HELP .... Trojan en pagaille .... Au SECOURS
Fermé
Julien
-
22 nov. 2007 à 07:51
chrifleur Messages postés 1091 Date d'inscription samedi 29 septembre 2007 Statut Contributeur Dernière intervention 19 novembre 2008 - 26 nov. 2007 à 22:15
chrifleur Messages postés 1091 Date d'inscription samedi 29 septembre 2007 Statut Contributeur Dernière intervention 19 novembre 2008 - 26 nov. 2007 à 22:15
A voir également:
- HELP .... Trojan en pagaille .... Au SECOURS
- Trojan remover - Télécharger - Antivirus & Antimalwares
- Trojan al11 - Forum Virus
- Csrss.exe trojan - Forum Virus
- Csrss.exe : processus suspect/virus ? - Forum Virus
- Trojan agent ✓ - Forum Virus
26 réponses
chrifleur
Messages postés
1091
Date d'inscription
samedi 29 septembre 2007
Statut
Contributeur
Dernière intervention
19 novembre 2008
18
26 nov. 2007 à 22:15
26 nov. 2007 à 22:15
si tout va bien, bonne continuation
et bon courage
et bon courage
chrifleur
Messages postés
1091
Date d'inscription
samedi 29 septembre 2007
Statut
Contributeur
Dernière intervention
19 novembre 2008
18
22 nov. 2007 à 08:36
22 nov. 2007 à 08:36
bonjour
Télécharge SDFix d’ Andy Manchesta sur ton bureau
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
clic double sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.
Redémarre ton ordinateur en mode sans échec
Comment aller en Mode sans échec lettre C
https://forum.pcastuces.com/sujet.asp?f=25&s=3902
1) Redémarre ton ordi
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
3) Tu verras un écran avec options de démarrage apparaître
4) Choisi la première option : Sans Échec, et valide avec "Entrée"
5) Choisi ton compte régulier, et non Administrateur
Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et clic double sur RunThis.cmd
Appuie sur Y pour commencer le nettoyage.
Il va supprimer les services et les entrées du Registre infectés puis te demandera d'appuyer sur une touche pour redémarrer.
Appuie sur une touche pour redémarrer le PC.
Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
Enfin, poste le contenu du fichier Report.txt dans ta prochaine réponse sur le forum,
et un rapport hijack this
Télécharge SDFix d’ Andy Manchesta sur ton bureau
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
clic double sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.
Redémarre ton ordinateur en mode sans échec
Comment aller en Mode sans échec lettre C
https://forum.pcastuces.com/sujet.asp?f=25&s=3902
1) Redémarre ton ordi
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
3) Tu verras un écran avec options de démarrage apparaître
4) Choisi la première option : Sans Échec, et valide avec "Entrée"
5) Choisi ton compte régulier, et non Administrateur
Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et clic double sur RunThis.cmd
Appuie sur Y pour commencer le nettoyage.
Il va supprimer les services et les entrées du Registre infectés puis te demandera d'appuyer sur une touche pour redémarrer.
Appuie sur une touche pour redémarrer le PC.
Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
Enfin, poste le contenu du fichier Report.txt dans ta prochaine réponse sur le forum,
et un rapport hijack this
Merci deja pour ta reponse. SDFix chargé et exécuté. Le LogFile est joint ci dessous et le HijackThis aussi.
Par contre j'ai toujours des popups qui apparaissent.
Donc je pense qu'il y aurai encore quelques etapes ;-)
SDFix: Version 1.115
Run by julien. on 22/11/2007 at 21:36
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\JULIEN~1.LAL\Bureau\SCFix\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\Documents and Settings\julien.\x.dat - Deleted
C:\Documents and Settings\julien.\z.dat - Deleted
C:\DOCUME~1\JULIEN~1.LAL\LOCALS~1\Temp\removalfile.bat - Deleted
C:\services.exe - Deleted
C:\WINDOWS\Fonts\Crack.exe - Deleted
C:\WINDOWS\Fonts\svchost.exe - Deleted
x.dat and z.dat data copied to \SDFix\Data.txt
Folder C:\WINDOWS\Fonts\' - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-22 21:51:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\\xd8\x2022\x20ac|\xff\xff\xff\xff\22\x2022\x20ac|\xf9\x20229~\2]
"C040A10900063D11C8EF10054038389C"="C?\WINDOWS\system32\FM20ENU.DLL"
scanning hidden files ...
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\22\1622-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1622-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1622-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1904 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\22\2222-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2222-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2222-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1352 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\45\2145-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2145-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2145-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1200 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\73\173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1110 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\73\173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 120 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\73\2173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1328 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\00\1600-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1600-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1600-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2064 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\01\10-{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}-v1-{F79EE1E9-B56C-46F1-B2B5-B539B5DA86C1}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\01\1601-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1601-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1601-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2392 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\01\2201-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2201-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2201-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1056 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\02\1602-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1602-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1602-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2152 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\03\1603-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1603-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1603-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2344 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\04\1604-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1604-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1604-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2384 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\04\2204-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2204-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2204-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1440 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\05\1605-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1605-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1605-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2064 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\06\1606-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1606-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1606-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2160 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\06\1706-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1706-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1706-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 528 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\07\1607-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1607-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1607-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2056 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\07\1707-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1707-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1707-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 520 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\07\2207-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2207-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2207-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1288 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\08\1608-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1608-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1608-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2160 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\08\1708-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1708-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1708-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 464 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\09\1609-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1609-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1609-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2344 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\09\1709-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1709-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1709-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 512 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\10\1610-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1610-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1610-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2280 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\10\1710-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1710-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1710-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 560 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\10\2210-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2210-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2210-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1328 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\11\1611-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1611-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1611-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2152 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\11\1711-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1711-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1711-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 520 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\12\1612-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1612-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1612-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1880 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\12\1712-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1712-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1712-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 480 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\13\1613-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1613-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1613-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.g@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\13\1713-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1713-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1713-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\13\2213-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2213-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2213-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1016 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\14\1614-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1614-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1614-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2000 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\14\1714-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1714-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1714-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 560 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\15\1615-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1615-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1615-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2360 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\15\1715-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1715-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1715-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 512 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\16\1616-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1616-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1616-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2120 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\16\1716-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1716-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1716-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 512 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\16\2216-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2216-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2216-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1120 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\17\1617-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1617-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1617-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2104 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\18\1618-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1618-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1618-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2304 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\19\1619-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1619-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1619-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\19\2219-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2219-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2219-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1440 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\20\1620-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1620-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1620-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1832 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\21\1621-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1621-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1621-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2112 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\74\2174-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2174-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2174-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1184 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\75\2175-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2175-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2175-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1368 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\76\2176-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2176-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2176-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\77\2177-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2177-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2177-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1224 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\78\1578-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1578-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1578-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 10232 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\78\2178-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2178-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2178-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1040 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\79\1579-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1579-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1579-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2000 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\79\2179-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2179-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2179-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1232 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\80\1580-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1580-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1580-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2160 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\81\1581-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1581-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1581-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2288 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\82\1582-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1582-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1582-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2368 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\83\1583-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1583-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1583-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2376 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\83\2183-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2183-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2183-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 184 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\84\1584-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1584-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1584-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2256 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\84\2184-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2184-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2184-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 696 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\85\1585-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1585-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1585-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1888 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\85\2185-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2185-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2185-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\86\1586-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1586-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1586-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2072 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\86\2186-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2186-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2186-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 984 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\87\1587-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1587-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1587-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1912 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\87\2187-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2187-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2187-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1136 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\88\1588-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1588-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1588-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2112 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\89\1589-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1589-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1589-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2104 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\89\2189-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2189-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2189-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1096 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\90\1590-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1590-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1590-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2200 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\90\2190-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2190-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2190-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1272 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\91\1591-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1591-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1591-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2128 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\91\2191-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2191-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2191-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1040 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\92\1592-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1592-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1592-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2080 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\93\1593-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1593-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1593-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2152 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\94\1594-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1594-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1594-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2072 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\94\1694-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1694-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1694-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 352 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\95\1595-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1595-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1595-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2184 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\95\1695-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1695-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1695-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 328 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\95\2195-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2195-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2195-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1280 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\96\1596-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1596-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1596-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2304 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\96\2196-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2196-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2196-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1128 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\97\1597-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1597-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1597-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2304 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\98\1598-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1598-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1598-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2240 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\98\2198-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2198-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2198-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1240 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\99\1599-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1599-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1599-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2032 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\23\1623-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1623-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1623-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2256 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\24\1624-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1624-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1624-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2168 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\25\1625-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1625-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1625-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2312 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\25\2225-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2225-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2225-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1360 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\26\1626-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1626-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1626-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2192 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\27\1627-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1627-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1627-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2032 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\28\1628-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1628-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1628-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2160 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\28\2228-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2228-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2228-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\29\1629-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1629-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1629-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1984 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\30\1630-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1630-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1630-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1952 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\31\1631-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1631-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1631-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1912 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\31\2131-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2131-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2131-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1440 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\31\2231-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2231-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2231-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1328 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\32\1632-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1632-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1632-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1784 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\32\2132-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2132-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2132-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1104 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\33\1633-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1633-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1633-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1720 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\33\2133-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2133-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2133-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1096 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\34\2134-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2134-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2134-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1120 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\34\2234-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2234-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2234-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1104 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\35\2135-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2135-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2135-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1248 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\36\2136-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2136-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2136-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1176 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\37\2137-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2137-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2137-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1368 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\37\2237-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2237-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2237-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1368 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\38\2138-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2138-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2138-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1464 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\39\2139-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2139-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2139-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1464 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\40\2140-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2140-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2140-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1248 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\40\2240-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2240-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2240-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1168 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\41\2141-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2141-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2141-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1264 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\42\2142-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2142-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2142-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1344 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\43\2143-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2143-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2143-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1184 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\44\2144-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2144-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2144-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1416 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\46\2146-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2146-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2146-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1400 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\46\2246-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2246-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2246-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1112 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\47\2147-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2147-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2147-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1312 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\48\2148-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2148-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2148-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1192 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\49\2149-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2149-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2149-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1192 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\49\2249-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2249-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2249-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1080 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\50\2150-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2150-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2150-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1168 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\51\2151-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2151-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1136 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\52\2152-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2152-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2152-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1280 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\53\2153-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2153-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1256 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\53\2253-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2253-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2253-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\54\2154-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2154-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2154-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1352 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\55\2155-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2155-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1360 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\56\2156-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2156-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2156-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1272 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\56\2256-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2256-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2256-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1104 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\57\2157-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2157-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1064 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\58\2158-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2158-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2158-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1448 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\59\2159-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2159-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2159-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1056 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\59\2259-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2259-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2259-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1096 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\60\2160-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2160-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1288 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\61\161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 116886 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\61\161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 8292 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\61\161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 15064 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\61\2161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1288 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\62\2162-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2162-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2162-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1216 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\62\2262-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2262-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2262-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1344 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\63\2163-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2163-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2163-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1056 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\64\2164-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2164-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2164-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1328 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\65\2165-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2165-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2165-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1024 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\66\2166-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2166-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2166-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1120 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\68\2168-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2168-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2168-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 984 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\69\2169-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2169-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2169-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\70\2170-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2170-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2170-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1048 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\71\2171-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2171-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2171-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1440 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\72\2172-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2172-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1360 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\lyly19847@hotmail.com\DFSR\Staging\CS{56230327-70B7-3C67-A343-C4A25FE625AF}\01\11-{56230327-70B7-3C67-A343-C4A25FE625AF}-v1-{F79EE1E9-B56C-46F1-B2B5-B539B5DA86C1}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 155
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Expl
Par contre j'ai toujours des popups qui apparaissent.
Donc je pense qu'il y aurai encore quelques etapes ;-)
SDFix: Version 1.115
Run by julien. on 22/11/2007 at 21:36
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\JULIEN~1.LAL\Bureau\SCFix\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\Documents and Settings\julien.\x.dat - Deleted
C:\Documents and Settings\julien.\z.dat - Deleted
C:\DOCUME~1\JULIEN~1.LAL\LOCALS~1\Temp\removalfile.bat - Deleted
C:\services.exe - Deleted
C:\WINDOWS\Fonts\Crack.exe - Deleted
C:\WINDOWS\Fonts\svchost.exe - Deleted
x.dat and z.dat data copied to \SDFix\Data.txt
Folder C:\WINDOWS\Fonts\' - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-22 21:51:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\\xd8\x2022\x20ac|\xff\xff\xff\xff\22\x2022\x20ac|\xf9\x20229~\2]
"C040A10900063D11C8EF10054038389C"="C?\WINDOWS\system32\FM20ENU.DLL"
scanning hidden files ...
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\22\1622-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1622-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1622-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1904 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\22\2222-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2222-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2222-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1352 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\45\2145-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2145-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2145-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1200 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\73\173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1110 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\73\173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 120 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\73\2173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2173-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1328 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\00\1600-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1600-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1600-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2064 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\01\10-{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}-v1-{F79EE1E9-B56C-46F1-B2B5-B539B5DA86C1}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\01\1601-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1601-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1601-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2392 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\01\2201-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2201-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2201-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1056 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\02\1602-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1602-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1602-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2152 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\03\1603-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1603-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1603-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2344 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\04\1604-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1604-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1604-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2384 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\04\2204-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2204-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2204-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1440 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\05\1605-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1605-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1605-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2064 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\06\1606-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1606-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1606-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2160 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\06\1706-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1706-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1706-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 528 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\07\1607-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1607-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1607-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2056 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\07\1707-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1707-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1707-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 520 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\07\2207-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2207-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2207-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1288 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\08\1608-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1608-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1608-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2160 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\08\1708-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1708-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1708-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 464 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\09\1609-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1609-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1609-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2344 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\09\1709-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1709-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1709-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 512 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\10\1610-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1610-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1610-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2280 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\10\1710-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1710-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1710-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 560 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\10\2210-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2210-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2210-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1328 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\11\1611-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1611-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1611-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2152 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\11\1711-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1711-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1711-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 520 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\12\1612-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1612-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1612-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1880 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\12\1712-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1712-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1712-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 480 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\13\1613-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1613-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1613-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.g@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\13\1713-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1713-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1713-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\13\2213-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2213-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2213-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1016 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\14\1614-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1614-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1614-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2000 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\14\1714-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1714-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1714-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 560 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\15\1615-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1615-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1615-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2360 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\15\1715-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1715-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1715-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 512 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\16\1616-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1616-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1616-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2120 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\16\1716-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1716-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1716-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 512 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\16\2216-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2216-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2216-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1120 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\17\1617-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1617-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1617-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2104 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\18\1618-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1618-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1618-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2304 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\19\1619-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1619-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1619-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\19\2219-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2219-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2219-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1440 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\20\1620-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1620-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1620-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1832 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\21\1621-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1621-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1621-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2112 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\74\2174-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2174-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2174-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1184 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\75\2175-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2175-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2175-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1368 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\76\2176-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2176-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2176-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\77\2177-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2177-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2177-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1224 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\78\1578-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1578-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1578-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 10232 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\78\2178-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2178-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2178-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1040 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\79\1579-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1579-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1579-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2000 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\79\2179-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2179-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2179-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1232 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\80\1580-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1580-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1580-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2160 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\81\1581-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1581-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1581-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2288 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\82\1582-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1582-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1582-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2368 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\83\1583-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1583-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1583-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2376 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\83\2183-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2183-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2183-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 184 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\84\1584-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1584-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1584-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2256 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\84\2184-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2184-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2184-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 696 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\85\1585-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1585-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1585-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1888 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\85\2185-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2185-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2185-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\86\1586-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1586-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1586-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2072 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\86\2186-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2186-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2186-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 984 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\87\1587-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1587-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1587-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1912 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\87\2187-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2187-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2187-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1136 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\88\1588-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1588-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1588-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2112 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\89\1589-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1589-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1589-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2104 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\89\2189-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2189-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2189-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1096 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\90\1590-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1590-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1590-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2200 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\90\2190-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2190-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2190-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1272 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\91\1591-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1591-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1591-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2128 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\91\2191-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2191-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2191-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1040 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\92\1592-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1592-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1592-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2080 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\93\1593-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1593-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1593-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2152 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\94\1594-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1594-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1594-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2072 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\94\1694-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1694-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1694-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 352 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\95\1595-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1595-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1595-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2184 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\95\1695-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1695-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1695-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 328 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\95\2195-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2195-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2195-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1280 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\96\1596-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1596-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1596-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2304 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\96\2196-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2196-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2196-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1128 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\97\1597-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1597-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1597-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2304 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\98\1598-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1598-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1598-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2240 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\98\2198-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2198-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2198-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1240 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\99\1599-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1599-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1599-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2032 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\23\1623-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1623-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1623-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2256 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\24\1624-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1624-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1624-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2168 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\25\1625-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1625-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1625-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2312 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\25\2225-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2225-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2225-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1360 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\26\1626-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1626-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1626-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2192 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\27\1627-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1627-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1627-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2032 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\28\1628-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1628-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1628-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2160 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\28\2228-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2228-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2228-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\29\1629-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1629-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1629-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1984 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\30\1630-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1630-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1630-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1952 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\31\1631-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1631-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1631-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1912 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\31\2131-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2131-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2131-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1440 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\31\2231-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2231-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2231-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1328 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\32\1632-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1632-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1632-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1784 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\32\2132-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2132-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2132-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1104 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\33\1633-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1633-{C50F1137-A183-445D-997F-1C07BC1E058D}-v1633-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1720 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\33\2133-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2133-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2133-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1096 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\34\2134-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2134-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2134-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1120 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\34\2234-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2234-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2234-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1104 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\35\2135-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2135-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2135-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1248 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\36\2136-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2136-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2136-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1176 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\37\2137-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2137-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2137-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1368 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\37\2237-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2237-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2237-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1368 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\38\2138-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2138-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2138-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1464 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\39\2139-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2139-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2139-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1464 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\40\2140-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2140-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2140-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1248 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\40\2240-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2240-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2240-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1168 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\41\2141-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2141-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2141-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1264 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\42\2142-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2142-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2142-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1344 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\43\2143-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2143-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2143-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1184 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\44\2144-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2144-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2144-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1416 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\46\2146-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2146-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2146-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1400 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\46\2246-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2246-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2246-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1112 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\47\2147-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2147-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2147-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1312 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\48\2148-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2148-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2148-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1192 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\49\2149-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2149-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2149-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1192 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\49\2249-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2249-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2249-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1080 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\50\2150-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2150-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2150-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1168 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\51\2151-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2151-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1136 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\52\2152-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2152-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2152-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1280 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\53\2153-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2153-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1256 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\53\2253-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2253-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2253-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1088 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\54\2154-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2154-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2154-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1352 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\55\2155-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2155-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1360 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\56\2156-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2156-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2156-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1272 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\56\2256-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2256-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2256-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1104 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\57\2157-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2157-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1064 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\58\2158-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2158-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2158-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1448 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\59\2159-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2159-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2159-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1056 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\59\2259-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2259-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2259-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1096 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\60\2160-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2160-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1288 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\61\161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 116886 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\61\161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 8292 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\61\161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 15064 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\61\2161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2161-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1288 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\62\2162-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2162-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2162-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1216 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\62\2262-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2262-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2262-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1344 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\63\2163-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2163-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2163-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1056 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\64\2164-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2164-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2164-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1328 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\65\2165-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2165-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2165-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1024 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\66\2166-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2166-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2166-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1120 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\68\2168-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2168-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2168-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 984 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\69\2169-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2169-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2169-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\70\2170-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2170-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2170-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1048 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\71\2171-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2171-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2171-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1440 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\chinoiserie13015@hotmail.fr\DFSR\Staging\CS{B7AF24A7-7935-DBBC-DD81-4FCFB38F6DBD}\72\2172-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2172-{C50F1137-A183-445D-997F-1C07BC1E058D}-v2172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1360 bytes hidden from API
C:\Documents and Settings\julien.\Local Settings\Application Data\Microsoft\Messenger\julien.@wanadoo.fr\SharingMetadata\lyly19847@hotmail.com\DFSR\Staging\CS{56230327-70B7-3C67-A343-C4A25FE625AF}\01\11-{56230327-70B7-3C67-A343-C4A25FE625AF}-v1-{F79EE1E9-B56C-46F1-B2B5-B539B5DA86C1}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 155
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Expl
chrifleur
Messages postés
1091
Date d'inscription
samedi 29 septembre 2007
Statut
Contributeur
Dernière intervention
19 novembre 2008
18
23 nov. 2007 à 08:45
23 nov. 2007 à 08:45
quel genre de pub?
on continue
Télécharge VundoFix.exe (par Atribune) sur ton Bureau
http://www.atribune.org/ccount/click.php?id=4
clic double sur VundoFix.exe afin de le lancer
clic sur le bouton Scan for Vundo
Lorsque le scan est complété, clic sur le bouton Remove Vundo
Une invite te demandera si tu veux supprimer les fichiers, clic YES
Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
Tu verras une invite qui t'annonce que ton PC va redémarrer;
clic OK
Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci haut, à partir de "clic sur le bouton Scan for Vundo".
Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse
on continue
Télécharge VundoFix.exe (par Atribune) sur ton Bureau
http://www.atribune.org/ccount/click.php?id=4
clic double sur VundoFix.exe afin de le lancer
clic sur le bouton Scan for Vundo
Lorsque le scan est complété, clic sur le bouton Remove Vundo
Une invite te demandera si tu veux supprimer les fichiers, clic YES
Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
Tu verras une invite qui t'annonce que ton PC va redémarrer;
clic OK
Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci haut, à partir de "clic sur le bouton Scan for Vundo".
Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Mes pubs et résumé de mes pbs :
- démarrage interminable et lenteur du pc
- triangle jaune dans la barre des tâches avec infos bulle du style "Security Alert : ... PC infected ou trojan"
- ouverture de pages pub intempestive :
http://ad.bannerconnect.net
ebay
logiciels antispyware ou antivirus
http://www.savetheinformation.com/v5/?gai=hamm_h8_hmp&gli=homepaga&gff=hamm__9434ef71%20D773886BD0A44D78A16146528D414915&eai=hamm_h8_hmp&eli=homepaga&eaf=hamm__9434ef71%20D773886BD0A44D78A16146528D414915&air=hamm_h8_hmp&lir=homepaga&afr=hamm__9434ef71%20D773886BD0A44D78A16146528D414915
- security toolbar que je n'ai pas installée et que je n'arrive pas à virer
- modif de la page de démarrage de mon IExplorer que je n'arrive pas à restaurer
http://kukkakreck.com/cehpmoin/?cmp=hmr&lid=0_1&gai=hamm_h8_hmp&gli=homepaga&affid=&uid=9434ef71+D773886BD0A44D78A16146528D414915
- Vurus Scan qui me detecte des Vundo et des AdClicker.FK à tout bout de champ
Voilà pour le diagnostic et les symptomes
Ce qui n'est pas super reluisant je dois avouer et accepter
Pour ce qui est VundoFix et de te conseils je m'y attèle directement là et je posterai le message des LogFiles.
Merci et à de suite
- démarrage interminable et lenteur du pc
- triangle jaune dans la barre des tâches avec infos bulle du style "Security Alert : ... PC infected ou trojan"
- ouverture de pages pub intempestive :
http://ad.bannerconnect.net
ebay
logiciels antispyware ou antivirus
http://www.savetheinformation.com/v5/?gai=hamm_h8_hmp&gli=homepaga&gff=hamm__9434ef71%20D773886BD0A44D78A16146528D414915&eai=hamm_h8_hmp&eli=homepaga&eaf=hamm__9434ef71%20D773886BD0A44D78A16146528D414915&air=hamm_h8_hmp&lir=homepaga&afr=hamm__9434ef71%20D773886BD0A44D78A16146528D414915
- security toolbar que je n'ai pas installée et que je n'arrive pas à virer
- modif de la page de démarrage de mon IExplorer que je n'arrive pas à restaurer
http://kukkakreck.com/cehpmoin/?cmp=hmr&lid=0_1&gai=hamm_h8_hmp&gli=homepaga&affid=&uid=9434ef71+D773886BD0A44D78A16146528D414915
- Vurus Scan qui me detecte des Vundo et des AdClicker.FK à tout bout de champ
Voilà pour le diagnostic et les symptomes
Ce qui n'est pas super reluisant je dois avouer et accepter
Pour ce qui est VundoFix et de te conseils je m'y attèle directement là et je posterai le message des LogFiles.
Merci et à de suite
Voilà donc j'ai bien suivi tes conseils et je te fais suivre les VundoFix Logfile et les hijackthis :
VundoFix V6.6.1
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 22:20:13 14/11/2007
Listing files found while scanning....
C:\WINDOWS\system32\extxbyhc.dll
C:\windows\SYSTEM32\tuvwuuu(2).dll
C:\windows\SYSTEM32\tuvwuuu(3).dll
C:\WINDOWS\system32\tuvwuuu.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\extxbyhc.dll
C:\WINDOWS\system32\extxbyhc.dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\tuvwuuu(2).dll
C:\windows\SYSTEM32\tuvwuuu(2).dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\tuvwuuu(3).dll
C:\windows\SYSTEM32\tuvwuuu(3).dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\tuvwuuu.dll
C:\WINDOWS\system32\tuvwuuu.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\tuvwuuu.dll
C:\WINDOWS\system32\tuvwuuu.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.6.1
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 23:23:53 14/11/2007
Listing files found while scanning....
No infected files were found.
VundoFix V6.6.2
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 22:36:38 23/11/2007
Listing files found while scanning....
C:\windows\SYSTEM32\eqjnwerh.dll
C:\windows\SYSTEM32\eqjnwerh.dllbox
C:\windows\SYSTEM32\extxbyhc.dllbox
Beginning removal...
Attempting to delete C:\windows\SYSTEM32\eqjnwerh.dll
C:\windows\SYSTEM32\eqjnwerh.dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\eqjnwerh.dllbox
C:\windows\SYSTEM32\eqjnwerh.dllbox Has been deleted!
Attempting to delete C:\windows\SYSTEM32\extxbyhc.dllbox
C:\windows\SYSTEM32\extxbyhc.dllbox Has been deleted!
Performing Repairs to the registry.
Done!
Le hijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:21:39, on 23/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\jplmhirv.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00E5E95.dat
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
VundoFix V6.6.1
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 22:20:13 14/11/2007
Listing files found while scanning....
C:\WINDOWS\system32\extxbyhc.dll
C:\windows\SYSTEM32\tuvwuuu(2).dll
C:\windows\SYSTEM32\tuvwuuu(3).dll
C:\WINDOWS\system32\tuvwuuu.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\extxbyhc.dll
C:\WINDOWS\system32\extxbyhc.dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\tuvwuuu(2).dll
C:\windows\SYSTEM32\tuvwuuu(2).dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\tuvwuuu(3).dll
C:\windows\SYSTEM32\tuvwuuu(3).dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\tuvwuuu.dll
C:\WINDOWS\system32\tuvwuuu.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\tuvwuuu.dll
C:\WINDOWS\system32\tuvwuuu.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.6.1
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 23:23:53 14/11/2007
Listing files found while scanning....
No infected files were found.
VundoFix V6.6.2
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 22:36:38 23/11/2007
Listing files found while scanning....
C:\windows\SYSTEM32\eqjnwerh.dll
C:\windows\SYSTEM32\eqjnwerh.dllbox
C:\windows\SYSTEM32\extxbyhc.dllbox
Beginning removal...
Attempting to delete C:\windows\SYSTEM32\eqjnwerh.dll
C:\windows\SYSTEM32\eqjnwerh.dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\eqjnwerh.dllbox
C:\windows\SYSTEM32\eqjnwerh.dllbox Has been deleted!
Attempting to delete C:\windows\SYSTEM32\extxbyhc.dllbox
C:\windows\SYSTEM32\extxbyhc.dllbox Has been deleted!
Performing Repairs to the registry.
Done!
Le hijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:21:39, on 23/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\jplmhirv.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00E5E95.dat
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
chrifleur
Messages postés
1091
Date d'inscription
samedi 29 septembre 2007
Statut
Contributeur
Dernière intervention
19 novembre 2008
18
24 nov. 2007 à 10:38
24 nov. 2007 à 10:38
ce n'est pas terminé
on continue mais tout d'abord une ou deux questions réponds y c'est important
ProxyServer = erkisa01:8080 ==>tu connais? c'est toi qui a paramétré ceci?
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nord son.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16 .5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.ha rting.com;<local> ==>même question
Domain = eu.nordson.com ==> idem tu connais?
je dois le savoir pour déterminer si je dois ou pas te les faire supprimer....
relance vundofix
* Ne clique pas sur "Scan for a vundo"
* Clique droit au milieu de la fenêtre
* Clique sur Add more files ?
* Copie/colle les fichiers ci-dessous ( un par case) :
C:\WINDOWS\system32\jplmhirv.dll
C:\WINDOWS\system32\__c00E5E95.dat
* Clique sur Add files
* Ensuite clique sur Close Windows
* Enfin, clique sur Remove Vundo ( les fichiers précédents doivent apparaître dans la fenêtre principale)
* Si l'outils demande un redémarrage, accepte
· Poste le rapport Vundofix, ainsi qu'un nouveau log hijackthis
Télécharge VirtumundoBeGone sur ton bureau .
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
* double-clic sur VirtumundoBeGone.exe
* Suis les instructions à l'écran
* Quand le scan est terminé, enregistre le rapport.
* Copie/Colle le ici
poste les rapports obtenus et un rapport Hijack This
Télécharge combofix.exe (par sUBs) sur ton Bureau
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
désactive ton antivirus, antispyware, et Spybot (résident) durant l'utilisation de ComboFix . Merci. Tu réactives ensuite.
Double clique combofix.exe.
Tape sur la touche Y (Yes) pour démarrer le scan.
Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
poste les rapports obtenus
Vundofix
VirtumondoBeGone
Combofix
et un rapport Hijack this
on continue mais tout d'abord une ou deux questions réponds y c'est important
ProxyServer = erkisa01:8080 ==>tu connais? c'est toi qui a paramétré ceci?
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nord son.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16 .5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.ha rting.com;<local> ==>même question
Domain = eu.nordson.com ==> idem tu connais?
je dois le savoir pour déterminer si je dois ou pas te les faire supprimer....
relance vundofix
* Ne clique pas sur "Scan for a vundo"
* Clique droit au milieu de la fenêtre
* Clique sur Add more files ?
* Copie/colle les fichiers ci-dessous ( un par case) :
C:\WINDOWS\system32\jplmhirv.dll
C:\WINDOWS\system32\__c00E5E95.dat
* Clique sur Add files
* Ensuite clique sur Close Windows
* Enfin, clique sur Remove Vundo ( les fichiers précédents doivent apparaître dans la fenêtre principale)
* Si l'outils demande un redémarrage, accepte
· Poste le rapport Vundofix, ainsi qu'un nouveau log hijackthis
Télécharge VirtumundoBeGone sur ton bureau .
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
* double-clic sur VirtumundoBeGone.exe
* Suis les instructions à l'écran
* Quand le scan est terminé, enregistre le rapport.
* Copie/Colle le ici
poste les rapports obtenus et un rapport Hijack This
Télécharge combofix.exe (par sUBs) sur ton Bureau
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
désactive ton antivirus, antispyware, et Spybot (résident) durant l'utilisation de ComboFix . Merci. Tu réactives ensuite.
Double clique combofix.exe.
Tape sur la touche Y (Yes) pour démarrer le scan.
Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
poste les rapports obtenus
Vundofix
VirtumondoBeGone
Combofix
et un rapport Hijack this
Hello,
Pour commencer, le ProxyServer erkisa, ainsi que les items contenant "nordson" sont définis par ma société et sont donc des attributs normaux à ne pas virer. Effectué par l'IT service de ma société (mais je ne peux pas aller les voir avec mon pb de virus et trojan sinon je me fais flinguer ... ).
Pour le reste je vais de ce pas effectuer les différentes tâches avec mon PC.
A tout de suite.
Julien
Pour commencer, le ProxyServer erkisa, ainsi que les items contenant "nordson" sont définis par ma société et sont donc des attributs normaux à ne pas virer. Effectué par l'IT service de ma société (mais je ne peux pas aller les voir avec mon pb de virus et trojan sinon je me fais flinguer ... ).
Pour le reste je vais de ce pas effectuer les différentes tâches avec mon PC.
A tout de suite.
Julien
chrifleur
Messages postés
1091
Date d'inscription
samedi 29 septembre 2007
Statut
Contributeur
Dernière intervention
19 novembre 2008
18
24 nov. 2007 à 16:34
24 nov. 2007 à 16:34
ok, c'est ce que je voulais savoir, donc on n'y touche pas
j'attends tes rapports
j'attends tes rapports
Le VundoFix report :
VundoFix V6.6.1
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 22:20:13 14/11/2007
Listing files found while scanning....
C:\WINDOWS\system32\extxbyhc.dll
C:\windows\SYSTEM32\tuvwuuu(2).dll
C:\windows\SYSTEM32\tuvwuuu(3).dll
C:\WINDOWS\system32\tuvwuuu.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\extxbyhc.dll
C:\WINDOWS\system32\extxbyhc.dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\tuvwuuu(2).dll
C:\windows\SYSTEM32\tuvwuuu(2).dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\tuvwuuu(3).dll
C:\windows\SYSTEM32\tuvwuuu(3).dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\tuvwuuu.dll
C:\WINDOWS\system32\tuvwuuu.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\tuvwuuu.dll
C:\WINDOWS\system32\tuvwuuu.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.6.1
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 23:23:53 14/11/2007
Listing files found while scanning....
No infected files were found.
VundoFix V6.6.2
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 22:36:38 23/11/2007
Listing files found while scanning....
C:\windows\SYSTEM32\eqjnwerh.dll
C:\windows\SYSTEM32\eqjnwerh.dllbox
C:\windows\SYSTEM32\extxbyhc.dllbox
Beginning removal...
Attempting to delete C:\windows\SYSTEM32\eqjnwerh.dll
C:\windows\SYSTEM32\eqjnwerh.dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\eqjnwerh.dllbox
C:\windows\SYSTEM32\eqjnwerh.dllbox Has been deleted!
Attempting to delete C:\windows\SYSTEM32\extxbyhc.dllbox
C:\windows\SYSTEM32\extxbyhc.dllbox Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\jplmhirv.dll
C:\WINDOWS\system32\jplmhirv.dll Has been deleted!
Performing Repairs to the registry.
Done!
(je ne sais pas si le .txt a été mis à jour depuis mon dernier check .... il fallait supprimer le rapport ancien avant de relancer un VundoFix ?)
Et voici le HijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:34:43, on 24/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Apoint\Apoint.exe
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\stakvhlx.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\okpaknyr.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00E5E95.dat
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
VundoFix V6.6.1
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 22:20:13 14/11/2007
Listing files found while scanning....
C:\WINDOWS\system32\extxbyhc.dll
C:\windows\SYSTEM32\tuvwuuu(2).dll
C:\windows\SYSTEM32\tuvwuuu(3).dll
C:\WINDOWS\system32\tuvwuuu.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\extxbyhc.dll
C:\WINDOWS\system32\extxbyhc.dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\tuvwuuu(2).dll
C:\windows\SYSTEM32\tuvwuuu(2).dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\tuvwuuu(3).dll
C:\windows\SYSTEM32\tuvwuuu(3).dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\tuvwuuu.dll
C:\WINDOWS\system32\tuvwuuu.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\tuvwuuu.dll
C:\WINDOWS\system32\tuvwuuu.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.6.1
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 23:23:53 14/11/2007
Listing files found while scanning....
No infected files were found.
VundoFix V6.6.2
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 22:36:38 23/11/2007
Listing files found while scanning....
C:\windows\SYSTEM32\eqjnwerh.dll
C:\windows\SYSTEM32\eqjnwerh.dllbox
C:\windows\SYSTEM32\extxbyhc.dllbox
Beginning removal...
Attempting to delete C:\windows\SYSTEM32\eqjnwerh.dll
C:\windows\SYSTEM32\eqjnwerh.dll Has been deleted!
Attempting to delete C:\windows\SYSTEM32\eqjnwerh.dllbox
C:\windows\SYSTEM32\eqjnwerh.dllbox Has been deleted!
Attempting to delete C:\windows\SYSTEM32\extxbyhc.dllbox
C:\windows\SYSTEM32\extxbyhc.dllbox Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\jplmhirv.dll
C:\WINDOWS\system32\jplmhirv.dll Has been deleted!
Performing Repairs to the registry.
Done!
(je ne sais pas si le .txt a été mis à jour depuis mon dernier check .... il fallait supprimer le rapport ancien avant de relancer un VundoFix ?)
Et voici le HijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:34:43, on 24/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Apoint\Apoint.exe
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\stakvhlx.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\okpaknyr.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00E5E95.dat
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
Voilà le report de VBG :
[11/24/2007, 16:41:04] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\julien.\Bureau\VirtumundoBeGone.exe" )
[11/24/2007, 16:41:09] - Detected System Information:
[11/24/2007, 16:41:09] - Windows Version: 5.1.2600, Service Pack 2
[11/24/2007, 16:41:09] - Current Username: julien. (Admin)
[11/24/2007, 16:41:09] - Windows is in NORMAL mode.
[11/24/2007, 16:41:09] - Searching for Browser Helper Objects:
[11/24/2007, 16:41:09] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[11/24/2007, 16:41:09] - BHO 2: {4bc6942e-6898-4580-9ab5-d23ad15b8078} ()
[11/24/2007, 16:41:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:09] - Checking for HKLM\...\Winlogon\Notify\sxohioph
[11/24/2007, 16:41:09] - Key not found: HKLM\...\Winlogon\Notify\sxohioph, continuing.
[11/24/2007, 16:41:09] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[11/24/2007, 16:41:09] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/24/2007, 16:41:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:09] - No filename found. Continuing.
[11/24/2007, 16:41:09] - BHO 5: {A95B2816-1D7E-4561-A202-68C0DE02353A} ()
[11/24/2007, 16:41:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:09] - Checking for HKLM\...\Winlogon\Notify\stakvhlx
[11/24/2007, 16:41:09] - Found: HKLM\...\Winlogon\Notify\stakvhlx - This is probably Virtumundo.
[11/24/2007, 16:41:09] - Assigning {A95B2816-1D7E-4561-A202-68C0DE02353A} MSEvents Object
[11/24/2007, 16:41:09] - BHO list has been changed! Starting over...
[11/24/2007, 16:41:09] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[11/24/2007, 16:41:10] - BHO 2: {4bc6942e-6898-4580-9ab5-d23ad15b8078} ()
[11/24/2007, 16:41:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:10] - Checking for HKLM\...\Winlogon\Notify\sxohioph
[11/24/2007, 16:41:10] - Key not found: HKLM\...\Winlogon\Notify\sxohioph, continuing.
[11/24/2007, 16:41:10] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[11/24/2007, 16:41:10] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/24/2007, 16:41:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:10] - No filename found. Continuing.
[11/24/2007, 16:41:10] - BHO 5: {A95B2816-1D7E-4561-A202-68C0DE02353A} (MSEvents Object)
[11/24/2007, 16:41:10] - ALERT: Found MSEvents Object!
[11/24/2007, 16:41:10] - BHO 6: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/24/2007, 16:41:10] - BHO 7: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/24/2007, 16:41:10] - BHO 8: {EFD1FD48-501E-4119-B9E2-9B7B0FCA6CC7} ()
[11/24/2007, 16:41:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:10] - Checking for HKLM\...\Winlogon\Notify\urspn
[11/24/2007, 16:41:10] - Key not found: HKLM\...\Winlogon\Notify\urspn, continuing.
[11/24/2007, 16:41:10] - Finished Searching Browser Helper Objects
[11/24/2007, 16:41:10] - *** Detected MSEvents Object
[11/24/2007, 16:41:10] - Trying to remove MSEvents Object...
[11/24/2007, 16:41:11] - Terminating Process: IEXPLORE.EXE
[11/24/2007, 16:41:12] - Terminating Process: RUNDLL32.EXE
[11/24/2007, 16:41:12] - Disabling Automatic Shell Restart
[11/24/2007, 16:41:12] - Terminating Process: EXPLORER.EXE
[11/24/2007, 16:41:13] - Suspending the NT Session Manager System Service
[11/24/2007, 16:41:13] - Terminating Windows NT Logon/Logoff Manager
[11/24/2007, 16:41:14] - Re-enabling Automatic Shell Restart
[11/24/2007, 16:41:15] - File to disable: C:\WINDOWS\system32\stakvhlx.dll
[11/24/2007, 16:41:15] - Renaming C:\WINDOWS\system32\stakvhlx.dll -> C:\WINDOWS\system32\stakvhlx.dll.vir
[11/24/2007, 16:41:15] - File successfully renamed!
[11/24/2007, 16:41:16] - Removing HKLM\...\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/24/2007, 16:41:16] - Removing HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/24/2007, 16:41:16] - Adding Kill Bit for ActiveX for GUID: {A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/24/2007, 16:41:16] - Deleting ATLEvents/MSEvents Registry entries
[11/24/2007, 16:41:16] - Removing HKLM\...\Winlogon\Notify\stakvhlx
[11/24/2007, 16:41:16] - Searching for Browser Helper Objects:
[11/24/2007, 16:41:16] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[11/24/2007, 16:41:16] - BHO 2: {4bc6942e-6898-4580-9ab5-d23ad15b8078} ()
[11/24/2007, 16:41:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:16] - Checking for HKLM\...\Winlogon\Notify\sxohioph
[11/24/2007, 16:41:16] - Key not found: HKLM\...\Winlogon\Notify\sxohioph, continuing.
[11/24/2007, 16:41:16] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[11/24/2007, 16:41:16] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/24/2007, 16:41:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:17] - No filename found. Continuing.
[11/24/2007, 16:41:17] - BHO 5: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/24/2007, 16:41:17] - BHO 6: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/24/2007, 16:41:17] - BHO 7: {EFD1FD48-501E-4119-B9E2-9B7B0FCA6CC7} ()
[11/24/2007, 16:41:17] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:17] - Checking for HKLM\...\Winlogon\Notify\urspn
[11/24/2007, 16:41:17] - Key not found: HKLM\...\Winlogon\Notify\urspn, continuing.
[11/24/2007, 16:41:17] - Finished Searching Browser Helper Objects
[11/24/2007, 16:41:17] - Finishing up...
[11/24/2007, 16:41:17] - A restart is needed.
[11/24/2007, 16:41:17] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[11/24/2007, 16:45:15] - Attempting to Restart via STOP error (Blue Screen!)
Et le HijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:52:11, on 24/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\xrbhhjue.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\aawymofe.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0069E9D.dat
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
End of file - 9634 bytes
Pour info, après VBG j'ai eu un écran bleu (j'ai cru voir sur les autres ofrums que c t normal mais je le signale malgré tout).
Le fichier __cxxxxx.dat apparait toujours et la sécurity bar qui avait disparu semble etre revenue.
Le premier VundoFix que nous avons fait avait règlé des pb qui sont réapparu (je pense que Vundo est dynamique, cad qu'il se régénère .... Il se régénère au fur et à mesure des rebbot ou au fur et à mesure de l'utilisation du pc meme sans faire rien tourner comme appli ?)
Je vais m'atteler au combofix
@+
[11/24/2007, 16:41:04] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\julien.\Bureau\VirtumundoBeGone.exe" )
[11/24/2007, 16:41:09] - Detected System Information:
[11/24/2007, 16:41:09] - Windows Version: 5.1.2600, Service Pack 2
[11/24/2007, 16:41:09] - Current Username: julien. (Admin)
[11/24/2007, 16:41:09] - Windows is in NORMAL mode.
[11/24/2007, 16:41:09] - Searching for Browser Helper Objects:
[11/24/2007, 16:41:09] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[11/24/2007, 16:41:09] - BHO 2: {4bc6942e-6898-4580-9ab5-d23ad15b8078} ()
[11/24/2007, 16:41:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:09] - Checking for HKLM\...\Winlogon\Notify\sxohioph
[11/24/2007, 16:41:09] - Key not found: HKLM\...\Winlogon\Notify\sxohioph, continuing.
[11/24/2007, 16:41:09] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[11/24/2007, 16:41:09] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/24/2007, 16:41:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:09] - No filename found. Continuing.
[11/24/2007, 16:41:09] - BHO 5: {A95B2816-1D7E-4561-A202-68C0DE02353A} ()
[11/24/2007, 16:41:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:09] - Checking for HKLM\...\Winlogon\Notify\stakvhlx
[11/24/2007, 16:41:09] - Found: HKLM\...\Winlogon\Notify\stakvhlx - This is probably Virtumundo.
[11/24/2007, 16:41:09] - Assigning {A95B2816-1D7E-4561-A202-68C0DE02353A} MSEvents Object
[11/24/2007, 16:41:09] - BHO list has been changed! Starting over...
[11/24/2007, 16:41:09] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[11/24/2007, 16:41:10] - BHO 2: {4bc6942e-6898-4580-9ab5-d23ad15b8078} ()
[11/24/2007, 16:41:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:10] - Checking for HKLM\...\Winlogon\Notify\sxohioph
[11/24/2007, 16:41:10] - Key not found: HKLM\...\Winlogon\Notify\sxohioph, continuing.
[11/24/2007, 16:41:10] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[11/24/2007, 16:41:10] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/24/2007, 16:41:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:10] - No filename found. Continuing.
[11/24/2007, 16:41:10] - BHO 5: {A95B2816-1D7E-4561-A202-68C0DE02353A} (MSEvents Object)
[11/24/2007, 16:41:10] - ALERT: Found MSEvents Object!
[11/24/2007, 16:41:10] - BHO 6: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/24/2007, 16:41:10] - BHO 7: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/24/2007, 16:41:10] - BHO 8: {EFD1FD48-501E-4119-B9E2-9B7B0FCA6CC7} ()
[11/24/2007, 16:41:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:10] - Checking for HKLM\...\Winlogon\Notify\urspn
[11/24/2007, 16:41:10] - Key not found: HKLM\...\Winlogon\Notify\urspn, continuing.
[11/24/2007, 16:41:10] - Finished Searching Browser Helper Objects
[11/24/2007, 16:41:10] - *** Detected MSEvents Object
[11/24/2007, 16:41:10] - Trying to remove MSEvents Object...
[11/24/2007, 16:41:11] - Terminating Process: IEXPLORE.EXE
[11/24/2007, 16:41:12] - Terminating Process: RUNDLL32.EXE
[11/24/2007, 16:41:12] - Disabling Automatic Shell Restart
[11/24/2007, 16:41:12] - Terminating Process: EXPLORER.EXE
[11/24/2007, 16:41:13] - Suspending the NT Session Manager System Service
[11/24/2007, 16:41:13] - Terminating Windows NT Logon/Logoff Manager
[11/24/2007, 16:41:14] - Re-enabling Automatic Shell Restart
[11/24/2007, 16:41:15] - File to disable: C:\WINDOWS\system32\stakvhlx.dll
[11/24/2007, 16:41:15] - Renaming C:\WINDOWS\system32\stakvhlx.dll -> C:\WINDOWS\system32\stakvhlx.dll.vir
[11/24/2007, 16:41:15] - File successfully renamed!
[11/24/2007, 16:41:16] - Removing HKLM\...\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/24/2007, 16:41:16] - Removing HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/24/2007, 16:41:16] - Adding Kill Bit for ActiveX for GUID: {A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/24/2007, 16:41:16] - Deleting ATLEvents/MSEvents Registry entries
[11/24/2007, 16:41:16] - Removing HKLM\...\Winlogon\Notify\stakvhlx
[11/24/2007, 16:41:16] - Searching for Browser Helper Objects:
[11/24/2007, 16:41:16] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[11/24/2007, 16:41:16] - BHO 2: {4bc6942e-6898-4580-9ab5-d23ad15b8078} ()
[11/24/2007, 16:41:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:16] - Checking for HKLM\...\Winlogon\Notify\sxohioph
[11/24/2007, 16:41:16] - Key not found: HKLM\...\Winlogon\Notify\sxohioph, continuing.
[11/24/2007, 16:41:16] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[11/24/2007, 16:41:16] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/24/2007, 16:41:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:17] - No filename found. Continuing.
[11/24/2007, 16:41:17] - BHO 5: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/24/2007, 16:41:17] - BHO 6: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/24/2007, 16:41:17] - BHO 7: {EFD1FD48-501E-4119-B9E2-9B7B0FCA6CC7} ()
[11/24/2007, 16:41:17] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/24/2007, 16:41:17] - Checking for HKLM\...\Winlogon\Notify\urspn
[11/24/2007, 16:41:17] - Key not found: HKLM\...\Winlogon\Notify\urspn, continuing.
[11/24/2007, 16:41:17] - Finished Searching Browser Helper Objects
[11/24/2007, 16:41:17] - Finishing up...
[11/24/2007, 16:41:17] - A restart is needed.
[11/24/2007, 16:41:17] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[11/24/2007, 16:45:15] - Attempting to Restart via STOP error (Blue Screen!)
Et le HijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:52:11, on 24/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\xrbhhjue.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\aawymofe.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0069E9D.dat
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
End of file - 9634 bytes
Pour info, après VBG j'ai eu un écran bleu (j'ai cru voir sur les autres ofrums que c t normal mais je le signale malgré tout).
Le fichier __cxxxxx.dat apparait toujours et la sécurity bar qui avait disparu semble etre revenue.
Le premier VundoFix que nous avons fait avait règlé des pb qui sont réapparu (je pense que Vundo est dynamique, cad qu'il se régénère .... Il se régénère au fur et à mesure des rebbot ou au fur et à mesure de l'utilisation du pc meme sans faire rien tourner comme appli ?)
Je vais m'atteler au combofix
@+
chrifleur
Messages postés
1091
Date d'inscription
samedi 29 septembre 2007
Statut
Contributeur
Dernière intervention
19 novembre 2008
18
24 nov. 2007 à 20:50
24 nov. 2007 à 20:50
oui passe combofix, il va faire encore pas mal de travail...
salut, voici le combofix.txt
ComboFix 07-11-19.3 - julien. 2007-11-24 18:20:04.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.67 [GMT 1:00]
Running from: C:\Documents and Settings\julien.\Bureau\ComboFix.exe
* Created a new restore point
.
Incapable d'obtenir les privilèges Système
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Menu Démarrer\Live Safety Center.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Online Security Guide.lnk
C:\Documents and Settings\julien.\Bureau\Live Safety Center.lnk
C:\Documents and Settings\julien.\Bureau\Online Security Guide.lnk
C:\Documents and Settings\julien.\Favoris\Online Security Guide.lnk
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\axbblama.dll
C:\WINDOWS\system32\glulnsfn.dll
C:\WINDOWS\system32\gvhlqjac.dll
C:\WINDOWS\SYSTEM32\npsru.bak1
C:\WINDOWS\SYSTEM32\npsru.bak2
C:\WINDOWS\SYSTEM32\npsru.ini
C:\WINDOWS\SYSTEM32\npsru.ini2
C:\WINDOWS\SYSTEM32\npsru.tmp
C:\WINDOWS\system32\pcjeewyg.dll
C:\WINDOWS\system32\stakvhlx.dllbox
C:\WINDOWS\system32\urspn.dll
C:\WINDOWS\system32\xiqmwoar.dll
C:\WINDOWS\system32\xrbhhjue.dllbox
.
((((((((((((((((((((((((((((( Fichiers cr''s 2007-10-24 to 2007-11-24 ))))))))))))))))))))))))))))))))))))
.
2007-11-24 18:16 775,832 ---hs---- C:\WINDOWS\SYSTEM32\uobxorpn.ini
2007-11-24 18:15 85,056 --a------ C:\WINDOWS\SYSTEM32\nproxbou.dll
2007-11-24 17:03 776,072 ---hs---- C:\WINDOWS\SYSTEM32\efomywaa.ini
2007-11-24 17:03 85,056 --a------ C:\WINDOWS\SYSTEM32\aawymofe.dll
2007-11-24 17:00 144,480 --a------ C:\WINDOWS\SYSTEM32\xrbhhjue.dll
2007-11-24 17:00 144,480 --a------ C:\WINDOWS\SYSTEM32\afsftirn.dll
2007-11-24 16:33 776,021 ---hs---- C:\WINDOWS\SYSTEM32\kjuffnod.ini
2007-11-24 16:18 144,480 --a------ C:\WINDOWS\SYSTEM32\stakvhlx.dll.vir
2007-11-24 16:17 144,480 --a------ C:\WINDOWS\SYSTEM32\lwpehbvv.dll
2007-11-24 16:09 775,892 ---hs---- C:\WINDOWS\SYSTEM32\rynkapko.ini
2007-11-23 23:19 775,832 ---hs---- C:\WINDOWS\SYSTEM32\vrihmlpj.ini
2007-11-23 22:21 776,012 ---hs---- C:\WINDOWS\SYSTEM32\mrlyqwxn.ini
2007-11-22 23:01 75,795 --a------ C:\WINDOWS\SYSTEM32\ggmwribn.dll
2007-11-22 22:55 738,356 ---hs---- C:\WINDOWS\SYSTEM32\dwranrrm.ini
2007-11-22 22:04 738,296 ---hs---- C:\WINDOWS\SYSTEM32\bvrperoe.ini
2007-11-22 21:35 <REP> d-------- C:\WINDOWS\ERUNT
2007-11-22 20:58 88,640 --a------ C:\WINDOWS\SYSTEM32\xdacpyyn.dll
2007-11-22 20:58 534 ---hs---- C:\WINDOWS\SYSTEM32\nyypcadx.ini
2007-11-22 15:14 474 ---hs---- C:\WINDOWS\SYSTEM32\fktbjgkb.ini
2007-11-21 19:21 354 ---hs---- C:\WINDOWS\SYSTEM32\kpvsenrb.ini
2007-11-20 23:34 354 ---hs---- C:\WINDOWS\SYSTEM32\fgcxjlts.ini
2007-11-20 22:40 294 ---hs---- C:\WINDOWS\SYSTEM32\thcaolmi.ini
2007-11-20 19:08 354 ---hs---- C:\WINDOWS\SYSTEM32\ephebuja.ini
2007-11-20 15:18 <REP> d-------- C:\HijackThis
2007-11-20 14:07 <REP> d-------- C:\Program Files\MSBuild
2007-11-20 13:58 <REP> d-------- C:\WINDOWS\SYSTEM32\XPSViewer
2007-11-20 13:54 <REP> d-------- C:\Program Files\Reference Assemblies
2007-11-20 13:50 14,048 --------- C:\WINDOWS\SYSTEM32\spmsg2.dll
2007-11-20 13:45 2,129,920 --a------ C:\WINDOWS\SYSTEM32\WLBCGCBPRO731.DLL
2007-11-20 13:45 1,392,640 --a------ C:\WINDOWS\SYSTEM32\WLTRAY.EXE
2007-11-20 13:45 757,760 --a------ C:\WINDOWS\SYSTEM32\bcm1xsup.dll
2007-11-20 13:45 86,016 --a------ C:\WINDOWS\SYSTEM32\preflib.dll
2007-11-20 13:45 69,632 --a------ C:\WINDOWS\SYSTEM32\bcmwlpkt.dll
2007-11-20 13:45 44,032 --a------ C:\WINDOWS\SYSTEM32\wltrynt.dll
2007-11-20 13:45 33,664 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\BCMWLNPF.SYS
2007-11-20 13:45 20,480 --a------ C:\WINDOWS\SYSTEM32\WLTRYSVC.EXE
2007-11-20 13:45 349 --a------ C:\WINDOWS\SYSTEM32\results.txt
2007-11-20 13:01 85,056 --a------ C:\WINDOWS\SYSTEM32\hcjjowcu.dll
2007-11-20 13:01 294 ---hs---- C:\WINDOWS\SYSTEM32\ucwojjch.ini
2007-11-20 09:30 294 ---hs---- C:\WINDOWS\SYSTEM32\engmskgh.ini
2007-11-20 09:29 85,056 --a------ C:\WINDOWS\SYSTEM32\hgksmgne.dll
2007-11-19 17:05 85,056 --a------ C:\WINDOWS\SYSTEM32\disrdjod.dll
2007-11-19 17:05 654 ---hs---- C:\WINDOWS\SYSTEM32\dojdrsid.ini
2007-11-19 16:59 78,715 --a------ C:\WINDOWS\SYSTEM32\axkpetff.dll
2007-11-15 00:15 76,985 --a------ C:\WINDOWS\SYSTEM32\ncmuhhxi.dll
2007-11-15 00:15 594 ---hs---- C:\WINDOWS\SYSTEM32\sgvbqtcn.ini
2007-11-15 00:13 144,480 --a------ C:\WINDOWS\SYSTEM32\yqakcipk.dll
2007-11-14 23:19 294 ---hs---- C:\WINDOWS\SYSTEM32\kyqxekgq.ini
2007-11-14 22:20 <REP> d-------- C:\VundoFix Backups
2007-11-14 21:47 294 ---hs---- C:\WINDOWS\SYSTEM32\trbnavdj.ini
2007-11-14 21:41 3,137 --a------ C:\WINDOWS\SYSTEM32\ecjwkhta.dll
2007-11-14 09:37 144,480 --a------ C:\WINDOWS\SYSTEM32\xwwbjxgs.dll
2007-11-14 09:31 726 --a------ C:\WINDOWS\SYSTEM32\ilorrfih.dll
2007-11-14 09:28 576,785 ---hs---- C:\WINDOWS\SYSTEM32\xxlusmoo.ini
2007-11-14 09:28 85,056 --a------ C:\WINDOWS\SYSTEM32\oomsulxx.dll
2007-11-14 09:22 13,783 --a------ C:\WINDOWS\SYSTEM32\lqarhxpu.dll
2007-11-14 09:06 577,505 ---hs---- C:\WINDOWS\SYSTEM32\fiphfyat.ini
2007-11-14 07:51 577,385 ---hs---- C:\WINDOWS\SYSTEM32\nvxjowfo.ini
2007-11-13 22:09 577,265 ---hs---- C:\WINDOWS\SYSTEM32\yvggllqb.ini
2007-11-12 20:27 584,192 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll
2007-11-12 19:12 30,040 --a------ C:\WINDOWS\SYSTEM32\wuapi.dll.mui
2007-11-08 14:11 <REP> d-------- C:\Program Files\Nordson Corporation
2007-11-07 14:57 6,452 --a------ C:\WINDOWS\SYSTEM32\haawwlpb.dll
2007-11-07 14:54 6,452 --a------ C:\WINDOWS\SYSTEM32\glwctlle.dll
2007-11-07 14:48 6,452 --a------ C:\WINDOWS\SYSTEM32\byqevtju.dll
2007-11-06 19:16 128 --a------ C:\Documents and Settings\julien.\pdf.exe
2007-11-06 09:08 577,145 ---hs---- C:\WINDOWS\SYSTEM32\nciffcjt.ini
2007-11-05 17:01 143 --a------ C:\WINDOWS\SYSTEM32\mcrh.tmp
2007-11-05 14:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-05 01:24 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-11-05 01:00 576,845 ---hs---- C:\WINDOWS\SYSTEM32\ptrqwhtp.ini
2007-11-01 21:43 147,456 --a------ C:\WINDOWS\SYSTEM32\vbzip10.dll
2007-11-01 21:38 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-20 12:45 --------- d-----w C:\Program Files\Dell
2007-11-13 19:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-09 12:08 --------- d-----w C:\Program Files\Java
2007-09-26 12:11 --------- d-----w C:\Program Files\DivX
2007-09-05 21:27 512 ----a-w C:\drmHeader.bin
2007-07-02 12:42 26,160 ----a-w C:\Documents and Settings\julien.\Application Data\GDIPFONTCACHEV1.DAT
2004-10-20 14:33 203 ----a-w C:\Program Files\Raccourci vers Lecteur CD.lnk
2005-04-18 15:54 8 --sh--r C:\WINDOWS\SYSTEM32\929981F961.sys
2005-03-13 15:51 56 --sh--r C:\WINDOWS\SYSTEM32\DF06BCDE3B.sys
2005-08-30 21:51 9,342 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les 'l'ments vides & les 'l'ments initiaux l'gitimes ne sont pas list's
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4bc6942e-6898-4580-9ab5-d23ad15b8078}]
C:\WINDOWS\system32\sxohioph.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-24 17:00 144480 --a------ C:\WINDOWS\system32\xrbhhjue.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\xrbhhjue.dll [2007-11-24 17:00 144480]
[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-01 18:33]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-02 15:32]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-03-04 20:59]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-07-17 10:18]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 12:28]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 17:50]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-20 00:09]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 08:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 08:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 08:36]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-03 21:43]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 07:00]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2005-12-07 02:55]
"Network Associates Error Reporting Service"="C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe" [2003-10-07 08:48]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 20:48]
"9434efde"="C:\WINDOWS\system32\nproxbou.dll" [2007-11-24 18:15]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 00:09]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifecde]
iifecde.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xrbhhjue]
xrbhhjue.dll 2007-11-24 17:00 144480 C:\WINDOWS\SYSTEM32\xrbhhjue.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\urspn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\[u]0/u\[u]0/u]
"Script"=\\eu\netlogon\dst\tzupdate_gpo.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\[u]0/u]
"Script"=MaxAllowedZone.bat
R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R1 UdfReadr;UdfReadr;C:\WINDOWS\system32\drivers\UdfReadr.sys
R2 iPCAgent;iPCAgent;C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
R2 MDC80211;iPass Protocol (IEEE 802.1x) v2.3.1.9;C:\WINDOWS\system32\DRIVERS\mdc80211.sys
R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S3 {E2B953A7-195A-44F9-9BA3-3D5F4E32BB55};AIM 3.0 Part 01 Codec Driver CH-7009-B;C:\WINDOWS\system32\drivers\wA301b.sys
S3 ExtranetAccess;Contivity VPN Service;"C:\Program Files\Nortel Networks\Extranet_serv.exe"
S3 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys
S3 PID_400C;Video Blaster WebCam 5 (WDM);C:\WINDOWS\system32\DRIVERS\Pd100Vid.sys
.
Contenu du dossier 'Scheduled Tasks/Tfches planifi'es'
"2007-09-26 09:21:00 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1088241064.job"
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 18:39:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-24 18:41:52 - machine was rebooted
.
--- E O F ---
Et le hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:06, on 2007-11-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\internet explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: {8708b51d-a32d-5ba9-0854-8986e2496cb4} - {4bc6942e-6898-4580-9ab5-d23ad15b8078} - C:\WINDOWS\system32\sxohioph.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\xrbhhjue.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\xrbhhjue.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\nproxbou.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O20 - Winlogon Notify: iifecde - iifecde.dll (file missing)
O20 - Winlogon Notify: xrbhhjue - C:\WINDOWS\SYSTEM32\xrbhhjue.dll
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
End of file - 10168 bytes
Voilà, au niveau diagnostic, y'a toujours le triangle jaune dans la barre des taches, la security toolbar, et un popup m'invitant à télécharger des saletés. Puis toujours une page d'ouverture de IE qui n'est pas celle paramétrée. Il y a du pain sur la planche je pense .
Merci et à plus
ComboFix 07-11-19.3 - julien. 2007-11-24 18:20:04.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.67 [GMT 1:00]
Running from: C:\Documents and Settings\julien.\Bureau\ComboFix.exe
* Created a new restore point
.
Incapable d'obtenir les privilèges Système
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Menu Démarrer\Live Safety Center.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Online Security Guide.lnk
C:\Documents and Settings\julien.\Bureau\Live Safety Center.lnk
C:\Documents and Settings\julien.\Bureau\Online Security Guide.lnk
C:\Documents and Settings\julien.\Favoris\Online Security Guide.lnk
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\axbblama.dll
C:\WINDOWS\system32\glulnsfn.dll
C:\WINDOWS\system32\gvhlqjac.dll
C:\WINDOWS\SYSTEM32\npsru.bak1
C:\WINDOWS\SYSTEM32\npsru.bak2
C:\WINDOWS\SYSTEM32\npsru.ini
C:\WINDOWS\SYSTEM32\npsru.ini2
C:\WINDOWS\SYSTEM32\npsru.tmp
C:\WINDOWS\system32\pcjeewyg.dll
C:\WINDOWS\system32\stakvhlx.dllbox
C:\WINDOWS\system32\urspn.dll
C:\WINDOWS\system32\xiqmwoar.dll
C:\WINDOWS\system32\xrbhhjue.dllbox
.
((((((((((((((((((((((((((((( Fichiers cr''s 2007-10-24 to 2007-11-24 ))))))))))))))))))))))))))))))))))))
.
2007-11-24 18:16 775,832 ---hs---- C:\WINDOWS\SYSTEM32\uobxorpn.ini
2007-11-24 18:15 85,056 --a------ C:\WINDOWS\SYSTEM32\nproxbou.dll
2007-11-24 17:03 776,072 ---hs---- C:\WINDOWS\SYSTEM32\efomywaa.ini
2007-11-24 17:03 85,056 --a------ C:\WINDOWS\SYSTEM32\aawymofe.dll
2007-11-24 17:00 144,480 --a------ C:\WINDOWS\SYSTEM32\xrbhhjue.dll
2007-11-24 17:00 144,480 --a------ C:\WINDOWS\SYSTEM32\afsftirn.dll
2007-11-24 16:33 776,021 ---hs---- C:\WINDOWS\SYSTEM32\kjuffnod.ini
2007-11-24 16:18 144,480 --a------ C:\WINDOWS\SYSTEM32\stakvhlx.dll.vir
2007-11-24 16:17 144,480 --a------ C:\WINDOWS\SYSTEM32\lwpehbvv.dll
2007-11-24 16:09 775,892 ---hs---- C:\WINDOWS\SYSTEM32\rynkapko.ini
2007-11-23 23:19 775,832 ---hs---- C:\WINDOWS\SYSTEM32\vrihmlpj.ini
2007-11-23 22:21 776,012 ---hs---- C:\WINDOWS\SYSTEM32\mrlyqwxn.ini
2007-11-22 23:01 75,795 --a------ C:\WINDOWS\SYSTEM32\ggmwribn.dll
2007-11-22 22:55 738,356 ---hs---- C:\WINDOWS\SYSTEM32\dwranrrm.ini
2007-11-22 22:04 738,296 ---hs---- C:\WINDOWS\SYSTEM32\bvrperoe.ini
2007-11-22 21:35 <REP> d-------- C:\WINDOWS\ERUNT
2007-11-22 20:58 88,640 --a------ C:\WINDOWS\SYSTEM32\xdacpyyn.dll
2007-11-22 20:58 534 ---hs---- C:\WINDOWS\SYSTEM32\nyypcadx.ini
2007-11-22 15:14 474 ---hs---- C:\WINDOWS\SYSTEM32\fktbjgkb.ini
2007-11-21 19:21 354 ---hs---- C:\WINDOWS\SYSTEM32\kpvsenrb.ini
2007-11-20 23:34 354 ---hs---- C:\WINDOWS\SYSTEM32\fgcxjlts.ini
2007-11-20 22:40 294 ---hs---- C:\WINDOWS\SYSTEM32\thcaolmi.ini
2007-11-20 19:08 354 ---hs---- C:\WINDOWS\SYSTEM32\ephebuja.ini
2007-11-20 15:18 <REP> d-------- C:\HijackThis
2007-11-20 14:07 <REP> d-------- C:\Program Files\MSBuild
2007-11-20 13:58 <REP> d-------- C:\WINDOWS\SYSTEM32\XPSViewer
2007-11-20 13:54 <REP> d-------- C:\Program Files\Reference Assemblies
2007-11-20 13:50 14,048 --------- C:\WINDOWS\SYSTEM32\spmsg2.dll
2007-11-20 13:45 2,129,920 --a------ C:\WINDOWS\SYSTEM32\WLBCGCBPRO731.DLL
2007-11-20 13:45 1,392,640 --a------ C:\WINDOWS\SYSTEM32\WLTRAY.EXE
2007-11-20 13:45 757,760 --a------ C:\WINDOWS\SYSTEM32\bcm1xsup.dll
2007-11-20 13:45 86,016 --a------ C:\WINDOWS\SYSTEM32\preflib.dll
2007-11-20 13:45 69,632 --a------ C:\WINDOWS\SYSTEM32\bcmwlpkt.dll
2007-11-20 13:45 44,032 --a------ C:\WINDOWS\SYSTEM32\wltrynt.dll
2007-11-20 13:45 33,664 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\BCMWLNPF.SYS
2007-11-20 13:45 20,480 --a------ C:\WINDOWS\SYSTEM32\WLTRYSVC.EXE
2007-11-20 13:45 349 --a------ C:\WINDOWS\SYSTEM32\results.txt
2007-11-20 13:01 85,056 --a------ C:\WINDOWS\SYSTEM32\hcjjowcu.dll
2007-11-20 13:01 294 ---hs---- C:\WINDOWS\SYSTEM32\ucwojjch.ini
2007-11-20 09:30 294 ---hs---- C:\WINDOWS\SYSTEM32\engmskgh.ini
2007-11-20 09:29 85,056 --a------ C:\WINDOWS\SYSTEM32\hgksmgne.dll
2007-11-19 17:05 85,056 --a------ C:\WINDOWS\SYSTEM32\disrdjod.dll
2007-11-19 17:05 654 ---hs---- C:\WINDOWS\SYSTEM32\dojdrsid.ini
2007-11-19 16:59 78,715 --a------ C:\WINDOWS\SYSTEM32\axkpetff.dll
2007-11-15 00:15 76,985 --a------ C:\WINDOWS\SYSTEM32\ncmuhhxi.dll
2007-11-15 00:15 594 ---hs---- C:\WINDOWS\SYSTEM32\sgvbqtcn.ini
2007-11-15 00:13 144,480 --a------ C:\WINDOWS\SYSTEM32\yqakcipk.dll
2007-11-14 23:19 294 ---hs---- C:\WINDOWS\SYSTEM32\kyqxekgq.ini
2007-11-14 22:20 <REP> d-------- C:\VundoFix Backups
2007-11-14 21:47 294 ---hs---- C:\WINDOWS\SYSTEM32\trbnavdj.ini
2007-11-14 21:41 3,137 --a------ C:\WINDOWS\SYSTEM32\ecjwkhta.dll
2007-11-14 09:37 144,480 --a------ C:\WINDOWS\SYSTEM32\xwwbjxgs.dll
2007-11-14 09:31 726 --a------ C:\WINDOWS\SYSTEM32\ilorrfih.dll
2007-11-14 09:28 576,785 ---hs---- C:\WINDOWS\SYSTEM32\xxlusmoo.ini
2007-11-14 09:28 85,056 --a------ C:\WINDOWS\SYSTEM32\oomsulxx.dll
2007-11-14 09:22 13,783 --a------ C:\WINDOWS\SYSTEM32\lqarhxpu.dll
2007-11-14 09:06 577,505 ---hs---- C:\WINDOWS\SYSTEM32\fiphfyat.ini
2007-11-14 07:51 577,385 ---hs---- C:\WINDOWS\SYSTEM32\nvxjowfo.ini
2007-11-13 22:09 577,265 ---hs---- C:\WINDOWS\SYSTEM32\yvggllqb.ini
2007-11-12 20:27 584,192 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll
2007-11-12 19:12 30,040 --a------ C:\WINDOWS\SYSTEM32\wuapi.dll.mui
2007-11-08 14:11 <REP> d-------- C:\Program Files\Nordson Corporation
2007-11-07 14:57 6,452 --a------ C:\WINDOWS\SYSTEM32\haawwlpb.dll
2007-11-07 14:54 6,452 --a------ C:\WINDOWS\SYSTEM32\glwctlle.dll
2007-11-07 14:48 6,452 --a------ C:\WINDOWS\SYSTEM32\byqevtju.dll
2007-11-06 19:16 128 --a------ C:\Documents and Settings\julien.\pdf.exe
2007-11-06 09:08 577,145 ---hs---- C:\WINDOWS\SYSTEM32\nciffcjt.ini
2007-11-05 17:01 143 --a------ C:\WINDOWS\SYSTEM32\mcrh.tmp
2007-11-05 14:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-05 01:24 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-11-05 01:00 576,845 ---hs---- C:\WINDOWS\SYSTEM32\ptrqwhtp.ini
2007-11-01 21:43 147,456 --a------ C:\WINDOWS\SYSTEM32\vbzip10.dll
2007-11-01 21:38 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-20 12:45 --------- d-----w C:\Program Files\Dell
2007-11-13 19:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-09 12:08 --------- d-----w C:\Program Files\Java
2007-09-26 12:11 --------- d-----w C:\Program Files\DivX
2007-09-05 21:27 512 ----a-w C:\drmHeader.bin
2007-07-02 12:42 26,160 ----a-w C:\Documents and Settings\julien.\Application Data\GDIPFONTCACHEV1.DAT
2004-10-20 14:33 203 ----a-w C:\Program Files\Raccourci vers Lecteur CD.lnk
2005-04-18 15:54 8 --sh--r C:\WINDOWS\SYSTEM32\929981F961.sys
2005-03-13 15:51 56 --sh--r C:\WINDOWS\SYSTEM32\DF06BCDE3B.sys
2005-08-30 21:51 9,342 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les 'l'ments vides & les 'l'ments initiaux l'gitimes ne sont pas list's
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4bc6942e-6898-4580-9ab5-d23ad15b8078}]
C:\WINDOWS\system32\sxohioph.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-24 17:00 144480 --a------ C:\WINDOWS\system32\xrbhhjue.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\xrbhhjue.dll [2007-11-24 17:00 144480]
[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-01 18:33]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-02 15:32]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-03-04 20:59]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-07-17 10:18]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 12:28]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 17:50]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-20 00:09]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 08:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 08:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 08:36]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-03 21:43]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 07:00]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2005-12-07 02:55]
"Network Associates Error Reporting Service"="C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe" [2003-10-07 08:48]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 20:48]
"9434efde"="C:\WINDOWS\system32\nproxbou.dll" [2007-11-24 18:15]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 00:09]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifecde]
iifecde.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xrbhhjue]
xrbhhjue.dll 2007-11-24 17:00 144480 C:\WINDOWS\SYSTEM32\xrbhhjue.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\urspn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\[u]0/u\[u]0/u]
"Script"=\\eu\netlogon\dst\tzupdate_gpo.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\[u]0/u]
"Script"=MaxAllowedZone.bat
R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R1 UdfReadr;UdfReadr;C:\WINDOWS\system32\drivers\UdfReadr.sys
R2 iPCAgent;iPCAgent;C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
R2 MDC80211;iPass Protocol (IEEE 802.1x) v2.3.1.9;C:\WINDOWS\system32\DRIVERS\mdc80211.sys
R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S3 {E2B953A7-195A-44F9-9BA3-3D5F4E32BB55};AIM 3.0 Part 01 Codec Driver CH-7009-B;C:\WINDOWS\system32\drivers\wA301b.sys
S3 ExtranetAccess;Contivity VPN Service;"C:\Program Files\Nortel Networks\Extranet_serv.exe"
S3 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys
S3 PID_400C;Video Blaster WebCam 5 (WDM);C:\WINDOWS\system32\DRIVERS\Pd100Vid.sys
.
Contenu du dossier 'Scheduled Tasks/Tfches planifi'es'
"2007-09-26 09:21:00 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1088241064.job"
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 18:39:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-24 18:41:52 - machine was rebooted
.
--- E O F ---
Et le hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:06, on 2007-11-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\internet explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: {8708b51d-a32d-5ba9-0854-8986e2496cb4} - {4bc6942e-6898-4580-9ab5-d23ad15b8078} - C:\WINDOWS\system32\sxohioph.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\xrbhhjue.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\xrbhhjue.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\nproxbou.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O20 - Winlogon Notify: iifecde - iifecde.dll (file missing)
O20 - Winlogon Notify: xrbhhjue - C:\WINDOWS\SYSTEM32\xrbhhjue.dll
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
End of file - 10168 bytes
Voilà, au niveau diagnostic, y'a toujours le triangle jaune dans la barre des taches, la security toolbar, et un popup m'invitant à télécharger des saletés. Puis toujours une page d'ouverture de IE qui n'est pas celle paramétrée. Il y a du pain sur la planche je pense .
Merci et à plus
chrifleur
Messages postés
1091
Date d'inscription
samedi 29 septembre 2007
Statut
Contributeur
Dernière intervention
19 novembre 2008
18
25 nov. 2007 à 18:40
25 nov. 2007 à 18:40
copieux le rapport
on continue
Copie (Ctrl+C) le texte ci-dessous :
Ouvre le Bloc-Notes puis colle (Ctrl+V) le texte précedemment copié.
Sauvegarde ce fichier sous le nom de CFScript.txt
http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
Comme l'image le montre, fait glisser CFScript.txt sur Combofix.exe
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
on continue
Copie (Ctrl+C) le texte ci-dessous :
File:: C:\WINDOWS\SYSTEM32\uobxorpn.ini C:\WINDOWS\SYSTEM32\nproxbou.dll C:\WINDOWS\SYSTEM32\efomywaa.ini C:\WINDOWS\SYSTEM32\aawymofe.dll C:\WINDOWS\SYSTEM32\xrbhhjue.dll C:\WINDOWS\SYSTEM32\afsftirn.dll C:\WINDOWS\SYSTEM32\kjuffnod.ini C:\WINDOWS\SYSTEM32\stakvhlx.dll.vir C:\WINDOWS\SYSTEM32\lwpehbvv.dll C:\WINDOWS\SYSTEM32\rynkapko.ini C:\WINDOWS\SYSTEM32\vrihmlpj.ini C:\WINDOWS\SYSTEM32\mrlyqwxn.ini C:\WINDOWS\SYSTEM32\ggmwribn.dll C:\WINDOWS\SYSTEM32\dwranrrm.ini C:\WINDOWS\SYSTEM32\bvrperoe.ini C:\WINDOWS\SYSTEM32\xdacpyyn.dll C:\WINDOWS\SYSTEM32\nyypcadx.ini C:\WINDOWS\SYSTEM32\fktbjgkb.ini C:\WINDOWS\SYSTEM32\kpvsenrb.ini C:\WINDOWS\SYSTEM32\fgcxjlts.ini C:\WINDOWS\SYSTEM32\thcaolmi.ini C:\WINDOWS\SYSTEM32\ephebuja.ini c:\WINDOWS\SYSTEM32\hcjjowcu.dll C:\WINDOWS\SYSTEM32\ucwojjch.ini C:\WINDOWS\SYSTEM32\engmskgh.ini C:\WINDOWS\SYSTEM32\hgksmgne.dll C:\WINDOWS\SYSTEM32\disrdjod.dll C:\WINDOWS\SYSTEM32\dojdrsid.ini C:\WINDOWS\SYSTEM32\axkpetff.dll C:\WINDOWS\SYSTEM32\ncmuhhxi.dll C:\WINDOWS\SYSTEM32\sgvbqtcn.ini C:\WINDOWS\SYSTEM32\yqakcipk.dll C:\WINDOWS\SYSTEM32\kyqxekgq.ini C:\WINDOWS\SYSTEM32\trbnavdj.ini C:\WINDOWS\SYSTEM32\ecjwkhta.dll C:\WINDOWS\SYSTEM32\xwwbjxgs.dll C:\WINDOWS\SYSTEM32\ilorrfih.dll C:\WINDOWS\SYSTEM32\xxlusmoo.ini C:\WINDOWS\SYSTEM32\oomsulxx.dll C:\WINDOWS\SYSTEM32\lqarhxpu.dll C:\WINDOWS\SYSTEM32\fiphfyat.ini C:\WINDOWS\SYSTEM32\nvxjowfo.ini C:\WINDOWS\SYSTEM32\yvggllqb.ini C:\WINDOWS\SYSTEM32\haawwlpb.dll C:\WINDOWS\SYSTEM32\glwctlle.dll C:\WINDOWS\SYSTEM32\byqevtju.dll C:\WINDOWS\SYSTEM32\nciffcjt.ini C:\WINDOWS\SYSTEM32\mcrh.tmp C:\WINDOWS\SYSTEM32\ptrqwhtp.ini C:\WINDOWS\SYSTEM32\vbzip10.dll C:\WINDOWS\system32\sxohioph.dll C:\WINDOWS\system32\iifecde.dll C:\WINDOWS\system32\urspn.dll Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4bc6942e-6898-4580-9ab5-d23ad15b8078}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{11A69AE4-FBED-4832-A2BF-45AF82825583}"="- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "9434efde"="- [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifecde] [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xrbhhjue] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] "Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
Ouvre le Bloc-Notes puis colle (Ctrl+V) le texte précedemment copié.
Sauvegarde ce fichier sous le nom de CFScript.txt
http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
Comme l'image le montre, fait glisser CFScript.txt sur Combofix.exe
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
Au moment de l'ouverture d'une deuxieme fenetre y'a un texte qui s'affiche sur la fentre cmd.exe : " SED" n'est pas reconnu comme une commande ... c'est normal ou il faut préparer un truc pour y remédier ?
le combofix report :
ComboFix 07-11-19.3 - julien. 2007-11-25 19:37:13.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.83 [GMT 1:00]
Running from: C:\Documents and Settings\julien.\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\julien.\Bureau\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\SYSTEM32\aawymofe.dll
C:\WINDOWS\SYSTEM32\afsftirn.dll
C:\WINDOWS\SYSTEM32\axkpetff.dll
C:\WINDOWS\SYSTEM32\bvrperoe.ini
C:\WINDOWS\SYSTEM32\byqevtju.dll
C:\WINDOWS\SYSTEM32\disrdjod.dll
C:\WINDOWS\SYSTEM32\dojdrsid.ini
C:\WINDOWS\SYSTEM32\dwranrrm.ini
C:\WINDOWS\SYSTEM32\ecjwkhta.dll
C:\WINDOWS\SYSTEM32\efomywaa.ini
C:\WINDOWS\SYSTEM32\engmskgh.ini
C:\WINDOWS\SYSTEM32\ephebuja.ini
C:\WINDOWS\SYSTEM32\fgcxjlts.ini
C:\WINDOWS\SYSTEM32\fiphfyat.ini
C:\WINDOWS\SYSTEM32\fktbjgkb.ini
C:\WINDOWS\SYSTEM32\ggmwribn.dll
C:\WINDOWS\SYSTEM32\glwctlle.dll
C:\WINDOWS\SYSTEM32\haawwlpb.dll
c:\WINDOWS\SYSTEM32\hcjjowcu.dll
C:\WINDOWS\SYSTEM32\hgksmgne.dll
C:\WINDOWS\system32\iifecde.dll
C:\WINDOWS\SYSTEM32\ilorrfih.dll
C:\WINDOWS\SYSTEM32\kjuffnod.ini
C:\WINDOWS\SYSTEM32\kpvsenrb.ini
C:\WINDOWS\SYSTEM32\kyqxekgq.ini
C:\WINDOWS\SYSTEM32\lqarhxpu.dll
C:\WINDOWS\SYSTEM32\lwpehbvv.dll
C:\WINDOWS\SYSTEM32\mcrh.tmp
C:\WINDOWS\SYSTEM32\mrlyqwxn.ini
C:\WINDOWS\SYSTEM32\nciffcjt.ini
C:\WINDOWS\SYSTEM32\ncmuhhxi.dll
C:\WINDOWS\SYSTEM32\nproxbou.dll
C:\WINDOWS\SYSTEM32\nvxjowfo.ini
C:\WINDOWS\SYSTEM32\nyypcadx.ini
C:\WINDOWS\SYSTEM32\oomsulxx.dll
C:\WINDOWS\SYSTEM32\ptrqwhtp.ini
C:\WINDOWS\SYSTEM32\rynkapko.ini
C:\WINDOWS\SYSTEM32\sgvbqtcn.ini
C:\WINDOWS\SYSTEM32\stakvhlx.dll.vir
C:\WINDOWS\system32\sxohioph.dll
C:\WINDOWS\SYSTEM32\thcaolmi.ini
C:\WINDOWS\SYSTEM32\trbnavdj.ini
C:\WINDOWS\SYSTEM32\ucwojjch.ini
C:\WINDOWS\SYSTEM32\uobxorpn.ini
C:\WINDOWS\system32\urspn.dll
C:\WINDOWS\SYSTEM32\vbzip10.dll
C:\WINDOWS\SYSTEM32\vrihmlpj.ini
C:\WINDOWS\SYSTEM32\xdacpyyn.dll
C:\WINDOWS\SYSTEM32\xrbhhjue.dll
C:\WINDOWS\SYSTEM32\xwwbjxgs.dll
C:\WINDOWS\SYSTEM32\xxlusmoo.ini
C:\WINDOWS\SYSTEM32\yqakcipk.dll
C:\WINDOWS\SYSTEM32\yvggllqb.ini
.
Incapable d'obtenir les privilèges Système
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Menu Démarrer\Live Safety Center.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Online Security Guide.lnk
C:\Documents and Settings\julien.\Bureau\Live Safety Center.lnk
C:\Documents and Settings\julien.\Bureau\Online Security Guide.lnk
C:\Documents and Settings\julien.\Favoris\Online Security Guide.lnk
C:\WINDOWS\SYSTEM32\aawymofe.dll
C:\WINDOWS\SYSTEM32\afsftirn.dll
C:\WINDOWS\SYSTEM32\axkpetff.dll
C:\WINDOWS\SYSTEM32\bvrperoe.ini
C:\WINDOWS\SYSTEM32\byqevtju.dll
C:\WINDOWS\SYSTEM32\disrdjod.dll
C:\WINDOWS\SYSTEM32\dojdrsid.ini
C:\WINDOWS\SYSTEM32\dwranrrm.ini
C:\WINDOWS\SYSTEM32\ecjwkhta.dll
C:\WINDOWS\SYSTEM32\efomywaa.ini
C:\WINDOWS\SYSTEM32\engmskgh.ini
C:\WINDOWS\SYSTEM32\ephebuja.ini
C:\WINDOWS\SYSTEM32\fgcxjlts.ini
C:\WINDOWS\SYSTEM32\fiphfyat.ini
C:\WINDOWS\SYSTEM32\fktbjgkb.ini
C:\WINDOWS\SYSTEM32\ggmwribn.dll
C:\WINDOWS\SYSTEM32\glwctlle.dll
C:\WINDOWS\SYSTEM32\haawwlpb.dll
c:\WINDOWS\SYSTEM32\hcjjowcu.dll
C:\WINDOWS\SYSTEM32\hgksmgne.dll
C:\WINDOWS\SYSTEM32\ilorrfih.dll
C:\WINDOWS\SYSTEM32\kjuffnod.ini
C:\WINDOWS\SYSTEM32\kpvsenrb.ini
C:\WINDOWS\SYSTEM32\kyqxekgq.ini
C:\WINDOWS\SYSTEM32\lqarhxpu.dll
C:\WINDOWS\SYSTEM32\lwpehbvv.dll
C:\WINDOWS\SYSTEM32\mcrh.tmp
C:\WINDOWS\SYSTEM32\mrlyqwxn.ini
C:\WINDOWS\SYSTEM32\nciffcjt.ini
C:\WINDOWS\SYSTEM32\ncmuhhxi.dll
C:\WINDOWS\SYSTEM32\nproxbou.dll
C:\WINDOWS\SYSTEM32\nvxjowfo.ini
C:\WINDOWS\SYSTEM32\nyypcadx.ini
C:\WINDOWS\SYSTEM32\oomsulxx.dll
C:\WINDOWS\SYSTEM32\ptrqwhtp.ini
C:\WINDOWS\SYSTEM32\rynkapko.ini
C:\WINDOWS\SYSTEM32\sgvbqtcn.ini
C:\WINDOWS\SYSTEM32\stakvhlx.dll.vir
C:\WINDOWS\SYSTEM32\thcaolmi.ini
C:\WINDOWS\SYSTEM32\trbnavdj.ini
C:\WINDOWS\SYSTEM32\ucwojjch.ini
C:\WINDOWS\SYSTEM32\uobxorpn.ini
C:\WINDOWS\SYSTEM32\vbzip10.dll
C:\WINDOWS\SYSTEM32\vrihmlpj.ini
C:\WINDOWS\SYSTEM32\xdacpyyn.dll
C:\WINDOWS\SYSTEM32\xrbhhjue.dll
C:\WINDOWS\system32\xrbhhjue.dllbox
C:\WINDOWS\SYSTEM32\xwwbjxgs.dll
C:\WINDOWS\SYSTEM32\xxlusmoo.ini
C:\WINDOWS\SYSTEM32\yqakcipk.dll
C:\WINDOWS\SYSTEM32\yvggllqb.ini
.
((((((((((((((((((((((((((((( Fichiers cr''s 2007-10-25 to 2007-11-25 ))))))))))))))))))))))))))))))))))))
.
2007-11-22 21:35 <REP> d-------- C:\WINDOWS\ERUNT
2007-11-20 15:18 <REP> d-------- C:\HijackThis
2007-11-20 14:07 <REP> d-------- C:\Program Files\MSBuild
2007-11-20 13:58 <REP> d-------- C:\WINDOWS\SYSTEM32\XPSViewer
2007-11-20 13:54 <REP> d-------- C:\Program Files\Reference Assemblies
2007-11-14 22:20 <REP> d-------- C:\VundoFix Backups
2007-11-12 20:27 584,192 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll
2007-11-12 19:12 30,040 --a------ C:\WINDOWS\SYSTEM32\wuapi.dll.mui
2007-11-08 14:11 <REP> d-------- C:\Program Files\Nordson Corporation
2007-11-06 19:16 128 --a------ C:\Documents and Settings\julien.\pdf.exe
2007-11-05 14:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-05 01:24 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-11-01 21:38 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-20 12:45 --------- d-----w C:\Program Files\Dell
2007-11-13 19:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-09 12:08 --------- d-----w C:\Program Files\Java
2007-09-26 12:11 --------- d-----w C:\Program Files\DivX
2007-09-05 21:27 512 ----a-w C:\drmHeader.bin
2007-07-02 12:42 26,160 ----a-w C:\Documents and Settings\julien.\Application Data\GDIPFONTCACHEV1.DAT
2004-10-20 14:33 203 ----a-w C:\Program Files\Raccourci vers Lecteur CD.lnk
2005-04-18 15:54 8 --sh--r C:\WINDOWS\SYSTEM32\929981F961.sys
2005-03-13 15:51 56 --sh--r C:\WINDOWS\SYSTEM32\DF06BCDE3B.sys
2005-08-30 21:51 9,342 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2007-11-24_18.40.37.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-25 18:48:04 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_21c.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les 'l'ments vides & les 'l'ments initiaux l'gitimes ne sont pas list's
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-01 18:33]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-02 15:32]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-03-04 20:59]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-07-17 10:18]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 12:28]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 17:50]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-20 00:09]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 08:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 08:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 08:36]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-03 21:43]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 07:00]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2005-12-07 02:55]
"Network Associates Error Reporting Service"="C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe" [2003-10-07 08:48]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 20:48]
"9434efde"="C:\WINDOWS\system32\nproxbou.dll" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 00:09]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\[u]0/u\[u]0/u]
"Script"=\\eu\netlogon\dst\tzupdate_gpo.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\[u]0/u]
"Script"=MaxAllowedZone.bat
R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R2 MDC80211;iPass Protocol (IEEE 802.1x) v2.3.1.9;C:\WINDOWS\system32\DRIVERS\mdc80211.sys
R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S3 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys
.
Contenu du dossier 'Scheduled Tasks/Tfches planifi'es'
"2007-09-26 09:21:00 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1088241064.job"
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-25 19:49:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-25 19:53:24 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-24 18:41
.
--- E O F ---
ComboFix 07-11-19.3 - julien. 2007-11-25 19:37:13.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.83 [GMT 1:00]
Running from: C:\Documents and Settings\julien.\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\julien.\Bureau\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\SYSTEM32\aawymofe.dll
C:\WINDOWS\SYSTEM32\afsftirn.dll
C:\WINDOWS\SYSTEM32\axkpetff.dll
C:\WINDOWS\SYSTEM32\bvrperoe.ini
C:\WINDOWS\SYSTEM32\byqevtju.dll
C:\WINDOWS\SYSTEM32\disrdjod.dll
C:\WINDOWS\SYSTEM32\dojdrsid.ini
C:\WINDOWS\SYSTEM32\dwranrrm.ini
C:\WINDOWS\SYSTEM32\ecjwkhta.dll
C:\WINDOWS\SYSTEM32\efomywaa.ini
C:\WINDOWS\SYSTEM32\engmskgh.ini
C:\WINDOWS\SYSTEM32\ephebuja.ini
C:\WINDOWS\SYSTEM32\fgcxjlts.ini
C:\WINDOWS\SYSTEM32\fiphfyat.ini
C:\WINDOWS\SYSTEM32\fktbjgkb.ini
C:\WINDOWS\SYSTEM32\ggmwribn.dll
C:\WINDOWS\SYSTEM32\glwctlle.dll
C:\WINDOWS\SYSTEM32\haawwlpb.dll
c:\WINDOWS\SYSTEM32\hcjjowcu.dll
C:\WINDOWS\SYSTEM32\hgksmgne.dll
C:\WINDOWS\system32\iifecde.dll
C:\WINDOWS\SYSTEM32\ilorrfih.dll
C:\WINDOWS\SYSTEM32\kjuffnod.ini
C:\WINDOWS\SYSTEM32\kpvsenrb.ini
C:\WINDOWS\SYSTEM32\kyqxekgq.ini
C:\WINDOWS\SYSTEM32\lqarhxpu.dll
C:\WINDOWS\SYSTEM32\lwpehbvv.dll
C:\WINDOWS\SYSTEM32\mcrh.tmp
C:\WINDOWS\SYSTEM32\mrlyqwxn.ini
C:\WINDOWS\SYSTEM32\nciffcjt.ini
C:\WINDOWS\SYSTEM32\ncmuhhxi.dll
C:\WINDOWS\SYSTEM32\nproxbou.dll
C:\WINDOWS\SYSTEM32\nvxjowfo.ini
C:\WINDOWS\SYSTEM32\nyypcadx.ini
C:\WINDOWS\SYSTEM32\oomsulxx.dll
C:\WINDOWS\SYSTEM32\ptrqwhtp.ini
C:\WINDOWS\SYSTEM32\rynkapko.ini
C:\WINDOWS\SYSTEM32\sgvbqtcn.ini
C:\WINDOWS\SYSTEM32\stakvhlx.dll.vir
C:\WINDOWS\system32\sxohioph.dll
C:\WINDOWS\SYSTEM32\thcaolmi.ini
C:\WINDOWS\SYSTEM32\trbnavdj.ini
C:\WINDOWS\SYSTEM32\ucwojjch.ini
C:\WINDOWS\SYSTEM32\uobxorpn.ini
C:\WINDOWS\system32\urspn.dll
C:\WINDOWS\SYSTEM32\vbzip10.dll
C:\WINDOWS\SYSTEM32\vrihmlpj.ini
C:\WINDOWS\SYSTEM32\xdacpyyn.dll
C:\WINDOWS\SYSTEM32\xrbhhjue.dll
C:\WINDOWS\SYSTEM32\xwwbjxgs.dll
C:\WINDOWS\SYSTEM32\xxlusmoo.ini
C:\WINDOWS\SYSTEM32\yqakcipk.dll
C:\WINDOWS\SYSTEM32\yvggllqb.ini
.
Incapable d'obtenir les privilèges Système
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Menu Démarrer\Live Safety Center.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Online Security Guide.lnk
C:\Documents and Settings\julien.\Bureau\Live Safety Center.lnk
C:\Documents and Settings\julien.\Bureau\Online Security Guide.lnk
C:\Documents and Settings\julien.\Favoris\Online Security Guide.lnk
C:\WINDOWS\SYSTEM32\aawymofe.dll
C:\WINDOWS\SYSTEM32\afsftirn.dll
C:\WINDOWS\SYSTEM32\axkpetff.dll
C:\WINDOWS\SYSTEM32\bvrperoe.ini
C:\WINDOWS\SYSTEM32\byqevtju.dll
C:\WINDOWS\SYSTEM32\disrdjod.dll
C:\WINDOWS\SYSTEM32\dojdrsid.ini
C:\WINDOWS\SYSTEM32\dwranrrm.ini
C:\WINDOWS\SYSTEM32\ecjwkhta.dll
C:\WINDOWS\SYSTEM32\efomywaa.ini
C:\WINDOWS\SYSTEM32\engmskgh.ini
C:\WINDOWS\SYSTEM32\ephebuja.ini
C:\WINDOWS\SYSTEM32\fgcxjlts.ini
C:\WINDOWS\SYSTEM32\fiphfyat.ini
C:\WINDOWS\SYSTEM32\fktbjgkb.ini
C:\WINDOWS\SYSTEM32\ggmwribn.dll
C:\WINDOWS\SYSTEM32\glwctlle.dll
C:\WINDOWS\SYSTEM32\haawwlpb.dll
c:\WINDOWS\SYSTEM32\hcjjowcu.dll
C:\WINDOWS\SYSTEM32\hgksmgne.dll
C:\WINDOWS\SYSTEM32\ilorrfih.dll
C:\WINDOWS\SYSTEM32\kjuffnod.ini
C:\WINDOWS\SYSTEM32\kpvsenrb.ini
C:\WINDOWS\SYSTEM32\kyqxekgq.ini
C:\WINDOWS\SYSTEM32\lqarhxpu.dll
C:\WINDOWS\SYSTEM32\lwpehbvv.dll
C:\WINDOWS\SYSTEM32\mcrh.tmp
C:\WINDOWS\SYSTEM32\mrlyqwxn.ini
C:\WINDOWS\SYSTEM32\nciffcjt.ini
C:\WINDOWS\SYSTEM32\ncmuhhxi.dll
C:\WINDOWS\SYSTEM32\nproxbou.dll
C:\WINDOWS\SYSTEM32\nvxjowfo.ini
C:\WINDOWS\SYSTEM32\nyypcadx.ini
C:\WINDOWS\SYSTEM32\oomsulxx.dll
C:\WINDOWS\SYSTEM32\ptrqwhtp.ini
C:\WINDOWS\SYSTEM32\rynkapko.ini
C:\WINDOWS\SYSTEM32\sgvbqtcn.ini
C:\WINDOWS\SYSTEM32\stakvhlx.dll.vir
C:\WINDOWS\SYSTEM32\thcaolmi.ini
C:\WINDOWS\SYSTEM32\trbnavdj.ini
C:\WINDOWS\SYSTEM32\ucwojjch.ini
C:\WINDOWS\SYSTEM32\uobxorpn.ini
C:\WINDOWS\SYSTEM32\vbzip10.dll
C:\WINDOWS\SYSTEM32\vrihmlpj.ini
C:\WINDOWS\SYSTEM32\xdacpyyn.dll
C:\WINDOWS\SYSTEM32\xrbhhjue.dll
C:\WINDOWS\system32\xrbhhjue.dllbox
C:\WINDOWS\SYSTEM32\xwwbjxgs.dll
C:\WINDOWS\SYSTEM32\xxlusmoo.ini
C:\WINDOWS\SYSTEM32\yqakcipk.dll
C:\WINDOWS\SYSTEM32\yvggllqb.ini
.
((((((((((((((((((((((((((((( Fichiers cr''s 2007-10-25 to 2007-11-25 ))))))))))))))))))))))))))))))))))))
.
2007-11-22 21:35 <REP> d-------- C:\WINDOWS\ERUNT
2007-11-20 15:18 <REP> d-------- C:\HijackThis
2007-11-20 14:07 <REP> d-------- C:\Program Files\MSBuild
2007-11-20 13:58 <REP> d-------- C:\WINDOWS\SYSTEM32\XPSViewer
2007-11-20 13:54 <REP> d-------- C:\Program Files\Reference Assemblies
2007-11-14 22:20 <REP> d-------- C:\VundoFix Backups
2007-11-12 20:27 584,192 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll
2007-11-12 19:12 30,040 --a------ C:\WINDOWS\SYSTEM32\wuapi.dll.mui
2007-11-08 14:11 <REP> d-------- C:\Program Files\Nordson Corporation
2007-11-06 19:16 128 --a------ C:\Documents and Settings\julien.\pdf.exe
2007-11-05 14:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-05 01:24 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-11-01 21:38 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-20 12:45 --------- d-----w C:\Program Files\Dell
2007-11-13 19:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-09 12:08 --------- d-----w C:\Program Files\Java
2007-09-26 12:11 --------- d-----w C:\Program Files\DivX
2007-09-05 21:27 512 ----a-w C:\drmHeader.bin
2007-07-02 12:42 26,160 ----a-w C:\Documents and Settings\julien.\Application Data\GDIPFONTCACHEV1.DAT
2004-10-20 14:33 203 ----a-w C:\Program Files\Raccourci vers Lecteur CD.lnk
2005-04-18 15:54 8 --sh--r C:\WINDOWS\SYSTEM32\929981F961.sys
2005-03-13 15:51 56 --sh--r C:\WINDOWS\SYSTEM32\DF06BCDE3B.sys
2005-08-30 21:51 9,342 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2007-11-24_18.40.37.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-25 18:48:04 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_21c.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les 'l'ments vides & les 'l'ments initiaux l'gitimes ne sont pas list's
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-01 18:33]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-02 15:32]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-03-04 20:59]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-07-17 10:18]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 12:28]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 17:50]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-20 00:09]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 08:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 08:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 08:36]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-03 21:43]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 07:00]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2005-12-07 02:55]
"Network Associates Error Reporting Service"="C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe" [2003-10-07 08:48]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 20:48]
"9434efde"="C:\WINDOWS\system32\nproxbou.dll" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 00:09]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\[u]0/u\[u]0/u]
"Script"=\\eu\netlogon\dst\tzupdate_gpo.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\[u]0/u]
"Script"=MaxAllowedZone.bat
R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R2 MDC80211;iPass Protocol (IEEE 802.1x) v2.3.1.9;C:\WINDOWS\system32\DRIVERS\mdc80211.sys
R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S3 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys
.
Contenu du dossier 'Scheduled Tasks/Tfches planifi'es'
"2007-09-26 09:21:00 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1088241064.job"
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-25 19:49:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-25 19:53:24 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-24 18:41
.
--- E O F ---
chrifleur
Messages postés
1091
Date d'inscription
samedi 29 septembre 2007
Statut
Contributeur
Dernière intervention
19 novembre 2008
18
25 nov. 2007 à 20:01
25 nov. 2007 à 20:01
cette fois il y a du mieux?
un rapport hijack this stp
un rapport hijack this stp
Et voici le HijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:59, on 2007-11-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\nproxbou.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:59, on 2007-11-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\nproxbou.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
chrifleur
Messages postés
1091
Date d'inscription
samedi 29 septembre 2007
Statut
Contributeur
Dernière intervention
19 novembre 2008
18
25 nov. 2007 à 20:06
25 nov. 2007 à 20:06
lance hijack this pour un scan et coche cette ligne
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\nproxbou.dll",b
ferme toutes tes applications y comrpis internet et clique sur fix checked
Fais un scan en ligne avec
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
NOTE: le scan est à faire avec Internet Explorer
Dans la nouvelle fenêtre qui s'affiche clique sur J'accepte
On va te demander de télécharger des contrôles ActiveX, accepte .
Laisse le faire les mises à jour puis quand il aura fini, clique sur Suivant
Dans le menu Choisissez la cible de l'analyse , sélectionne Poste de travail .
Le scan va commencer.
Reviens avec le rapport de scan obtenu
O4 - HKLM\..\Run: [9434efde] rundll32.exe "C:\WINDOWS\system32\nproxbou.dll",b
ferme toutes tes applications y comrpis internet et clique sur fix checked
Fais un scan en ligne avec
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
NOTE: le scan est à faire avec Internet Explorer
Dans la nouvelle fenêtre qui s'affiche clique sur J'accepte
On va te demander de télécharger des contrôles ActiveX, accepte .
Laisse le faire les mises à jour puis quand il aura fini, clique sur Suivant
Dans le menu Choisissez la cible de l'analyse , sélectionne Poste de travail .
Le scan va commencer.
Reviens avec le rapport de scan obtenu
Depuis hier j'essaie de faire suivre le rapport de kaspersky mais je n'y arrive pas car j epense que le log est trop gros (1,87 Mo en .txt).
J'ai essayé en mettant une première moitié puis une autre moitié mais ça ne marche pas ... J'ai vu par contre que j'avais reçu le mail de confirmation sur ma boîte, donc peut être l'as tu reçu aussi ....
Sinon je peux te le faire suivre directement, à moins qu'on trouve un endroit tampon pour stocker le fichier et se l'échanger ...
En tout état de cause, 2 virus trouvés, 4 fichiers traîtés et des dizaines et des dizaines de fichiers dont l'accès est vérouillé, et qui ont donc été ignorés par Kasperski (fichiers IE5.Content par exemple ...)
Je te fais suivre un HijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:44, on 2007-11-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
J'ai essayé en mettant une première moitié puis une autre moitié mais ça ne marche pas ... J'ai vu par contre que j'avais reçu le mail de confirmation sur ma boîte, donc peut être l'as tu reçu aussi ....
Sinon je peux te le faire suivre directement, à moins qu'on trouve un endroit tampon pour stocker le fichier et se l'échanger ...
En tout état de cause, 2 virus trouvés, 4 fichiers traîtés et des dizaines et des dizaines de fichiers dont l'accès est vérouillé, et qui ont donc été ignorés par Kasperski (fichiers IE5.Content par exemple ...)
Je te fais suivre un HijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:44, on 2007-11-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPass\iPassConnect NORD_PROD\downloader\ipccheck.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.fr/portail
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = erkisa01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.nordson.com;*.enordson.net;amhwss18.nordson.com;mymail.nordson.com;192.168.0.99;www.nordson.*;*.enordson.com;*.3dpublisher.net;enordson.net;www.zoomerang.com;192.168.0.100;172.16.5.*;solutionbrowser.erp.sap.fmpmedia.com;*enordson.com;www.puffe.com;http://www.harkis.harting.com;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.orange.fr/portail
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\Software\..\Telephony: DomainName = eu.nordson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eu.nordson.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eu.nordson.com
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect NORD_PROD\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect NORD_PROD\iPCAgent.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE