A voir également:
- Virus " Adclicker-AJ",
- Youtu.be virus - Accueil - Guide virus
- Svchost.exe virus - Guide
- Virus mcafee - Accueil - Piratage
- Faux message virus ordinateur - Accueil - Arnaque
- Faux message virus iphone ✓ - Forum Virus
3 réponses
Utilisateur anonyme
21 sept. 2005 à 11:47
21 sept. 2005 à 11:47
Bonjour
Désactive le teatimer de Spybot, car il risque de gêner les corrections.
1 Télécharge
CCleaner.
http://www.filehippo.com/download_ccleaner.html
Installe le dans un répertoire dédié.
About Buster
http://www.malwarebytes.biz/index.php?page=downloads
Une fois téléchargé,tu le dézippe,et tu mets un raccourci sur le bureau.
Cws-hsa.reg
http://www.bleepingcomputer.com/forums/index.php?act=Attach&type=post&id=22927
Installe le sur le Bureau
Ewido
http://www.ewido.net/fr/download/
Tu l'installes et tu le mets à jour.
SpHjfix
http://www.trojaner-info.de/cgi-bin/download.cgi?file=sphjfix
Installer dans un répertoire dédié et placer un raccourci sur le bureau
2 Tu clique sur Démarrer puis Exécuter, tu tapes services.msc et tu cliques sur OK.
Dans la liste des services, cherche et sélectionne
"Network Security Service" / double clique sur la ligne
/ vérifie dans Chemin d'accès des fichiers exécutables qu'il
s'agit bien de "C:\WINDOWS\system32\addgy.exe" / dans Type de démarrage,
sélectionne Désactiver / valide la modification.
3 Lancer SpHjfix.
cliquer sur le bouton "start disinfection"
en cas d'infection sp.exe, l'ordinateur est redémarré
4 Redémarre en mode sans échec. Attention, tu n'as pas accès à internet dans ce mode, note bien ce que tu as à faire.
Démarre l'ordinateur.
Une fois le chargement du BIOS terminé, il y a un écran noir. Appuye sur la touche F8 ou F5 jusqu'à l'affichage du menu des options avancées de Windows.
En utilisant les touches du curseur, sélectionne le mode sans échec approprié et appuye sur Entrée.
5 Relance un scan HijackThis et coche les lignes ci-dessous :
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dkgay.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {4FBD5745-B5C3-0C90-BAD1-7677913D28A7} - C:\WINDOWS\system32\apixw32.dll
O2 - BHO: Class - {A0B5AE4D-89E5-F22A-060E-06256A646F77} - C:\WINDOWS\mfchi32.dll
O4 - HKLM\..\Run: [appye32.exe] C:\WINDOWS\system32\appye32.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addgy.exe
Ferme toutes les fenêtres Windows, Internet explorer, Outlook,sauf le logiciel Hijackthis et clique sur « Fix checked »
6 Assure toi d'avoir accés à tous les fichiers.
Démarrer, Poste de travail ou autre dossier, Menu Outils, Option des dossiers, onglet Affichage :
Activer la case : Afficher les fichiers et dossiers cachés
Désactiver la case : Masquer les extensions des fichiers dont le type est connu
Désactiver la case : Masquer les fichiers protégés du système d'exploitation
Puis Appliquer
7 Supprime les fichiers/dossiers incriminés (s'ils existent encore) :
C:\WINDOWS\system32\addgy.exe
C:\WINDOWS\system32\jcsfw.dll
C:\WINDOWS\system32\apixw32.dll
C:\WINDOWS\system32\appye32.exe
C:\WINDOWS\system32\dkgay.dll
C:\WINDOWS\mfchi32.dll
8 Double clique sur About:Buster
Clique sur Begin Removal
Un scan est exécuté.
Refaire un second scan.
Continue les scans tant qu'il trouve quelque chose.
Sauvegardes le rapport ici.
9 Double clique sur Cws-hsa.reg
10 Lance Ewido.
Fais un scan en mode complet.
Sauvegardes le rapport.
11 Lance et exécute CCleaner.
12 Redémarre normalement et poste un nouveau log HijackThis avec les rappors de About:Buster, Ewido et de SpHjfix.
Désactive le teatimer de Spybot, car il risque de gêner les corrections.
1 Télécharge
CCleaner.
http://www.filehippo.com/download_ccleaner.html
Installe le dans un répertoire dédié.
About Buster
http://www.malwarebytes.biz/index.php?page=downloads
Une fois téléchargé,tu le dézippe,et tu mets un raccourci sur le bureau.
Cws-hsa.reg
http://www.bleepingcomputer.com/forums/index.php?act=Attach&type=post&id=22927
Installe le sur le Bureau
Ewido
http://www.ewido.net/fr/download/
Tu l'installes et tu le mets à jour.
SpHjfix
http://www.trojaner-info.de/cgi-bin/download.cgi?file=sphjfix
Installer dans un répertoire dédié et placer un raccourci sur le bureau
2 Tu clique sur Démarrer puis Exécuter, tu tapes services.msc et tu cliques sur OK.
Dans la liste des services, cherche et sélectionne
"Network Security Service" / double clique sur la ligne
/ vérifie dans Chemin d'accès des fichiers exécutables qu'il
s'agit bien de "C:\WINDOWS\system32\addgy.exe" / dans Type de démarrage,
sélectionne Désactiver / valide la modification.
3 Lancer SpHjfix.
cliquer sur le bouton "start disinfection"
en cas d'infection sp.exe, l'ordinateur est redémarré
4 Redémarre en mode sans échec. Attention, tu n'as pas accès à internet dans ce mode, note bien ce que tu as à faire.
Démarre l'ordinateur.
Une fois le chargement du BIOS terminé, il y a un écran noir. Appuye sur la touche F8 ou F5 jusqu'à l'affichage du menu des options avancées de Windows.
En utilisant les touches du curseur, sélectionne le mode sans échec approprié et appuye sur Entrée.
5 Relance un scan HijackThis et coche les lignes ci-dessous :
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dkgay.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jcsfw.dll/sp.html#17702
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {4FBD5745-B5C3-0C90-BAD1-7677913D28A7} - C:\WINDOWS\system32\apixw32.dll
O2 - BHO: Class - {A0B5AE4D-89E5-F22A-060E-06256A646F77} - C:\WINDOWS\mfchi32.dll
O4 - HKLM\..\Run: [appye32.exe] C:\WINDOWS\system32\appye32.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addgy.exe
Ferme toutes les fenêtres Windows, Internet explorer, Outlook,sauf le logiciel Hijackthis et clique sur « Fix checked »
6 Assure toi d'avoir accés à tous les fichiers.
Démarrer, Poste de travail ou autre dossier, Menu Outils, Option des dossiers, onglet Affichage :
Activer la case : Afficher les fichiers et dossiers cachés
Désactiver la case : Masquer les extensions des fichiers dont le type est connu
Désactiver la case : Masquer les fichiers protégés du système d'exploitation
Puis Appliquer
7 Supprime les fichiers/dossiers incriminés (s'ils existent encore) :
C:\WINDOWS\system32\addgy.exe
C:\WINDOWS\system32\jcsfw.dll
C:\WINDOWS\system32\apixw32.dll
C:\WINDOWS\system32\appye32.exe
C:\WINDOWS\system32\dkgay.dll
C:\WINDOWS\mfchi32.dll
8 Double clique sur About:Buster
Clique sur Begin Removal
Un scan est exécuté.
Refaire un second scan.
Continue les scans tant qu'il trouve quelque chose.
Sauvegardes le rapport ici.
9 Double clique sur Cws-hsa.reg
10 Lance Ewido.
Fais un scan en mode complet.
Sauvegardes le rapport.
11 Lance et exécute CCleaner.
12 Redémarre normalement et poste un nouveau log HijackThis avec les rappors de About:Buster, Ewido et de SpHjfix.
Utilisateur anonyme
22 sept. 2005 à 14:59
22 sept. 2005 à 14:59
Bonjour
HijackThis est propre.
* Vide la quarantaine d'Ewido.
* Télécharge Ad-Aware SE Personnal
http://www.lavasoftusa.com/default.shtml.fr
Tutorial
http://home.tiscali.be/schouppeguy/adawarese/adawase.htm
Mettre à jour, scanner et supprimer tout ce qu'il trouve.
* Fais une analyse antivirus en ligne sur Panda
http://www.pandasoftware.com/activescan/fr/activescan_principal.htm
Colle son rapport ici.
HijackThis est propre.
* Vide la quarantaine d'Ewido.
* Télécharge Ad-Aware SE Personnal
http://www.lavasoftusa.com/default.shtml.fr
Tutorial
http://home.tiscali.be/schouppeguy/adawarese/adawase.htm
Mettre à jour, scanner et supprimer tout ce qu'il trouve.
* Fais une analyse antivirus en ligne sur Panda
http://www.pandasoftware.com/activescan/fr/activescan_principal.htm
Colle son rapport ici.
22 sept. 2005 à 11:59
merci bcp pour ces première infos ! Je n'ai plus l'air d'avoir ce virus ! Mais par contre j'arrive difficilemet me connecter au net (Réseau d'entreprise) et mon outlook pédale dans la semoule pour envoyer un message, il plante...
Voici le dernier HijackThis
Logfile of HijackThis v1.99.1
Scan saved at 11:40:11, on 22.09.2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\LxrHP30s.exe
c:\progra~1\COCREA~1\MEls.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\CoCreate\OSD_MO~1.8\binNT\SDserver.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Visage\PDF Printer\vspdfprsrv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot\Spybot\TeaTimer.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Documents and Settings\Yangus.PRESTIGE\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ch/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\Spybot\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visage\PDF Printer\vspdfprsrv.exe --background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\Spybot\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr/
O16 - DPF: {22945A69-1191-4DCF-9E6F-409BDE94D101} (EModelNonVersionSpecificViewControl Class) - http://www.solidworks.com/plugins/edrawings/download.cfm?Release=rel
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = prestigedor.ch
O17 - HKLM\Software\..\Telephony: DomainName = prestigedor.ch
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC87C492-1FEC-4D59-A42F-D227D0AD1D35}: NameServer = 195.186.1.111,192.168.1.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = prestigedor.ch
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = prestigedor.ch
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Lexar HP30 (LxrHP30s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrHP30s.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
O23 - Service: MEls - Unknown owner - c:\progra~1\COCREA~1\MEls.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SDserver12.0.0.8 - CoCreate Software GmbH - C:\PROGRA~1\CoCreate\OSD_MO~1.8\binNT\SDserver.exe
O23 - Service: SDserver2005 - CoCreate Software GmbH - C:\Program Files\CoCreate2005\OSDM_Server_2005\SDserver.exe
et le ccleaner :
NETTOYAGE COMPLET - (8.854 secs)
------------------------------------------------------------------------------------------
390.1MB supprimés.
Détails des fichiers à effacer
------------------------------------------------------------------------------------------
Fichiers Temporaires d'Internet Explorer (fichiers 343) 3.50MB
Cookie:yangus@ivwbox.de/(&H100001) 78 bytes
Cookie:yangus@lea.lycos.fr/(&H100001) 77 bytes
Cookie:yangus@imrworldwide.com/cgi-bin(&H100001) 262 bytes
Cookie:yangus@www.chantdugros.ch/(&H100001) 209 bytes
Cookie:yangus@mail.prestigedor.ch/(&H100001) 382 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@apmebf[3].txt 177 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@caramail.lycos[1].txt 220 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@caramail.lycos[2].txt 226 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@caramail.lycos[3].txt 226 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@caramail.lycos[5].txt 226 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@cgi-bin[4].txt 261 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@ebay[1].txt 1.12KB
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@ebay[3].txt 169 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@ebay[4].txt 260 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@ebay[5].txt 338 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@ebay[6].txt 408 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@ebay[7].txt 408 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@ebay[8].txt 748 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@ebay[9].txt 740 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@f002.mail.caramail.lycos[1].txt 88 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@f002.mail.caramail.lycos[2].txt 87 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@f002.mail.caramail.lycos[3].txt 88 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@f003.mail.caramail.lycos[1].txt 86 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@lea.lycos[3].txt 74 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@lsu[1].txt 65 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@lsu[2].txt 67 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@lsu[3].txt 67 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@lsu[5].txt 67 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@lycos[1].txt 676 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@mail.prestigedor[10].txt 375 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@mail.prestigedor[2].txt 378 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@mail.prestigedor[3].txt 378 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@mail.prestigedor[4].txt 382 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@mail.prestigedor[5].txt 378 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@mail.prestigedor[6].txt 381 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@mail.prestigedor[7].txt 378 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@mail.prestigedor[8].txt 378 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@mail.prestigedor[9].txt 376 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@secure.caramail.lycos[1].txt 84 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@secure.caramail.lycos[2].txt 85 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@secure.caramail.lycos[3].txt 85 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@secure.caramail.lycos[4].txt 85 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@secure.caramail.lycos[5].txt 85 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@www.bluewin[2].txt 67 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@www.caramail.lycos[1].txt 82 bytes
Marqué pour l'effacement: C:\Documents and Settings\Yangus.PRESTIGE\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Marqué pour l'effacement: C:\Documents and Settings\Yangus.PRESTIGE\Cookies\index.dat
Poubelle vidée (18 fichiers) 16.7MB
C:\WINDOWS\TEMP\Cookies\index.dat 16.00KB
C:\WINDOWS\TEMP\Historique\History.IE5\desktop.ini 113 bytes
C:\WINDOWS\TEMP\Historique\History.IE5\index.dat 16.00KB
C:\WINDOWS\TEMP\LogMesg.dll 1.50KB
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\0WVBA8DX\desktop.ini 67 bytes
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\2UFASHP8\desktop.ini 67 bytes
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\desktop.ini 67 bytes
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\EQFRLLWW\desktop.ini 67 bytes
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat 32.00KB
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\XQT6JFO3\desktop.ini 67 bytes
C:\WINDOWS\TEMP\WebPoolFileFile 261 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\08ijga519b7n0kb.mi 0.24MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\08ijga51bc3dme8.mi 0.83MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\08ijga51be6njag.mi 0.11MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\1065be2.mst 47.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\10e1a5d.mst 44.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\1170d61.mst 44.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\1178b6b.mst 44.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\11804f0.mst 44.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\11862fe.mst 44.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\118e127.mst 44.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\1193756.mst 44.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\1198518.mst 44.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\30.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\4BD7B929E04BC562.tmp 1 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\6.tmp 10.56KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\8.tmp 2.49KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Access 2000 Runtime Setup(0002).txt 1.30KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Access 2000 Runtime Setup(0002)_MsiExec.txt 0.13MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\adapters.log 1.19KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\CacheInfo.dnl 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\classpath.bat 37 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\E3BFE4E7.TMP 96 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\errorlog 238 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Excel8.0\MSACAL.exd 11.39KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\fla4.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\flaD.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\ima17.tmp 64.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\ima18.tmp 64.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\JET9988.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\LogMesg.dll 1.50KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\mm.log 118 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\mso1B.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\mso1E.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\mso25.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\mso26.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\mso27.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\mso28.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\mso315.xls 25.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\mso3D8.wmf 23.65KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\mso8.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\mso9.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\msoA.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\M_a00208.mi 0.15MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\M_a00372.mi 534 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\M_a01096.mi 0.15MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\M_a01148.mi 0.49MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\M_a01440.mi 11.43KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\M_a01640.mi 0.18MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\M_a04008.mi 0.11MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\offcln9.log 32.43KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Office 2000 CD2 Setup(0002).txt 1.23KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Office 2000 CD2 Setup(0002)_MsiExec.txt 0.20MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Office 2000 SR-1 Professional Setup (0002).txt 1.29KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Office 2000 SR-1 Professional Setup (0002)_MsiExec.txt 0.29MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Office 2000 SR-1 Professional Setup (0003).txt 335 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\OsdmRegistration_prestige_Yangus.log 192 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Outlook Startup.BAK 893 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Outlook Startup.Log 1.06KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\flag.bm1 256 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\head.bm1 87 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-01\f-01.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-01\f-02.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-01\f-03.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-01\f-04.bm1 0.76MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-01\f-05.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-01\f-06.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-01\f-07.bm1 0.38MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-01\f-08.bm1 5.12KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-01\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-01\head.bm1 309 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-02\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\MASTER\m-02\head.bm1 45 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\prostep_config 4.19KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1092\tool_err.eng 37.97KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\flag.bm1 256 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\head.bm1 87 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-01\f-01.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-01\f-02.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-01\f-03.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-01\f-04.bm1 0.76MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-01\f-05.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-01\f-06.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-01\f-07.bm1 0.38MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-01\f-08.bm1 5.12KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-01\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-01\head.bm1 309 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-02\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\MASTER\m-02\head.bm1 45 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\prostep_config 4.19KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1904\tool_err.eng 37.97KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\flag.bm1 256 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\head.bm1 87 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-01\f-01.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-01\f-02.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-01\f-03.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-01\f-04.bm1 0.76MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-01\f-05.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-01\f-06.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-01\f-07.bm1 0.38MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-01\f-08.bm1 5.12KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-01\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-01\head.bm1 309 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-02\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\MASTER\m-02\head.bm1 45 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\prostep_config 4.19KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_1980\tool_err.eng 37.97KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\flag.bm1 256 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\head.bm1 87 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-01\f-01.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-01\f-02.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-01\f-03.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-01\f-04.bm1 0.76MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-01\f-05.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-01\f-06.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-01\f-07.bm1 0.38MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-01\f-08.bm1 5.12KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-01\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-01\head.bm1 309 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-02\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\MASTER\m-02\head.bm1 45 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\prostep_config 4.19KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_264\tool_err.eng 37.97KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\flag.bm1 256 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\head.bm1 87 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-01\f-01.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-01\f-02.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-01\f-03.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-01\f-04.bm1 0.76MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-01\f-05.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-01\f-06.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-01\f-07.bm1 0.38MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-01\f-08.bm1 5.12KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-01\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-01\head.bm1 309 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-02\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\MASTER\m-02\head.bm1 45 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\prostep_config 4.19KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_2844\tool_err.eng 37.97KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\flag.bm1 256 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\head.bm1 87 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-01\f-01.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-01\f-02.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-01\f-03.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-01\f-04.bm1 0.76MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-01\f-05.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-01\f-06.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-01\f-07.bm1 0.38MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-01\f-08.bm1 5.12KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-01\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-01\head.bm1 309 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-02\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\MASTER\m-02\head.bm1 45 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\prostep_config 4.19KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_448\tool_err.eng 37.97KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\flag.bm1 256 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\head.bm1 87 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-01\f-01.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-01\f-02.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-01\f-03.bm1 0.31MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-01\f-04.bm1 0.76MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-01\f-05.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-01\f-06.bm1 0.87MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-01\f-07.bm1 0.38MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-01\f-08.bm1 5.12KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-01\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-01\head.bm1 309 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-02\flag.bm1 510 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\MASTER\m-02\head.bm1 45 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\prostep_config 4.19KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\step_database_692\tool_err.eng 37.97KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Stp12.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Stp12_TMP.EXE 99.2MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\tmp26.tmp 1.00MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\TWAIN.LOG 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Twain001.Mtx 3 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\VBE\MSForms.exd 0.14MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER1.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER1.tmp.dir00\manifest.txt 1.22KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER1.tmp.dir00\sysdata.xml 0.12MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER11E.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER11E.tmp.dir00\appcompat.txt 228 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER15.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER15.tmp.dir00\appcompat.txt 228 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER1E.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER1E.tmp.dir00\SolidDesigner.exe.hdmp 38.6MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER1E.tmp.dir00\SolidDesigner.exe.mdmp 2.10MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER1F.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER1F.tmp.dir00\SolidDesigner.exe.hdmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER1F.tmp.dir00\SolidDesigner.exe.mdmp 57.27KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER2.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER2.tmp.dir00\appcompat.txt 31.45KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER20.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER20.tmp.dir00\appcompat.txt 31.45KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER21.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER21.tmp.dir00\appcompat.txt 228 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER22.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER22.tmp.dir00\appcompat.txt 228 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER23.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER23.tmp.dir00\appcompat.txt 31.45KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER24.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER24.tmp.dir00\SolidDesigner.exe.hdmp 0.82MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER24.tmp.dir00\SolidDesigner.exe.mdmp 2.10MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER29.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER29.tmp.dir00\appcompat.txt 31.45KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER3.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER3.tmp.dir01\appcompat.txt 31.45KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER30.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER30.tmp.dir00\appcompat.txt 31.45KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER32.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER32.tmp.dir00\appcompat.txt 1.61KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER36.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER4.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER4.tmp.dir00\appcompat.txt 31.45KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER4B.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER4B.tmp.dir00\appcompat.txt 10.65KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER5.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER5.tmp.dir00\appcompat.txt 7.91KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER51.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER51.tmp.dir00\IEXPLORE.EXE.hdmp 16.9MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER51.tmp.dir00\IEXPLORE.EXE.mdmp 0.18MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER52.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER52.tmp.dir00\IEXPLORE.EXE.hdmp 15.8MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER52.tmp.dir00\IEXPLORE.EXE.mdmp 0.18MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER53.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER53.tmp.dir00\IEXPLORE.EXE.hdmp 16.9MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER53.tmp.dir00\IEXPLORE.EXE.mdmp 0.18MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER54.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER54.tmp.dir00\IEXPLORE.EXE.hdmp 16.9MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER54.tmp.dir00\IEXPLORE.EXE.mdmp 0.18MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER55.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER55.tmp.dir00\IEXPLORE.EXE.hdmp 16.9MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER55.tmp.dir00\IEXPLORE.EXE.mdmp 0.18MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER56.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER56.tmp.dir00\IEXPLORE.EXE.hdmp 16.9MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER56.tmp.dir00\IEXPLORE.EXE.mdmp 0.18MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER57.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER57.tmp.dir00\IEXPLORE.EXE.hdmp 15.8MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER57.tmp.dir00\IEXPLORE.EXE.mdmp 0.18MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER58.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER58.tmp.dir00\IEXPLORE.EXE.hdmp 15.8MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER58.tmp.dir00\IEXPLORE.EXE.mdmp 0.18MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER59.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER59.tmp.dir00\IEXPLORE.EXE.hdmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER59.tmp.dir00\IEXPLORE.EXE.mdmp 0.18MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER6E.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WER6E.tmp.dir00\appcompat.txt 228 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WERC.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WERC.tmp.dir00\appcompat.txt 31.45KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WERD.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WERE.tmp 0 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\WERE.tmp.dir00\appcompat.txt 31.45KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Word8.0\LiquidMotion.exd 0.15MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Word8.0\MSACAL.exd 8.02KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\Word8.0\MSForms.exd 0.16MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\__keyword_idx.html 1.43KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\__sd2iehlp.html 398 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DF19C7.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DF1CD5.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DF3856.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DF3872.tmp 512 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DF50D2.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DF5CC1.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DF77C9.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DF9321.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DF9A4E.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DFAA20.tmp 0.16MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DFBB0.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DFBCB2.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DFCEA0.tmp 512 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DFD70E.tmp 16.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DFD72A.tmp 512 bytes
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DFE655.tmp 32.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~DFEB86.tmp 0.14MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~present.rtf 2.72MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~WRD0001.doc 3.51KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~WRF0000.tmp 48.5MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~WRF0001.tmp 0.41MB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~WRS0002.tmp 37.00KB
C:\DOCUME~1\YANGUS~1.PRE\LOCALS~1\Temp\~WRS0004.tmp 9.50KB
C:\WINDOWS\MiniDump\Mini020105-01.dmp 64.00KB
C:\WINDOWS\MiniDump\Mini031505-01.dmp 64.00KB
C:\WINDOWS\MiniDump\Mini031605-01.dmp 64.00KB
C:\WINDOWS\MiniDump\Mini041905-01.dmp 64.00KB
C:\WINDOWS\MiniDump\Mini051005-01.dmp 64.00KB
C:\WINDOWS\MiniDump\Mini060305-01.dmp 64.00KB
C:\WINDOWS\MiniDump\Mini062105-01.dmp 64.00KB
C:\WINDOWS\MiniDump\Mini120804-01.dmp 64.00KB
C:\WINDOWS\MiniDump\Mini121604-01.dmp 64.00KB
C:\WINDOWS\MiniDump\Mini121704-01.dmp 64.00KB
C:\WINDOWS\system32\wbem\Logs\FrameWork.log 260 bytes
C:\WINDOWS\system32\wbem\Logs\mofcomp.log 10.93KB
C:\WINDOWS\system32\wbem\Logs\setup.log 4.83KB
C:\WINDOWS\system32\wbem\Logs\wbemcore.log 119 bytes
C:\WINDOWS\system32\wbem\Logs\wbemess.log 14.73KB
C:\WINDOWS\system32\wbem\Logs\wbemprox.log 3.02KB
C:\WINDOWS\system32\wbem\Logs\WinMgmt.log 13.87KB
C:\WINDOWS\system32\wbem\Logs\wmiadap.log 279 bytes
C:\WINDOWS\system32\wbem\Logs\wmiprov.log 60.20KB
C:\WINDOWS\system32\wbem\Logs\wbemess.lo_ 64.04KB
C:\WINDOWS\0.log 0 bytes
C:\WINDOWS\avrrh.log 0 bytes
C:\WINDOWS\comsetup.log 36.65KB
C:\WINDOWS\Directx.log 0.17MB
C:\WINDOWS\DtcInstall.log 128 bytes
C:\WINDOWS\FaxSetup.log 65.61KB
C:\WINDOWS\fcltq.log 0 bytes
C:\WINDOWS\fpvpb.log 13.26KB
C:\WINDOWS\hpdlk.log 0 bytes
C:\WINDOWS\iis6.log 0.10MB
C:\WINDOWS\imsins.log 1.34KB
C:\WINDOWS\itxnx.log 0 bytes
C:\WINDOWS\jlhjn.log 0 bytes
C:\WINDOWS\KB828741.log 20.50KB
C:\WINDOWS\KB833987.log 6.64KB
C:\WINDOWS\KB835732.log 14.84KB
C:\WINDOWS\KB840987.log 17.10KB
C:\WINDOWS\KB841356.log 24.42KB
C:\WINDOWS\KB841533.log 8.23KB
C:\WINDOWS\KB842773.log 5.78KB
C:\WINDOWS\KB873376.log 23.63KB
C:\WINDOWS\KB889293-IE6SP1-20041111.235619.log 6.42KB
C:\WINDOWS\msgsocm.log 3.55KB
C:\WINDOWS\msmqinst.log 26.52KB
C:\WINDOWS\netfxocm.log 11.94KB
C:\WINDOWS\ntdtcsetup.log 22.05KB
C:\WINDOWS\ocgen.log 42.26KB
C:\WINDOWS\ocmsn.log 2.90KB
C:\WINDOWS\pudqo.log 0 bytes
C:\WINDOWS\qkscg.log 0 bytes
C:\WINDOWS\regopt.log 2.73KB
C:\WINDOWS\sdwve.log 0 bytes
C:\WINDOWS\sessmgr.setup.log 1.03KB
C:\WINDOWS\setupact.log 0.15MB
C:\WINDOWS\setupapi.log 0.59MB
C:\WINDOWS\setuperr.log 0 bytes
C:\WINDOWS\Sti_Trace.log 0 bytes
C:\WINDOWS\tabletoc.log 4.02KB
C:\WINDOWS\tsoc.log 34.77KB
C:\WINDOWS\vminst.log 2.03KB
C:\WINDOWS\vxoch.log 0 bytes
C:\WINDOWS\wiadebug.log 216 bytes
C:\WINDOWS\wiaservc.log 50 bytes
C:\WINDOWS\Windows Update.log 836 bytes
C:\WINDOWS\WindowsUpdate.log 0.45MB
C:\WINDOWS\wmsetup.log 24.01KB
C:\WINDOWS\xpsp1hfm.log 2.01KB
C:\WINDOWS\imsins.BAK 1.34KB
C:\WINDOWS\Active Setup Log.txt 7.68KB
C:\WINDOWS\ntbtlog.txt 0.25MB
C:\WINDOWS\OEWABLog.txt 833 bytes
C:\WINDOWS\setuplog.txt 0.66MB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Dr Watson\drwtsn32.log 1.58MB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Dr Watson\user.dmp 52.70KB
C:\WINDOWS\Debug\Netlogon.log 0 bytes
C:\WINDOWS\Debug\NetSetup.LOG 19.18KB
C:\WINDOWS\Debug\oakley.log 0 bytes
C:\WINDOWS\Debug\UserMode\userenv.log 0.20MB
C:\WINDOWS\Debug\UserMode\userenv.bak 0.29MB
C:\WINDOWS\SchedLgU.Txt 31.78KB
C:\WINDOWS\security\logs\backup.log 3.34KB
C:\WINDOWS\security\logs\diagnosis.log 304 bytes
C:\WINDOWS\security\logs\SceRoot.log 624 bytes
C:\WINDOWS\security\logs\scesetup.log 0.43MB
C:\WINDOWS\security\logs\winlogon.log 90.32KB
C:\WINDOWS\security\logs\diagnosis.old 5.59KB
C:\Documents and Settings\Yangus.PRESTIGE\Application Data\Macromedia\Flash Player\#SharedObjects\EP4PKYRJ\nike.com\nikeid\v2\media\swf\main.swf\nikeid_global.sol 122 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Application Data\Macromedia\Flash Player\#SharedObjects\EP4PKYRJ\planetactive.com\dbplayer\12909\9801\33347\player.swf\data_fr_300x250_lastVisit.sol 82 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#nike.com\settings.sol 78 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#planetactive.com\settings.sol 86 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 346 bytes
C:\Documents and Settings\Yangus.PRESTIGE\Local Settings\Application Data\Microsoft\Terminal Server Client\Cache\bcache2.bmc 2.40MB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050217-1504.txt 2.35KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050316-1634.log 998 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050316-1637.txt 1.23KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050316-1638.log 241 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050316-1641.txt 551 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050412-1515.log 410 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050412-1517.txt 665 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050511-1437.log 330 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050511-1440.txt 584 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050518-1147.log 241 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050518-1150.txt 551 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050912-0804.log 2.84KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050912-0804.txt 978 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050912-0805.log 2.65KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050912-0805.txt 978 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050912-0806.log 5.41KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050912-0806.txt 978 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050912-0813.txt 9.61KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050912-1538.log 1.03KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050912-1542.txt 2.52KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050919-0817.log 5.14KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050919-0822.txt 9.11KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050919-1146.log 607 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Checks.050919-1151.txt 1.75KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Fixes.050217-1504.txt 2.24KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Fixes.050316-1637.txt 1.17KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Fixes.050412-1518.txt 1.27KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Fixes.050511-1441.txt 1.13KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Fixes.050912-0815.txt 9.32KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Fixes.050912-1542.txt 2.43KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Fixes.050919-1146.txt 17.65KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Fixes.050919-1251.txt 1.71KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Resident.log 25.44KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Logs\Update downloads.log 10.82KB
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Statistics.ini 1.52KB
------------------------------------------------------------------------------------------
et le ewido :
---------------------------------------------------------
ewido security suite - Rapport de scan
---------------------------------------------------------
+ Créé le: 07:35:04, 22.09.2005
+ Somme de contrôle: 78126EFE
+ Résultats du scan:
HKLM\SOFTWARE\Classes\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Nettoyer sans sauvegarder
HKLM\SOFTWARE\Classes\CLSID\{3D1F3C37-49CA-66D3-9877-04375ADE521D} -> Spyware.CoolWebSearch : Nettoyer et sauvegarder
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Nettoyer et sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@247realmedia[3].txt -> Spyware.Cookie.247realmedia : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@advertising[1].txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@as-us.falkag[1].txt -> Spyware.Cookie.Falkag : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@atdmt[1].txt -> Spyware.Cookie.Atdmt : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@bilbo.counted[2].txt -> Spyware.Cookie.Counted : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@bluestreak[3].txt -> Spyware.Cookie.Bluestreak : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@com[2].txt -> Spyware.Cookie.Com : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@count.xhit[1].txt -> Spyware.Cookie.Xhit : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@counter15.sextracker[1].txt -> Spyware.Cookie.Sextracker : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@doubleclick[4].txt -> Spyware.Cookie.Doubleclick : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@ehg-swisscom.hitbox[2].txt -> Spyware.Cookie.Hitbox : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@estat[2].txt -> Spyware.Cookie.Estat : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@fl01.ct2.comclick[2].txt -> Spyware.Cookie.Comclick : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@gator[2].txt -> Spyware.Cookie.Gator : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@hitbox[1].txt -> Spyware.Cookie.Hitbox : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@hitbox[2].txt -> Spyware.Cookie.Hitbox : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@hotlog[1].txt -> Spyware.Cookie.Hotlog : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@ivwbox[2].txt -> Spyware.Cookie.Ivwbox : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@mediaplex[4].txt -> Spyware.Cookie.Mediaplex : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@realmedia[2].txt -> Spyware.Cookie.Realmedia : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@revenue[3].txt -> Spyware.Cookie.Revenue : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@s.abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@servedby.advertising[1].txt -> Spyware.Cookie.Advertising : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@sextracker[2].txt -> Spyware.Cookie.Sextracker : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@spylog[1].txt -> Spyware.Cookie.Spylog : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@statcounter[1].txt -> Spyware.Cookie.Statcounter : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@valueclick[1].txt -> Spyware.Cookie.Valueclick : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@weborama[7].txt -> Spyware.Cookie.Weborama : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Cookies\ernest.oppliger@www.smartadserver[2].txt -> Spyware.Cookie.Smartadserver : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Local Settings\Temporary Internet Files\Content.IE5\1OJRP77I\optimize[1] -> TrojanDownloader.Dyfuca.bq : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Local Settings\Temporary Internet Files\Content.IE5\1OJRP77I\v10[1].dat -> TrojanDownloader.Esepor.m : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Local Settings\Temporary Internet Files\Content.IE5\6TQBYLUB\conn[1].dat -> Spyware.Hijacker.Generic : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Local Settings\Temporary Internet Files\Content.IE5\6TQBYLUB\wsem218[1].txt -> TrojanDownloader.Dyfuca.cn : Nettoyer sans sauvegarder
C:\Documents and Settings\ernest.oppliger\Local Settings\Temporary Internet Files\Content.IE5\8RSBUDWX\nem216[1].txt -> TrojanDownloader.Dyfuca.bx : Nettoyer sans sauvegarder
C:\Documents and Settings\LocalService.AUTORITE NT\Cookies\yangus@ads.addynamix[2].txt -> Spyware.Cookie.Addynamix : Nettoyer sans sauvegarder
C:\Documents and Settings\LocalService.AUTORITE NT\Cookies\yangus@as1.falkag[1].txt -> Spyware.Cookie.Falkag : Nettoyer sans sauvegarder
C:\Documents and Settings\LocalService.AUTORITE NT\Cookies\yangus@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Nettoyer sans sauvegarder
C:\Documents and Settings\LocalService.AUTORITE NT\Cookies\yangus@weborama[1].txt -> Spyware.Cookie.Weborama : Nettoyer sans sauvegarder
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@burstnet[2].txt -> Spyware.Cookie.Burstnet : Nettoyer sans sauvegarder
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Nettoyer sans sauvegarder
C:\Documents and Settings\Yangus.PRESTIGE\Cookies\yangus@ivwbox[2].txt -> Spyware.Cookie.Ivwbox : Nettoyer sans sauvegarder
C:\ms32.tmp -> TrojanDownloader.Small.azk : Nettoyer sans sauvegarder
C:\Program Files\Cram Toolbar\untitled.dll -> Spyware.SideSearch : Nettoyer sans sauvegarder
C:\WINDOWS\msfk32.exe -> Trojan.Agent.bi : Nettoyer sans sauvegarder
C:\WINDOWS\system32:niaa.dll -> TrojanDownloader.Small.azk : Nettoyer sans sauvegarder
C:\WINDOWS\system32\apihn.exe -> Trojan.Agent.bi : Nettoyer sans sauvegarder
C:\WINDOWS\system32\appot.exe -> Trojan.Agent.bi : Nettoyer sans sauvegarder
C:\WINDOWS\system32\netgr.exe -> Trojan.Agent.bi : Nettoyer sans sauvegarder
C:\WINDOWS\system32\sdkcf.exe -> Trojan.Agent.bi : Nettoyer sans sauvegarder
C:\WINNT\notepad.com -> TrojanDownloader.Delf.ks : Nettoyer sans sauvegarder
::Fin du rapport
Merci enocre de ton aide...
Yannick