HELP !!!!!!!! Virus msn "album photo"

Fermé
Gillou - 15 déc. 2007 à 15:30
 Utilisateur anonyme - 16 déc. 2007 à 18:08
Bonjour,j'ai chopé le virus msn : album.zip . Après plusieurs scan , le virus est toujours sur mon PC. Après une recherche sur le forum, j'ai trouvé une manip avec msnfix et HijackThis. Voici les rapports. Le virus est il toujours sur mon PC ? merci pour votre aide...


MSNFix 1.605

C:\Documents and Settings\utilisateur\Bureau\MSNFix
Fix exécuté le 15/12/2007 - 9:23:49,42 By utilisateur
mode normal

************************ Recherche les fichiers présents

... C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\removalfile.bat
... C:\WINDOWS\image08.zip
... C:\WINDOWS\img3858.zip

************************ MSNCHK ***** /!\ beta test /!\



************************ Recherche les dossiers présents

Aucun dossier trouvé




************************ Suppression des fichiers

.. OK ... C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\removalfile.bat
.. OK ... C:\WINDOWS\image08.zip
.. OK ... C:\WINDOWS\img3858.zip



************************ Nettoyage du registre



************************ Fichiers suspects

/!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

[C:\lir.exe] DEE93E9B21ABADCEB148DEADD93E8371

[color=#FF0000][b]==>[/b][/color] SVP merci d'envoyer le fichier [b] C:\DOCUME~1\UTILIS~1\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr



Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 15122007_ 9260803.zip


------------------------------------------------------------------------
Auteur : !aur3n7 Contact: https://www.ionos.fr/
------------------------------------------------------------------------

--------------------------------------------- END ---------------------------------------------



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:36:43, on 15/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\WINDOWS\system32\rgluulll.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\utilisateur\Bureau\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O5 "LPT1:" /M "Stylus CX6600"
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P36 "EPSON Stylus CX6600 Series (Copie 1)" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Image Remote Players] sysvn.exe
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKLM\..\Run: [fc318db8] rundll32.exe "C:\WINDOWS\system32\oobwllud.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/default.aspx
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\rgluulll.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
A voir également:

19 réponses

Utilisateur anonyme
15 déc. 2007 à 15:36
bonjour il semble y avoir une autre infection effectue ceci

Télécharge VundoFix.exe par Atribune http://www.atribune.org/content/view/24/2/ sur ton Bureau.

* Double-clique sur VundoFix.exe afin de le lancer
* Clique sur le bouton Scan for Vundo
* Lorsque le scan est terminé, clique sur le bouton Remove Vundo
* Une invite te demandera si tu veux supprimer les fichiers, clique YES
* Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
* Tu verras une invite qui t'annonce que ton PC va redémarrer; clique sur OK

--> Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse

Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".
0
Voici les 2 rapports. Un grand merci pour ton aide.


VundoFix V6.7.3

Checking Java version...

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Scan started at 15:42:59 15/12/2007

Listing files found while scanning....

C:\windows\system32\byxurpp.dll
C:\windows\system32\cbxxust.dll
C:\windows\system32\hggfecy.dll
C:\windows\system32\jkkhffg.dll
C:\windows\system32\ljjigdc.dll
C:\windows\system32\nnnolml.dll
C:\windows\system32\qomljkl.dll
C:\windows\system32\ssqomki.dll
C:\windows\system32\wvuutuv.dll
C:\WINDOWS\system32\yayywwx.dll

Beginning removal...

Attempting to delete C:\windows\system32\byxurpp.dll
C:\windows\system32\byxurpp.dll Has been deleted!

Attempting to delete C:\windows\system32\cbxxust.dll
C:\windows\system32\cbxxust.dll Has been deleted!

Attempting to delete C:\windows\system32\hggfecy.dll
C:\windows\system32\hggfecy.dll Has been deleted!

Attempting to delete C:\windows\system32\jkkhffg.dll
C:\windows\system32\jkkhffg.dll Has been deleted!

Attempting to delete C:\windows\system32\ljjigdc.dll
C:\windows\system32\ljjigdc.dll Has been deleted!

Attempting to delete C:\windows\system32\nnnolml.dll
C:\windows\system32\nnnolml.dll Has been deleted!

Attempting to delete C:\windows\system32\qomljkl.dll
C:\windows\system32\qomljkl.dll Has been deleted!

Attempting to delete C:\windows\system32\ssqomki.dll
C:\windows\system32\ssqomki.dll Has been deleted!

Attempting to delete C:\windows\system32\wvuutuv.dll
C:\windows\system32\wvuutuv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yayywwx.dll
C:\WINDOWS\system32\yayywwx.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\yayywwx.dll
C:\WINDOWS\system32\yayywwx.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

------------------------------------------------------------------------------------------------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:05:07, on 15/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\sysvn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\utilisateur\Bureau\HijackThis.exe
C:\Documents and Settings\utilisateur\Bureau\VundoFix.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O5 "LPT1:" /M "Stylus CX6600"
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P36 "EPSON Stylus CX6600 Series (Copie 1)" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Image Remote Players] sysvn.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [fc318db8] rundll32.exe "C:\WINDOWS\system32\nyrscqlo.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\rgluulll.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
0
Utilisateur anonyme
15 déc. 2007 à 16:11
ok ca avavnce ensuite
Télécharge sur le bureau
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
=> Double clic sur VirtumundoBeGone.exe
=> Clic Continue ==> clic Start
=> Clic Oui
=> A la fin si Vundo est présent , le PC s’éteint et redémarre
- Si Ecran bleu et message : Erreur fatale .. pas de problème
=> Poster le rapport VBG.TXT qui est sur le bureau
0
Voici le rapport VBG TXT :


[12/15/2007, 16:15:41] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\utilisateur\Bureau\VirtumundoBeGone.exe" )
[12/15/2007, 16:16:09] - Detected System Information:
[12/15/2007, 16:16:09] - Windows Version: 5.1.2600, Service Pack 2
[12/15/2007, 16:16:09] - Current Username: utilisateur (Admin)
[12/15/2007, 16:16:09] - Windows is in NORMAL mode.
[12/15/2007, 16:16:09] - Searching for Browser Helper Objects:
[12/15/2007, 16:16:09] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[12/15/2007, 16:16:09] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[12/15/2007, 16:16:09] - BHO 3: {22BF413B-C6D2-4d91-82A9-A0F997BA588C} (Skype add-on (mastermind))
[12/15/2007, 16:16:09] - BHO 4: {84DC55C3-0F9E-4866-A570-CD98DDF28DCF} ()
[12/15/2007, 16:16:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2007, 16:16:09] - Checking for HKLM\...\Winlogon\Notify\vturp
[12/15/2007, 16:16:09] - Key not found: HKLM\...\Winlogon\Notify\vturp, continuing.
[12/15/2007, 16:16:09] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[12/15/2007, 16:16:09] - BHO 6: {925a3780-7c27-40a5-a159-a72cdf80f4d8} ()
[12/15/2007, 16:16:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2007, 16:16:09] - Checking for HKLM\...\Winlogon\Notify\xrmvbldr
[12/15/2007, 16:16:09] - Key not found: HKLM\...\Winlogon\Notify\xrmvbldr, continuing.
[12/15/2007, 16:16:09] - BHO 7: {a24a872b-073a-43c4-a7e9-02f5f71fb975} ()
[12/15/2007, 16:16:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2007, 16:16:09] - Checking for HKLM\...\Winlogon\Notify\wbwwncsg
[12/15/2007, 16:16:09] - Key not found: HKLM\...\Winlogon\Notify\wbwwncsg, continuing.
[12/15/2007, 16:16:09] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[12/15/2007, 16:16:09] - BHO 9: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[12/15/2007, 16:16:09] - BHO 10: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Windows Live Toolbar Helper)
[12/15/2007, 16:16:10] - BHO 11: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[12/15/2007, 16:16:10] - Finished Searching Browser Helper Objects
[12/15/2007, 16:16:10] - Finishing up...
[12/15/2007, 16:16:10] - Nothing found! Exiting...
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
15 déc. 2007 à 17:53
peu tu poster un nouvel hijackthis stp

comment se porte ton ordi il dois deja y avoir du mieux !! non
0
Oui c'est beaucoup mieux, merci !!!! voici le rapport hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:59:24, on 15/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\sysvn.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\utilisateur\Bureau\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.msn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O5 "LPT1:" /M "Stylus CX6600"
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P36 "EPSON Stylus CX6600 Series (Copie 1)" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Image Remote Players] sysvn.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [fc318db8] rundll32.exe "C:\WINDOWS\system32\nyrscqlo.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\rgluulll.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
0
Bon effectivement l'ordi fonctionne mieux mais malheureusemnt il y a encore ce pu**** de virus sur msn....Je c'est plus quoi faire...
0
Utilisateur anonyme
15 déc. 2007 à 22:47
telecharge et execute sdfix sur ce lien tu le fix et un tutoriel d'utilisation net'inquiete pas on vas l'avoir se petit morpion !!http://mickael.barroux.free.fr/securite/sdfix.php

ps copie moi le rapport sdfix
0
Bonjour, il fait pas chaud ce matin...Je viens de faire le nettoyage avec sdfix mais dès que ma connexion se met en route, une fenêtre s'affiche 1 sec et disparait. Je pense que c'est le virus mais impossible de voir son nom car trop rapide pour moi.... En tout cas voici le rapport sdfix :


SDFix: Version 1.118

Run by Administrateur on 16/12/2007 at 09:34

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\img3858.zip - Deleted
C:\WINDOWS\image08.zip - Deleted




Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-16 09:48:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\01\26-{A86E1DE7-8589-2358-D779-07C28590219E}-v1-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\03\42-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v203-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 44958 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\03\42-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v203-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3180 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\03\42-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v203-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4992 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\08\213-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v208-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v213-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 57324 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\08\213-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v208-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v213-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3936 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\08\213-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v208-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v213-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6304 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\14\217-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v214-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v217-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 32952 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\14\217-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v214-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v217-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2424 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\14\217-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v214-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v217-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3672 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\18\220-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v218-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v220-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 35616 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\18\220-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v218-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v220-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2496 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\18\220-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v218-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v220-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4024 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\18\224-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v218-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v224-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 35616 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\18\224-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v218-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v224-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4024 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\23\53-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v223-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 30018 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\23\53-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v223-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3304 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\27\15-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v27-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 22494 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\27\15-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v27-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2488 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\27\59-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v227-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 42582 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\27\59-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v227-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3180 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\27\59-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v227-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4824 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\33\235-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v233-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v235-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 41124 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\33\235-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v233-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v235-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2964 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\33\235-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v233-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v235-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4544 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\33\237-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v233-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v237-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 41124 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\33\237-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v233-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v237-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4544 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\36\44-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v36-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v44-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4530 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\36\44-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v36-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v44-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 504 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\38\243-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v238-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v243-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 57180 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\38\243-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v238-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v243-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6352 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\39\45-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v39-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v45-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 28236 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\39\45-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v39-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v45-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2082 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\39\45-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v39-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v45-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3160 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\41\23-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v41-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 27354 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\41\23-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v41-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2992 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\42\26-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v42-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 14502 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\42\26-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v42-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1608 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\43\33-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v43-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 13584 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\43\33-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v43-{44E7658C-92BB-4BC3-AE0A-EE48442A5C85}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1496 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\54\57-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v54-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4278 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\54\57-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v54-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 512 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\98\200-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v198-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v200-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 47154 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\98\200-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v198-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v200-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3270 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\98\200-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v198-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v200-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5280 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\98\202-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v198-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v202-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 47154 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\blandinou12@hotmail.fr\DFSR\Staging\CS{A86E1DE7-8589-2358-D779-07C28590219E}\98\202-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v198-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v202-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5280 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\01\14-{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}-v1-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\05\306-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v305-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v306-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 12720 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\05\306-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v305-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v306-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1432 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\11\196-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v11-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v196-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 62976 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\11\196-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v11-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v196-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4674 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\11\196-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v11-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v196-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6984 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\11\197-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v11-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v197-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 62976 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\11\197-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v11-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v197-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6984 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\18\307-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v18-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v307-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 61320 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\18\307-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v18-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v307-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6816 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\22\322-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v22-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v322-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 62688 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\22\322-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v22-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v322-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4566 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\22\322-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v22-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v322-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7040 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\22\323-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v22-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v323-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 62688 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\22\323-{7B7F14FB-7677-4FD4-A91F-23CAAE6810F9}-v22-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v323-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7040 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\48\189-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v148-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v189-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 9228 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\fred_meuh@hotmail.com\DFSR\Staging\CS{0F52CB7E-AF75-BBBE-BA55-11EAF03FF2CE}\48\189-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v148-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v189-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1032 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\22\184-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v122-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v184-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7320 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\22\184-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v122-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v184-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\59\71-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v59-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8796 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\59\71-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v59-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 992 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\00\155-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v100-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7302 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\00\155-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v100-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 832 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\01\15-{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}-v1-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\01\156-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v101-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v156-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7374 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\01\156-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v101-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v156-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\02\158-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v102-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v158-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7194 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\02\158-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v102-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v158-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 832 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\02\193-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v102-{19483608-C9DD-4400-BB5B-4513868F6B02}-v193-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 832 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\03\157-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v103-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7392 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\03\157-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v103-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 848 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\04\159-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v104-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v159-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7374 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\04\159-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v104-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v159-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\04\195-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v104-{19483608-C9DD-4400-BB5B-4513868F6B02}-v195-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\05\160-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v105-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5574 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\05\160-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v105-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\06\161-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v106-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6888 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\06\161-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v106-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\06\197-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v106-{19483608-C9DD-4400-BB5B-4513868F6B02}-v197-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\07\162-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v107-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v162-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6780 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\07\162-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v107-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v162-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 768 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\07\198-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v107-{19483608-C9DD-4400-BB5B-4513868F6B02}-v198-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 768 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\08\163-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v108-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v163-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8328 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\08\163-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v108-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v163-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 944 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\08\199-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v108-{19483608-C9DD-4400-BB5B-4513868F6B02}-v199-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 944 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\09\165-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v109-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v165-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7500 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\09\165-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v109-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v165-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 848 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\09\166-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v109-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v166-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7500 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\09\166-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v109-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v166-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 848 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\10\173-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v110-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8850 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\10\173-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v110-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1016 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\11\174-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v111-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v174-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8832 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\11\174-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v111-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v174-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 984 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\12\175-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v112-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v175-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7860 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\12\175-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v112-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v175-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 880 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\13\172-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v113-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7860 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\13\172-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v113-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 880 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\14\176-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v114-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v176-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7284 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\14\176-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v114-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v176-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\15\177-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v115-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v177-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7140 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\15\177-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v115-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v177-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 808 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\16\178-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v116-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v178-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8544 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\16\178-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v116-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v178-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 952 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\17\179-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v117-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v179-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8490 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\17\179-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v117-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v179-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 960 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\18\180-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v118-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v180-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7968 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\18\180-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v118-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v180-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 912 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\19\181-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v119-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v181-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6744 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\19\181-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v119-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v181-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 760 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\20\182-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v120-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v182-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8022 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\20\182-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v120-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v182-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 896 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\21\183-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v121-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v183-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8490 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\21\183-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v121-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v183-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 936 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\60\72-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v60-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v72-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7428 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\60\72-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v60-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v72-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 848 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\61\73-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v61-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v73-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8076 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\61\73-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v61-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v73-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 920 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\62\74-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v62-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v74-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8256 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\62\74-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v62-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v74-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 928 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\63\75-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v63-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v75-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8508 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\63\75-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v63-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v75-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 960 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\64\76-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v64-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v76-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7446 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\64\76-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v64-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v76-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 856 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\65\77-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v65-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v77-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8292 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\65\77-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v65-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v77-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 912 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\67\79-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v67-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v79-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7482 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\67\79-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v67-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v79-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\68\82-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v68-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v82-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6726 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\68\82-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v68-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v82-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 760 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\69\83-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v69-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v83-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8094 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\69\83-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v69-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v83-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 904 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\70\84-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v70-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v84-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7788 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\70\84-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v70-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v84-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 904 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\71\85-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v71-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v85-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7986 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\71\85-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v71-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v85-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 904 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\72\86-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v72-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v86-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7410 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\72\86-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v72-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v86-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 824 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\73\87-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v73-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v87-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7788 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\73\87-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v73-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v87-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 888 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\74\88-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v74-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v88-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 9354 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\74\88-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v74-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v88-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1048 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\75\187-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v75-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v187-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7986 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\75\187-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v75-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v187-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 904 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\76\80-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v76-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v80-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6708 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\76\80-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v76-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v80-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 760 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\77\89-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v77-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v89-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8454 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\77\89-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v77-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v89-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 928 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\78\91-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v78-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v91-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8256 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\78\91-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v78-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v91-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 936 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\79\90-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v79-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v90-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6924 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\79\90-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v79-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v90-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 760 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\80\188-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v80-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v188-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7698 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\80\188-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v80-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v188-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 872 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\81\137-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v81-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v137-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7716 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\81\137-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v81-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v137-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 872 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\82\138-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v82-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v138-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6708 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.com\SharingMetadata\julye@tele2.fr\DFSR\Staging\CS{2199A563-D396-50CC-A6F1-A6B7D4DB9A41}\82\138-{27032494-4103-4EB4-B0AA-4CD0CCACC97D}-v82-{5AD0AC2F-C819-4D28-9C91-FE0FB831870B}-v138-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 752 bytes hidden from API
C:\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Messenger\gilloulefou7@hotmail.co
0
C'est bon j'ai réussi à voir les mots qui sont sur la fenetre qui s'ouvre durant la connexion :

C:\windows\sdrv\helper.exe

writing to c:\windows\system32\drivers\etc\hosts
0
Utilisateur anonyme
16 déc. 2007 à 12:01
bonjour tu as un belle infection , ne t'inquiete nous allons en venir a bout ! normalement pour msn ca dois etre bon , tu peu essayer mais fait attention de bloquer le contact qui te la envoyer !
0
jfkpresident Messages postés 13408 Date d'inscription lundi 3 septembre 2007 Statut Contributeur sécurité Dernière intervention 5 janvier 2015 1 175
16 déc. 2007 à 12:18
salut carossier qu'est tu penses de ces lignes?:O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\rgluulll.exe (file missing
O4 - HKLM\..\Run: [fc318db8] rundll32.exe "C:\WINDOWS\system32\nyrscqlo.dll",b
O4 - HKLM\..\Run: [Image Remote Players] sysvn.exe
C:\WINDOWS\sysvn.exe

**si je ne répond pas de suite c'est que moi aussi j'ai un métier et une famille**
0
Et bien non le virus est toujours présent...j'ai bloquer le contact qui me la envoyer (heureusement que c'est pas ma copine!!!!) J'espère qu'ont va la trouver cett belle infection
0
Utilisateur anonyme
16 déc. 2007 à 13:23
pour ²ommencer il faut imperativement que tu instal un pare feu !!

http://www.commentcamarche.net/telecharger/telechargement 157 zonealarm

il est aussi tres important que tu te separe de avast car il beaucoup de point faible en ce moment je te conseil avira antivir qui est plus performant !!

anti virus : antivir

https://www.malekal.com/avira-free-security-antivirus-gratuit/

http://mickael.barroux.free.fr/securite/antivir.php <- tutoriel + complet
0
Utilisateur anonyme
16 déc. 2007 à 13:26
une fois ceci effectue voici la suite de la procedure

Télécharge Combofix.exe de sUBs sur ton Bureau,

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Déconnecte toi du net et désactive ton antivirus pour que Combofix puisse s'exécuter normalement

Double clique sur Combofix.exe
Mets le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan
Lorsque le scan sera terminé, un rapport apparaîtra.

Poste lerapport dans ta prochaine réponse.

Note : Le rapport se trouve également là : C:\Combofix.txt+
0
Je crois que nous tenons le bon bout !!! j'ai bien viré avast et installé antivir et 2 sec après l'installation il me demandait de supprimer :

c:\windows\system32\drivers\etc\hosts. Bon maintenant voici le rapport de comboFix :

ComboFix 07-12-16.3 - utilisateur 2007-12-16 14:39:12.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.553 [GMT 1:00]
Running from: C:\Documents and Settings\utilisateur\Bureau\ComboFix.exe
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini
C:\WINDOWS\image08.zip
C:\WINDOWS\system32\abjrvtey.exe
C:\WINDOWS\system32\awtsqnl.dll
C:\WINDOWS\system32\awtsqop.dll
C:\WINDOWS\system32\awtssrq.dll
C:\WINDOWS\system32\awtstut.dll
C:\WINDOWS\system32\awttqoo.dll
C:\WINDOWS\system32\awttuvv.dll
C:\WINDOWS\system32\byxuspn.dll
C:\WINDOWS\system32\byxxyaa.dll
C:\WINDOWS\system32\cbxxwur.dll
C:\WINDOWS\system32\cmmobuos.exe
C:\WINDOWS\system32\ddcccay.dll
C:\WINDOWS\system32\ddcccba.dll
C:\WINDOWS\system32\efpqucag.dll
C:\WINDOWS\system32\gebcbya.dll
C:\WINDOWS\system32\hgghhfd.dll
C:\WINDOWS\system32\iifccyy.dll
C:\WINDOWS\system32\iifebaa.dll
C:\WINDOWS\system32\iifeccy.dll
C:\WINDOWS\system32\jkklkji.dll
C:\WINDOWS\system32\kboxjduj.dll
C:\WINDOWS\system32\khffecy.dll
C:\WINDOWS\system32\kokugpte.exe
C:\WINDOWS\system32\lmkgvvdi.dll
C:\WINDOWS\system32\lolgwhru.exe
C:\WINDOWS\system32\lrtdpkbo.exe
C:\WINDOWS\system32\mljjkhf.dll
C:\WINDOWS\system32\mtqqtwbk.dll
C:\WINDOWS\system32\mumslvst.dll
C:\WINDOWS\system32\nefyklcd.dll
C:\WINDOWS\system32\nnnlmlm.dll
C:\WINDOWS\system32\nyrscqlo.dll
C:\WINDOWS\system32\olqcsryn.ini
C:\WINDOWS\system32\opnllii.dll
C:\WINDOWS\system32\opnlmnk.dll
C:\WINDOWS\system32\pajokwoq.exe
C:\WINDOWS\system32\prutv.ini
C:\WINDOWS\system32\prutv.ini2
C:\WINDOWS\system32\qomkhij.dll
C:\WINDOWS\system32\rqroonl.dll
C:\WINDOWS\system32\seqbcguw.dll
C:\WINDOWS\system32\ssqqpqp.dll
C:\WINDOWS\system32\ummhhkic.exe
C:\WINDOWS\system32\urqonnm.dll
C:\WINDOWS\system32\vturp.dll
C:\WINDOWS\system32\vtuurpp.dll
C:\WINDOWS\system32\wbwwncsg.dll
C:\WINDOWS\system32\wvurqpn.dll
C:\WINDOWS\system32\wvussro.dll
C:\WINDOWS\system32\xrmvbldr.dll
C:\WINDOWS\system32\xxyayaa.dll
C:\WINDOWS\system32\xxyvttq.dll
C:\WINDOWS\system32\xxyvwww.dll
C:\WINDOWS\system32\xxyvwxy.dll
C:\WINDOWS\system32\xxyyvsq.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_DOMAINSERVICE
-------\DomainService


((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-16 to 2007-12-16 ))))))))))))))))))))))))))))))))))))
.

2007-12-16 14:19 . 2007-12-16 14:19 <REP> d-------- C:\Program Files\Avira
2007-12-16 14:19 . 2007-12-16 14:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-12-16 14:06 . 2007-12-16 14:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-16 14:06 . 2007-12-16 14:08 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-12-16 14:05 . 2007-12-16 15:01 172,064 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-16 14:05 . 2007-12-16 14:05 75,932 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-12-16 14:05 . 2007-06-21 21:54 75,248 --a------ C:\WINDOWS\zllsputility.exe
2007-12-16 14:05 . 2007-12-16 14:05 74,396 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-12-16 14:05 . 2007-06-21 21:55 54,672 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2007-12-16 14:05 . 2007-06-21 21:55 42,384 --a------ C:\WINDOWS\zllsputility_loc040c.dll
2007-12-16 14:05 . 2007-06-21 21:55 21,904 --a------ C:\WINDOWS\system32\imsinstall_loc040c.dll
2007-12-16 14:05 . 2007-06-21 21:55 17,808 --a------ C:\WINDOWS\system32\imslsp_install_loc040c.dll
2007-12-16 14:05 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-12-16 14:05 . 2007-12-16 14:59 3,068 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-16 14:03 . 2007-12-16 14:55 <REP> d-------- C:\WINDOWS\Internet Logs
2007-12-16 09:52 . 2007-12-16 14:12 51,864 --a------ C:\WINDOWS\img3858.zip
2007-12-16 09:33 . 2007-12-16 09:33 <REP> d-------- C:\WINDOWS\ERUNT
2007-12-15 15:42 . 2007-12-15 15:59 <REP> d-------- C:\VundoFix Backups
2007-12-15 14:48 . 2007-12-15 14:54 1,393 --a------ C:\WINDOWS\imsins.BAK
2007-12-15 10:07 . 2007-12-15 10:07 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Grisoft
2007-12-15 10:06 . 2007-10-28 20:48 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2007-12-15 10:06 . 2007-10-28 20:48 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-12-15 10:06 . 2007-10-28 19:58 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2007-12-15 10:06 . 2007-10-28 20:48 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2007-12-15 10:06 . 2007-10-28 20:48 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2007-12-15 10:06 . 2007-10-28 20:48 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2007-12-15 10:06 . 2007-12-15 14:27 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-12-15 09:59 . 2007-12-15 09:59 <REP> d-------- C:\Documents and Settings\utilisateur\Application Data\Grisoft
2007-12-15 09:58 . 2007-12-15 09:58 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-15 09:58 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-14 14:29 . 2007-12-15 15:20 894,916 ---hs---- C:\WINDOWS\system32\dullwboo.ini
2007-12-14 14:21 . 2007-12-16 10:36 132,250 --a------ C:\lir.exe
2007-12-12 20:35 . 2007-12-14 14:21 970,423 ---hs---- C:\WINDOWS\system32\vepvaykj.ini
2007-12-11 20:34 . 2007-12-12 20:35 892,186 ---hs---- C:\WINDOWS\system32\jppwqtgf.ini
2007-12-10 20:36 . 2007-12-11 18:32 859,664 ---hs---- C:\WINDOWS\system32\khpcitaj.ini
2007-12-10 20:10 . 2007-12-10 20:10 <REP> d-------- C:\Program Files\directx
2007-12-10 20:10 . 2007-12-10 20:11 3,086 --a------ C:\WINDOWS\Corsairs.isu
2007-12-10 20:08 . 1998-01-23 12:22 304,128 --a------ C:\WINDOWS\IsUninst.exe
2007-12-10 20:07 . 2007-12-10 20:07 <REP> d-------- C:\Documents and Settings\utilisateur\WINDOWS
2007-12-09 20:54 . 2007-12-09 20:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-09 20:50 . 2007-12-15 10:04 <REP> d-------- C:\Program Files\a-squared Anti-Malware
2007-12-09 20:48 . 2007-12-09 20:49 <REP> d-------- C:\Program Files\Yahoo!
2007-12-09 20:48 . 2007-12-09 20:49 <REP> d-------- C:\Program Files\CCleaner
2007-12-09 20:47 . 2007-12-10 20:19 834,700 ---hs---- C:\WINDOWS\system32\xuxxwned.ini
2007-12-09 18:38 . 2007-12-09 18:38 834,520 ---hs---- C:\WINDOWS\system32\rigeacle.ini
2007-12-08 10:10 . 2007-12-09 18:26 834,460 ---hs---- C:\WINDOWS\system32\yyympywi.ini
2007-12-07 22:54 . 2007-12-07 22:55 <REP> d-------- C:\Program Files\LiveKillCleanMessenger
2007-12-07 22:54 . 2007-12-07 22:54 <REP> d-------- C:\Documents and Settings\utilisateur\Application Data\Live-Prod
2007-12-07 21:58 . 2007-12-08 09:59 834,220 ---hs---- C:\WINDOWS\system32\luyretaa.ini
2007-11-28 22:39 . 2007-11-28 22:39 <REP> d-------- C:\WINDOWS\Sun
2007-11-27 09:27 . 2007-11-27 09:27 <REP> d-------- C:\Documents and Settings\utilisateur\Application Data\AdobeUM
2007-11-18 15:15 . 2007-12-16 00:08 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-11-18 15:15 . 2007-11-18 15:15 1,409 --a------ C:\WINDOWS\QTFont.for
2007-11-17 16:19 . 2007-11-17 16:19 <REP> d-------- C:\Documents and Settings\utilisateur\Application Data\Snapfish
2007-11-16 22:12 . 2007-11-16 22:12 <REP> d--h----- C:\WINDOWS\msdownld.tmp
2007-11-16 22:11 . 2007-11-16 22:11 <REP> d-------- C:\Program Files\Windows Live Favorites
2007-11-16 22:11 . 2007-11-16 22:11 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-11-16 22:10 . 2007-11-16 22:11 <REP> d-------- C:\Program Files\Windows Live Toolbar

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-14 23:07 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\Skype
2007-12-12 20:39 --------- d-----w C:\Program Files\eMule
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 23:59 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\Apple Computer
2007-11-09 22:34 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-11-07 21:23 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\Smart Panel
2007-11-06 18:50 --------- d-----w C:\Program Files\Windows Live
2007-11-06 18:50 --------- d-----w C:\Program Files\MSN Messenger
2007-11-06 18:50 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-11-05 12:45 --------- d-----w C:\Program Files\QuickTime
2007-11-05 12:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-05 12:44 --------- d-----w C:\Program Files\Apple Software Update
2007-11-05 12:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-05 11:01 --------- d-----w C:\Program Files\Orange HSS
2007-11-05 10:59 --------- d-----w C:\Program Files\Fichiers communs\France Telecom
2007-11-05 10:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-05 10:52 --------- d-----w C:\Program Files\SAGEM WiFi manager
2007-11-05 10:51 --------- d-----w C:\Program Files\SAGEM
2007-11-05 10:51 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\InstallShield
2007-11-05 10:49 --------- d-----w C:\Program Files\Securitoo
2007-11-03 14:00 --------- d-----w C:\Program Files\Windows Mobile Device Handbook
2007-11-02 18:17 --------- d-----w C:\Program Files\Ubisoft
2007-10-30 23:59 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\Winamp
2007-10-30 22:30 --------- d-----w C:\Program Files\Winamp
2007-10-30 21:08 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\vlc
2007-10-30 21:07 --------- d-----w C:\Program Files\VideoLAN
2007-10-30 20:21 --------- d-----w C:\Program Files\AIDA32 - Personal System Information
2007-10-30 19:52 --------- d-----w C:\Program Files\Google
2007-10-30 19:18 --------- d-----w C:\Program Files\epson
2007-10-30 19:17 --------- d-----w C:\Program Files\Smart Panel
2007-10-30 19:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL
2007-10-30 19:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-10-30 17:08 --------- d-----w C:\Program Files\Skype
2007-10-30 17:08 --------- d-----w C:\Program Files\Fichiers communs\Skype
2007-10-30 17:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-10-30 16:34 --------- d-----w C:\Program Files\Fichiers communs\Logitech
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 15:34 --------- d-----w C:\Program Files\ma-config.com
2007-10-29 15:34 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\ma-config.com
2007-10-29 15:28 --------- d-----w C:\Program Files\Microsoft.NET
2007-10-29 15:04 --------- d-----w C:\Program Files\Fichiers communs\Nero
2007-10-29 15:01 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2007-10-29 15:01 --------- d-----w C:\Program Files\Ahead
2007-10-29 14:46 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-10-29 14:46 --------- d-----w C:\Program Files\CyberLink
2007-10-29 14:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2007-10-28 19:49 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
2007-10-28 19:49 --------- d-----w C:\Program Files\Fichiers communs\ODBC
2007-10-28 19:38 --------- d-----w C:\Program Files\Alwil Software
2007-10-28 19:36 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-10-28 19:30 --------- d-----w C:\Program Files\PowerArchiver
2007-10-28 19:20 315,392 ----a-w C:\WINDOWS\HideWin.exe
2007-10-28 19:20 --------- d-----w C:\Program Files\Realtek
2007-10-28 19:19 --------- d-----w C:\Program Files\S3
2007-10-28 19:12 --------- d-----w C:\Program Files\VIA
2007-10-28 19:05 --------- d-----w C:\Program Files\microsoft frontpage
2007-10-28 19:05 --------- d-----w C:\Program Files\Java
2007-10-28 19:05 --------- d-----w C:\Program Files\Fichiers communs\Java
2007-10-28 19:01 --------- d-----w C:\Program Files\Services en ligne
2007-10-28 19:00 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
2007-10-20 05:01 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-30 18:13]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 14:07]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe" [2007-10-28 20:05]
"VTTimer"="VTTimer.exe" [2006-09-21 09:36 C:\WINDOWS\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [2007-02-06 00:30 C:\WINDOWS\system32\S3Trayp.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 08:03 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 11:04 C:\WINDOWS\SkyTel.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 17:32]
"EPSON Stylus CX6600 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.exe" [2004-03-01 04:00]
"EPSON Stylus CX6600 Series (Copie 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.exe" [2004-03-01 04:00]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 06:28]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"Image Remote Players"="sysvn.exe" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-08-31 12:25]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

R0 ViBus;ViBus;C:\WINDOWS\system32\DRIVERS\ViBus.sys
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\system32\DRIVERS\ViPrt.sys
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys
R3 S3GIGP;S3GIGP;C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys
S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys
S3 ZDCndis5;ZDCndis5 Protocol Driver;\??\C:\WINDOWS\system32\ZDCndis5.SYS
S3 ZDPNDIS5;ZDPNDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\ZDPNDIS5.SYS

.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-12-07 11:22:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-16 13:56:12 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-16 15:01:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-16 15:03:55 - machine was rebooted
.
2007-12-15 14:02:34 --- E O F ---
0
Utilisateur anonyme
16 déc. 2007 à 16:29
poste un nouvel hijackthis stp !
0
le voici :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:54:17, on 16/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\utilisateur\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O5 "LPT1:" /M "Stylus CX6600"
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P36 "EPSON Stylus CX6600 Series (Copie 1)" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Image Remote Players] sysvn.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
0
jfkpresident Messages postés 13408 Date d'inscription lundi 3 septembre 2007 Statut Contributeur sécurité Dernière intervention 5 janvier 2015 1 175
16 déc. 2007 à 17:59
ca a l'air clean tout ca!
0
Utilisateur anonyme
16 déc. 2007 à 18:08
ca m'as l'air d'etre bon !! comment se porte ton pc ??

effectue cette petite manip ainsi qu'un scan en ligne ( supprim les outils utilises msnfix , vundofix,....)
bien sur tu garde antivir zone alarm et avg anti spy!

il faut purger ta restauration du systeme histoire de ne pas restaurer tes ennuies !

fait demarer / tout les programes / accessoires / outils systemes / restaurations systeme / clic sur parametres resturation , coche la cas desactiver restauration puis applique , redemarre ton ordi et fait le chemin inverse reactive ta restauration systeme et essaie de cree un nouveau point de restauration si tu ne peu pas tans pis il se creeras plus tard!!

effectue un scan online pour voire s'il reste quelque chose copie et colle le rapport du scan ici !

scan en ligne :

Assure-toi que les contrôles active x soient bien configurés dans les options internet comme décrit sur ce lien=> http://www.inoculer.com/activex.php3

Fais un scan en ligne avec https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

Dans la nouvelle fenêtre qui s'affiche clique sur J'accepte

On va te demander de télécharger un ou deux contrôles active x, accepte . Laisse le faire les mises à jour puis quand il aura fini, clique sur Suivant

Dans le menu Choisissez la cible de l'analyse , sélectionne Poste de travail .
Le scan va commencer.Poste le rapport qui sera généré stp.

Aide en cas de problème : http://cybersecurite.xooit.com/t100-Scan-e...spersky.htm#768

NOTE: le scan est à faire avec Internet Explorer
0