Virus via msn
luceva1416
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour, j 'ai attrapé un virus via msn et depuis mon pc rame et deconne à fond, j ai fait HIJACKTHIS voici ce que ça donne.
quelqu'un pourrait m'aider s'il vous plait, merci d'avance
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:07:54, on 17/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\iexploore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\fxstaller.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\DOCUME~1\FRANCK~1\LOCALS~1\Temp\1540083044.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Franck et Béné\Local Settings\Temporary Internet Files\Content.IE5\JZ7CO8HP\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {d1a0d754-8148-4505-8935-6b27fbfafd3d} - C:\WINDOWS\system32\safodaru.dll
O2 - BHO: C:\WINDOWS\system32\jh9fgo4ksdgf.dll - {d7bf4552-94f1-42bd-f434-3604812c856d} - C:\WINDOWS\system32\jh9fgo4ksdgf.dll
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows UDP Control Center] fxstaller.exe
O4 - HKLM\..\Run: [badozerati] Rundll32.exe "C:\WINDOWS\system32\zugovela.dll",s
O4 - HKLM\..\Run: [0cc1982a] rundll32.exe "C:\WINDOWS\system32\setelojo.dll",b
O4 - HKLM\..\Run: [CPM0ff2abb6] Rundll32.exe "C:\WINDOWS\system32\yoyaheku.dll",a
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Diagnostic Manager] C:\DOCUME~1\FRANCK~1\LOCALS~1\Temp\1540083044.exe
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game14.zylom.com/activex/zylomgamesplayer.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\tuhuduta c:\windows\system32\bosurezo.dll C:\WINDOWS\system32\tuhuduta.dll C:\WINDOWS\system32\litugesi.dll c:\windows\system32\yoyaheku.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yoyaheku.dll
O22 - SharedTaskScheduler: sfdawtawgreage4tregrgae34 - {D7BF4552-94F1-42BD-F434-3604812C856D} - C:\WINDOWS\system32\jh9fgo4ksdgf.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yoyaheku.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB (pnkbstrb) - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
quelqu'un pourrait m'aider s'il vous plait, merci d'avance
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:07:54, on 17/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\iexploore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\fxstaller.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\DOCUME~1\FRANCK~1\LOCALS~1\Temp\1540083044.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Franck et Béné\Local Settings\Temporary Internet Files\Content.IE5\JZ7CO8HP\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {d1a0d754-8148-4505-8935-6b27fbfafd3d} - C:\WINDOWS\system32\safodaru.dll
O2 - BHO: C:\WINDOWS\system32\jh9fgo4ksdgf.dll - {d7bf4552-94f1-42bd-f434-3604812c856d} - C:\WINDOWS\system32\jh9fgo4ksdgf.dll
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows UDP Control Center] fxstaller.exe
O4 - HKLM\..\Run: [badozerati] Rundll32.exe "C:\WINDOWS\system32\zugovela.dll",s
O4 - HKLM\..\Run: [0cc1982a] rundll32.exe "C:\WINDOWS\system32\setelojo.dll",b
O4 - HKLM\..\Run: [CPM0ff2abb6] Rundll32.exe "C:\WINDOWS\system32\yoyaheku.dll",a
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Diagnostic Manager] C:\DOCUME~1\FRANCK~1\LOCALS~1\Temp\1540083044.exe
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game14.zylom.com/activex/zylomgamesplayer.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\tuhuduta c:\windows\system32\bosurezo.dll C:\WINDOWS\system32\tuhuduta.dll C:\WINDOWS\system32\litugesi.dll c:\windows\system32\yoyaheku.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yoyaheku.dll
O22 - SharedTaskScheduler: sfdawtawgreage4tregrgae34 - {D7BF4552-94F1-42BD-F434-3604812C856D} - C:\WINDOWS\system32\jh9fgo4ksdgf.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yoyaheku.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB (pnkbstrb) - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
A voir également:
- Virus via msn
- Virus mcafee - Accueil - Piratage
- Telecharger msn - Télécharger - Messagerie
- Msn messenger - Télécharger - Messagerie
- Virus facebook demande d'amis - Accueil - Facebook
- Virus informatique - Guide
38 réponses
si je ne te repond splus ce soir je serai la demain :)
Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
! Ne ferme pas la fenêtre lors de la suppression !
Un rapport sera généré, poste son contenu ici.
NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
! Ne ferme pas la fenêtre lors de la suppression !
Un rapport sera généré, poste son contenu ici.
NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
luceva1416
ok merci et bonne soirée
apres toolsbar sd tu fera ceci pour avancer en attendant neophyte*** qui finira pro!
scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
______________________
Télécharge ici :
http://images.malwareremoval.com/random/RSIT.exe
random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.
Double-clique sur RSIT.exe afin de lancer RSIT.
Clique Continue à l'écran Disclaimer.
Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.
Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).
NB : Les rapports sont sauvegardés dans le dossier C:\rsit
scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
______________________
Télécharge ici :
http://images.malwareremoval.com/random/RSIT.exe
random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.
Double-clique sur RSIT.exe afin de lancer RSIT.
Clique Continue à l'écran Disclaimer.
Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.
Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).
NB : Les rapports sont sauvegardés dans le dossier C:\rsit
slt
quelle efficacité ce norton :)
____________
Télécharge MSNFix de Laurent
http://sosvirus.changelog.fr/MSNFix.zip
Décompresse-le et double clic sur le fichier MSNFix.bat.
- Exécute l'option R.
--Si l'infection est détectée, exécute l'option N
- Sauvegarde ce rapport puis fais un copier/coller de ce rapport sur le forum.
Note :
Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
Sauvegarder et fermer le rapport pour que Windows termine de se lancer normalement.
envoyer le fichier [b] C:\DOCUME~1\florian\Bureau\Upload_Me.zip /b sur http://upload.changelog.fr pour faire evoluer msnfix
----------------------
scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
______________________
Télécharge ici :
http://images.malwareremoval.com/random/RSIT.exe
random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.
Double-clique sur RSIT.exe afin de lancer RSIT.
Clique Continue à l'écran Disclaimer.
Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.
Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).
NB : Les rapports sont sauvegardés dans le dossier C:\rsit
quelle efficacité ce norton :)
____________
Télécharge MSNFix de Laurent
http://sosvirus.changelog.fr/MSNFix.zip
Décompresse-le et double clic sur le fichier MSNFix.bat.
- Exécute l'option R.
--Si l'infection est détectée, exécute l'option N
- Sauvegarde ce rapport puis fais un copier/coller de ce rapport sur le forum.
Note :
Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
Sauvegarder et fermer le rapport pour que Windows termine de se lancer normalement.
envoyer le fichier [b] C:\DOCUME~1\florian\Bureau\Upload_Me.zip /b sur http://upload.changelog.fr pour faire evoluer msnfix
----------------------
scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
______________________
Télécharge ici :
http://images.malwareremoval.com/random/RSIT.exe
random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.
Double-clique sur RSIT.exe afin de lancer RSIT.
Clique Continue à l'écran Disclaimer.
Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.
Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).
NB : Les rapports sont sauvegardés dans le dossier C:\rsit
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
sur infecté !!!
==> Télécharger et enregistre sur ton bureau SDFix(créé par AndyManchesta)
==> Double cliquer sur SDFix.exe et choisir Install pour l'extraire dans un dossier dédié sur ton disque C:.
/!\ Démarre en mode sans échec : après le bip et avant le logo windows tapoter sur la touche F8 (ou F5): menu M.S.E..
==> Choisir son compte, pas celui de l'Administrateur ou autre.
==> Dérouler la liste des instructions ci-dessous :
Ouvrir le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
Appuyer sur Y pour commencer le processus de nettoyage.
Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
Appuyer sur une touche pour redémarrer le PC.
Le système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
Appuyer sur une touche pour finir l'exécution du script et charger les icônes du Bureau.
Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
Enfin, copier/coller le contenu du fichier Report.txt dans la prochaine réponse sur le forum
==> Télécharger et enregistre sur ton bureau SDFix(créé par AndyManchesta)
==> Double cliquer sur SDFix.exe et choisir Install pour l'extraire dans un dossier dédié sur ton disque C:.
/!\ Démarre en mode sans échec : après le bip et avant le logo windows tapoter sur la touche F8 (ou F5): menu M.S.E..
==> Choisir son compte, pas celui de l'Administrateur ou autre.
==> Dérouler la liste des instructions ci-dessous :
Ouvrir le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
Appuyer sur Y pour commencer le processus de nettoyage.
Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
Appuyer sur une touche pour redémarrer le PC.
Le système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
Appuyer sur une touche pour finir l'exécution du script et charger les icônes du Bureau.
Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
Enfin, copier/coller le contenu du fichier Report.txt dans la prochaine réponse sur le forum
Télécharge ad aware et ccleaner et sa devrait étre ok c pas un gros trucs tkt
ARRETEZ de dire n'importe quoi !
son pc est sur-infecté :(((((((((
ARRETEZ de dire n'importe quoi !
son pc est sur-infecté :(((((((((
ad adawe va pouvoir remplacer a lui seul ces outils :
usbfix
toolsbarsd
mbam
sdfix
et vu les infections a mon avis il en restera !!!
bah vive adware alors et mettons tous ces outils de desinfection a la corbeille alors
puisqu'ils ne servent a rien ...
usbfix
toolsbarsd
mbam
sdfix
et vu les infections a mon avis il en restera !!!
bah vive adware alors et mettons tous ces outils de desinfection a la corbeille alors
puisqu'ils ne servent a rien ...
je t'ai donné une procedure a suivre au post 3
commences deja par ca mais j'espere que t'es motivé car pour remettre ton pc a neuf, y'a du boulot
si tu suis ce que je te dis, aucun probleme, et je ne te laisse pas avant que ton pc soit sain :)
commences deja par ca mais j'espere que t'es motivé car pour remettre ton pc a neuf, y'a du boulot
si tu suis ce que je te dis, aucun probleme, et je ne te laisse pas avant que ton pc soit sain :)
slt jlp :)
tu dis pas bjr t'es de mauvaise humeur lol
edit :
c'est en relisant le topic que j'ai vu t'avais posté le 1er je te laisse ;)
dsl :)
tu dis pas bjr t'es de mauvaise humeur lol
edit :
c'est en relisant le topic que j'ai vu t'avais posté le 1er je te laisse ;)
dsl :)
oups
je pensais avoir fais ;)
slt neophyte*** !!!!!!!!!!!!!!!!!!
de plus
je te laisses finir ce post!
je pensais avoir fais ;)
slt neophyte*** !!!!!!!!!!!!!!!!!!
de plus
je te laisses finir ce post!
bon voila j ai fait ce que tu as di et voici le rapport
qu'en penses tu?
[b]SDFix: Version 1.240 [/b]
Run by Franck et B‚n‚ on 17/04/2009 at 19:43
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\Franck et B‚n‚\Mes documents\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Restoring Default HKCU HomePage
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\system32\p2hhr.bat - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-17 19:57:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ovfsthxlnpkmfdn]
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=str(2):"\systemroot\system32\drivers\ovfsthxcoedvcye.sys"
"inst"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ovfsthxlnpkmfdn\main]
"ver"="dec080409"
"cid"="01"
"bid"="214014085-602162358-1767777339-682003330"
"aid"="303369"
"sid"="16"
"feed"=hex:22,64,78,36,3c,2e,3b,29,39,3b,3b,3a,04,4f,01,0c,09,65
"cmddelay"=dword:00003841
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ovfsthxlnpkmfdn\modules]
"ovfsthx.sys"="\systemroot\system32\drivers\ovfsthxcoedvcye.sys"
"ovfsthx.dll"="\systemroot\system32\ovfsthxvaqggoov.dll"
"ovfsthxlog.dat"="\systemroot\system32\ovfsthxrjbtjdli.dat"
"ovfsthxwi.dll"="\systemroot\system32\ovfsthxyblondmy.dll"
"ovfsthxff.dll"="\systemroot\system32\ovfsthxnkcvoqov.dll"
"ovfsthx.dat"="\systemroot\system32\ovfsthxrrpuyxex.dat"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ovfsthxlnpkmfdn]
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=str(2):"\systemroot\system32\drivers\ovfsthxcoedvcye.sys"
"inst"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ovfsthxlnpkmfdn\main]
"ver"="dec080409"
"cid"="01"
"bid"="214014085-602162358-1767777339-682003330"
"aid"="303369"
"sid"="16"
"feed"=hex:22,64,78,36,3c,2e,3b,29,39,3b,3b,3a,04,4f,01,0c,09,65
"cmddelay"=dword:00003841
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ovfsthxlnpkmfdn\modules]
"ovfsthx.sys"="\systemroot\system32\drivers\ovfsthxcoedvcye.sys"
"ovfsthx.dll"="\systemroot\system32\ovfsthxvaqggoov.dll"
"ovfsthxlog.dat"="\systemroot\system32\ovfsthxrjbtjdli.dat"
"ovfsthxwi.dll"="\systemroot\system32\ovfsthxyblondmy.dll"
"ovfsthxff.dll"="\systemroot\system32\ovfsthxnkcvoqov.dll"
"ovfsthx.dat"="\systemroot\system32\ovfsthxrrpuyxex.dat"
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000002c4
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\eChanblard\\emule.exe"="C:\\Program Files\\eChanblard\\emule.exe:*:Enabled:eChanblard"
"C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"="C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\system32\\winlogon.exe"="C:\\WINDOWS\\system32\\winlogon.exe:*:Enabled:winlogon"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
[b]Remaining Files [/b]:
File Backups: - C:\DOCUME~1\FRANCK~1\MESDOC~1\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Tue 14 Apr 2009 38,962 ..SHR --- "C:\WINDOWS\iexploore.exe"
Fri 17 Apr 2009 29,696 ..SHR --- "C:\WINDOWS\taskmam.exe"
Mon 13 Apr 2009 38,962 ..SHR --- "C:\WINDOWS\winslogon.exe"
Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll"
Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll"
Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Thu 5 Mar 2009 2,260,480 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 22 Oct 2008 962,896 A.SH. --- "C:\Program Files\Spybot - Search & Destroy\Tools.dll"
Tue 13 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\gokozape.dll.tmp"
Sat 17 Jan 2009 49,152 A.SH. --- "C:\WINDOWS\system32\litugesi.dll"
Tue 14 Apr 2009 51,200 A.SH. --- "C:\WINDOWS\system32\madudori.exe"
Mon 13 Apr 2009 51,200 A.SH. --- "C:\WINDOWS\system32\nolagube.exe"
Fri 17 Apr 2009 49,152 A.SH. --- "C:\WINDOWS\system32\rudagitu.dll"
Sat 17 Jan 2009 49,152 A.SH. --- "C:\WINDOWS\system32\safodaru.dll"
Tue 13 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\semabawe.dll.tmp"
Fri 17 Apr 2009 79,872 A.SH. --- "C:\WINDOWS\system32\setelojo.dll"
Fri 16 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\tesusatu.dll.tmp"
Fri 16 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\tizoyate.dll.tmp"
Tue 13 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\tojojena.dll.tmp"
Fri 17 Apr 2009 87,552 A.SH. --- "C:\WINDOWS\system32\yefanopa.dll"
Fri 17 Apr 2009 87,552 A.SH. --- "C:\WINDOWS\system32\yoyaheku.dll"
Sat 17 Jan 2009 49,152 A.SH. --- "C:\WINDOWS\system32\zugovela.dll"
Fri 16 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\zuwupima.dll.tmp"
Sat 17 Jan 2009 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 3 Apr 2009 52,224 ...H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\~WRL0004.tmp"
Tue 21 Oct 2008 615,936 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL0005.tmp"
Tue 21 Oct 2008 389,120 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL0006.tmp"
Sat 3 Jan 2009 693,760 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL0007.tmp"
Tue 21 Oct 2008 449,536 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL0921.tmp"
Sun 30 Nov 2008 589,824 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL0929.tmp"
Sat 3 Jan 2009 606,720 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL1180.tmp"
Sat 3 Jan 2009 444,416 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL1430.tmp"
Sat 3 Jan 2009 585,216 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL2376.tmp"
Sun 30 Nov 2008 425,984 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL2572.tmp"
Tue 21 Oct 2008 545,792 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL2636.tmp"
Sat 3 Jan 2009 431,104 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL2752.tmp"
Tue 21 Oct 2008 486,400 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL3092.tmp"
Sun 30 Nov 2008 529,920 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL3204.tmp"
Sun 30 Nov 2008 466,432 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL3801.tmp"
Thu 7 Aug 2008 573,952 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\recette cuisine\~WRL0005.tmp"
Thu 7 Aug 2008 473,088 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\recette cuisine\~WRL1916.tmp"
Wed 6 Aug 2008 250,730 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Cafe\cafe.exe"
Mon 11 Aug 2008 244,602 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Cafe\cafestop.exe"
Wed 6 Aug 2008 244,752 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Catalogue\catalogue.exe"
Wed 6 Aug 2008 244,754 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Desktop\desktop.exe"
Mon 21 Jul 2008 82,518 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\PortableGIMP.exe"
Mon 21 Jul 2008 41,053 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoMath.exe"
Mon 21 Jul 2008 77,359 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOpenOffice.exe"
Mon 21 Jul 2008 41,056 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoWriter.exe"
Mon 21 Jul 2008 41,053 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoBase.exe"
Mon 21 Jul 2008 41,052 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoCalc.exe"
Mon 21 Jul 2008 41,053 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoDraw.exe"
Mon 21 Jul 2008 41,056 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoImpress.exe"
Mon 21 Jul 2008 81,873 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableNotepad2\PortableNotepad2.exe"
Mon 21 Jul 2008 56,762 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\Portable7-Zip.exe"
Mon 4 Aug 2008 113,706 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableaMSN\PortableaMSN.exe"
Mon 21 Jul 2008 100,044 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableClamWin\PortableClamWin.exe"
Tue 29 Jul 2008 102,177 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\PortableFirefox.exe"
Mon 14 May 2007 577,536 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableNotepad2\notepad2\Notepad2.exe"
Thu 6 Dec 2007 69,632 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\7-zip.dll"
Thu 6 Dec 2007 599,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\7z.dll"
Thu 6 Dec 2007 147,968 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\7z.exe"
Thu 6 Dec 2007 377,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\7zFM.exe"
Thu 6 Dec 2007 208,896 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\7zG.exe"
Tue 15 Apr 2008 59,302 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\Uninstall.exe"
Fri 24 Nov 2006 32,768 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableaMSN\amsn\amsn.exe"
Mon 4 Aug 2008 17,408 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\AccessibleMarshal.dll"
Mon 4 Aug 2008 185,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\crashreporter.exe"
Mon 4 Aug 2008 307,712 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\firefox.exe"
Mon 4 Aug 2008 233,472 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\freebl3.dll"
Mon 4 Aug 2008 695,296 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\js3250.dll"
Mon 4 Aug 2008 710,144 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\mozcrt19.dll"
Mon 4 Aug 2008 198,144 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\nspr4.dll"
Mon 4 Aug 2008 697,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\nss3.dll"
Mon 4 Aug 2008 304,640 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\nssckbi.dll"
Mon 4 Aug 2008 103,936 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\nssdbm3.dll"
Mon 4 Aug 2008 87,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\nssutil3.dll"
Mon 4 Aug 2008 20,480 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\plc4.dll"
Mon 4 Aug 2008 17,408 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\plds4.dll"
Mon 4 Aug 2008 103,936 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\smime3.dll"
Mon 4 Aug 2008 151,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\softokn3.dll"
Mon 4 Aug 2008 395,776 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\sqlite3.dll"
Mon 4 Aug 2008 136,704 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\ssl3.dll"
Mon 4 Aug 2008 241,664 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\updater.exe"
Mon 4 Aug 2008 17,920 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\xpcom.dll"
Mon 4 Aug 2008 9,704,960 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\xul.dll"
Sat 15 Apr 2006 70,704 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\bzip2.dll"
Sat 15 Apr 2006 119,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\bzip2.exe"
Sat 15 Apr 2006 3,686,960 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\gimp-2.2.exe"
Sat 15 Apr 2006 34,864 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\gimp-win-remote.exe"
Sat 15 Apr 2006 62,512 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpui-2.0-0.dll"
Sat 15 Apr 2006 902,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpwidgets-2.0-0.dll"
Sat 15 Apr 2006 23,088 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpmodule-2.0-0.dll"
Sat 15 Apr 2006 37,424 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpthumb-2.0-0.dll"
Sat 15 Apr 2006 98,352 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libart_lgpl_2-2.dll"
Sat 15 Apr 2006 222,256 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libcroco-0.6-3.dll"
Sat 15 Apr 2006 102,960 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libexif-10.dll"
Sat 15 Apr 2006 158,768 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimp-2.0-0.dll"
Sat 15 Apr 2006 56,368 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpbase-2.0-0.dll"
Sat 15 Apr 2006 44,592 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpcolor-2.0-0.dll"
Sat 15 Apr 2006 23,600 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpmath-2.0-0.dll"
Sat 15 Apr 2006 127,536 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgsf-1-1.dll"
Sat 15 Apr 2006 138,800 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\liblcms-1.dll"
Sat 15 Apr 2006 170,032 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\librsvg-2-2.dll"
Sat 15 Apr 2006 1,075,760 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libwmf-0-2-7.dll"
Sat 15 Apr 2006 107,056 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libwmflite-0-2-7.dll"
Sat 15 Apr 2006 1,002,544 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libxml2.dll"
Sat 15 Apr 2006 45,104 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libXpm-noX4.dll"
Sat 15 Apr 2006 7,728 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\minigzip.exe"
Sat 10 Jan 2004 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\asprintf.dll"
Sat 24 May 2003 4,608 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\charset.dll"
Sun 9 May 2004 221,184 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\freetype6.dll"
Tue 2 Aug 2005 20,954 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\gspawn-win32-helper.exe"
Sat 24 May 2003 634,368 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\iconv.dll"
Sat 10 Jan 2004 20,480 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\intl.dll"
Sun 15 May 2005 68,096 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\jpeg62.dll"
Sun 6 Feb 2005 81,921 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libatk-1.0-0.dll"
Sun 9 May 2004 66,864 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libexpat-0.dll"
Mon 12 Apr 2004 113,749 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libfontconfig-1.dll"
Tue 23 Aug 2005 630,781 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgdk-win32-2.0-0.dll"
Tue 23 Aug 2005 73,451 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgdk_pixbuf-2.0-0.dll"
Tue 2 Aug 2005 305,147 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libglib-2.0-0.dll"
Tue 2 Aug 2005 23,311 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgmodule-2.0-0.dll"
Tue 2 Aug 2005 135,527 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgobject-2.0-0.dll"
Tue 2 Aug 2005 26,933 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgthread-2.0-0.dll"
Tue 23 Aug 2005 1,580,196 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgtk-win32-2.0-0.dll"
Mon 23 May 2005 525,476 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgtkhtml-2-0.dll"
Wed 27 Jul 2005 149,668 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libpango-1.0-0.dll"
Wed 27 Jul 2005 102,655 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libpangoft2-1.0-0.dll"
Wed 27 Jul 2005 54,073 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libpangowin32-1.0-0.dll"
Thu 15 Jan 2004 121,913 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libpng12.dll"
Sat 4 Dec 2004 94,208 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libpng13.dll"
Sun 17 Jul 2005 126,976 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libtiff3.dll"
Wed 27 Jul 2005 20,407 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\pango-querymodules.exe"
Mon 22 May 2000 24,576 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\xmlparse.dll"
Fri 12 May 2000 22,528 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\xmltok.dll"
Sat 13 Dec 2003 40,960 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\zlib1.dll"
Fri 8 Feb 2008 29,696 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\abp680mi.dll"
Fri 25 Jan 2008 126,464 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\acc680mi.dll"
Wed 6 Feb 2008 16,384 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\acceptor.uno.dll"
Mon 21 Jan 2008 57,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\adabas2.dll"
Mon 21 Jan 2008 92,160 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ado2.dll"
Wed 19 Dec 2007 7,680 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\affine_uno_uno.dll"
Wed 19 Dec 2007 51,200 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\agg680mi.dll"
Wed 6 Feb 2008 69,632 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\analysis680mi.dll"
Wed 19 Dec 2007 24,064 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\animcore.dll"
Fri 8 Feb 2008 27,648 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\avmedia680mi.dll"
Fri 8 Feb 2008 23,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\avmediawin.dll"
Mon 11 Feb 2008 197,632 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\basctl680mi.dll"
Wed 19 Dec 2007 128,000 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\basegfx680mi.dll"
Fri 8 Feb 2008 21,504 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\basprov680mi.uno.dll"
Wed 19 Dec 2007 11,264 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\behelper.uno.dll"
Mon 21 Jan 2008 184,832 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_frm680mi.dll"
Mon 21 Jan 2008 25,600 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_go680mi.dll"
Mon 21 Jan 2008 14,336 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_migratefilter680mi.dll"
Mon 21 Jan 2008 11,264 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_ofa680mi.dll"
Mon 21 Jan 2008 122,880 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sb680mi.dll"
Mon 21 Jan 2008 657,920 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sc680mi.dll"
Mon 21 Jan 2008 171,008 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sch680mi.dll"
Mon 21 Jan 2008 154,624 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sd680mi.dll"
Mon 21 Jan 2008 85,504 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sm680mi.dll"
Mon 21 Jan 2008 125,952 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_so680mi.dll"
Mon 21 Jan 2008 785,408 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_svx680mi.dll"
Mon 21 Jan 2008 887,296 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sw680mi.dll"
Mon 21 Jan 2008 24,064 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_wrapper680mi.dll"
Mon 21 Jan 2008 558,592 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_xo680mi.dll"
Fri 8 Feb 2008 64,512 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bib680mi.dll"
Mon 21 Jan 2008 15,872 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bindet680mi.dll"
Wed 19 Dec 2007 102,400 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bootstrap.uno.dll"
Wed 19 Dec 2007 15,360 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bridgefac.uno.dll"
Wed 19 Dec 2007 33,280 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cached1.dll"
Mon 21 Jan 2008 39,936 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\calc680mi.dll"
Mon 21 Jan 2008 11,776 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\canvasfactory.uno.dll"
Mon 21 Jan 2008 85,504 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\canvastools680mi.dll"
Mon 11 Feb 2008 305,664 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\chartcontroller680mi.dll"
Mon 11 Feb 2008 127,488 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\chartmodel680mi.dll"
Fri 8 Feb 2008 192,512 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\charttools680mi.dll"
Mon 11 Feb 2008 199,168 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\chartview680mi.dll"
Wed 19 Dec 2007 114,688 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cli_uno.dll"
Mon 21 Jan 2008 533,504 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\collator_data.dll"
Mon 21 Jan 2008 16,384 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\communi680mi.dll"
Fri 18 Jan 2008 155,648 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\comphelp4MSC.dll"
Wed 19 Dec 2007 330,752 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\configmgr2.uno.dll"
Wed 19 Dec 2007 18,944 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\configimport.exe"
Wed 6 Feb 2008 15,360 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\connector.uno.dll"
Mon 21 Jan 2008 62,976 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cppcanvas680mi.dll"
Wed 19 Dec 2007 47,104 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cppu3.dll"
Wed 6 Feb 2008 120,320 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cppuhelper3MSC.dll"
Wed 19 Dec 2007 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\crashrep.com"
Wed 6 Feb 2008 145,920 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\crashrep.exe"
Mon 21 Jan 2008 32,256 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ctl680mi.dll"
Wed 12 Mar 2008 441,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cui680mi.dll"
Wed 6 Feb 2008 20,992 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\date680mi.dll"
Wed 12 Mar 2008 275,456 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dba680mi.dll"
Fri 8 Feb 2008 29,696 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbacfg680mi.dll"
Mon 21 Jan 2008 71,680 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbase680mi.dll"
Fri 8 Feb 2008 55,808 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbaxml680mi.dll"
Sat 14 Dec 2002 290,304 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbghelp.dll"
Fri 8 Feb 2008 38,400 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbp680mi.dll"
Mon 21 Jan 2008 24,064 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbpool2.dll"
Fri 8 Feb 2008 311,296 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbtools680mi.dll"
Wed 5 Mar 2008 590,848 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbu680mi.dll"
Fri 7 Mar 2008 97,280 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\deployment680mi.uno.dll"
Tue 26 Feb 2008 76,288 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\deploymentgui680mi.uno.dll"
Fri 7 Mar 2008 32,256 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\deploymentmisc680mi.dll"
Mon 21 Jan 2008 509,440 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dict_ja.dll"
Mon 21 Jan 2008 1,236,992 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dict_zh.dll"
Fri 8 Feb 2008 19,968 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dlgprov680mi.uno.dll"
Mon 21 Jan 2008 34,816 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dnd.dll"
Mon 21 Jan 2008 12,800 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dtrans.dll"
Mon 21 Jan 2008 10,240 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\egi680mi.dll"
Mon 21 Jan 2008 67,072 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\embobj.dll"
Mon 21 Jan 2008 49,664 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\emboleobj.dll"
Mon 21 Jan 2008 16,896 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\eme680mi.dll"
Mon 11 Feb 2008 75,264 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\emp680mi.dll"
Thu 24 Jan 2008 49,664 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\emser680mi.dll"
Mon 21 Jan 2008 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\epb680mi.dll"
Mon 21 Jan 2008 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\epg680mi.dll"
Mon 21 Jan 2008 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\epp680mi.dll"
Mon 21 Jan 2008 23,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\eps680mi.dll"
Mon 21 Jan 2008 16,384 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ept680mi.dll"
Mon 21 Jan 2008 6,144 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\era680mi.dll"
Mon 21 Jan 2008 7,680 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\eti680mi.dll"
Wed 19 Dec 2007 13,824 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\evtatt.dll"
Mon 21 Jan 2008 6,656 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\exp680mi.dll"
Mon 21 Jan 2008 103,424 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\file680mi.dll"
Mon 21 Jan 2008 15,872 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fileacc.dll"
Fri 8 Feb 2008 50,176 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\filterconfig1.dll"
Fri 8 Feb 2008 50,176 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\flash680mi.dll"
Mon 21 Jan 2008 39,936 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\flat680mi.dll"
Fri 1 Feb 2008 13,824 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fop.dll"
Mon 21 Jan 2008 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fpicker.uno.dll"
Fri 1 Feb 2008 35,328 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fps.dll"
Fri 1 Feb 2008 56,320 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fps_office.uno.dll"
Mon 11 Feb 2008 334,848 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\frm680mi.dll"
Mon 21 Jan 2008 25,600 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fsstorage.uno.dll"
Mon 21 Jan 2008 16,896 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ftransl.dll"
Fri 25 Jan 2008 102,912 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fwe680mi.dll"
Mon 21 Jan 2008 58,368 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fwi680mi.dll"
Tue 26 Feb 2008 402,944 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fwk680mi.dll"
Mon 21 Jan 2008 31,232 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fwl680mi.dll"
Fri 8 Feb 2008 26,112 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fwm680mi.dll"
Tue 18 Apr 2006 833,800 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\gdiplus.dll"
Mon 11 Feb 2008 13,824 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\gengal.exe"
Mon 21 Jan 2008 89,600 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\go680mi.dll"
Fri 8 Feb 2008 13,312 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\guesslang680mi.dll"
Mon 21 Jan 2008 16,896 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\hatchwindowfactory.uno.dll"
Mon 21 Jan 2008 59,392 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\helplinker680mi.dll"
Mon 21 Jan 2008 56,320 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\hsqldb2.dll"
Fri 8 Feb 2008 5,120 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\hunspell.dll"
Wed 19 Dec 2007 150,528 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\hwp.dll"
Fri 8 Feb 2008 20,992 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\hyphen680mi.dll"
Mon 21 Jan 2008 10,240 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\i18nisolang1MSC.dll"
Fri 8 Feb 2008 160,256 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\i18npool.uno.dll"
Mon 21 Jan 2008 13,312 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\i18nregexpMSC.dll"
Mon 21 Jan 2008 15,360 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\i18nsearch.uno.dll"
Mon 21 Jan 2008 18,432 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\i18nutilMSC.dll"
Mon 21 Jan 2008 6,656 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icd680mi.dll"
Mon 21 Jan 2008 36,864 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icg680mi.dll"
Fri 1 Feb 2008 3,069,952 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icudt36l.dll"
Fri 1 Feb 2008 372,736 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icuin36.dll"
Fri 1 Feb 2008 87,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icule36.dll"
Fri 1 Feb 2008 391,168 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icuuc36.dll"
Mon 21 Jan 2008 22,528 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\idx680mi.dll"
Mon 21 Jan 2008 17,408 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ime680mi.dll"
Mon 21 Jan 2008 160,256 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\index_data.dll"
Fri 18 Jan 2008 26,112 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\introspection.uno.dll"
Wed 19 Dec 2007 15,360 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\invocadapt.uno.dll"
Wed 19 Dec 2007 16,384 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\invocation.uno.dll"
Mon 21 Jan 2008 6,656 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ipb680mi.dll"
Mon 21 Jan 2008 7,680 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ipd680mi.dll"
Mon 21 Jan 2008 10,240 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ips680mi.dll"
Mon 21 Jan 2008 12,800 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ipt680mi.dll"
Mon 21 Jan 2008 7,168 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ipx680mi.dll"
Mon 21 Jan 2008 6,144 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ira680mi.dll"
Mon 21 Jan 2008 7,168 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\itg680mi.dll"
Mon 21 Jan 2008 16,384 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\iti680mi.dll"
Mon 21 Jan 2008 11,264 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\j680mi_g.dll"
Wed 19 Dec 2007 11,264 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\javaloader.uno.dll"
Wed 19 Dec 2007 27,136 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\javavm.uno.dll"
Thu 24 Jan 2008 31,232 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\java_uno.dll"
Mon 21 Jan 2008 8,192 A..H. --- "C:\Doc
qu'en penses tu?
[b]SDFix: Version 1.240 [/b]
Run by Franck et B‚n‚ on 17/04/2009 at 19:43
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\Franck et B‚n‚\Mes documents\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Restoring Default HKCU HomePage
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\system32\p2hhr.bat - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-17 19:57:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ovfsthxlnpkmfdn]
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=str(2):"\systemroot\system32\drivers\ovfsthxcoedvcye.sys"
"inst"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ovfsthxlnpkmfdn\main]
"ver"="dec080409"
"cid"="01"
"bid"="214014085-602162358-1767777339-682003330"
"aid"="303369"
"sid"="16"
"feed"=hex:22,64,78,36,3c,2e,3b,29,39,3b,3b,3a,04,4f,01,0c,09,65
"cmddelay"=dword:00003841
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ovfsthxlnpkmfdn\modules]
"ovfsthx.sys"="\systemroot\system32\drivers\ovfsthxcoedvcye.sys"
"ovfsthx.dll"="\systemroot\system32\ovfsthxvaqggoov.dll"
"ovfsthxlog.dat"="\systemroot\system32\ovfsthxrjbtjdli.dat"
"ovfsthxwi.dll"="\systemroot\system32\ovfsthxyblondmy.dll"
"ovfsthxff.dll"="\systemroot\system32\ovfsthxnkcvoqov.dll"
"ovfsthx.dat"="\systemroot\system32\ovfsthxrrpuyxex.dat"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ovfsthxlnpkmfdn]
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=str(2):"\systemroot\system32\drivers\ovfsthxcoedvcye.sys"
"inst"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ovfsthxlnpkmfdn\main]
"ver"="dec080409"
"cid"="01"
"bid"="214014085-602162358-1767777339-682003330"
"aid"="303369"
"sid"="16"
"feed"=hex:22,64,78,36,3c,2e,3b,29,39,3b,3b,3a,04,4f,01,0c,09,65
"cmddelay"=dword:00003841
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ovfsthxlnpkmfdn\modules]
"ovfsthx.sys"="\systemroot\system32\drivers\ovfsthxcoedvcye.sys"
"ovfsthx.dll"="\systemroot\system32\ovfsthxvaqggoov.dll"
"ovfsthxlog.dat"="\systemroot\system32\ovfsthxrjbtjdli.dat"
"ovfsthxwi.dll"="\systemroot\system32\ovfsthxyblondmy.dll"
"ovfsthxff.dll"="\systemroot\system32\ovfsthxnkcvoqov.dll"
"ovfsthx.dat"="\systemroot\system32\ovfsthxrrpuyxex.dat"
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000002c4
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\eChanblard\\emule.exe"="C:\\Program Files\\eChanblard\\emule.exe:*:Enabled:eChanblard"
"C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"="C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\system32\\winlogon.exe"="C:\\WINDOWS\\system32\\winlogon.exe:*:Enabled:winlogon"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
[b]Remaining Files [/b]:
File Backups: - C:\DOCUME~1\FRANCK~1\MESDOC~1\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Tue 14 Apr 2009 38,962 ..SHR --- "C:\WINDOWS\iexploore.exe"
Fri 17 Apr 2009 29,696 ..SHR --- "C:\WINDOWS\taskmam.exe"
Mon 13 Apr 2009 38,962 ..SHR --- "C:\WINDOWS\winslogon.exe"
Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll"
Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll"
Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Thu 5 Mar 2009 2,260,480 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 22 Oct 2008 962,896 A.SH. --- "C:\Program Files\Spybot - Search & Destroy\Tools.dll"
Tue 13 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\gokozape.dll.tmp"
Sat 17 Jan 2009 49,152 A.SH. --- "C:\WINDOWS\system32\litugesi.dll"
Tue 14 Apr 2009 51,200 A.SH. --- "C:\WINDOWS\system32\madudori.exe"
Mon 13 Apr 2009 51,200 A.SH. --- "C:\WINDOWS\system32\nolagube.exe"
Fri 17 Apr 2009 49,152 A.SH. --- "C:\WINDOWS\system32\rudagitu.dll"
Sat 17 Jan 2009 49,152 A.SH. --- "C:\WINDOWS\system32\safodaru.dll"
Tue 13 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\semabawe.dll.tmp"
Fri 17 Apr 2009 79,872 A.SH. --- "C:\WINDOWS\system32\setelojo.dll"
Fri 16 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\tesusatu.dll.tmp"
Fri 16 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\tizoyate.dll.tmp"
Tue 13 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\tojojena.dll.tmp"
Fri 17 Apr 2009 87,552 A.SH. --- "C:\WINDOWS\system32\yefanopa.dll"
Fri 17 Apr 2009 87,552 A.SH. --- "C:\WINDOWS\system32\yoyaheku.dll"
Sat 17 Jan 2009 49,152 A.SH. --- "C:\WINDOWS\system32\zugovela.dll"
Fri 16 Jan 2009 48,640 A.SH. --- "C:\WINDOWS\system32\zuwupima.dll.tmp"
Sat 17 Jan 2009 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 3 Apr 2009 52,224 ...H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\~WRL0004.tmp"
Tue 21 Oct 2008 615,936 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL0005.tmp"
Tue 21 Oct 2008 389,120 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL0006.tmp"
Sat 3 Jan 2009 693,760 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL0007.tmp"
Tue 21 Oct 2008 449,536 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL0921.tmp"
Sun 30 Nov 2008 589,824 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL0929.tmp"
Sat 3 Jan 2009 606,720 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL1180.tmp"
Sat 3 Jan 2009 444,416 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL1430.tmp"
Sat 3 Jan 2009 585,216 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL2376.tmp"
Sun 30 Nov 2008 425,984 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL2572.tmp"
Tue 21 Oct 2008 545,792 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL2636.tmp"
Sat 3 Jan 2009 431,104 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL2752.tmp"
Tue 21 Oct 2008 486,400 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL3092.tmp"
Sun 30 Nov 2008 529,920 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL3204.tmp"
Sun 30 Nov 2008 466,432 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\~WRL3801.tmp"
Thu 7 Aug 2008 573,952 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\recette cuisine\~WRL0005.tmp"
Thu 7 Aug 2008 473,088 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\recette cuisine\~WRL1916.tmp"
Wed 6 Aug 2008 250,730 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Cafe\cafe.exe"
Mon 11 Aug 2008 244,602 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Cafe\cafestop.exe"
Wed 6 Aug 2008 244,752 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Catalogue\catalogue.exe"
Wed 6 Aug 2008 244,754 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Desktop\desktop.exe"
Mon 21 Jul 2008 82,518 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\PortableGIMP.exe"
Mon 21 Jul 2008 41,053 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoMath.exe"
Mon 21 Jul 2008 77,359 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOpenOffice.exe"
Mon 21 Jul 2008 41,056 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoWriter.exe"
Mon 21 Jul 2008 41,053 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoBase.exe"
Mon 21 Jul 2008 41,052 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoCalc.exe"
Mon 21 Jul 2008 41,053 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoDraw.exe"
Mon 21 Jul 2008 41,056 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\PortableOoImpress.exe"
Mon 21 Jul 2008 81,873 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableNotepad2\PortableNotepad2.exe"
Mon 21 Jul 2008 56,762 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\Portable7-Zip.exe"
Mon 4 Aug 2008 113,706 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableaMSN\PortableaMSN.exe"
Mon 21 Jul 2008 100,044 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableClamWin\PortableClamWin.exe"
Tue 29 Jul 2008 102,177 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\PortableFirefox.exe"
Mon 14 May 2007 577,536 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableNotepad2\notepad2\Notepad2.exe"
Thu 6 Dec 2007 69,632 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\7-zip.dll"
Thu 6 Dec 2007 599,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\7z.dll"
Thu 6 Dec 2007 147,968 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\7z.exe"
Thu 6 Dec 2007 377,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\7zFM.exe"
Thu 6 Dec 2007 208,896 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\7zG.exe"
Tue 15 Apr 2008 59,302 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\Portable7-Zip\7-Zip\Uninstall.exe"
Fri 24 Nov 2006 32,768 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableaMSN\amsn\amsn.exe"
Mon 4 Aug 2008 17,408 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\AccessibleMarshal.dll"
Mon 4 Aug 2008 185,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\crashreporter.exe"
Mon 4 Aug 2008 307,712 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\firefox.exe"
Mon 4 Aug 2008 233,472 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\freebl3.dll"
Mon 4 Aug 2008 695,296 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\js3250.dll"
Mon 4 Aug 2008 710,144 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\mozcrt19.dll"
Mon 4 Aug 2008 198,144 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\nspr4.dll"
Mon 4 Aug 2008 697,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\nss3.dll"
Mon 4 Aug 2008 304,640 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\nssckbi.dll"
Mon 4 Aug 2008 103,936 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\nssdbm3.dll"
Mon 4 Aug 2008 87,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\nssutil3.dll"
Mon 4 Aug 2008 20,480 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\plc4.dll"
Mon 4 Aug 2008 17,408 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\plds4.dll"
Mon 4 Aug 2008 103,936 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\smime3.dll"
Mon 4 Aug 2008 151,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\softokn3.dll"
Mon 4 Aug 2008 395,776 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\sqlite3.dll"
Mon 4 Aug 2008 136,704 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\ssl3.dll"
Mon 4 Aug 2008 241,664 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\updater.exe"
Mon 4 Aug 2008 17,920 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\xpcom.dll"
Mon 4 Aug 2008 9,704,960 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableFirefox\firefox\xul.dll"
Sat 15 Apr 2006 70,704 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\bzip2.dll"
Sat 15 Apr 2006 119,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\bzip2.exe"
Sat 15 Apr 2006 3,686,960 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\gimp-2.2.exe"
Sat 15 Apr 2006 34,864 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\gimp-win-remote.exe"
Sat 15 Apr 2006 62,512 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpui-2.0-0.dll"
Sat 15 Apr 2006 902,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpwidgets-2.0-0.dll"
Sat 15 Apr 2006 23,088 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpmodule-2.0-0.dll"
Sat 15 Apr 2006 37,424 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpthumb-2.0-0.dll"
Sat 15 Apr 2006 98,352 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libart_lgpl_2-2.dll"
Sat 15 Apr 2006 222,256 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libcroco-0.6-3.dll"
Sat 15 Apr 2006 102,960 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libexif-10.dll"
Sat 15 Apr 2006 158,768 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimp-2.0-0.dll"
Sat 15 Apr 2006 56,368 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpbase-2.0-0.dll"
Sat 15 Apr 2006 44,592 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpcolor-2.0-0.dll"
Sat 15 Apr 2006 23,600 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgimpmath-2.0-0.dll"
Sat 15 Apr 2006 127,536 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libgsf-1-1.dll"
Sat 15 Apr 2006 138,800 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\liblcms-1.dll"
Sat 15 Apr 2006 170,032 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\librsvg-2-2.dll"
Sat 15 Apr 2006 1,075,760 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libwmf-0-2-7.dll"
Sat 15 Apr 2006 107,056 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libwmflite-0-2-7.dll"
Sat 15 Apr 2006 1,002,544 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libxml2.dll"
Sat 15 Apr 2006 45,104 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\libXpm-noX4.dll"
Sat 15 Apr 2006 7,728 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gimp\bin\minigzip.exe"
Sat 10 Jan 2004 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\asprintf.dll"
Sat 24 May 2003 4,608 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\charset.dll"
Sun 9 May 2004 221,184 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\freetype6.dll"
Tue 2 Aug 2005 20,954 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\gspawn-win32-helper.exe"
Sat 24 May 2003 634,368 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\iconv.dll"
Sat 10 Jan 2004 20,480 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\intl.dll"
Sun 15 May 2005 68,096 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\jpeg62.dll"
Sun 6 Feb 2005 81,921 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libatk-1.0-0.dll"
Sun 9 May 2004 66,864 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libexpat-0.dll"
Mon 12 Apr 2004 113,749 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libfontconfig-1.dll"
Tue 23 Aug 2005 630,781 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgdk-win32-2.0-0.dll"
Tue 23 Aug 2005 73,451 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgdk_pixbuf-2.0-0.dll"
Tue 2 Aug 2005 305,147 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libglib-2.0-0.dll"
Tue 2 Aug 2005 23,311 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgmodule-2.0-0.dll"
Tue 2 Aug 2005 135,527 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgobject-2.0-0.dll"
Tue 2 Aug 2005 26,933 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgthread-2.0-0.dll"
Tue 23 Aug 2005 1,580,196 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgtk-win32-2.0-0.dll"
Mon 23 May 2005 525,476 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libgtkhtml-2-0.dll"
Wed 27 Jul 2005 149,668 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libpango-1.0-0.dll"
Wed 27 Jul 2005 102,655 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libpangoft2-1.0-0.dll"
Wed 27 Jul 2005 54,073 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libpangowin32-1.0-0.dll"
Thu 15 Jan 2004 121,913 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libpng12.dll"
Sat 4 Dec 2004 94,208 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libpng13.dll"
Sun 17 Jul 2005 126,976 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\libtiff3.dll"
Wed 27 Jul 2005 20,407 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\pango-querymodules.exe"
Mon 22 May 2000 24,576 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\xmlparse.dll"
Fri 12 May 2000 22,528 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\xmltok.dll"
Sat 13 Dec 2003 40,960 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableGIMP\gtk\bin\zlib1.dll"
Fri 8 Feb 2008 29,696 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\abp680mi.dll"
Fri 25 Jan 2008 126,464 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\acc680mi.dll"
Wed 6 Feb 2008 16,384 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\acceptor.uno.dll"
Mon 21 Jan 2008 57,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\adabas2.dll"
Mon 21 Jan 2008 92,160 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ado2.dll"
Wed 19 Dec 2007 7,680 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\affine_uno_uno.dll"
Wed 19 Dec 2007 51,200 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\agg680mi.dll"
Wed 6 Feb 2008 69,632 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\analysis680mi.dll"
Wed 19 Dec 2007 24,064 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\animcore.dll"
Fri 8 Feb 2008 27,648 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\avmedia680mi.dll"
Fri 8 Feb 2008 23,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\avmediawin.dll"
Mon 11 Feb 2008 197,632 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\basctl680mi.dll"
Wed 19 Dec 2007 128,000 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\basegfx680mi.dll"
Fri 8 Feb 2008 21,504 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\basprov680mi.uno.dll"
Wed 19 Dec 2007 11,264 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\behelper.uno.dll"
Mon 21 Jan 2008 184,832 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_frm680mi.dll"
Mon 21 Jan 2008 25,600 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_go680mi.dll"
Mon 21 Jan 2008 14,336 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_migratefilter680mi.dll"
Mon 21 Jan 2008 11,264 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_ofa680mi.dll"
Mon 21 Jan 2008 122,880 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sb680mi.dll"
Mon 21 Jan 2008 657,920 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sc680mi.dll"
Mon 21 Jan 2008 171,008 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sch680mi.dll"
Mon 21 Jan 2008 154,624 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sd680mi.dll"
Mon 21 Jan 2008 85,504 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sm680mi.dll"
Mon 21 Jan 2008 125,952 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_so680mi.dll"
Mon 21 Jan 2008 785,408 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_svx680mi.dll"
Mon 21 Jan 2008 887,296 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_sw680mi.dll"
Mon 21 Jan 2008 24,064 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_wrapper680mi.dll"
Mon 21 Jan 2008 558,592 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bf_xo680mi.dll"
Fri 8 Feb 2008 64,512 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bib680mi.dll"
Mon 21 Jan 2008 15,872 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bindet680mi.dll"
Wed 19 Dec 2007 102,400 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bootstrap.uno.dll"
Wed 19 Dec 2007 15,360 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\bridgefac.uno.dll"
Wed 19 Dec 2007 33,280 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cached1.dll"
Mon 21 Jan 2008 39,936 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\calc680mi.dll"
Mon 21 Jan 2008 11,776 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\canvasfactory.uno.dll"
Mon 21 Jan 2008 85,504 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\canvastools680mi.dll"
Mon 11 Feb 2008 305,664 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\chartcontroller680mi.dll"
Mon 11 Feb 2008 127,488 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\chartmodel680mi.dll"
Fri 8 Feb 2008 192,512 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\charttools680mi.dll"
Mon 11 Feb 2008 199,168 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\chartview680mi.dll"
Wed 19 Dec 2007 114,688 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cli_uno.dll"
Mon 21 Jan 2008 533,504 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\collator_data.dll"
Mon 21 Jan 2008 16,384 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\communi680mi.dll"
Fri 18 Jan 2008 155,648 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\comphelp4MSC.dll"
Wed 19 Dec 2007 330,752 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\configmgr2.uno.dll"
Wed 19 Dec 2007 18,944 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\configimport.exe"
Wed 6 Feb 2008 15,360 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\connector.uno.dll"
Mon 21 Jan 2008 62,976 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cppcanvas680mi.dll"
Wed 19 Dec 2007 47,104 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cppu3.dll"
Wed 6 Feb 2008 120,320 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cppuhelper3MSC.dll"
Wed 19 Dec 2007 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\crashrep.com"
Wed 6 Feb 2008 145,920 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\crashrep.exe"
Mon 21 Jan 2008 32,256 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ctl680mi.dll"
Wed 12 Mar 2008 441,856 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\cui680mi.dll"
Wed 6 Feb 2008 20,992 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\date680mi.dll"
Wed 12 Mar 2008 275,456 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dba680mi.dll"
Fri 8 Feb 2008 29,696 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbacfg680mi.dll"
Mon 21 Jan 2008 71,680 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbase680mi.dll"
Fri 8 Feb 2008 55,808 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbaxml680mi.dll"
Sat 14 Dec 2002 290,304 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbghelp.dll"
Fri 8 Feb 2008 38,400 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbp680mi.dll"
Mon 21 Jan 2008 24,064 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbpool2.dll"
Fri 8 Feb 2008 311,296 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbtools680mi.dll"
Wed 5 Mar 2008 590,848 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dbu680mi.dll"
Fri 7 Mar 2008 97,280 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\deployment680mi.uno.dll"
Tue 26 Feb 2008 76,288 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\deploymentgui680mi.uno.dll"
Fri 7 Mar 2008 32,256 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\deploymentmisc680mi.dll"
Mon 21 Jan 2008 509,440 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dict_ja.dll"
Mon 21 Jan 2008 1,236,992 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dict_zh.dll"
Fri 8 Feb 2008 19,968 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dlgprov680mi.uno.dll"
Mon 21 Jan 2008 34,816 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dnd.dll"
Mon 21 Jan 2008 12,800 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\dtrans.dll"
Mon 21 Jan 2008 10,240 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\egi680mi.dll"
Mon 21 Jan 2008 67,072 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\embobj.dll"
Mon 21 Jan 2008 49,664 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\emboleobj.dll"
Mon 21 Jan 2008 16,896 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\eme680mi.dll"
Mon 11 Feb 2008 75,264 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\emp680mi.dll"
Thu 24 Jan 2008 49,664 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\emser680mi.dll"
Mon 21 Jan 2008 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\epb680mi.dll"
Mon 21 Jan 2008 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\epg680mi.dll"
Mon 21 Jan 2008 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\epp680mi.dll"
Mon 21 Jan 2008 23,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\eps680mi.dll"
Mon 21 Jan 2008 16,384 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ept680mi.dll"
Mon 21 Jan 2008 6,144 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\era680mi.dll"
Mon 21 Jan 2008 7,680 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\eti680mi.dll"
Wed 19 Dec 2007 13,824 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\evtatt.dll"
Mon 21 Jan 2008 6,656 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\exp680mi.dll"
Mon 21 Jan 2008 103,424 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\file680mi.dll"
Mon 21 Jan 2008 15,872 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fileacc.dll"
Fri 8 Feb 2008 50,176 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\filterconfig1.dll"
Fri 8 Feb 2008 50,176 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\flash680mi.dll"
Mon 21 Jan 2008 39,936 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\flat680mi.dll"
Fri 1 Feb 2008 13,824 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fop.dll"
Mon 21 Jan 2008 8,192 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fpicker.uno.dll"
Fri 1 Feb 2008 35,328 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fps.dll"
Fri 1 Feb 2008 56,320 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fps_office.uno.dll"
Mon 11 Feb 2008 334,848 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\frm680mi.dll"
Mon 21 Jan 2008 25,600 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fsstorage.uno.dll"
Mon 21 Jan 2008 16,896 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ftransl.dll"
Fri 25 Jan 2008 102,912 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fwe680mi.dll"
Mon 21 Jan 2008 58,368 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fwi680mi.dll"
Tue 26 Feb 2008 402,944 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fwk680mi.dll"
Mon 21 Jan 2008 31,232 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fwl680mi.dll"
Fri 8 Feb 2008 26,112 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\fwm680mi.dll"
Tue 18 Apr 2006 833,800 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\gdiplus.dll"
Mon 11 Feb 2008 13,824 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\gengal.exe"
Mon 21 Jan 2008 89,600 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\go680mi.dll"
Fri 8 Feb 2008 13,312 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\guesslang680mi.dll"
Mon 21 Jan 2008 16,896 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\hatchwindowfactory.uno.dll"
Mon 21 Jan 2008 59,392 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\helplinker680mi.dll"
Mon 21 Jan 2008 56,320 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\hsqldb2.dll"
Fri 8 Feb 2008 5,120 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\hunspell.dll"
Wed 19 Dec 2007 150,528 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\hwp.dll"
Fri 8 Feb 2008 20,992 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\hyphen680mi.dll"
Mon 21 Jan 2008 10,240 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\i18nisolang1MSC.dll"
Fri 8 Feb 2008 160,256 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\i18npool.uno.dll"
Mon 21 Jan 2008 13,312 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\i18nregexpMSC.dll"
Mon 21 Jan 2008 15,360 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\i18nsearch.uno.dll"
Mon 21 Jan 2008 18,432 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\i18nutilMSC.dll"
Mon 21 Jan 2008 6,656 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icd680mi.dll"
Mon 21 Jan 2008 36,864 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icg680mi.dll"
Fri 1 Feb 2008 3,069,952 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icudt36l.dll"
Fri 1 Feb 2008 372,736 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icuin36.dll"
Fri 1 Feb 2008 87,552 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icule36.dll"
Fri 1 Feb 2008 391,168 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\icuuc36.dll"
Mon 21 Jan 2008 22,528 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\idx680mi.dll"
Mon 21 Jan 2008 17,408 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ime680mi.dll"
Mon 21 Jan 2008 160,256 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\index_data.dll"
Fri 18 Jan 2008 26,112 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\introspection.uno.dll"
Wed 19 Dec 2007 15,360 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\invocadapt.uno.dll"
Wed 19 Dec 2007 16,384 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\invocation.uno.dll"
Mon 21 Jan 2008 6,656 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ipb680mi.dll"
Mon 21 Jan 2008 7,680 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ipd680mi.dll"
Mon 21 Jan 2008 10,240 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ips680mi.dll"
Mon 21 Jan 2008 12,800 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ipt680mi.dll"
Mon 21 Jan 2008 7,168 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ipx680mi.dll"
Mon 21 Jan 2008 6,144 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\ira680mi.dll"
Mon 21 Jan 2008 7,168 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\itg680mi.dll"
Mon 21 Jan 2008 16,384 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\iti680mi.dll"
Mon 21 Jan 2008 11,264 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\j680mi_g.dll"
Wed 19 Dec 2007 11,264 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\javaloader.uno.dll"
Wed 19 Dec 2007 27,136 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\javavm.uno.dll"
Thu 24 Jan 2008 31,232 A..H. --- "C:\Documents and Settings\Franck et B‚n‚\Mes documents\BENE A GARDER\Ma musique\elie\Sony Ericsson\dist\win32\Apps\PortableOpenOffice\OpenOffice\program\java_uno.dll"
Mon 21 Jan 2008 8,192 A..H. --- "C:\Doc
qu'en penses tu?
que c'est bien mais qui y a encore du boulot :
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
que c'est bien mais qui y a encore du boulot :
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Franck et Béné ( Administrator )
BOOT : Normal boot
Antivirus : Symantec AntiVirus Corporate Edition 10.1.4.4000 (Activated)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:11 Go)
D:\ (Local Disk) - NTFS - Total:38 Go (Free:7 Go)
E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 17/04/2009|20:33 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\4_elements16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\about.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\action.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\airport_mania_first_flight16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\alice_greenfingers216x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\arcade.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\bejeweled_twist16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\buy.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\call_of_atlantis16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\cards.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\chicken_invaders_3_xmas16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\color_cross16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\deals.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\download.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\dream_day_wedding_216x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\feedback.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\help.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\highlight.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\jigsaw.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\kids.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mahjong.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mygames.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mystery_pi_the_vegas_heist16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\my_tribe16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\newGames.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\oberonconfig.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\onload
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\partner.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_off.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_on.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\puzzle.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\saqqarah16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sendafriend.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sherlock_holmes16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sports.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\treasures_of_mystery_island16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\trial.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\uninstall.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\update.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\virtual_pool316x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\womens_murder_club_fr16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\onload\loading.gif
C:\Program Files\GamesBar
C:\Program Files\GamesBar\Localization2-French.ini
C:\Program Files\GamesBar\oberontb.dll
C:\Program Files\GamesBar\uninst.exe
C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\GamesBar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.google.com/webhp?gws_rd=ssl"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="http://www.ustart.org"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
1 - "C:\ToolBar SD\TB_1.txt" - 17/04/2009|20:34 - Option : [1]
-----------\\ Fin du rapport a 20:34:04,07
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Franck et Béné ( Administrator )
BOOT : Normal boot
Antivirus : Symantec AntiVirus Corporate Edition 10.1.4.4000 (Activated)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:11 Go)
D:\ (Local Disk) - NTFS - Total:38 Go (Free:7 Go)
E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 17/04/2009|20:33 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\4_elements16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\about.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\action.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\airport_mania_first_flight16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\alice_greenfingers216x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\arcade.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\bejeweled_twist16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\buy.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\call_of_atlantis16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\cards.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\chicken_invaders_3_xmas16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\color_cross16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\deals.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\download.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\dream_day_wedding_216x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\feedback.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\help.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\highlight.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\jigsaw.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\kids.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mahjong.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mygames.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mystery_pi_the_vegas_heist16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\my_tribe16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\newGames.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\oberonconfig.xm_
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\onload
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\partner.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_off.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_on.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\puzzle.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\saqqarah16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sendafriend.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sherlock_holmes16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sports.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\treasures_of_mystery_island16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\trial.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\uninstall.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\update.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\virtual_pool316x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\womens_murder_club_fr16x16.gif
C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\onload\loading.gif
C:\Program Files\GamesBar
C:\Program Files\GamesBar\Localization2-French.ini
C:\Program Files\GamesBar\oberontb.dll
C:\Program Files\GamesBar\uninst.exe
C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\GamesBar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.google.com/webhp?gws_rd=ssl"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="http://www.ustart.org"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
1 - "C:\ToolBar SD\TB_1.txt" - 17/04/2009|20:34 - Option : [1]
-----------\\ Fin du rapport a 20:34:04,07
salut comme prevu j ai refait tolbar voici le rapport
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Franck et Béné ( Administrator )
BOOT : Normal boot
Antivirus : Symantec AntiVirus Corporate Edition 10.1.4.4000 (Activated)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:11 Go)
D:\ (Local Disk) - NTFS - Total:38 Go (Free:7 Go)
E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 18/04/2009| 8:36 )
-----------\\ SUPPRESSION
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\4_elements16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\about.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\action.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\airport_mania_first_flight16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\alice_greenfingers216x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\arcade.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\bejeweled_twist16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\buy.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\call_of_atlantis16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\cards.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\chicken_invaders_3_xmas16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\color_cross16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\deals.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\download.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\dream_day_wedding_216x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\feedback.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\help.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\highlight.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\jigsaw.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\kids.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mahjong.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mygames.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mystery_pi_the_vegas_heist16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\my_tribe16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\newGames.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\oberonconfig.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\onload
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\partner.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_off.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_on.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\puzzle.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\saqqarah16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sendafriend.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sherlock_holmes16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sports.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\treasures_of_mystery_island16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\trial.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\uninstall.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\update.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\virtual_pool316x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\womens_murder_club_fr16x16.gif
Supprime! - C:\Program Files\GamesBar\Localization2-French.ini
Supprime! - C:\Program Files\GamesBar\oberontb.dll
Supprime! - C:\Program Files\GamesBar\uninst.exe
Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\GamesBar
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
Supprime! - C:\Program Files\GamesBar
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="http://www.freeart1cile.com"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
1 - "C:\ToolBar SD\TB_1.txt" - 17/04/2009|20:34 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 18/04/2009| 8:38 - Option : [2]
-----------\\ Fin du rapport a 8:38:14,67
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Franck et Béné ( Administrator )
BOOT : Normal boot
Antivirus : Symantec AntiVirus Corporate Edition 10.1.4.4000 (Activated)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:11 Go)
D:\ (Local Disk) - NTFS - Total:38 Go (Free:7 Go)
E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 18/04/2009| 8:36 )
-----------\\ SUPPRESSION
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\4_elements16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\about.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\action.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\airport_mania_first_flight16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\alice_greenfingers216x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\arcade.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\bejeweled_twist16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\buy.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\call_of_atlantis16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\cards.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\chicken_invaders_3_xmas16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\color_cross16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\deals.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\download.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\dream_day_wedding_216x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\feedback.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\help.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\highlight.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\jigsaw.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\kids.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mahjong.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mygames.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\mystery_pi_the_vegas_heist16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\my_tribe16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\newGames.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\oberonconfig.xm_
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\onload
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\partner.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_off.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\popup_on.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\puzzle.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\saqqarah16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\search.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sendafriend.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sherlock_holmes16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\sports.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\treasures_of_mystery_island16x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\trial.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\uninstall.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\update.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\virtual_pool316x16.gif
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar\womens_murder_club_fr16x16.gif
Supprime! - C:\Program Files\GamesBar\Localization2-French.ini
Supprime! - C:\Program Files\GamesBar\oberontb.dll
Supprime! - C:\Program Files\GamesBar\uninst.exe
Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\GamesBar
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
Supprime! - C:\Program Files\GamesBar
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="http://www.freeart1cile.com"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
1 - "C:\ToolBar SD\TB_1.txt" - 17/04/2009|20:34 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 18/04/2009| 8:38 - Option : [2]
-----------\\ Fin du rapport a 8:38:14,67
slt luceva
tres bien tu peux faire maintenant ce que jlp t'a dit au post 20 MBAM ET RSIT
tres bien tu peux faire maintenant ce que jlp t'a dit au post 20 MBAM ET RSIT
voila la suite la c'est le rapport mbam et je fais a present rsit
Malwarebytes' Anti-Malware 1.36
Version de la base de données: 1998
Windows 5.1.2600 Service Pack 3
18/04/2009 10:25:03
mbam-log-2009-04-18 (10-25-03).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 151897
Temps écoulé: 1 hour(s), 30 minute(s), 42 second(s)
Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 6
Clé(s) du Registre infectée(s): 10
Valeur(s) du Registre infectée(s): 7
Elément(s) de données du Registre infecté(s): 7
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 28
Processus mémoire infecté(s):
C:\WINDOWS\taskmam.exe (Backdoor.Bot) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\lemetuku.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\litugesi.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\zugovela.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\safodaru.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\juruzuhu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\jh9fgo4ksdgf.dll (Trojan.Ertfor) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{d7bf4552-94f1-42bd-f434-3604812c856d} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d1a0d754-8148-4505-8935-6b27fbfafd3d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d1a0d754-8148-4505-8935-6b27fbfafd3d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d7bf4552-94f1-42bd-f434-3604812c856d} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d7bf4552-94f1-42bd-f434-3604812c856d} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d1a0d754-8148-4505-8935-6b27fbfafd3d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\0cc1982a (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\badozerati (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm0ff2abb6 (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{d7bf4552-94f1-42bd-f434-3604812c856d} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\diagnostic manager (Trojan.Downloader) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\litugesi.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\litugesi.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\juruzuhu.dll -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://freeart1cile.com) Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\lemetuku.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\ukutemel.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\zugovela.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\juruzuhu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\jh9fgo4ksdgf.dll (Trojan.Zlob.H) -> Delete on reboot.
C:\WINDOWS\system32\litugesi.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\safodaru.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Documents and Settings\Franck et Béné\Mes documents\MSNFix\backup\fxstaller.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Franck et Béné\Mes documents\MSNFix\backup\xdyx.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Program Files\eChanblard\EvID4226Patch.exe (Malware.Tool) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{77F3E34F-0EF3-4EDB-A75E-6D7AEAF03F0C}\RP117\A0025265.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{77F3E34F-0EF3-4EDB-A75E-6D7AEAF03F0C}\RP117\A0025269.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\fxstaller.MSNFix (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ak1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rudagitu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gokozape.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\semabawe.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tesusatu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tizoyate.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tojojena.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\zuwupima.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\madudori.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ovfsthxvaqggoov.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ovfsthxrjbtjdli.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ovfsthxrrpuyxex.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\taskmam.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Franck et Béné\Local Settings\Temp\646191400.exe (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\Franck et Béné\Local Settings\Temp\ovfsthxbvfewiwqio.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.36
Version de la base de données: 1998
Windows 5.1.2600 Service Pack 3
18/04/2009 10:25:03
mbam-log-2009-04-18 (10-25-03).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 151897
Temps écoulé: 1 hour(s), 30 minute(s), 42 second(s)
Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 6
Clé(s) du Registre infectée(s): 10
Valeur(s) du Registre infectée(s): 7
Elément(s) de données du Registre infecté(s): 7
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 28
Processus mémoire infecté(s):
C:\WINDOWS\taskmam.exe (Backdoor.Bot) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\lemetuku.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\litugesi.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\zugovela.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\safodaru.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\juruzuhu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\jh9fgo4ksdgf.dll (Trojan.Ertfor) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{d7bf4552-94f1-42bd-f434-3604812c856d} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d1a0d754-8148-4505-8935-6b27fbfafd3d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d1a0d754-8148-4505-8935-6b27fbfafd3d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d7bf4552-94f1-42bd-f434-3604812c856d} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d7bf4552-94f1-42bd-f434-3604812c856d} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d1a0d754-8148-4505-8935-6b27fbfafd3d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\0cc1982a (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\badozerati (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm0ff2abb6 (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{d7bf4552-94f1-42bd-f434-3604812c856d} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\diagnostic manager (Trojan.Downloader) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\litugesi.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\litugesi.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\juruzuhu.dll -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://freeart1cile.com) Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\lemetuku.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\ukutemel.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\zugovela.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\juruzuhu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\jh9fgo4ksdgf.dll (Trojan.Zlob.H) -> Delete on reboot.
C:\WINDOWS\system32\litugesi.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\safodaru.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Documents and Settings\Franck et Béné\Mes documents\MSNFix\backup\fxstaller.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Franck et Béné\Mes documents\MSNFix\backup\xdyx.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Program Files\eChanblard\EvID4226Patch.exe (Malware.Tool) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{77F3E34F-0EF3-4EDB-A75E-6D7AEAF03F0C}\RP117\A0025265.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{77F3E34F-0EF3-4EDB-A75E-6D7AEAF03F0C}\RP117\A0025269.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\fxstaller.MSNFix (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ak1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rudagitu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gokozape.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\semabawe.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tesusatu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tizoyate.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tojojena.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\zuwupima.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\madudori.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ovfsthxvaqggoov.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ovfsthxrjbtjdli.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ovfsthxrrpuyxex.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\taskmam.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Franck et Béné\Local Settings\Temp\646191400.exe (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\Franck et Béné\Local Settings\Temp\ovfsthxbvfewiwqio.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
voici le 1er rapport
info.txt logfile of random's system information tool 1.06 2009-04-18 10:33:06
======Uninstall list======
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{363435F2-7426-11D8-9966-00A0C9663221}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC067AB0-2594-4A7E-A1DE-ADEB7D15EB4B}\setup.exe" -l0x40c
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABBYY FineReader 5.0 Sprint-->MsiExec.exe /X{D1696920-9794-4BBC-8A30-7A88763DE5A2}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
Apple Mobile Device Support-->MsiExec.exe /I{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}
Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
ArcSoft Multimedia Email-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD54CF66-090B-43E7-97C1-110EF526474D}\SETUP.EXE" -l0x40c -uninst
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
Bonjour-->MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch-->C:\Program Files\InstallShield Installation Information\{E5141379-B2D9-4BBC-BB2A-5805541571DD}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch-->C:\Program Files\InstallShield Installation Information\{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch-->C:\Program Files\InstallShield Installation Information\{8503C901-85D7-4262-88D2-8D8B2A7B08B8}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch-->C:\Program Files\InstallShield Installation Information\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch-->C:\Program Files\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x040c
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Cossacks - Back To War-->C:\WINDOWS\una2setup.exe
Creative WebCam Center-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{363435F2-7426-11D8-9966-00A0C9663221}\setup.exe" -l0x40c /remove
Creative WebCam Vista Plus Driver (1.00.05.0906)-->C:\WINDOWS\CtDrvIns.exe -uninstall -script VF0090.uns -unsext NT -plugin V0090Pin.dll -pluginres CtCamPin.crl
Cross Fire En-->"C:\CrossFire\unins000.exe"
Dofus 1.27.0-->C:\Program Files\Dofus\uninstall.exe
FaxTools-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F45298E5-0083-426F-A668-1A2C5F04B8A0}\setup.exe" -l0x40c ControlPanel
Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
HijackThis 2.0.2-->"C:\Documents and Settings\Franck et Béné\Local Settings\Temporary Internet Files\Content.IE5\JZ7CO8HP\HijackThis.exe" /uninstall
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
Installer Yahoo! Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC067AB0-2594-4A7E-A1DE-ADEB7D15EB4B}\setup.exe" -l0x40c /remove
iTunes-->MsiExec.exe /I{3DE0053C-FD9A-483E-B7C9-B06E4392206E}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
Lexmark X1100 Series-->C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBKUN5C.EXE -dLexmark X1100 Series
livebox-->C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly
LiveUpdate 3.0 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Manuel d'utilisation de Creative WebCam Vista Plus (Français)-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Creative\Creative WebCam Vista Plus\Manuel d'utilisation de Creative WebCam Vista Plus\French\CTManual.isu"
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 CD-ROM 2-->MsiExec.exe /I{0004040C-78E1-11D2-B60F-006097C998E7}
Microsoft Office 2000 Professional-->MsiExec.exe /I{0001040C-78E1-11D2-B60F-006097C998E7}
Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Navigateur Orange-->C:\Program Files\Orange\Uninstall\Browser\Shell.exe MainUninstall.shl
Nero 7 Ultra Edition-->MsiExec.exe /X{847CAE64-4CD2-4B2D-AF00-978FF5431036}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
Orange - Logiciels Internet-->C:\Program Files\Orange\installation\core\Installgui.exe -u
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
PCI Audio Driver-->cmuninst.exe
QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Sony Ericsson Themes Creator 3.19-->C:\Program Files\Sony Ericsson\Themes Creator\Uninstall.exe
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Symantec AntiVirus-->MsiExec.exe /I{78D891EF-9E2D-4FC8-A71F-E6F897BA1B21}
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Zuma Deluxe-->"C:\Program Files\orange\jeux\Zuma Deluxe\Uninstall.exe" "C:\Program Files\orange\jeux\Zuma Deluxe\install.log"
======Hosts File======
127.0.0.1 localhost
82.98.231.89 url.adtrgt.com
82.98.231.89 googleads2.gdoubleclick.net
======Security center information======
AV: Symantec AntiVirus Corporate Edition
======System event log======
Computer Name: BENEDICTE
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service PnkBstrB.
Record Number: 10539
Source Name: Service Control Manager
Time Written: 20090411122622.000000+120
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: BENEDICTE
Event Code: 7036
Message: Le service PnkBstrB est entré dans l'état : en cours d'exécution.
Record Number: 10538
Source Name: Service Control Manager
Time Written: 20090411122622.000000+120
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 7035
Message: Un contrôle Arrêter a correctement été envoyé au service PnkBstrB.
Record Number: 10537
Source Name: Service Control Manager
Time Written: 20090411122617.000000+120
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: BENEDICTE
Event Code: 7036
Message: Le service PnkBstrB est entré dans l'état : arrêté.
Record Number: 10536
Source Name: Service Control Manager
Time Written: 20090411122617.000000+120
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service NPPTNT2.
Record Number: 10535
Source Name: Service Control Manager
Time Written: 20090411122455.000000+120
Event Type: Informations
User: BENEDICTE\Franck et Béné
=====Application event log=====
Computer Name: BENEDICTE
Event Code: 14
Message:
Le démarrage des services Symantec AntiVirus a réussi.
Record Number: 1886
Source Name: Symantec AntiVirus
Time Written: 20090226173118.000000+060
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 0
Message:
Record Number: 1885
Source Name: NMIndexingService
Time Written: 20090226173057.000000+060
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 3
Message:
Analyse lancée sur lecteurs et dossiers sélectionnés et toutes les extensions.
Record Number: 1884
Source Name: Symantec AntiVirus
Time Written: 20090226173054.000000+060
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 1800
Message: Le service Centre de sécurité Windows a démarré.
Record Number: 1883
Source Name: SecurityCenter
Time Written: 20090226173054.000000+060
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 0
Message:
Record Number: 1882
Source Name: SeaPort
Time Written: 20090226173052.000000+060
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 43 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=2b01
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip
-----------------EOF-----------------
voilà le 2 eme rapport
Logfile of random's system information tool 1.06 (written by random/random)
Run by Franck et Béné at 2009-04-18 10:32:54
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 12 GB (15%) free of 76 GB
Total RAM: 2047 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:33:04, on 18/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Documents and Settings\Franck et Béné\Mes documents\RSIT.exe
C:\Program Files\trend micro\Franck et Béné.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O1 - Hosts: 82.98.231.89 url.adtrgt.com
O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Tasks Sheduler] taskmam.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Franck et Béné] C:\Documents and Settings\Franck et Béné\Franck et Béné.exe /i
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game14.zylom.com/activex/zylomgamesplayer.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\tuhuduta c:\windows\system32\bosurezo.dll C:\WINDOWS\system32\tuhuduta.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB (pnkbstrb) - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
info.txt logfile of random's system information tool 1.06 2009-04-18 10:33:06
======Uninstall list======
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{363435F2-7426-11D8-9966-00A0C9663221}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC067AB0-2594-4A7E-A1DE-ADEB7D15EB4B}\setup.exe" -l0x40c
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABBYY FineReader 5.0 Sprint-->MsiExec.exe /X{D1696920-9794-4BBC-8A30-7A88763DE5A2}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
Apple Mobile Device Support-->MsiExec.exe /I{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}
Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
ArcSoft Multimedia Email-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD54CF66-090B-43E7-97C1-110EF526474D}\SETUP.EXE" -l0x40c -uninst
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
Bonjour-->MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch-->C:\Program Files\InstallShield Installation Information\{E5141379-B2D9-4BBC-BB2A-5805541571DD}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch-->C:\Program Files\InstallShield Installation Information\{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch-->C:\Program Files\InstallShield Installation Information\{8503C901-85D7-4262-88D2-8D8B2A7B08B8}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch-->C:\Program Files\InstallShield Installation Information\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch-->C:\Program Files\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x040c
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Cossacks - Back To War-->C:\WINDOWS\una2setup.exe
Creative WebCam Center-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{363435F2-7426-11D8-9966-00A0C9663221}\setup.exe" -l0x40c /remove
Creative WebCam Vista Plus Driver (1.00.05.0906)-->C:\WINDOWS\CtDrvIns.exe -uninstall -script VF0090.uns -unsext NT -plugin V0090Pin.dll -pluginres CtCamPin.crl
Cross Fire En-->"C:\CrossFire\unins000.exe"
Dofus 1.27.0-->C:\Program Files\Dofus\uninstall.exe
FaxTools-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F45298E5-0083-426F-A668-1A2C5F04B8A0}\setup.exe" -l0x40c ControlPanel
Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
HijackThis 2.0.2-->"C:\Documents and Settings\Franck et Béné\Local Settings\Temporary Internet Files\Content.IE5\JZ7CO8HP\HijackThis.exe" /uninstall
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
Installer Yahoo! Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC067AB0-2594-4A7E-A1DE-ADEB7D15EB4B}\setup.exe" -l0x40c /remove
iTunes-->MsiExec.exe /I{3DE0053C-FD9A-483E-B7C9-B06E4392206E}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
Lexmark X1100 Series-->C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBKUN5C.EXE -dLexmark X1100 Series
livebox-->C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly
LiveUpdate 3.0 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Manuel d'utilisation de Creative WebCam Vista Plus (Français)-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Creative\Creative WebCam Vista Plus\Manuel d'utilisation de Creative WebCam Vista Plus\French\CTManual.isu"
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 CD-ROM 2-->MsiExec.exe /I{0004040C-78E1-11D2-B60F-006097C998E7}
Microsoft Office 2000 Professional-->MsiExec.exe /I{0001040C-78E1-11D2-B60F-006097C998E7}
Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Navigateur Orange-->C:\Program Files\Orange\Uninstall\Browser\Shell.exe MainUninstall.shl
Nero 7 Ultra Edition-->MsiExec.exe /X{847CAE64-4CD2-4B2D-AF00-978FF5431036}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
Orange - Logiciels Internet-->C:\Program Files\Orange\installation\core\Installgui.exe -u
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
PCI Audio Driver-->cmuninst.exe
QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Sony Ericsson Themes Creator 3.19-->C:\Program Files\Sony Ericsson\Themes Creator\Uninstall.exe
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Symantec AntiVirus-->MsiExec.exe /I{78D891EF-9E2D-4FC8-A71F-E6F897BA1B21}
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Zuma Deluxe-->"C:\Program Files\orange\jeux\Zuma Deluxe\Uninstall.exe" "C:\Program Files\orange\jeux\Zuma Deluxe\install.log"
======Hosts File======
127.0.0.1 localhost
82.98.231.89 url.adtrgt.com
82.98.231.89 googleads2.gdoubleclick.net
======Security center information======
AV: Symantec AntiVirus Corporate Edition
======System event log======
Computer Name: BENEDICTE
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service PnkBstrB.
Record Number: 10539
Source Name: Service Control Manager
Time Written: 20090411122622.000000+120
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: BENEDICTE
Event Code: 7036
Message: Le service PnkBstrB est entré dans l'état : en cours d'exécution.
Record Number: 10538
Source Name: Service Control Manager
Time Written: 20090411122622.000000+120
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 7035
Message: Un contrôle Arrêter a correctement été envoyé au service PnkBstrB.
Record Number: 10537
Source Name: Service Control Manager
Time Written: 20090411122617.000000+120
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: BENEDICTE
Event Code: 7036
Message: Le service PnkBstrB est entré dans l'état : arrêté.
Record Number: 10536
Source Name: Service Control Manager
Time Written: 20090411122617.000000+120
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service NPPTNT2.
Record Number: 10535
Source Name: Service Control Manager
Time Written: 20090411122455.000000+120
Event Type: Informations
User: BENEDICTE\Franck et Béné
=====Application event log=====
Computer Name: BENEDICTE
Event Code: 14
Message:
Le démarrage des services Symantec AntiVirus a réussi.
Record Number: 1886
Source Name: Symantec AntiVirus
Time Written: 20090226173118.000000+060
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 0
Message:
Record Number: 1885
Source Name: NMIndexingService
Time Written: 20090226173057.000000+060
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 3
Message:
Analyse lancée sur lecteurs et dossiers sélectionnés et toutes les extensions.
Record Number: 1884
Source Name: Symantec AntiVirus
Time Written: 20090226173054.000000+060
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 1800
Message: Le service Centre de sécurité Windows a démarré.
Record Number: 1883
Source Name: SecurityCenter
Time Written: 20090226173054.000000+060
Event Type: Informations
User:
Computer Name: BENEDICTE
Event Code: 0
Message:
Record Number: 1882
Source Name: SeaPort
Time Written: 20090226173052.000000+060
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 43 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=2b01
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip
-----------------EOF-----------------
voilà le 2 eme rapport
Logfile of random's system information tool 1.06 (written by random/random)
Run by Franck et Béné at 2009-04-18 10:32:54
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 12 GB (15%) free of 76 GB
Total RAM: 2047 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:33:04, on 18/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Documents and Settings\Franck et Béné\Mes documents\RSIT.exe
C:\Program Files\trend micro\Franck et Béné.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O1 - Hosts: 82.98.231.89 url.adtrgt.com
O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Tasks Sheduler] taskmam.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Franck et Béné] C:\Documents and Settings\Franck et Béné\Franck et Béné.exe /i
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game14.zylom.com/activex/zylomgamesplayer.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\tuhuduta c:\windows\system32\bosurezo.dll C:\WINDOWS\system32\tuhuduta.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB (pnkbstrb) - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Delete on reboot penses a redemarrer ton pc si ce n'est pas fait apres MBAM
(supprimé au redemarrage)
penses a vider la quarantaine de MBAM
ensuite
* Telecharge UsbFix de C_XX & Chiquitine29
http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe
* Lance l installation avec les parametres par default
* Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d'avoir été infectés sans les ouvrir
* Double clic sur le raccourci UsbFix sur ton bureau
* Choisi l'option 1 (recherche)
* Laisse travailler l'outil
* Ensuite post le rapport UsbFix.txt qui apparaîtra
* Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
* Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus
(supprimé au redemarrage)
penses a vider la quarantaine de MBAM
ensuite
* Telecharge UsbFix de C_XX & Chiquitine29
http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe
* Lance l installation avec les parametres par default
* Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d'avoir été infectés sans les ouvrir
* Double clic sur le raccourci UsbFix sur ton bureau
* Choisi l'option 1 (recherche)
* Laisse travailler l'outil
* Ensuite post le rapport UsbFix.txt qui apparaîtra
* Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
* Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus
le dernier rapport
############################## [ UsbFix V3.008 ]
# User : Franck et Béné (Administrateurs) # BENEDICTE
# Update on 13/04/09 by C_XX & Chiquitine29
# Start at: 10:53:33 | 18/04/2009
# AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# AV : Symantec AntiVirus Corporate Edition 10.1.4.4000 [ Enabled | Updated ]
# C:\ # Disque fixe local # 74,52 Go (11,51 Go free) # NTFS
# D:\ # Disque fixe local # 38,28 Go (7,63 Go free) # NTFS
# E:\ # Disque CD-ROM # 696,19 Mo (0 Mo free) [Mon disque] # CDFS
# F:\ # Disque amovible
# G:\ # Disque amovible
# H:\ # Disque amovible
# I:\ # Disque amovible
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Registre # Startup ]
HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
HKCU_Main: "Start Page"="https://www.google.com/?gws_rd=ssl"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="Franck et B‚n‚"
HKLM_logon: "AltDefaultUserName"="Franck et B‚n‚"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
HKCU_Run: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
HKCU_Run: Messenger (Yahoo!)="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKCU_Run: Franck et Béné=C:\Documents and Settings\Franck et Béné\Franck et Béné.exe /i
HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM_Run: nwiz=nwiz.exe /install
HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM_Run: C-Media Mixer=Mixer.exe /startup
HKLM_Run: ccApp="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
HKLM_Run: vptray=C:\PROGRA~1\SYMANT~1\VPTray.exe
HKLM_Run: NeroFilterCheck=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
HKLM_Run: SystrayORAHSS="C:\Program Files\Orange\Systray\SystrayApp.exe"
HKLM_Run: ORAHSSSessionManager=C:\Program Files\Orange\SessionManager\SessionManager.exe
HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM_Run: Lexmark X1100 Series="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
HKLM_Run: fssui="C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
HKLM_Run: AppleSyncNotifier=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
HKLM_Run: iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
HKLM_Run: Creative WebCam Tray=C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
HKLM_Run: Windows Tasks Sheduler=taskmam.exe
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
################## [ Informations ]
# -> ( Value | Good = 0x0 Bad = 0x1 )
# HKCU\SOFTWARE\...\Policies\System "DisableRegedit" = (0x0)
# HKCU\SOFTWARE\...\Policies\System "DisableRegistryTools" = (0x0)
# HKCU\SOFTWARE\...\Policies\System "DisableTaskMgr" = (0x0)
# HKLM\SOFTWARE\...\Policies\System "DisableRegedit" = (0x0)
# HKLM\SOFTWARE\...\Policies\System "DisableRegistryTools" = (0x0)
# HKLM\SOFTWARE\...\Policies\System "DisableTaskMgr" = (0x0)
################## [ Fichiers # Dossiers infectieux ]
################## [ Registre # Clés Run infectieuses ]
# -> Not Found !
################## [ Registre # Mountpoints2 ]
HKCU\Software\Microsoft\....\MountPoints2\{c8cc7823-e2b7-11dd-824d-001109d57772}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{d67b2fe3-ead6-11dd-825d-001109d57772}\Shell\AutoRun\command
################## [ ! Fin du rapport # UsbFix V3.008 ! ]
############################## [ UsbFix V3.008 ]
# User : Franck et Béné (Administrateurs) # BENEDICTE
# Update on 13/04/09 by C_XX & Chiquitine29
# Start at: 10:53:33 | 18/04/2009
# AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# AV : Symantec AntiVirus Corporate Edition 10.1.4.4000 [ Enabled | Updated ]
# C:\ # Disque fixe local # 74,52 Go (11,51 Go free) # NTFS
# D:\ # Disque fixe local # 38,28 Go (7,63 Go free) # NTFS
# E:\ # Disque CD-ROM # 696,19 Mo (0 Mo free) [Mon disque] # CDFS
# F:\ # Disque amovible
# G:\ # Disque amovible
# H:\ # Disque amovible
# I:\ # Disque amovible
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Registre # Startup ]
HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
HKCU_Main: "Start Page"="https://www.google.com/?gws_rd=ssl"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="Franck et B‚n‚"
HKLM_logon: "AltDefaultUserName"="Franck et B‚n‚"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
HKCU_Run: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
HKCU_Run: Messenger (Yahoo!)="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKCU_Run: Franck et Béné=C:\Documents and Settings\Franck et Béné\Franck et Béné.exe /i
HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM_Run: nwiz=nwiz.exe /install
HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM_Run: C-Media Mixer=Mixer.exe /startup
HKLM_Run: ccApp="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
HKLM_Run: vptray=C:\PROGRA~1\SYMANT~1\VPTray.exe
HKLM_Run: NeroFilterCheck=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
HKLM_Run: SystrayORAHSS="C:\Program Files\Orange\Systray\SystrayApp.exe"
HKLM_Run: ORAHSSSessionManager=C:\Program Files\Orange\SessionManager\SessionManager.exe
HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM_Run: Lexmark X1100 Series="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
HKLM_Run: fssui="C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
HKLM_Run: AppleSyncNotifier=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
HKLM_Run: iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
HKLM_Run: Creative WebCam Tray=C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
HKLM_Run: Windows Tasks Sheduler=taskmam.exe
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
################## [ Informations ]
# -> ( Value | Good = 0x0 Bad = 0x1 )
# HKCU\SOFTWARE\...\Policies\System "DisableRegedit" = (0x0)
# HKCU\SOFTWARE\...\Policies\System "DisableRegistryTools" = (0x0)
# HKCU\SOFTWARE\...\Policies\System "DisableTaskMgr" = (0x0)
# HKLM\SOFTWARE\...\Policies\System "DisableRegedit" = (0x0)
# HKLM\SOFTWARE\...\Policies\System "DisableRegistryTools" = (0x0)
# HKLM\SOFTWARE\...\Policies\System "DisableTaskMgr" = (0x0)
################## [ Fichiers # Dossiers infectieux ]
################## [ Registre # Clés Run infectieuses ]
# -> Not Found !
################## [ Registre # Mountpoints2 ]
HKCU\Software\Microsoft\....\MountPoints2\{c8cc7823-e2b7-11dd-824d-001109d57772}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{d67b2fe3-ead6-11dd-825d-001109d57772}\Shell\AutoRun\command
################## [ ! Fin du rapport # UsbFix V3.008 ! ]
* Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectés sans les ouvrir
* Double clic sur le raccourci UsbFix présent sur ton bureau
* choisi l'option 2 ( Suppression )
* Ton bureau disparaîtra et le pc redémarrera .
* Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
* Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .
* Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
ENSUITE
Télécharge RHosts (de SiRi)
Double clique dessus pour l'exécuter
et cliques sur " Restore original Hosts "
ps : c est normal que rien ne se passe
ensuire redémarre le pc
^^ ON t'avait prevenu que y'aurait du taf lol, mais on s'approche de la fin ;)
* Double clic sur le raccourci UsbFix présent sur ton bureau
* choisi l'option 2 ( Suppression )
* Ton bureau disparaîtra et le pc redémarrera .
* Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
* Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .
* Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
ENSUITE
Télécharge RHosts (de SiRi)
Double clique dessus pour l'exécuter
et cliques sur " Restore original Hosts "
ps : c est normal que rien ne se passe
ensuire redémarre le pc
^^ ON t'avait prevenu que y'aurait du taf lol, mais on s'approche de la fin ;)
############################## [ UsbFix V3.008 ]
# User : Franck et Béné (Administrateurs) # BENEDICTE
# Update on 13/04/09 by C_XX & Chiquitine29
# Start at: 11:23:44 | 18/04/2009
# AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# AV : Symantec AntiVirus Corporate Edition 10.1.4.4000 [ Enabled | Updated ]
# C:\ # Disque fixe local # 74,52 Go (11,51 Go free) # NTFS
# D:\ # Disque fixe local # 38,28 Go (7,63 Go free) # NTFS
# E:\ # Disque CD-ROM # 696,19 Mo (0 Mo free) [Mon disque] # CDFS
# F:\ # Disque amovible
# G:\ # Disque amovible
# H:\ # Disque amovible
# I:\ # Disque amovible
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wscntfy.exe
################## [ Fichiers # Dossiers infectieux ]
################## [ Registre # Clés Run infectieuses ]
# -> Not Found !
################## [ Registre # Mountpoints2 ]
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{c8cc7823-e2b7-11dd-824d-001109d57772}\Shell\AutoRun\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{d67b2fe3-ead6-11dd-825d-001109d57772}\Shell\AutoRun\command
################## [ Listing des fichiers présent ]
C:\AUTOEXEC.BAT
C:\NTDETECT.COM
C:\boot.ini
################## [ Vaccination ]
# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
################## [ ! Fin du rapport # UsbFix V3.008 ! ]
# User : Franck et Béné (Administrateurs) # BENEDICTE
# Update on 13/04/09 by C_XX & Chiquitine29
# Start at: 11:23:44 | 18/04/2009
# AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# AV : Symantec AntiVirus Corporate Edition 10.1.4.4000 [ Enabled | Updated ]
# C:\ # Disque fixe local # 74,52 Go (11,51 Go free) # NTFS
# D:\ # Disque fixe local # 38,28 Go (7,63 Go free) # NTFS
# E:\ # Disque CD-ROM # 696,19 Mo (0 Mo free) [Mon disque] # CDFS
# F:\ # Disque amovible
# G:\ # Disque amovible
# H:\ # Disque amovible
# I:\ # Disque amovible
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wscntfy.exe
################## [ Fichiers # Dossiers infectieux ]
################## [ Registre # Clés Run infectieuses ]
# -> Not Found !
################## [ Registre # Mountpoints2 ]
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{c8cc7823-e2b7-11dd-824d-001109d57772}\Shell\AutoRun\command
Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{d67b2fe3-ead6-11dd-825d-001109d57772}\Shell\AutoRun\command
################## [ Listing des fichiers présent ]
C:\AUTOEXEC.BAT
C:\NTDETECT.COM
C:\boot.ini
################## [ Vaccination ]
# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
################## [ ! Fin du rapport # UsbFix V3.008 ! ]