Problème antivirus XP 2010

Fermé
Gilraen - 15 mars 2010 à 22:28
 Utilisateur anonyme - 1 avril 2010 à 23:17
Bonjour,
Comme beaucoup je me suis chopé cette saleté d'antivirus XP 2010.
Je n'avais plus accès à internet par explorer mais ai réussi à contourner par Mozilla.
Le souci, c'est que je n'ai plus accès à mon panneau de config et à certaines de mes applic quand je double clic. J'ai éditer un rapport avec list&kill'em comme conseillé, je le poste ci dessous.

D'avance, un énorme merci à ceux qui pourraient m'aider.

Rapport :
List'em by g3n-h@ckm@n 1.3.2.3


Boot: Normal


¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

C:\Program Files\List_Kill'em\List_Kill'em.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\List_Kill'em\FxEx.scr
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\List_Kill'em\pv.exe

======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
MsnMsgr REG_SZ "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
Skype REG_SZ "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
HControl REG_SZ C:\WINDOWS\ATK0100\HControl.exe
Power_Gear REG_SZ C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
Wireless Console REG_SZ C:\Program Files\ASUS\Wireless Console\wcourier.exe
SynTPLpr REG_SZ C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz REG_SZ nwiz.exe /install
Zshutdown REG_SZ c:\sysprep\patch\sysprep.cmd
<NO NAME> REG_SZ
IntelWireless REG_SZ C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
EOUApp REG_SZ C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
NeroFilterCheck REG_SZ C:\WINDOWS\system32\NeroCheck.exe
InCD REG_SZ C:\Program Files\Ahead\InCD\InCD.exe
Raccourci vers la page des propriétés de High Definition Audio REG_SZ HDAShCut.exe
RemoteControl REG_SZ "C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"
QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
Omnipage REG_SZ C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
RTHDCPL REG_SZ RTHDCPL.EXE
Alcmtr REG_SZ ALCMTR.EXE
AVG8_TRAY REG_SZ C:\PROGRA~1\AVG\AVG8\avgtray.exe
Sony Ericsson PC Suite REG_SZ "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
BboxUpdate REG_SZ C:\Program Files\BboxUpdate\BTLiveUpdate.exe

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)

===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 36 (0x24)
NoDriveAutoRun REG_BINARY ffffffff

===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
HonorAutoRunSetting REG_DWORD 1 (0x1)

===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLS REG_SZ

===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
AutoRestartShell REG_DWORD 1 (0x1)
DefaultDomainName REG_SZ SANDRA11
DefaultUserName REG_SZ Sandra
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 1 (0x1)
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
DefaultPassword REG_SZ
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ Sandra
AltDefaultDomainName REG_SZ SANDRA11
ChangePasswordUseKerberos REG_DWORD 1 (0x1)

===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe REG_SZ C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Disabled:Kodak Software Updater
C:\Program Files\MSN Messenger\msnmsgr.exe REG_SZ C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
C:\Program Files\MSN Messenger\livecall.exe REG_SZ C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
C:\Program Files\Zattoo\Zattoo1.exe REG_SZ C:\Program Files\Zattoo\Zattoo1.exe:*:Enabled:
C:\Program Files\ScanSoft\OmniPageSE\EregEng\NAVBrowser.exe REG_SZ C:\Program Files\ScanSoft\OmniPageSE\EregEng\NAVBrowser.exe:*:Disabled:NAVBrowser
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\Zattoo\zattood.exe REG_SZ C:\Program Files\Zattoo\zattood.exe:*:Disabled:zattood
C:\Program Files\AVG\AVG8\avgupd.exe REG_SZ C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe
C:\Program Files\AVG\AVG8\avgnsx.exe REG_SZ C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe
E:\eSKernel.exe REG_SZ E:\eSKernel.exe:*:Enabled:Bbox assistant d'installation
C:\Program Files\Bbox\eSKernel.exe REG_SZ C:\Program Files\Bbox\eSKernel.exe:*:Enabled:Bbox assistant d'installation
C:\Program Files\BboxUpdate\BTLiveUpdate.exe REG_SZ C:\Program Files\BboxUpdate\BTLiveUpdate.exe:*:Enabled:Bbox - Bouygues Telecom - Utilitaire de mise à jour
C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
C:\Program Files\MSN Messenger\msnmsgr.exe REG_SZ C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
C:\Program Files\MSN Messenger\livecall.exe REG_SZ C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

===============
ActivX controls
===============
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\Microsoft XML Parser for Java]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{09C21411-B9A2-4DE6-8416-4E3B58577BE0}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}]

===============
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\WriteRegStr]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{12322000-FC00-BC00-0000-123220000001}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{166B1BCA-3F9C-11CF-8075-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]

==============
BHO :
======
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

===
DNS
===


================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ http://www.blackle.com/

========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

Ndisuio : 0x3 ( OK = 3 )
EapHost : 0x3 ( OK = 2 )
SharedAccess : 0x2 ( OK = 2 )
wuauserv : 0x2 ( OK = 2 )

=========
Atapi.sys
=========

%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
##
95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\SoftwareDistribution\Download\44b6174a4a693136d02d4a7ecd7cbd54\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\SoftwareDistribution\Download\44b6174a4a693136d02d4a7ecd7cbd54\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys

Référence :
==========

Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
Win XP_32b : a64013e98426e1877cb653685c5c0009
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

=======
Drive :
=======


¤¤¤¤¤¤¤¤¤¤ Files/folders :

Present !! : C:\WINDOWS\003158_.tmp
Present !! : C:\WINDOWS\000001_.tmp
Present !! : C:\WINDOWS\000002_.tmp
Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
Present !! : C:\Documents and Settings\Sandra\Application Data\wklnhst.dat
Present !! : C:\Documents and Settings\Sandra\Application Data\wklnhst.dat
Present !! : C:\Documents and Settings\Sandra\Local Settings\Application Data\av.exe
Present !! : C:\Documents and Settings\Sandra\Local Settings\Temp\dw.log
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\nircmd.exe
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\engine.exe
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\_is65.exe
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\regtdi.exe
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\_is66.exe
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\AVRES_OPTRF_LiveUpdate.dat
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\symcprop.dat
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\SymSCLiveUpdate.dat
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\IadHide5.dll
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\huffyuv.dll
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\DivXc32.dll
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\DivXc32f.dll
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\4.0.0.9-EasyShrx.Dll
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp569.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp55B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp599.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp574.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp581.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp580.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp56D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp57C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp589.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp577.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp58F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp597.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp600.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp593.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp5A4.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp584.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp585.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp5A0.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp5A7.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp596.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp5B7.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp588.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp5B9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp5EF.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp60D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp949.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp628.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp656.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp630.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp590.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp5C5.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp956.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp592.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp950.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp610.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp629.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp989.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp59D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp62E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp57D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp936.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp638.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp619.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp958.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp631.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp612.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6EB.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp62A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp965.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp64C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp5C4.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6EE.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6F0.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp76F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6F2.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp944.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6F4.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6F6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp939.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6F8.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp941.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6FA.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp93D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6FC.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp93C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp94B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp9E6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp95B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp94E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp937.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp969.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp93B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp942.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp95F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp97A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp96B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpB9B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpAD5.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp77.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp8.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpAE.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp94.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp139.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp7.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp207.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp110.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp14.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp49.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp30.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp16.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp37.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp44.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp4D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp4C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpE5.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp68.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpB9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp47.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp5A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp80.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp60.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp96.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp8C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp152.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp72.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp6D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp157.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp98.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp161.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp81.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp189.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp169.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp181.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp177.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp17B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp7E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp82.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp190.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp19C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1A9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1A2.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1B6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1BD.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp7F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1BF.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1C1.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1C4.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1C6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1C9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1CB.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1CE.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1D2.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1D4.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1D6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1DB.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1DD.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1DF.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp84.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp86.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp88.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp8A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp8D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp8E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp104.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp92.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp107.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp90.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpD2.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp9A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp9C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpA0.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpC1.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpA3.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpDD.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp109.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpA6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpA8.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpAA.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpFF.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpAD.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp101.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpE0.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp153.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpD5.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpD7.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpDC.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp122.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpE1.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpE3.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpE6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpE8.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpEB.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpC2.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpCF.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpE2.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpD3.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpE9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpD6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpED.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpFD.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp10B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp10D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp10F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp11C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp11E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp12F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp212.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp160.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp136.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp14A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp167.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp13D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp13F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp144.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp165.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp150.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp194.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpDF.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1A6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpEA.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpEC.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmpEE.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp15A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp137.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1B3.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp140.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp15C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp13A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp170.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp149.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1B9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp13E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp14C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp14E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp185.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp18A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp18F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp191.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp171.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1A1.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp158.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp193.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1D5.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1F3.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp22B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp22D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp22F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp231.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp15B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp15D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp251.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp198.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp16D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1B4.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp197.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp19D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1A3.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1AA.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1C2.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1C5.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1CA.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1F9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1F4.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1DA.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1DC.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp20A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1E0.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1FD.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp229.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1E3.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1CC.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1AB.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp247.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1E8.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp25A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1EB.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp25C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp2CE.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1A0.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp211.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp28C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1A4.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1AC.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp20B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp20D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp241.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp29B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp29D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp29F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp222.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp2C6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp2C9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp20F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp2CB.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1B5.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1C3.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1C7.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1CD.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1D8.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1E2.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1DE.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1CF.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp250.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1EC.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1E9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1E1.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1D9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1F5.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1FA.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp20C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp252.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp203.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1E7.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp259.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp216.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1ED.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp224.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1F6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp219.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp200.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp1FB.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp227.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp204.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp21E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp24C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp420.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp238.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp24E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp21F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp422.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp230.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp234.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp22A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp22E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp39C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp24B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp424.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp233.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp432.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp239.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp24F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp23E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp413.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp419.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp242.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp25B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp206.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp225.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp2BC.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp416.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp28D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp29C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp3E4.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp430.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp3C2.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp3E6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp40A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp2EA.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp40D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp215.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp217.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp41B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp41D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp33A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp313.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp434.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp454.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp232.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp43B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp443.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp456.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp447.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp437.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp439.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp22C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp43F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp445.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp235.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp505.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp441.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp23A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp23F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp45C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp45F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp30E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp24D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp30B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp25D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp320.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp240.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp23B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp346.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp2EB.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp30F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp2E5.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp321.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp30C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp357.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp371.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp327.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp338.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp341.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp392.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp33B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp358.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp33D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp33F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp343.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp345.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp3AF.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp349.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp34C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp364.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp34E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp34A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp370.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp384.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp368.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp397.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp363.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp38D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp41E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp39D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp3A4.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp36C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp36E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp35C.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp35E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp35D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp361.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp36B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp38B.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp36A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp362.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp360.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp365.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp477.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp369.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp36F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp3D9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp471.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp3D7.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp3C6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp3DA.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp409.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp43E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp475.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp488.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp499.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp4B6.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp4AF.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp4A5.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp4AE.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp4CF.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp4E4.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp4E8.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp511.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp50E.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp4C7.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp538.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp515.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp510.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp56F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp514.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp4D9.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp51A.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp534.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp540.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp52D.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp542.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp54F.tmp
Present !! : C:\Documents and Settings\Sandra\LOCAL Settings\Temp\tmp51D.tmp

¤¤¤¤¤¤¤¤¤¤ Keys :

Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Present !! : HKCR\secfile
Present !! : HKLM\Software\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}

============

driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-15 22:12:28
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: error reading MBR
kernel: error reading MBR


¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

C:\Illustrator 10\Adobe_Illustrator_10.0_Supergege\Crack.exe
C:\Photoshop 7\Adobe_Photoshop_7.0_Supergege\Crack.exe




¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

End of scan : 22:13:11,35
A voir également:

10 réponses

Utilisateur anonyme
15 mars 2010 à 22:32
Bonjour

Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
mais cette fois-ci :

. choisis l'option 2 = Mode Suppression

laisse travailler l'outil.

en fin de scan un rapport s'ouvre

. colle le contenu dans ta reponse


Fais sa Télécharge rkill
https://download.bleepingcomputer.com/grinler/rkill.exe
Enregistre-le sur ton Bureau
Double-clique sur l'icone rkill ( pour Vista/Seven clic-droit Exécuter en tant qu'Administrateur)
Un bref écran noir t'indiquera que le tool s'est correctement exécuter, s'il ne lance pas
change de lien de téléchargement en utilisant le suivant à partir d'ici:
http://download.bleepingcomputer.com/grinler/rkill.pif
https://download.bleepingcomputer.com/grinler/rkill.scr
https://download.bleepingcomputer.com/grinler/rkill.com

une fois qu'il aura terminé


Téléchargez MalwareByte's Anti-Malware

http://www.malwarebytes.org/mbam/program/mbam-setup.exe

. Enregistres le sur le bureau
. Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
. Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
. Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
. Une fois la mise à jour terminé
. Rend-toi dans l'onglet, Recherche
. Sélectionnes Exécuter un examen complet (examen assez long)
. Cliques sur Rechercher
. Le scan démarre.
. A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
. Cliques sur Ok pour poursuivre.
. Si des malwares ont été détectés, clique sur Afficher les résultats
. Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
. Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
. Rends toi dans l'onglet rapport/log
. Tu cliques dessus pour l'afficher, une fois affiché
. Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
. Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
. tu cliques droit dans le cadre de la reponse et coller


Si tu as besoin d'aide regarde ces tutoriels :
Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

PUIS

Télécharge ici : http://images.malwareremoval.com/random/RSIT.exe
random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.
• Double-clique sur RSIT.exe afin de lancer RSIT.(Avec VISTA/7 > clic-droit et > Exécuter en tant qu'administrateur.
• Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).
• Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
• Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.
• Poste le contenu de log.txt ainsi que info.txt
( tu peux héberger les rapports ici http://www.cijoint.fr/ et me joindre dans ton prochain message le lien )
0
Merci beaucoup pour cette réponse rapide.
J'ai fait une restauration du system ce midi en revenant une semaine en arrière et tout refonctionne normalement. Seulement, je suppose que le virus est toujours dans le système et peut revenir à tout instant et donc qu'il faut que je suive tes instructions pour le supprimer?
Je dois repartir au boulot (pas bcp de tps pour déjeuner) mais je lance tout çà ce soir et t'envoie les rapports.

Encore merci
à +

Gilraen
0
Utilisateur anonyme
16 mars 2010 à 18:02
les virus infecte la restauration du système fais quand même la procédure au dessus
0
OK,
voilà le rapport obtenu après avoir lancé Kill'em en mode supression, je continue la procédure comme tu me l'as indiqué:

Kill'em by g3n-h@ckm@n 1.3.2.3

User : Sandra (Administrateurs)
Update on 15/03/2010 by g3n-h@ckm@n ::::: 00.30
Start at: 22:06:23 | 16/03/2010
Contact : https://forums.commentcamarche.net/forum/virus-securite-7

Intel(R) Pentium(R) M processor 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 7.0.5730.13
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]

C:\ -> Disque fixe local | 43,64 Go (7,73 Go free) | FAT32
D:\ -> Disque fixe local | 29,02 Go (71,76 Mo free) [Disque local] | NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque amovible
G:\ -> Disque amovible


¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\cmd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\List_Kill'em\ERUNT.EXE
C:\Program Files\List_Kill'em\pv.exe

Detections :
==========


¤¤¤¤¤¤¤¤¤¤ Files/folders :



==============
host file OK !
==============

========
Registry
========

========
Services
=========

Ndisuio : Start = 3
EapHost : Start = 2
Ip6Fw : Start = 2
SharedAccess : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2

============
Disk Cleaned
============

=================
anti-ver blaster : OK !!
=================

================
Prefetch cleaned
================



¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
0
Pas de malware détecté détecté par Malwarebyte's (cf ci dessous) , je continue

Malwarebytes' Anti-Malware 1.44
Version de la base de données: 3874
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

16/03/2010 23:44:58
mbam-log-2010-03-16 (23-44-58).txt

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 234506
Temps écoulé: 1 hour(s), 9 minute(s), 36 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
0
Fin de la procédure :

voici les liens vers les fichiers log :
http://www.cijoint.fr/cjlink.php?file=cj201003/cijHqfLJld.txt

et info :
http://www.cijoint.fr/cjlink.php?file=cj201003/cijP76mUoy.txt


Encore merci pour tous ces conseils, j'espère que ces infos te permettront de repérer quelquechose.
Au fait, pendant que Malwarebyte's scannais, mon antivirus a détecté un cheval de troie : "Trojan horse SHeur3.EBY";"C:\System Volume Information\_restore{3A8B4664-C12C-4B38-B414-86F27AAB6D23}\RP655\A0123659.exe";"Moved to Virus Vault";"16/03/2010, 23:35:05";"file";"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe", c'est normal? çà veut dire que le programme Malwarebyte's contient un virus ???
0
Utilisateur anonyme
17 mars 2010 à 00:10
Bonjour,

oui ces normal

● Télécharge Ad-Remover (de C_XX) sur ton Bureau.
● Déconnecte-toi d'Internet et ferme toutes applications en cours.
● Double-clique sur le programme AD-R situé sur ton Bureau.
● Clique sur Nettoyer puis valide.
● Poste le rapport généré (C:\Ad-Report-CLEAN.log).

(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
0
Salut,

Ci dessous le rapport d'AD-REMOVER

======= RAPPORT D'AD-REMOVER 2.0.0.0,A | UNIQUEMENT XP/VISTA/7 =======
.
Mis à jour par C_XX le 17/03/10 à 15:10
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 19:36:38 le 17/03/2010 | Mode normal | Option: CLEAN
Exécuté de: C:\Ad-Remover\ADR.exe
SE: Microsoft® Windows XP™ Service Pack 3 - X86
Nom du PC: SANDRA11 | Utilisateur actuel: Sandra (Administrateur)
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.

(!) -- Fichiers temporaires supprimés.
.
.
============== SCAN ADDITIONNEL ==============
.
* Mozilla FireFox Version Impossible d'obtenir la version *
.
C:\Documents and Settings\Sandra\..\m21rkxge.default\prefs.js - browser.download.lastDir: C:\\Documents and Settings\\Sandra\\Bureau
C:\Documents and Settings\Sandra\..\m21rkxge.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.2
.
.
* Internet Explorer Version 7.0.5730.13 *
.
[HKCU\Software\Microsoft\Internet Explorer\Main]
.
AutoHide: yes
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/
.
[HKLM\Software\Microsoft\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: %SystemRoot%\system32\blank.htm
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
.
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm
.
========================================
.
C:\DOCUME~1\Sandra\LOCALS~1\Temp: 2 Fichier(s), 43 Dossier(s)
Temporary Internet Files: 2 Fichier(s), 29 Dossier(s)
.
C:\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Ad-Remover\Backup: 14 Fichier(s)
.
C:\Ad-Report-CLEAN[1].txt - 2250 Octet(s)
.
Fin à: 19:43:10, 17/03/2010
.
============== E.O.F - CLEAN[1] ==============
0
Utilisateur anonyme
17 mars 2010 à 20:00
Bonjour

• Télécharge UsbFix http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe­ usbfix (de Chiquitine29 & C_XX) sur ton Bureau.

/!\ Utilisateur de vista et windows 7 : ne pas oublier de désactiver Le contrôle des comptes utilisateurs
https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

• Lance l'installation avec les paramètres par défaut.
• Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
• Double-clique sur le raccourci UsbFix sur ton Bureau.
• Choisis l'option 1 (Recherche).
• Laisse travailler l'outil.
• Poste le rapport UsbFix.txt.


Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).

"Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Salut,
ci joint le rapport UbiFix


############################## | UsbFix V6.100 |

User : Sandra (Administrateurs) # SANDRA11
Update on 18/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 23:21:50 | 18/03/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

Intel(R) Pentium(R) M processor 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 7.0.5730.13
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]

C:\ -> Disque fixe local # 43,64 Go (11,12 Go free) # FAT32
D:\ -> Disque fixe local # 29,02 Go (307,57 Mo free) [Disque local] # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque amovible
G:\ -> Disque amovible
H:\ -> Disque fixe local # 465,64 Go (12,26 Go free) [RANGE TOUT] # FAT32
K:\ -> Disque amovible # 1,92 Go (1,49 Go free) [UBS SANDRA2] # FAT
L:\ -> Disque amovible # 480,73 Mo (316,43 Mo free) [ USB SANDRA] # FAT

################## | Elements infectieux |


################## | Registre |


################## | Mountpoints2 |

HKCU\..\..\Explorer\MountPoints2\{03a0e652-bf7b-11dc-85a6-0015000cb665}
Shell\Auto\command =RavMonE.exe e
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

HKCU\..\..\Explorer\MountPoints2\{16409adc-a33d-11dc-856f-0015000cb665}
Shell\Auto\command =AdobeR.exe e
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

HKCU\..\..\Explorer\MountPoints2\{1d8ca57c-c117-11dc-85aa-0015000cb665}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs

HKCU\..\..\Explorer\MountPoints2\{1f3b01d1-678e-11dc-852a-8ffccbadcc94}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs

HKCU\..\..\Explorer\MountPoints2\{5381c698-d71b-11dc-85ea-0015000cb665}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs

HKCU\..\..\Explorer\MountPoints2\{558aba40-357e-11de-87fe-0015000cb665}
Shell\1\Command =H:\Recycled.exe
Shell\2\Command =H:\Recycled.exe
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled.exe

HKCU\..\..\Explorer\MountPoints2\{6d72748e-3095-11dc-851f-ea511b9af294}
Shell\Auto\command =AdobeR.exe e
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

HKCU\..\..\Explorer\MountPoints2\{9e8fab82-d10f-11da-8416-0015000cb665}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs

HKCU\..\..\Explorer\MountPoints2\{a37334a2-c6a9-11dc-85bf-0015000cb665}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs

HKCU\..\..\Explorer\MountPoints2\{c7adec62-1a37-11de-87dc-0015000cb665}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe WIN31.dll.vbs

HKCU\..\..\Explorer\MountPoints2\{e915209c-d5a9-11dc-85e2-0015000cb665}
Shell\AutoRun\command =I:\AutoTransfer.exe

HKCU\..\..\Explorer\MountPoints2\{faa69a00-c03e-11dc-85a8-0015000cb665}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs

################## | Vaccin |

(!) Cet ordinateur n'est pas vacciné !

################## | ! Fin du rapport # UsbFix V6.100 ! |
0
Utilisateur anonyme
18 mars 2010 à 23:32
Suppression

Branche tes sources de données externes à ton PC, (clé USB, disque dur externe......) susceptibles d'avoir été infectés sans les ouvrir

(1) Double clic sur le raccourci UsbFix présent sur ton bureau

(2) Choisi l option 2 ( Suppression )

Ton bureau disparaitra et le pc redémarrera .

Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

Ensuite poste le rapport UsbFix.txt qui apparaitra avec le bureau .

Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
0
Bonjour!
çà fait un petit bout de temps que je n'ai pas touché à mon ordi perso, je suis revenue de vacances improvisées en début de semaine. J'ai essayé plusieurs fois de lancer UsbFix en mode suppression avec tous mes disques durs externes (x2) et clés usb (x2). Mais j'ai une de mes clés qui bloque mon ordi au démarrage (l'ordi n'a jamais voulu démarrer avec cette clé branchée, il dit toujours "replace disk and press any key ==> et donc problème lors du redemarrage en mode suppression) quant à mes deux disques durs externes, çà bloque lors de leur analyse, le logiciel reste bloqué des heures (littéralement) à 80% et plus rien ne se passe. J'ai essayé avec un, avec l'autre et même topo.
Donc j'ai juste laissé la clé qui ne bloque pas au redémarrage et lancer usbFix en mode suppression et voilà ce que çà donne :

############################## | UsbFix V6.100 |

User : Sandra (Administrateurs) # SANDRA11
Update on 18/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 21:16:57 | 01/04/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

Intel(R) Pentium(R) M processor 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 7.0.5730.13
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]

C:\ -> Disque fixe local # 43,64 Go (10,45 Go free) # FAT32
D:\ -> Disque fixe local # 29,02 Go (385,49 Mo free) [Disque local] # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque amovible
G:\ -> Disque amovible
K:\ -> Disque amovible # 1,92 Go (1,49 Go free) [UBS SANDRA2] # FAT

################## | Elements infectieux |

Supprimé ! D:\Recycler\S-1-5-21-2459149460-1490225042-2656327423-1005

################## | Registre |


################## | Mountpoints2 |


################## | Listing des fichiers présent |

[24/05/2001 12:59|--a------|162304] C:\UNWISE.EXE
[19/02/2003 16:28|--a------|37] C:\Store.LOG
[15/03/2010 22:13|--a------|56448] C:\List'em.txt
[16/03/2010 22:28|--a------|454] C:\rkill.log
[17/03/2010 19:43|--a------|2376] C:\Ad-Report-CLEAN[1].txt
[05/11/2003 19:02|-r-------|6] C:\A6V.20
[05/08/2004 14:00|-rahs----|4952] C:\Bootfont.bin
[12/11/2008 20:45|-rahs----|252240] C:\ntldr
[05/08/2004 14:00|-rahs----|47564] C:\NTDETECT.COM
[20/09/2004 11:12|--a------|14] C:\XPHF_SP2.FRN
[12/11/2008 18:35|-rahs----|216] C:\boot.ini
[17/10/2005 13:55|--a------|0] C:\CONFIG.SYS
[16/03/2010 22:17|--a------|4] C:\AUTOEXEC.BAT
[17/10/2005 13:55|-rahs----|0] C:\IO.SYS
[17/10/2005 13:55|-rahs----|0] C:\MSDOS.SYS
[01/04/2010 21:20|--a------|1802] C:\UsbFix.txt
[?|?|?] C:\pagefile.sys
[10/08/2006 17:55|--ahs----|194] C:\__IOM_DEVLIB__.__ATTRIBUTES__
[11/11/2008 10:07|--a------|22528] K:\Salut les poulots.doc
[04/05/2009 11:16|--a------|296] K:\WMPInfo.xml
[30/06/2009 21:46|--a------|843566] K:\CV Fr boulot 2p.pdf
[03/07/2009 13:19|--a------|529839] K:\CV En boulot Chronological.pdf
[03/07/2009 13:28|--a------|26624] K:\International Planning and Development.doc
[04/12/2009 14:28|--a------|9739116] K:\Simple OCR.exe
[11/12/2009 15:09|--a------|749965] K:\midnightsun_partial_draft4.pdf

################## | Vaccination |

# C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
# D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
# K:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

################## | Upload |

Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_SANDRA11.zip : https://www.ionos.fr/?affiliate_id=77097
Merci pour votre contribution .

################## | ! Fin du rapport # UsbFix V6.100 ! |

J'espère que çà t'aidera à trouver quelque chose.
Encore merci de m'aider dans cette croisade!
0
Utilisateur anonyme
1 avril 2010 à 22:57
comment va ton PC ?
0
Bah jusqu'ici, pas de rechute, mon frère s'en est servi pendant que j'étais en vadrouille et pas de problème. Je veux pas crier victoire trop vite, je touche du bois. Je me rachète un nouveau portable qui booste début mai. Celui la est vraiment trop lent (j'utilise des logiciels comme Autocad, le pack adobe ou des SIG et çà rame à mort), il a fait son temps, je veux juste qu'il tienne jusqu'à mai. Ensuite, je le reformaterai pour m'en faire mon ordi poubelle pour quand j'irai sur des sites internet bien pourris. De tout façon il a besoin d'être reformaté, j'ai un truc qui débloque depuis 3 mois, il ne veut plus s'arrêter et redémarre même quand je clic sur arrêter, donc je dois attendre qu'il redémarre et le forcer lors des premières secondes du redémarrage. Maintenant je m'y suis fait, çà ne me dérange plus.

Bref, fingers crossed en attendant mai et encore merci de m'avoir aidée dans cette galère de virus!
0
Utilisateur anonyme
1 avril 2010 à 23:17
de rien

bon formatage
0