KaZaA\plugins\unpack.xmd
C:\Program Files\KaZaA\plugins\update.txt
C:\Program Files\KaZaA\plugins\uudecode.xmd
C:\Program Files\KaZaA\plugins\ve.cvd
C:\Program Files\KaZaA\plugins\ve.ivd
C:\Program Files\KaZaA\plugins\ve.xmd
C:\Program Files\KaZaA\plugins\vedata.cvd
C:\Program Files\KaZaA\plugins\viza.xmd
C:\Program Files\KaZaA\plugins\xishield.xmd
C:\Program Files\KaZaA\plugins\z.xmd
C:\Program Files\KaZaA\plugins\zip.xmd
C:\Program Files\KaZaA\plugins\zoo.xmd
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@desktop.kazaa[2].txt
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@ssa.kazaa[1].txt
C:\Program Files\Myway
C:\Program Files\Myway\bar
C:\Program Files\Myway\myBar
C:\Program Files\Myway\SearchAt
C:\Program Files\Myway\bar\History
C:\Program Files\Myway\bar\Settings
C:\Program Files\Myway\bar\History\search
C:\Program Files\Myway\bar\Settings\settings.dat
C:\Program Files\Myway\bar\Settings\settings.htm
C:\Program Files\Myway\myBar\1.bin
C:\Program Files\Myway\myBar\History
C:\Program Files\Myway\myBar\Settings
C:\Program Files\Myway\myBar\1.bin\MYBAR.DLL
C:\Program Files\Myway\myBar\History\search
C:\Program Files\Myway\myBar\Settings\prevcfg.htm
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@myway[2].txt
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@myway[3].txt
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@mywebsearch[1].txt
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@mywebsearch[2].txt
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\log.txt
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\WeatherDPA
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\WeatherStartup.xml
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\Weather_XML
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\WeatherDPA\ACItems
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\WeatherDPA\WeatherPreferences
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\WeatherDPA\Weather_XML
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\WeatherDPA\Weather_XML\Display
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\WeatherDPA\Weather_XML\Loading
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\WeatherDPA\Weather_XML\soaperror
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\WeatherDPA\Weather_XML\Version
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\Weather_XML\Genera1
C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather\Weather_XML\General
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@hosted.zango[1].txt
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@www.zango[2].txt
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@www.zango[3].txt
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@www.zango[4].txt
C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@zango[2].txt
C:\DOCUME~1\ALLUSE~1\APPLIC~1\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
C:\WINDOWS\smdat32a.sys
C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\nsm15.tmp

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://mystart.magentic.com"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR"
"Search Bar"="http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"

--------------------\\ Recherche d'autres infections

Aucune autre infection trouvée !

1 - "C:\ToolBar SD\TB_1.txt" - 2009-01-01|14:12 - Option : [1]

-----------\\ Fin du rapport a 14:12:51,40

desoler pour ne pas avoir donner de precision
depuis que j ai installer windows live id il n a pas completer l installation
plus capable aller directement sur msn je suis oblige de passer par un autre chemin
merci
0
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".

! Ne ferme pas la fenêtre lors de la suppression !

Un rapport sera généré, poste son contenu ici.

NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.

0
carpat Messages postés 58 Statut Membre
 
-----------\\ ToolBar S&D 1.2.8 XP/Vista

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 2009-01-01|14:28 )

-----------\\ SUPPRESSION

Supprime! - C:\Program Files\AltNet\My Altnet Shares
Supprime! - C:\Program Files\FunWebProducts\Installr
Supprime! - C:\Program Files\FunWebProducts\PopSwatr
Supprime! - C:\Program Files\FunWebProducts\Shared
Supprime! - C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\HbTools.log
Supprime! - C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools\v3.0
Supprime! - C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\HbTools.log
Supprime! - C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\IESkins
Supprime! - C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar\v3.0
Supprime! - C:\Program Files\Hotbar\bin
Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\Hotbar
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@hotbar[2].txt
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@www.hotbar[2].txt
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSA.dat
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSAAbout.mht
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSAau.dat
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSAEula.mht
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSA_gdf.dat
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA\HotbarSA_kyf.dat
Supprime! - C:\Program Files\KaZaA\Db
Supprime! - C:\Program Files\KaZaA\My Shared Folder
Supprime! - C:\Program Files\KaZaA\plugins
Supprime! - C:\Program Files\KaZaA\plugins.htm
Supprime! - C:\Program Files\KaZaA\versions.dat
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@desktop.kazaa[2].txt
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@ssa.kazaa[1].txt
Supprime! - C:\Program Files\Myway\bar
Supprime! - C:\Program Files\Myway\myBar
Supprime! - C:\Program Files\Myway\SearchAt
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@myway[2].txt
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@myway[3].txt
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@mywebsearch[1].txt
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@mywebsearch[2].txt
Supprime! - C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA\Weather
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@hosted.zango[1].txt
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@www.zango[2].txt
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@www.zango[3].txt
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@www.zango[4].txt
Supprime! - C:\DOCUME~1\PROPRI~1\Cookies\propriétaire@zango[2].txt
Supprime! - C:\WINDOWS\smdat32a.sys
Supprime! - C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\nsm15.tmp
Supprime! - C:\Program Files\AltNet
Supprime! - C:\Program Files\FunWebProducts
Supprime! - C:\DOCUME~1\PROPRI~1\APPLIC~1\Hbtools
Supprime! - C:\DOCUME~1\PROPRI~1\APPLIC~1\Hotbar
Supprime! - C:\Program Files\Hotbar
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\HotbarSA
Supprime! - C:\Program Files\KaZaA
Supprime! - C:\Program Files\Myway
Supprime! - C:\DOCUME~1\PROPRI~1\APPLIC~1\WeatherDPA
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\2ACA5CC3-0F83-453D-A079-1076FE1A8B65

-----------\\ Recherche de Fichiers / Dossiers ...

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://mystart.magentic.com"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR"
"Search Bar"="http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/"

--------------------\\ Recherche d'autres infections

Aucune autre infection trouvée !

1 - "C:\ToolBar SD\TB_1.txt" - 2009-01-01|14:12 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 2009-01-01|14:32 - Option : [2]

-----------\\ Fin du rapport a 14:32:40,57

l ordi est tres lent aussi
merci encore
0
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Fais un nouvel Hijackthis stp
0
carpat Messages postés 58 Statut Membre
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:53:10, on 2009-01-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\MICROS~3\GAMECO~1\Common\SWTrayV4.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdnserv.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\oneclick\oneclick.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\lxdncoms.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Lexmark 2600 Series\lxdnmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Lexmark 2600 Series\lxdnMsdMon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\NetMeeting\conf.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\PROGRA~1\Magentic\bin\MgApp.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.magentic.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D28-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_5.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Windows Live Toolbar Beta - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_5.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Windows Live Toolbar Beta - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~3\GAMECO~1\Common\SWTrayV4.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\TotRecSched.exe
O4 - HKLM\..\Run: [AQ3HelperStartUp] C:\PROGRA~1\AQUATI~1\AQ3HEL~1.EXE /partner AQ3
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [OneClick] "C:\Program Files\oneclick\oneclick.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HotbarOE] C:\Program Files\Hotbar\bin\10.0.368.0\OEAddOn.exe
O4 - HKLM\..\Run: [HotbarSA] "C:\Program Files\Hotbar\bin\10.0.368.0\HotbarSA.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [lxdnmon.exe] "C:\Program Files\Lexmark 2600 Series\lxdnmon.exe"
O4 - HKLM\..\Run: [lxdnamon] "C:\Program Files\Lexmark 2600 Series\lxdnamon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\system32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft NetMeeting] "C:\Program Files\NetMeeting\conf.exe" -Background
O4 - HKCU\..\Run: [SoniqueQuickStart] C:\Program Files\Sonique\sqstart.exe -nostick
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Hotbar\bin\10.0.368.0\Weather.exe" -auto
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-1844237615-308236825-1801674531-501\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Invité')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www2.sympatico.ca/
O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} - https://www.afternic.com/domains/downloadv3.com
O16 - DPF: {4E7BD74F-2B8D-469E-CAF6-EF6DA692B53A} - http://toolbar.gograph.com/toolbar/install/GOgraphX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{37733992-8211-46A1-980C-01F20973C471}: NameServer = 142.217.192.9,142.217.192.8
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxdnCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdnserv.exe
O23 - Service: lxdn_device - - C:\WINDOWS\system32\lxdncoms.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Winkvn - Unknown owner - C:\WINDOWS\System32\Winkvn.exe (file missing)
0
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe

---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant ci-dessous :

:processes 
explorer.exe 

:files 
c:\program files\hotbar\bin\10.0.368.0\oeaddon.exe
c:\program files\hotbar\bin\10.0.368.0\hotbarsa.exe
c:\program files\hotbar\bin\10.0.368.0\weather.exe

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HotbarOE"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HotbarSA"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WeatherDPA"=-


:commands 
[emptytemp] 
[start explorer] 
[reboot]


---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

 
0
carpat Messages postés 58 Statut Membre
 
ensuite qu est que je fais
0
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Tu postes le rapport de OTMoveiT stp.
0
carpat Messages postés 58 Statut Membre
 
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder c:\program files\hotbar\bin\10.0.368.0\oeaddon.exe not found.
File/Folder c:\program files\hotbar\bin\10.0.368.0\hotbarsa.exe not found.
File/Folder c:\program files\hotbar\bin\10.0.368.0\weather.exe not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HotbarOE deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HotbarSA deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WeatherDPA deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\~DFDCDF.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 01012009_151307

Files moved on Reboot...
C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\~DFDCDF.tmp moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
0
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
OK, tu peux refaire un Hijackthis stp.
0
carpat Messages postés 58 Statut Membre
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:42:27, on 2009-01-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdnserv.exe
C:\WINDOWS\system32\lxdncoms.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\MICROS~3\GAMECO~1\Common\SWTrayV4.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\sm56hlpr.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\oneclick\oneclick.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Lexmark 2600 Series\lxdnmon.exe
C:\Program Files\Lexmark 2600 Series\lxdnMsdMon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\NetMeeting\conf.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\PROGRA~1\Magentic\bin\MgApp.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.magentic.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D28-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_5.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Windows Live Toolbar Beta - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_5.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Windows Live Toolbar Beta - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~3\GAMECO~1\Common\SWTrayV4.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\TotRecSched.exe
O4 - HKLM\..\Run: [AQ3HelperStartUp] C:\PROGRA~1\AQUATI~1\AQ3HEL~1.EXE /partner AQ3
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [OneClick] "C:\Program Files\oneclick\oneclick.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [lxdnmon.exe] "C:\Program Files\Lexmark 2600 Series\lxdnmon.exe"
O4 - HKLM\..\Run: [lxdnamon] "C:\Program Files\Lexmark 2600 Series\lxdnamon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\system32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft NetMeeting] "C:\Program Files\NetMeeting\conf.exe" -Background
O4 - HKCU\..\Run: [SoniqueQuickStart] C:\Program Files\Sonique\sqstart.exe -nostick
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-1844237615-308236825-1801674531-501\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Invité')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www2.sympatico.ca/
O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} - https://www.afternic.com/domains/downloadv3.com
O16 - DPF: {4E7BD74F-2B8D-469E-CAF6-EF6DA692B53A} - http://toolbar.gograph.com/toolbar/install/GOgraphX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{37733992-8211-46A1-980C-01F20973C471}: NameServer = 142.217.192.9,142.217.192.8
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxdnCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdnserv.exe
O23 - Service: lxdn_device - - C:\WINDOWS\system32\lxdncoms.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Winkvn - Unknown owner - C:\WINDOWS\System32\Winkvn.exe (file missing)
0
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Relance HijackThis.

Clique sur Do a System Scan Only et coche les lignes suivantes :

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~3\GAMECO~1\Common\SWTrayV4.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {4E7BD74F-2B8D-469E-CAF6-EF6DA692B53A} - ttp://toolbar.gograph.com/toolbar/install/GOgraphX.cab

Ferme toutes les autres fenêtres, tous les autres programmes. Pas de connection Internet.

Clique sur Fix checked puis clique sur OK
Puis ferme HijackThis.

Tuto : https://forum.pcastuces.com/hijackthis__fixer_les_elements_indesirables-f31s16.htm
0