Infection Storageprotector
Résolu/Fermé
bluael
Messages postés
37
Date d'inscription
lundi 19 novembre 2007
Statut
Membre
Dernière intervention
27 avril 2011
-
22 déc. 2007 à 13:22
raph83 - 13 janv. 2008 à 13:53
raph83 - 13 janv. 2008 à 13:53
A voir également:
- Infection Storageprotector
- [Pnkbstra]infection ✓ - Forum Virus
- Infection: URL:Mal !!!???? - Forum Virus
- Infection virus ✓ - Forum Virus
- Infection Bloom ? ✓ - Forum Virus
- Techscam...infection ✓ - Forum Virus
34 réponses
bluael
Messages postés
37
Date d'inscription
lundi 19 novembre 2007
Statut
Membre
Dernière intervention
27 avril 2011
25 déc. 2007 à 11:32
25 déc. 2007 à 11:32
Tout d'abord, Joyeux Noël à vous....
Et si un modérateur pouvait effacer le message juste avant, j'ai plantouillé...Merci !!!!
Je n'ai pas retrouvé le rapport FV monde ;-) mais il n'y avait rien de notable.
A ce qui était précisé...
-------------------------------------------------------------------
Pour Symantec Trojan.Vundo.B removal Tool :
Il n'a rien trouvé, alors qu'il a déclenché antivir plusieurs dizaines de fois ???
--------------------------------------------------------------------
Pour OT mOVE IT :
File/Folder C:\WINDOWS\SYSTEM32\wvuvsrq.dll not found.
File/Folder C:\WINDOWS\System32\nymjljoq.dll not found.
File/Folder C:\WINDOWS\bukmon.exe not found.
File/Folder C:\WINDOWS\system32\wvuvsrq.dll not found.
C:\WINDOWS\system32\tvtd.exe moved successfully.
C:\WINDOWS\system32\cly.exe moved successfully.
C:\WINDOWS\system32\slotnkmc.dll unregistered successfully.
C:\WINDOWS\system32\slotnkmc.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\awtss.dll
C:\WINDOWS\System32\awtss.dll NOT unregistered.
File move failed. C:\WINDOWS\System32\awtss.dll scheduled to be moved on reboot.
File/Folder C:\WINDOWS\System32\cwbkwlxw.dll not found.
File/Folder C:\WINDOWS\System32\ddcyy.dll not found.
File/Folder C:\WINDOWS\System32\ddcca.dll not found.
File/Folder C:\WINDOWS\System32\jkhfe.dll not found.
Created on 12/23/2007 23:54:41
--------------------------------------------------------------------
Pour Combofit :
ComboFix 07-12-21.4 - Propriétaire 2007-12-25 10:53:01.4 - NTFSx86
Running from: C:\Documents and Settings\Propriétaire\Bureau\Programmes desinfectionvirus\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\awtss.dll
C:\WINDOWS\system32\sstwa.ini
C:\WINDOWS\system32\sstwa.ini2
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-25 to 2007-12-25 ))))))))))))))))))))))))))))))))))))
.
2007-12-23 22:48 . 2007-12-23 22:48 <REP> d-------- C:\Program Files\Avira
2007-12-23 22:48 . 2007-12-23 22:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-12-23 21:08 . 2007-12-23 21:09 <REP> d-------- C:\Program Files\Panda Security
2007-12-23 20:41 . 2007-12-23 20:41 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-12-23 20:37 . 2007-12-23 21:56 <REP> d-------- C:\VundoFix Backups
2007-12-23 20:12 . 2007-12-23 20:12 <REP> d-------- C:\Documents and Settings\LocalService\Menu D‚marrer
2007-12-23 18:00 . 2004-08-20 00:09 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-12-23 17:50 . 2007-12-23 17:50 <REP> d-------- C:\WINDOWS\provisioning
2007-12-23 17:50 . 2007-12-23 17:50 <REP> d-------- C:\WINDOWS\peernet
2007-12-23 17:42 . 2007-12-23 17:42 <REP> d-------- C:\WINDOWS\ServicePackFiles
2007-12-23 17:20 . 2007-12-23 17:20 <REP> d-------- C:\WINDOWS\EHome
2007-12-23 16:47 . 2007-12-23 16:47 <REP> d-------- C:\Program Files\TresorNet
2007-12-23 16:46 . 2007-12-23 16:47 1,429,032 --a------ C:\WINDOWS\system32\No‰l Cadeaux.scr
2007-12-23 15:25 . 2002-04-15 21:11 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2007-12-23 15:25 . 2004-08-19 16:10 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
2007-12-23 15:25 . 2004-08-02 14:20 7,208 --------- C:\WINDOWS\system32\secupd.sig
2007-12-23 15:25 . 2004-08-02 14:20 4,569 --------- C:\WINDOWS\system32\secupd.dat
2007-12-23 13:58 . 2004-08-20 00:09 614,912 --a------ C:\WINDOWS\system32\h323msp.dll
2007-12-23 13:58 . 2004-08-20 00:09 332,800 --a------ C:\WINDOWS\system32\ipnathlp.dll
2007-12-23 13:58 . 2004-08-20 00:10 266,752 --a------ C:\WINDOWS\system32\h323.tsp
2007-12-23 13:58 . 2004-03-30 02:49 40,960 -----c--- C:\WINDOWS\system32\dllcache\evtgprov.dll
2007-12-23 13:07 . 2003-02-28 16:34 313,856 --a------ C:\WINDOWS\system32\dx3j.dll
2007-12-23 13:07 . 2003-02-28 18:26 171,280 --a------ C:\WINDOWS\system32\jit.dll
2007-12-23 13:07 . 2003-02-28 18:26 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2007-12-23 13:07 . 2003-02-28 18:26 46,352 --a------ C:\WINDOWS\setdebug.exe
2007-12-23 13:07 . 2003-02-28 16:54 7,315 --a------ C:\WINDOWS\system32\javasup.vxd
2007-12-23 13:07 . 2003-02-28 16:35 6,550 --a------ C:\WINDOWS\jautoexp.dat
2007-12-23 10:23 . 2007-12-23 10:24 267,624 --ah----- C:\WINDOWS\system32\yrtrpuda.exe
2007-12-23 10:22 . 2007-12-23 10:23 397,312 --ah----- C:\WINDOWS\system32\ptapdjp.exe
2007-12-23 10:21 . 2007-12-23 10:22 397,312 --ah----- C:\WINDOWS\system32\mcqgqob.exe
2007-12-23 10:12 . 2007-12-23 10:13 397,312 --ah----- C:\WINDOWS\system32\wchxl.exe
2007-12-23 09:59 . 2007-12-23 09:59 118 --a------ C:\WINDOWS\system32\wujjdpch.bat
2007-12-23 09:58 . 2007-12-23 09:59 397,312 --ah----- C:\WINDOWS\system32\zzezdyu.exe
2007-12-23 09:55 . 2007-12-23 09:56 397,312 --ah----- C:\WINDOWS\system32\rmdp.exe
2007-12-23 09:46 . 2007-12-23 13:26 <REP> d-------- C:\Program Files\a-squared Free
2007-12-23 09:31 . 2007-12-23 09:31 397,312 --ah----- C:\WINDOWS\system32\mjrfqd.exe
2007-12-23 09:30 . 2007-12-23 09:30 406,016 --ah----- C:\WINDOWS\system32\lbok.exe
2007-12-23 09:30 . 2007-12-23 09:31 397,312 --ah----- C:\WINDOWS\system32\nnxob.exe
2007-12-23 09:21 . 2007-12-23 09:22 397,312 --ah----- C:\WINDOWS\system32\vrkne.exe
2007-12-22 22:57 . 2007-12-22 22:58 406,016 --ah----- C:\WINDOWS\system32\ymfkvo.exe
2007-12-22 22:56 . 2007-12-22 22:58 300,444 --ah----- C:\WINDOWS\system32\rihxgm.exe
2007-12-22 22:55 . 2007-12-22 22:56 406,016 --ah----- C:\WINDOWS\system32\pfoxs.exe
2007-12-22 22:55 . 2007-12-22 22:56 406,016 --ah----- C:\WINDOWS\system32\ngpmexkj.exe
2007-12-22 22:52 . 2007-12-22 22:52 121 --a------ C:\WINDOWS\system32\wcamd.bat
2007-12-22 22:40 . 2007-12-22 22:40 123 --a------ C:\WINDOWS\system32\qqydyjm.bat
2007-12-22 22:39 . 2007-12-22 22:40 406,016 --ah----- C:\WINDOWS\system32\mrxgpms.exe
2007-12-22 22:37 . 2007-12-22 22:37 406,016 --ah----- C:\WINDOWS\system32\qkaws.exe
2007-12-22 22:34 . 2007-12-22 22:35 397,312 --ah----- C:\WINDOWS\system32\lvkxonr.exe
2007-12-22 22:33 . 2007-12-22 22:34 416,256 --ah----- C:\WINDOWS\system32\yvroe.exe
2007-12-22 22:32 . 2007-12-22 22:35 339,968 --ah----- C:\WINDOWS\system32\vniswk.exe
2007-12-22 22:31 . 2007-12-22 22:31 128 --a------ C:\WINDOWS\system32\mtcdqq.bat
2007-12-22 22:31 . 2007-12-22 22:31 124 --a------ C:\WINDOWS\system32\htrfx.bat
2007-12-22 22:29 . 2007-12-22 22:31 314,880 --ah----- C:\WINDOWS\system32\vsihhad.exe
2007-12-22 22:18 . 2007-12-22 22:19 119,708 --ah----- C:\WINDOWS\system32\xnsvb.exe
2007-12-22 22:15 . 2007-12-22 22:19 242,364 --ah----- C:\WINDOWS\system32\vuwip.exe
2007-12-22 22:05 . 2007-12-22 22:06 512 --ah----- C:\WINDOWS\system32\sexfvf.exe
2007-12-22 22:04 . 2007-12-22 22:05 134,656 --ah----- C:\WINDOWS\system32\xpyreb.exe
2007-12-22 21:55 . 2007-12-23 22:07 52,736 --a------ C:\WINDOWS\system\hpsysdrv .exe
2007-12-22 21:55 . 2007-12-23 23:54 181 --a------ C:\WINDOWS\system\hpsysdrv .DAT
2007-12-22 21:35 . 2007-12-22 21:35 406,016 --ah----- C:\WINDOWS\system32\zrxylezj.exe
2007-12-22 21:35 . 2007-12-22 21:35 16,308 --ah----- C:\WINDOWS\system32\nippom.exe
2007-12-22 21:33 . 2007-12-22 21:35 263,168 --ah----- C:\WINDOWS\system32\ygngoo.exe
2007-12-22 21:32 . 2007-12-22 21:35 352,768 --ah----- C:\WINDOWS\system32\xzkiwwsr.exe
2007-12-22 21:28 . 2007-12-22 21:28 3,584 --ah----- C:\WINDOWS\system32\hnqhx.exe
2007-12-22 21:22 . 2007-12-22 21:22 40,448 --ah----- C:\WINDOWS\system32\xhzczwrf.exe
2007-12-22 21:19 . 2007-12-22 21:19 0 --ah----- C:\WINDOWS\system32\yedh.exe
2007-12-22 21:18 . 2007-12-22 21:18 127 --a------ C:\WINDOWS\system32\yyiwk.bat
2007-12-22 21:18 . 2007-12-22 21:18 118 --a------ C:\WINDOWS\system32\ixfwg.bat
2007-12-22 21:15 . 2007-12-22 21:17 416,256 --ah----- C:\WINDOWS\system32\tjilus.exe
2007-12-22 21:12 . 2007-12-22 21:15 64,752 --ah----- C:\WINDOWS\system32\lvyppnbv.exe
2007-12-22 20:01 . 2005-10-20 23:25 1,097,728 --a------ C:\WINDOWS\system32\esent.dll
2007-12-22 13:13 . 2007-12-22 13:13 <REP> d-------- C:\Program Files\Trend Micro
2007-12-22 13:04 . 2007-12-22 13:04 <REP> d-------- C:\WINDOWS\system32\bits
2007-12-22 13:01 . 2007-12-25 10:51 <REP> d--h----- C:\WINDOWS\$hf_mig$
2007-12-22 13:01 . 2005-06-28 09:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-12-22 12:55 . 2004-08-20 00:09 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2007-12-22 12:55 . 2004-08-20 00:09 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-12-22 12:55 . 2004-08-20 00:09 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2007-12-22 12:55 . 2004-08-20 00:09 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2007-12-22 10:54 . 2007-12-22 10:57 256 --a------ C:\WINDOWS\wininit.ini
2007-12-21 17:16 . 2007-12-21 17:17 714 ---hs---- C:\WINDOWS\system32\iffruoww.ini
2007-12-19 20:17 . 2007-12-21 17:08 654 ---hs---- C:\WINDOWS\system32\ijlhiqto.ini
2007-12-19 14:18 . 2007-12-19 14:19 <REP> d-------- C:\Program Files\pfoc
2007-12-18 20:15 . 2007-12-19 20:15 474 ---hs---- C:\WINDOWS\system32\boxxabdd.ini
2007-12-18 18:59 . 2007-12-18 18:59 482 --a------ C:\WINDOWS\Disney.ini
2007-12-18 18:58 . 2007-12-18 18:58 <REP> d-------- C:\Program Files\Disney Interactive
2007-12-17 20:13 . 2007-12-18 20:13 354 ---hs---- C:\WINDOWS\system32\ofihltxw.ini
2007-12-16 10:47 . 2007-12-22 18:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-16 10:47 . 2007-12-16 10:47 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-14 20:10 . 2007-12-15 20:13 354 ---hs---- C:\WINDOWS\system32\imvlpwmp.ini
2007-12-14 19:57 . 2007-12-14 19:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-12-14 19:49 . 2007-12-25 10:11 88,566 --a------ C:\WINDOWS\system32\nvapps.xml
2007-12-14 19:47 . 2006-10-22 12:22 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-12-14 19:47 . 2006-10-22 12:22 17,056 --a------ C:\WINDOWS\system32\nvdisp.nvu
2007-12-14 19:46 . 2006-10-22 15:06 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-12-14 19:38 . 2007-12-14 19:54 <REP> d-------- C:\WINDOWS\nview
2007-12-14 18:49 . 2007-12-14 18:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
2007-12-13 21:03 . 2007-12-14 20:11 8 --a------ C:\WINDOWS\system32\nvModes.dat
2007-12-13 20:33 . 2007-12-13 20:33 <REP> d-------- C:\NVIDIA
2007-12-13 20:03 . 2007-12-13 20:03 294 ---hs---- C:\WINDOWS\system32\saipnoks.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 09:58 --------- d-----w C:\Program Files\Mozilla Thunderbird
2007-12-24 16:56 1,336 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2007-12-23 22:33 --------- d---a-w C:\Program Files\USB Storage RW
2007-12-19 18:30 --------- d-----w C:\Program Files\eMule
2007-12-12 11:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-12 11:27 --------- d---a-w C:\Program Files\Fichiers communs\InstallShield
2007-11-20 19:01 --------- d-----w C:\Program Files\QuickTime
2007-11-20 19:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2007-11-20 18:23 --------- d---a-w C:\Program Files\Fichiers communs\Adobe
2007-11-20 13:08 --------- d-----w C:\Program Files\EPSON
2007-11-18 20:27 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Grisoft
2007-11-18 20:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-18 09:45 --------- d-----w C:\Program Files\Java
2007-11-18 09:43 --------- d-----w C:\Program Files\Fichiers communs\Java
2007-11-18 09:12 --------- d-----w C:\Program Files\VideoLAN
2007-11-18 08:47 --------- d-----w C:\Program Files\Sunbelt Software
2007-11-18 08:32 --------- d-----w C:\Program Files\Alwil Software
2007-11-17 22:22 --------- d---a-w C:\Program Files\InterVideo
2007-11-17 21:59 --------- d---a-w C:\Program Files\Symantec
2007-11-17 21:59 --------- d---a-w C:\Program Files\Fichiers communs\Symantec Shared
2007-11-17 21:59 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-17 21:48 3,458 --sha-r C:\WINDOWS\system32\drivers\HP_DF101A-ABF 415_YC_Pavi_QCZB318_E32FRheBLF2_4_IKM266-8235_S_V_BAM37312_T030317_W1_L40C_M256_J40_7AMD_8Athlon XP 2000+_91,66_1_N10EC8139_P_Z14F12F00_K_A11063059_U11063038_G10DE0172.MRK
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{478c0e17-2915-49f1-9ace-4d1ec58a76e8}]
C:\WINDOWS\System32\cwbkwlxw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86BE360E-D40E-4212-B495-307A65FBAA89}]
C:\WINDOWS\System32\ddcyy.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97E2CE47-CA37-4E19-9780-7C15B780F4AA}]
C:\WINDOWS\System32\ddcca.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9C77AE8-BC56-4554-9A70-FB2C975521F6}]
C:\WINDOWS\System32\jkhfe.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" []
"KYE_Showicon"="C:\Program Files\USB Storage RW\shwicon.exe" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" [2007-12-25 10:11]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"NvMediaCenter"="RunDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"Local Security Authority Service"="C:\WINDOWS\System32\lssas.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuvsrq]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 10:21]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 06:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 07:08]
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 11:11:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-25 11:19:31 - machine was rebooted [Propri‚taire]
C:\ComboFix2.txt ... 2007-12-23 22:20
.
2007-12-23 19:00:59 --- E O F ---
---------------------------------------------------------------------
Je suis completement paumée là, je ne sais pas si je ne fais pas d'anneries dans mes manipulations...
Je poste tel quel et je file faire le scan en mode sans échec, car je perds régulièrement la connexion, alors, tant que je l'ai...
Et si un modérateur pouvait effacer le message juste avant, j'ai plantouillé...Merci !!!!
Je n'ai pas retrouvé le rapport FV monde ;-) mais il n'y avait rien de notable.
A ce qui était précisé...
-------------------------------------------------------------------
Pour Symantec Trojan.Vundo.B removal Tool :
Il n'a rien trouvé, alors qu'il a déclenché antivir plusieurs dizaines de fois ???
--------------------------------------------------------------------
Pour OT mOVE IT :
File/Folder C:\WINDOWS\SYSTEM32\wvuvsrq.dll not found.
File/Folder C:\WINDOWS\System32\nymjljoq.dll not found.
File/Folder C:\WINDOWS\bukmon.exe not found.
File/Folder C:\WINDOWS\system32\wvuvsrq.dll not found.
C:\WINDOWS\system32\tvtd.exe moved successfully.
C:\WINDOWS\system32\cly.exe moved successfully.
C:\WINDOWS\system32\slotnkmc.dll unregistered successfully.
C:\WINDOWS\system32\slotnkmc.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\awtss.dll
C:\WINDOWS\System32\awtss.dll NOT unregistered.
File move failed. C:\WINDOWS\System32\awtss.dll scheduled to be moved on reboot.
File/Folder C:\WINDOWS\System32\cwbkwlxw.dll not found.
File/Folder C:\WINDOWS\System32\ddcyy.dll not found.
File/Folder C:\WINDOWS\System32\ddcca.dll not found.
File/Folder C:\WINDOWS\System32\jkhfe.dll not found.
Created on 12/23/2007 23:54:41
--------------------------------------------------------------------
Pour Combofit :
ComboFix 07-12-21.4 - Propriétaire 2007-12-25 10:53:01.4 - NTFSx86
Running from: C:\Documents and Settings\Propriétaire\Bureau\Programmes desinfectionvirus\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\awtss.dll
C:\WINDOWS\system32\sstwa.ini
C:\WINDOWS\system32\sstwa.ini2
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-25 to 2007-12-25 ))))))))))))))))))))))))))))))))))))
.
2007-12-23 22:48 . 2007-12-23 22:48 <REP> d-------- C:\Program Files\Avira
2007-12-23 22:48 . 2007-12-23 22:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-12-23 21:08 . 2007-12-23 21:09 <REP> d-------- C:\Program Files\Panda Security
2007-12-23 20:41 . 2007-12-23 20:41 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-12-23 20:37 . 2007-12-23 21:56 <REP> d-------- C:\VundoFix Backups
2007-12-23 20:12 . 2007-12-23 20:12 <REP> d-------- C:\Documents and Settings\LocalService\Menu D‚marrer
2007-12-23 18:00 . 2004-08-20 00:09 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-12-23 17:50 . 2007-12-23 17:50 <REP> d-------- C:\WINDOWS\provisioning
2007-12-23 17:50 . 2007-12-23 17:50 <REP> d-------- C:\WINDOWS\peernet
2007-12-23 17:42 . 2007-12-23 17:42 <REP> d-------- C:\WINDOWS\ServicePackFiles
2007-12-23 17:20 . 2007-12-23 17:20 <REP> d-------- C:\WINDOWS\EHome
2007-12-23 16:47 . 2007-12-23 16:47 <REP> d-------- C:\Program Files\TresorNet
2007-12-23 16:46 . 2007-12-23 16:47 1,429,032 --a------ C:\WINDOWS\system32\No‰l Cadeaux.scr
2007-12-23 15:25 . 2002-04-15 21:11 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2007-12-23 15:25 . 2004-08-19 16:10 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
2007-12-23 15:25 . 2004-08-02 14:20 7,208 --------- C:\WINDOWS\system32\secupd.sig
2007-12-23 15:25 . 2004-08-02 14:20 4,569 --------- C:\WINDOWS\system32\secupd.dat
2007-12-23 13:58 . 2004-08-20 00:09 614,912 --a------ C:\WINDOWS\system32\h323msp.dll
2007-12-23 13:58 . 2004-08-20 00:09 332,800 --a------ C:\WINDOWS\system32\ipnathlp.dll
2007-12-23 13:58 . 2004-08-20 00:10 266,752 --a------ C:\WINDOWS\system32\h323.tsp
2007-12-23 13:58 . 2004-03-30 02:49 40,960 -----c--- C:\WINDOWS\system32\dllcache\evtgprov.dll
2007-12-23 13:07 . 2003-02-28 16:34 313,856 --a------ C:\WINDOWS\system32\dx3j.dll
2007-12-23 13:07 . 2003-02-28 18:26 171,280 --a------ C:\WINDOWS\system32\jit.dll
2007-12-23 13:07 . 2003-02-28 18:26 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2007-12-23 13:07 . 2003-02-28 18:26 46,352 --a------ C:\WINDOWS\setdebug.exe
2007-12-23 13:07 . 2003-02-28 16:54 7,315 --a------ C:\WINDOWS\system32\javasup.vxd
2007-12-23 13:07 . 2003-02-28 16:35 6,550 --a------ C:\WINDOWS\jautoexp.dat
2007-12-23 10:23 . 2007-12-23 10:24 267,624 --ah----- C:\WINDOWS\system32\yrtrpuda.exe
2007-12-23 10:22 . 2007-12-23 10:23 397,312 --ah----- C:\WINDOWS\system32\ptapdjp.exe
2007-12-23 10:21 . 2007-12-23 10:22 397,312 --ah----- C:\WINDOWS\system32\mcqgqob.exe
2007-12-23 10:12 . 2007-12-23 10:13 397,312 --ah----- C:\WINDOWS\system32\wchxl.exe
2007-12-23 09:59 . 2007-12-23 09:59 118 --a------ C:\WINDOWS\system32\wujjdpch.bat
2007-12-23 09:58 . 2007-12-23 09:59 397,312 --ah----- C:\WINDOWS\system32\zzezdyu.exe
2007-12-23 09:55 . 2007-12-23 09:56 397,312 --ah----- C:\WINDOWS\system32\rmdp.exe
2007-12-23 09:46 . 2007-12-23 13:26 <REP> d-------- C:\Program Files\a-squared Free
2007-12-23 09:31 . 2007-12-23 09:31 397,312 --ah----- C:\WINDOWS\system32\mjrfqd.exe
2007-12-23 09:30 . 2007-12-23 09:30 406,016 --ah----- C:\WINDOWS\system32\lbok.exe
2007-12-23 09:30 . 2007-12-23 09:31 397,312 --ah----- C:\WINDOWS\system32\nnxob.exe
2007-12-23 09:21 . 2007-12-23 09:22 397,312 --ah----- C:\WINDOWS\system32\vrkne.exe
2007-12-22 22:57 . 2007-12-22 22:58 406,016 --ah----- C:\WINDOWS\system32\ymfkvo.exe
2007-12-22 22:56 . 2007-12-22 22:58 300,444 --ah----- C:\WINDOWS\system32\rihxgm.exe
2007-12-22 22:55 . 2007-12-22 22:56 406,016 --ah----- C:\WINDOWS\system32\pfoxs.exe
2007-12-22 22:55 . 2007-12-22 22:56 406,016 --ah----- C:\WINDOWS\system32\ngpmexkj.exe
2007-12-22 22:52 . 2007-12-22 22:52 121 --a------ C:\WINDOWS\system32\wcamd.bat
2007-12-22 22:40 . 2007-12-22 22:40 123 --a------ C:\WINDOWS\system32\qqydyjm.bat
2007-12-22 22:39 . 2007-12-22 22:40 406,016 --ah----- C:\WINDOWS\system32\mrxgpms.exe
2007-12-22 22:37 . 2007-12-22 22:37 406,016 --ah----- C:\WINDOWS\system32\qkaws.exe
2007-12-22 22:34 . 2007-12-22 22:35 397,312 --ah----- C:\WINDOWS\system32\lvkxonr.exe
2007-12-22 22:33 . 2007-12-22 22:34 416,256 --ah----- C:\WINDOWS\system32\yvroe.exe
2007-12-22 22:32 . 2007-12-22 22:35 339,968 --ah----- C:\WINDOWS\system32\vniswk.exe
2007-12-22 22:31 . 2007-12-22 22:31 128 --a------ C:\WINDOWS\system32\mtcdqq.bat
2007-12-22 22:31 . 2007-12-22 22:31 124 --a------ C:\WINDOWS\system32\htrfx.bat
2007-12-22 22:29 . 2007-12-22 22:31 314,880 --ah----- C:\WINDOWS\system32\vsihhad.exe
2007-12-22 22:18 . 2007-12-22 22:19 119,708 --ah----- C:\WINDOWS\system32\xnsvb.exe
2007-12-22 22:15 . 2007-12-22 22:19 242,364 --ah----- C:\WINDOWS\system32\vuwip.exe
2007-12-22 22:05 . 2007-12-22 22:06 512 --ah----- C:\WINDOWS\system32\sexfvf.exe
2007-12-22 22:04 . 2007-12-22 22:05 134,656 --ah----- C:\WINDOWS\system32\xpyreb.exe
2007-12-22 21:55 . 2007-12-23 22:07 52,736 --a------ C:\WINDOWS\system\hpsysdrv .exe
2007-12-22 21:55 . 2007-12-23 23:54 181 --a------ C:\WINDOWS\system\hpsysdrv .DAT
2007-12-22 21:35 . 2007-12-22 21:35 406,016 --ah----- C:\WINDOWS\system32\zrxylezj.exe
2007-12-22 21:35 . 2007-12-22 21:35 16,308 --ah----- C:\WINDOWS\system32\nippom.exe
2007-12-22 21:33 . 2007-12-22 21:35 263,168 --ah----- C:\WINDOWS\system32\ygngoo.exe
2007-12-22 21:32 . 2007-12-22 21:35 352,768 --ah----- C:\WINDOWS\system32\xzkiwwsr.exe
2007-12-22 21:28 . 2007-12-22 21:28 3,584 --ah----- C:\WINDOWS\system32\hnqhx.exe
2007-12-22 21:22 . 2007-12-22 21:22 40,448 --ah----- C:\WINDOWS\system32\xhzczwrf.exe
2007-12-22 21:19 . 2007-12-22 21:19 0 --ah----- C:\WINDOWS\system32\yedh.exe
2007-12-22 21:18 . 2007-12-22 21:18 127 --a------ C:\WINDOWS\system32\yyiwk.bat
2007-12-22 21:18 . 2007-12-22 21:18 118 --a------ C:\WINDOWS\system32\ixfwg.bat
2007-12-22 21:15 . 2007-12-22 21:17 416,256 --ah----- C:\WINDOWS\system32\tjilus.exe
2007-12-22 21:12 . 2007-12-22 21:15 64,752 --ah----- C:\WINDOWS\system32\lvyppnbv.exe
2007-12-22 20:01 . 2005-10-20 23:25 1,097,728 --a------ C:\WINDOWS\system32\esent.dll
2007-12-22 13:13 . 2007-12-22 13:13 <REP> d-------- C:\Program Files\Trend Micro
2007-12-22 13:04 . 2007-12-22 13:04 <REP> d-------- C:\WINDOWS\system32\bits
2007-12-22 13:01 . 2007-12-25 10:51 <REP> d--h----- C:\WINDOWS\$hf_mig$
2007-12-22 13:01 . 2005-06-28 09:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-12-22 12:55 . 2004-08-20 00:09 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2007-12-22 12:55 . 2004-08-20 00:09 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-12-22 12:55 . 2004-08-20 00:09 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2007-12-22 12:55 . 2004-08-20 00:09 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2007-12-22 10:54 . 2007-12-22 10:57 256 --a------ C:\WINDOWS\wininit.ini
2007-12-21 17:16 . 2007-12-21 17:17 714 ---hs---- C:\WINDOWS\system32\iffruoww.ini
2007-12-19 20:17 . 2007-12-21 17:08 654 ---hs---- C:\WINDOWS\system32\ijlhiqto.ini
2007-12-19 14:18 . 2007-12-19 14:19 <REP> d-------- C:\Program Files\pfoc
2007-12-18 20:15 . 2007-12-19 20:15 474 ---hs---- C:\WINDOWS\system32\boxxabdd.ini
2007-12-18 18:59 . 2007-12-18 18:59 482 --a------ C:\WINDOWS\Disney.ini
2007-12-18 18:58 . 2007-12-18 18:58 <REP> d-------- C:\Program Files\Disney Interactive
2007-12-17 20:13 . 2007-12-18 20:13 354 ---hs---- C:\WINDOWS\system32\ofihltxw.ini
2007-12-16 10:47 . 2007-12-22 18:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-16 10:47 . 2007-12-16 10:47 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-14 20:10 . 2007-12-15 20:13 354 ---hs---- C:\WINDOWS\system32\imvlpwmp.ini
2007-12-14 19:57 . 2007-12-14 19:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-12-14 19:49 . 2007-12-25 10:11 88,566 --a------ C:\WINDOWS\system32\nvapps.xml
2007-12-14 19:47 . 2006-10-22 12:22 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-12-14 19:47 . 2006-10-22 12:22 17,056 --a------ C:\WINDOWS\system32\nvdisp.nvu
2007-12-14 19:46 . 2006-10-22 15:06 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-12-14 19:38 . 2007-12-14 19:54 <REP> d-------- C:\WINDOWS\nview
2007-12-14 18:49 . 2007-12-14 18:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
2007-12-13 21:03 . 2007-12-14 20:11 8 --a------ C:\WINDOWS\system32\nvModes.dat
2007-12-13 20:33 . 2007-12-13 20:33 <REP> d-------- C:\NVIDIA
2007-12-13 20:03 . 2007-12-13 20:03 294 ---hs---- C:\WINDOWS\system32\saipnoks.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 09:58 --------- d-----w C:\Program Files\Mozilla Thunderbird
2007-12-24 16:56 1,336 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2007-12-23 22:33 --------- d---a-w C:\Program Files\USB Storage RW
2007-12-19 18:30 --------- d-----w C:\Program Files\eMule
2007-12-12 11:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-12 11:27 --------- d---a-w C:\Program Files\Fichiers communs\InstallShield
2007-11-20 19:01 --------- d-----w C:\Program Files\QuickTime
2007-11-20 19:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2007-11-20 18:23 --------- d---a-w C:\Program Files\Fichiers communs\Adobe
2007-11-20 13:08 --------- d-----w C:\Program Files\EPSON
2007-11-18 20:27 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Grisoft
2007-11-18 20:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-18 09:45 --------- d-----w C:\Program Files\Java
2007-11-18 09:43 --------- d-----w C:\Program Files\Fichiers communs\Java
2007-11-18 09:12 --------- d-----w C:\Program Files\VideoLAN
2007-11-18 08:47 --------- d-----w C:\Program Files\Sunbelt Software
2007-11-18 08:32 --------- d-----w C:\Program Files\Alwil Software
2007-11-17 22:22 --------- d---a-w C:\Program Files\InterVideo
2007-11-17 21:59 --------- d---a-w C:\Program Files\Symantec
2007-11-17 21:59 --------- d---a-w C:\Program Files\Fichiers communs\Symantec Shared
2007-11-17 21:59 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-17 21:48 3,458 --sha-r C:\WINDOWS\system32\drivers\HP_DF101A-ABF 415_YC_Pavi_QCZB318_E32FRheBLF2_4_IKM266-8235_S_V_BAM37312_T030317_W1_L40C_M256_J40_7AMD_8Athlon XP 2000+_91,66_1_N10EC8139_P_Z14F12F00_K_A11063059_U11063038_G10DE0172.MRK
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{478c0e17-2915-49f1-9ace-4d1ec58a76e8}]
C:\WINDOWS\System32\cwbkwlxw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86BE360E-D40E-4212-B495-307A65FBAA89}]
C:\WINDOWS\System32\ddcyy.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97E2CE47-CA37-4E19-9780-7C15B780F4AA}]
C:\WINDOWS\System32\ddcca.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9C77AE8-BC56-4554-9A70-FB2C975521F6}]
C:\WINDOWS\System32\jkhfe.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" []
"KYE_Showicon"="C:\Program Files\USB Storage RW\shwicon.exe" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" [2007-12-25 10:11]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"NvMediaCenter"="RunDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"Local Security Authority Service"="C:\WINDOWS\System32\lssas.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuvsrq]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 10:21]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 06:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 07:08]
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 11:11:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-25 11:19:31 - machine was rebooted [Propri‚taire]
C:\ComboFix2.txt ... 2007-12-23 22:20
.
2007-12-23 19:00:59 --- E O F ---
---------------------------------------------------------------------
Je suis completement paumée là, je ne sais pas si je ne fais pas d'anneries dans mes manipulations...
Je poste tel quel et je file faire le scan en mode sans échec, car je perds régulièrement la connexion, alors, tant que je l'ai...
jlpjlp
Messages postés
51580
Date d'inscription
vendredi 18 mai 2007
Statut
Contributeur sécurité
Dernière intervention
3 mai 2022
5 040
25 déc. 2007 à 11:59
25 déc. 2007 à 11:59
y a du boulot!
analyse chque fichier suivant sur virus total : https://www.virustotal.com/gui/
ceux qui sont inféctés tu les vires avec otmovit en les mettant dans la citation comme precedemment et tu me colle le rapport
C:\WINDOWS\system32\wmpns.dll
C:\WINDOWS\system32\spnpinst.exe
C:\WINDOWS\system32\secupd.sig
C:\WINDOWS\system32\secupd.dat
C:\WINDOWS\system32\h323msp.dll
C:\WINDOWS\system32\ipnathlp.dll
C:\WINDOWS\system32\h323.tsp
C:\WINDOWS\system32\dllcache\evtgprov.dll
C:\WINDOWS\system32\dx3j.dll
C:\WINDOWS\system32\jit.dll
C:\WINDOWS\system32\javaee.dll
C:\WINDOWS\setdebug.exe
C:\WINDOWS\system32\javasup.vxd
C:\WINDOWS\jautoexp.dat
C:\WINDOWS\system32\yrtrpuda.exe
C:\WINDOWS\system32\ptapdjp.exe
C:\WINDOWS\system32\mcqgqob.exe
C:\WINDOWS\system32\wchxl.exe
C:\WINDOWS\system32\wujjdpch.bat
C:\WINDOWS\system32\zzezdyu.exe
C:\WINDOWS\system32\rmdp.exe
C:\Program Files\a-squared Free
C:\WINDOWS\system32\mjrfqd.exe
C:\WINDOWS\system32\lbok.exe
C:\WINDOWS\system32\nnxob.exe
C:\WINDOWS\system32\vrkne.exe
C:\WINDOWS\system32\ymfkvo.exe
C:\WINDOWS\system32\rihxgm.exe
C:\WINDOWS\system32\pfoxs.exe
C:\WINDOWS\system32\ngpmexkj.exe
C:\WINDOWS\system32\wcamd.bat
C:\WINDOWS\system32\qqydyjm.bat
C:\WINDOWS\system32\mrxgpms.exe
C:\WINDOWS\system32\qkaws.exe
C:\WINDOWS\system32\lvkxonr.exe
C:\WINDOWS\system32\yvroe.exe
C:\WINDOWS\system32\vniswk.exe
C:\WINDOWS\system32\mtcdqq.bat
C:\WINDOWS\system32\htrfx.bat
C:\WINDOWS\system32\xnsvb.exe
C:\WINDOWS\system32\vuwip.exe
C:\WINDOWS\system32\sexfvf.exe
C:\WINDOWS\system32\xpyreb.exe
C:\WINDOWS\system32\zrxylezj.exe
C:\WINDOWS\system32\nippom.exe
C:\WINDOWS\system32\ygngoo.exe
C:\WINDOWS\system32\xzkiwwsr.exe
C:\WINDOWS\system32\hnqhx.exe
C:\WINDOWS\system32\xhzczwrf.exe
C:\WINDOWS\system32\yedh.exe
C:\WINDOWS\system32\yyiwk.bat
C:\WINDOWS\system32\ixfwg.bat
C:\WINDOWS\system32\tjilus.exe
C:\WINDOWS\system32\lvyppnbv.exe
C:\WINDOWS\system32\esent.dll
C:\WINDOWS\system32\spupdsvc.exe
C:\WINDOWS\system32\winhttp.dll
C:\WINDOWS\system32\qmgrprxy.dll
C:\WINDOWS\system32\bitsprx2.dll
C:\WINDOWS\system32\bitsprx3.dll
C:\WINDOWS\system32\iffruoww.ini
C:\WINDOWS\system32\ijlhiqto.ini
C:\WINDOWS\system32\boxxabdd.ini
________________
ensuite recolle un rapport hijackhtis, combofix et dis tes soucis
C:\WINDOWS\system32\ofihltxw.ini
C:\WINDOWS\system32\imvlpwmp.ini
analyse chque fichier suivant sur virus total : https://www.virustotal.com/gui/
ceux qui sont inféctés tu les vires avec otmovit en les mettant dans la citation comme precedemment et tu me colle le rapport
C:\WINDOWS\system32\wmpns.dll
C:\WINDOWS\system32\spnpinst.exe
C:\WINDOWS\system32\secupd.sig
C:\WINDOWS\system32\secupd.dat
C:\WINDOWS\system32\h323msp.dll
C:\WINDOWS\system32\ipnathlp.dll
C:\WINDOWS\system32\h323.tsp
C:\WINDOWS\system32\dllcache\evtgprov.dll
C:\WINDOWS\system32\dx3j.dll
C:\WINDOWS\system32\jit.dll
C:\WINDOWS\system32\javaee.dll
C:\WINDOWS\setdebug.exe
C:\WINDOWS\system32\javasup.vxd
C:\WINDOWS\jautoexp.dat
C:\WINDOWS\system32\yrtrpuda.exe
C:\WINDOWS\system32\ptapdjp.exe
C:\WINDOWS\system32\mcqgqob.exe
C:\WINDOWS\system32\wchxl.exe
C:\WINDOWS\system32\wujjdpch.bat
C:\WINDOWS\system32\zzezdyu.exe
C:\WINDOWS\system32\rmdp.exe
C:\Program Files\a-squared Free
C:\WINDOWS\system32\mjrfqd.exe
C:\WINDOWS\system32\lbok.exe
C:\WINDOWS\system32\nnxob.exe
C:\WINDOWS\system32\vrkne.exe
C:\WINDOWS\system32\ymfkvo.exe
C:\WINDOWS\system32\rihxgm.exe
C:\WINDOWS\system32\pfoxs.exe
C:\WINDOWS\system32\ngpmexkj.exe
C:\WINDOWS\system32\wcamd.bat
C:\WINDOWS\system32\qqydyjm.bat
C:\WINDOWS\system32\mrxgpms.exe
C:\WINDOWS\system32\qkaws.exe
C:\WINDOWS\system32\lvkxonr.exe
C:\WINDOWS\system32\yvroe.exe
C:\WINDOWS\system32\vniswk.exe
C:\WINDOWS\system32\mtcdqq.bat
C:\WINDOWS\system32\htrfx.bat
C:\WINDOWS\system32\xnsvb.exe
C:\WINDOWS\system32\vuwip.exe
C:\WINDOWS\system32\sexfvf.exe
C:\WINDOWS\system32\xpyreb.exe
C:\WINDOWS\system32\zrxylezj.exe
C:\WINDOWS\system32\nippom.exe
C:\WINDOWS\system32\ygngoo.exe
C:\WINDOWS\system32\xzkiwwsr.exe
C:\WINDOWS\system32\hnqhx.exe
C:\WINDOWS\system32\xhzczwrf.exe
C:\WINDOWS\system32\yedh.exe
C:\WINDOWS\system32\yyiwk.bat
C:\WINDOWS\system32\ixfwg.bat
C:\WINDOWS\system32\tjilus.exe
C:\WINDOWS\system32\lvyppnbv.exe
C:\WINDOWS\system32\esent.dll
C:\WINDOWS\system32\spupdsvc.exe
C:\WINDOWS\system32\winhttp.dll
C:\WINDOWS\system32\qmgrprxy.dll
C:\WINDOWS\system32\bitsprx2.dll
C:\WINDOWS\system32\bitsprx3.dll
C:\WINDOWS\system32\iffruoww.ini
C:\WINDOWS\system32\ijlhiqto.ini
C:\WINDOWS\system32\boxxabdd.ini
________________
ensuite recolle un rapport hijackhtis, combofix et dis tes soucis
C:\WINDOWS\system32\ofihltxw.ini
C:\WINDOWS\system32\imvlpwmp.ini
bluael
Messages postés
37
Date d'inscription
lundi 19 novembre 2007
Statut
Membre
Dernière intervention
27 avril 2011
25 déc. 2007 à 19:38
25 déc. 2007 à 19:38
Les choses ont l'air de se régler, au moins au niveau de l'utilisation de l'ordinateur, il n'y a plus de messages intempestifs, plus de bugs (pour le moment !!!)
Voici les rapports de ce que j'ai executé sur ton conseil :
J'ai tout analysé avec le site Virus Total...
--------------------------------------------------------------------------------------------------------------
Résultats de OTMovit :
C:\WINDOWS\system32\sexfvf.exe moved successfully.
C:\WINDOWS\system32\hnqhx.exe moved successfully.
Created on 12/25/2007 18:04:21
------------------------------------------------------------------------------------------------
Rapport hitjackhis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:08:55, on 25/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: {8e67a85c-e1d4-eca9-1f94-519271e0c874} - {478c0e17-2915-49f1-9ace-4d1ec58a76e8} - C:\WINDOWS\System32\cwbkwlxw.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {86BE360E-D40E-4212-B495-307A65FBAA89} - C:\WINDOWS\System32\ddcyy.dll (file missing)
O2 - BHO: (no name) - {97E2CE47-CA37-4E19-9780-7C15B780F4AA} - C:\WINDOWS\System32\ddcca.dll (file missing)
O2 - BHO: (no name) - {F9C77AE8-BC56-4554-9A70-FB2C975521F6} - C:\WINDOWS\System32\jkhfe.dll (file missing)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O20 - Winlogon Notify: wvuvsrq - C:\WINDOWS\
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
-----------------------------------------------------------------------
Le rapport combofix :
ComboFix 07-12-21.4 - Propriétaire 2007-12-25 18:13:25.5 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.78 [GMT 1:00]
Running from: C:\Documents and Settings\Propriétaire\Bureau\Programmes desinfectionvirus\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-11-25 to 2007-12-25 ))))))))))))))))))))))))))))))))))))
.
2007-12-23 22:48 . 2007-12-23 22:48 <REP> d-------- C:\Program Files\Avira
2007-12-23 22:48 . 2007-12-23 22:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-12-23 21:08 . 2007-12-23 21:09 <REP> d-------- C:\Program Files\Panda Security
2007-12-23 20:41 . 2007-12-23 20:41 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-12-23 20:37 . 2007-12-25 12:32 <REP> d-------- C:\VundoFix Backups
2007-12-23 20:12 . 2007-12-23 20:12 <REP> d-------- C:\Documents and Settings\LocalService\Menu Démarrer
2007-12-23 18:00 . 2004-08-20 00:09 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-12-23 17:50 . 2007-12-23 17:50 <REP> d-------- C:\WINDOWS\provisioning
2007-12-23 17:50 . 2007-12-23 17:50 <REP> d-------- C:\WINDOWS\peernet
2007-12-23 17:42 . 2007-12-23 17:42 <REP> d-------- C:\WINDOWS\ServicePackFiles
2007-12-23 17:20 . 2007-12-23 17:20 <REP> d-------- C:\WINDOWS\EHome
2007-12-23 16:47 . 2007-12-23 16:47 <REP> d-------- C:\Program Files\TresorNet
2007-12-23 16:46 . 2007-12-23 16:47 1,429,032 --a------ C:\WINDOWS\system32\Noël Cadeaux.scr
2007-12-23 15:25 . 2002-04-15 21:11 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2007-12-23 15:25 . 2004-08-19 16:10 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
2007-12-23 15:25 . 2004-08-02 14:20 7,208 --------- C:\WINDOWS\system32\secupd.sig
2007-12-23 15:25 . 2004-08-02 14:20 4,569 --------- C:\WINDOWS\system32\secupd.dat
2007-12-23 13:58 . 2004-08-20 00:09 614,912 --a------ C:\WINDOWS\system32\h323msp.dll
2007-12-23 13:58 . 2004-08-20 00:09 332,800 --a------ C:\WINDOWS\system32\ipnathlp.dll
2007-12-23 13:58 . 2004-08-20 00:10 266,752 --a------ C:\WINDOWS\system32\h323.tsp
2007-12-23 13:58 . 2004-03-30 02:49 40,960 -----c--- C:\WINDOWS\system32\dllcache\evtgprov.dll
2007-12-23 13:07 . 2003-02-28 16:34 313,856 --a------ C:\WINDOWS\system32\dx3j.dll
2007-12-23 13:07 . 2003-02-28 18:26 171,280 --a------ C:\WINDOWS\system32\jit.dll
2007-12-23 13:07 . 2003-02-28 18:26 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2007-12-23 13:07 . 2003-02-28 18:26 46,352 --a------ C:\WINDOWS\setdebug.exe
2007-12-23 13:07 . 2003-02-28 16:54 7,315 --a------ C:\WINDOWS\system32\javasup.vxd
2007-12-23 13:07 . 2003-02-28 16:35 6,550 --a------ C:\WINDOWS\jautoexp.dat
2007-12-23 09:59 . 2007-12-23 09:59 118 --a------ C:\WINDOWS\system32\wujjdpch.bat
2007-12-23 09:46 . 2007-12-23 13:26 <REP> d-------- C:\Program Files\a-squared Free
2007-12-22 22:52 . 2007-12-22 22:52 121 --a------ C:\WINDOWS\system32\wcamd.bat
2007-12-22 22:40 . 2007-12-22 22:40 123 --a------ C:\WINDOWS\system32\qqydyjm.bat
2007-12-22 22:31 . 2007-12-22 22:31 128 --a------ C:\WINDOWS\system32\mtcdqq.bat
2007-12-22 22:31 . 2007-12-22 22:31 124 --a------ C:\WINDOWS\system32\htrfx.bat
2007-12-22 21:55 . 2007-12-23 22:07 52,736 --a------ C:\WINDOWS\system\hpsysdrv .exe
2007-12-22 21:55 . 2007-12-23 23:54 181 --a------ C:\WINDOWS\system\hpsysdrv .DAT
2007-12-22 21:35 . 2007-12-22 21:35 16,308 --ah----- C:\WINDOWS\system32\nippom.exe
2007-12-22 21:19 . 2007-12-22 21:19 0 --ah----- C:\WINDOWS\system32\yedh.exe
2007-12-22 21:18 . 2007-12-22 21:18 127 --a------ C:\WINDOWS\system32\yyiwk.bat
2007-12-22 21:18 . 2007-12-22 21:18 118 --a------ C:\WINDOWS\system32\ixfwg.bat
2007-12-22 20:01 . 2005-10-20 23:25 1,097,728 --a------ C:\WINDOWS\system32\esent.dll
2007-12-22 13:13 . 2007-12-22 13:13 <REP> d-------- C:\Program Files\Trend Micro
2007-12-22 13:04 . 2007-12-22 13:04 <REP> d-------- C:\WINDOWS\system32\bits
2007-12-22 13:01 . 2007-12-25 11:23 <REP> d--h----- C:\WINDOWS\$hf_mig$
2007-12-22 13:01 . 2005-06-28 09:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-12-22 12:55 . 2004-08-20 00:09 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2007-12-22 12:55 . 2004-08-20 00:09 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-12-22 12:55 . 2004-08-20 00:09 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2007-12-22 12:55 . 2004-08-20 00:09 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2007-12-22 10:54 . 2007-12-22 10:57 256 --a------ C:\WINDOWS\wininit.ini
2007-12-21 17:16 . 2007-12-21 17:17 714 ---hs---- C:\WINDOWS\system32\iffruoww.ini
2007-12-19 20:17 . 2007-12-21 17:08 654 ---hs---- C:\WINDOWS\system32\ijlhiqto.ini
2007-12-19 14:18 . 2007-12-19 14:19 <REP> d-------- C:\Program Files\pfoc
2007-12-18 20:15 . 2007-12-19 20:15 474 ---hs---- C:\WINDOWS\system32\boxxabdd.ini
2007-12-18 18:59 . 2007-12-18 18:59 482 --a------ C:\WINDOWS\Disney.ini
2007-12-18 18:58 . 2007-12-18 18:58 <REP> d-------- C:\Program Files\Disney Interactive
2007-12-17 20:13 . 2007-12-18 20:13 354 ---hs---- C:\WINDOWS\system32\ofihltxw.ini
2007-12-16 10:47 . 2007-12-22 18:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-16 10:47 . 2007-12-16 10:47 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-14 20:10 . 2007-12-15 20:13 354 ---hs---- C:\WINDOWS\system32\imvlpwmp.ini
2007-12-14 19:57 . 2007-12-14 19:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-12-14 19:49 . 2007-12-25 16:46 88,566 --a------ C:\WINDOWS\system32\nvapps.xml
2007-12-14 19:47 . 2006-10-22 12:22 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-12-14 19:47 . 2006-10-22 12:22 17,056 --a------ C:\WINDOWS\system32\nvdisp.nvu
2007-12-14 19:46 . 2006-10-22 15:06 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-12-14 19:38 . 2007-12-14 19:54 <REP> d-------- C:\WINDOWS\nview
2007-12-14 18:49 . 2007-12-14 18:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
2007-12-13 21:03 . 2007-12-14 20:11 8 --a------ C:\WINDOWS\system32\nvModes.dat
2007-12-13 20:33 . 2007-12-13 20:33 <REP> d-------- C:\NVIDIA
2007-12-13 20:03 . 2007-12-13 20:03 294 ---hs---- C:\WINDOWS\system32\saipnoks.ini
2007-12-12 20:06 . 2007-12-12 20:06 1,409 --a------ C:\WINDOWS\system32\tmp2DBDD.FOT
2007-12-12 19:58 . 2007-12-12 19:58 714 ---hs---- C:\WINDOWS\system32\bjrsofky.ini
2007-12-12 19:31 . 2007-07-30 19:19 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-12-12 19:31 . 2007-07-30 19:19 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-12-12 19:31 . 2007-07-30 19:19 216,408 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2007-12-12 19:31 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-12-12 19:31 . 2007-07-30 19:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2007-12-12 19:31 . 2007-07-30 19:18 33,624 --a------ C:\WINDOWS\system32\wups.dll
2007-12-12 19:31 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2007-12-12 19:31 . 2007-07-30 19:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2007-12-12 19:31 . 2007-07-30 19:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2007-12-12 19:27 . 2007-12-12 19:27 <REP> d---s---- C:\Documents and Settings\Propriétaire\UserData
2007-12-12 19:27 . 2007-12-12 19:27 <REP> d---s---- C:\Documents and Settings\Propriétaire\UserData
2007-12-12 12:29 . 2007-12-12 12:29 <REP> d-------- C:\Program Files\Avery Dennison
2007-12-12 12:29 . 2007-12-12 12:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avery
2007-12-11 20:00 . 2007-12-12 12:17 654 ---hs---- C:\WINDOWS\system32\uvkxqfom.ini
2007-12-11 18:33 . 2007-12-11 18:33 1,409 --a------ C:\WINDOWS\system32\tmp72774.FOT
2007-12-10 20:46 . 2007-12-10 20:46 <REP> d-------- C:\Documents and Settings\Propriétaire\Application Data\Avanquest
2007-12-10 20:46 . 2007-12-10 20:46 <REP> d-------- C:\Documents and Settings\Propriétaire\Application Data\Avanquest
2007-12-10 20:46 . 2007-12-10 20:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avanquest
2007-12-10 20:00 . 2007-12-11 17:39 414 ---hs---- C:\WINDOWS\system32\cuigirqx.ini
2007-12-10 19:26 . 2007-12-10 19:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2007-12-10 19:24 . 2007-12-10 19:24 <REP> dr-hs---- C:\_Backup.RC
2007-12-10 19:24 . 2007-12-23 10:48 <REP> d--h----- C:\_Backup
2007-12-10 19:20 . 2007-12-10 19:20 <REP> d-------- C:\Documents and Settings\Propriétaire\Application Data\VCOM
2007-12-10 19:20 . 2007-12-10 19:20 <REP> d-------- C:\Documents and Settings\Propriétaire\Application Data\VCOM
2007-12-10 19:17 . 2007-12-10 19:17 <REP> d-------- C:\Program Files\VCOM
2007-12-09 19:07 . 1994-09-21 01:00 12,800 --a------ C:\WINDOWS\system32\WING32.DLL
2007-12-09 19:06 . 2007-12-09 19:06 <REP> d-------- C:\TLCWIN
2007-12-09 11:19 . 2002-09-27 08:56 249,136 -r-hs---- C:\cmldr
2007-12-09 11:19 . 2007-11-18 02:56 184 -rahs---- C:\BOOT.BAK
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 17:06 --------- d-----w C:\Program Files\Mozilla Thunderbird
2007-12-25 10:44 1,503 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2007-12-23 22:33 --------- d---a-w C:\Program Files\USB Storage RW
2007-12-19 18:30 --------- d-----w C:\Program Files\eMule
2007-12-12 11:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-12 11:27 --------- d---a-w C:\Program Files\Fichiers communs\InstallShield
2007-11-20 21:59 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\vlc
2007-11-20 21:59 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\vlc
2007-11-20 19:01 --------- d-----w C:\Program Files\QuickTime
2007-11-20 19:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2007-11-20 18:23 --------- d---a-w C:\Program Files\Fichiers communs\Adobe
2007-11-20 13:08 --------- d-----w C:\Program Files\EPSON
2007-11-18 20:27 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Grisoft
2007-11-18 20:21 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Grisoft
2007-11-18 20:21 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Grisoft
2007-11-18 20:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-18 09:45 --------- d-----w C:\Program Files\Java
2007-11-18 09:43 --------- d-----w C:\Program Files\Fichiers communs\Java
2007-11-18 09:12 --------- d-----w C:\Program Files\VideoLAN
2007-11-18 08:56 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Thunderbird
2007-11-18 08:56 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Thunderbird
2007-11-18 08:52 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Talkback
2007-11-18 08:52 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Talkback
2007-11-18 08:47 --------- d-----w C:\Program Files\Sunbelt Software
2007-11-18 08:35 17,920 ----a-w C:\WINDOWS\system32\tftp.exe
2007-11-18 08:32 --------- d-----w C:\Program Files\Alwil Software
2007-11-17 22:22 --------- d---a-w C:\Program Files\InterVideo
2007-11-17 22:22 --------- d---a-w C:\Documents and Settings\Propriétaire\Application Data\VERITAS
2007-11-17 22:22 --------- d---a-w C:\Documents and Settings\Propriétaire\Application Data\VERITAS
2007-11-17 22:21 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\InterVideo
2007-11-17 22:21 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\InterVideo
2007-11-17 22:04 65,308 ---ha-w C:\WINDOWS\system32\hekpkpz.exe
2007-11-17 21:59 --------- d---a-w C:\Program Files\Symantec
2007-11-17 21:59 --------- d---a-w C:\Program Files\Fichiers communs\Symantec Shared
2007-11-17 21:59 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-17 21:48 3,458 --sha-r C:\WINDOWS\system32\drivers\HP_DF101A-ABF 415_YC_Pavi_QCZB318_E32FRheBLF2_4_IKM266-8235_S_V_BAM37312_T030317_W1_L40C_M256_J40_7AMD_8Athlon XP 2000+_91,66_1_N10EC8139_P_Z14F12F00_K_A11063059_U11063038_G10DE0172.MRK
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{478c0e17-2915-49f1-9ace-4d1ec58a76e8}]
C:\WINDOWS\System32\cwbkwlxw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86BE360E-D40E-4212-B495-307A65FBAA89}]
C:\WINDOWS\System32\ddcyy.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97E2CE47-CA37-4E19-9780-7C15B780F4AA}]
C:\WINDOWS\System32\ddcca.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9C77AE8-BC56-4554-9A70-FB2C975521F6}]
C:\WINDOWS\System32\jkhfe.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" []
"KYE_Showicon"="C:\Program Files\USB Storage RW\shwicon.exe" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" [2007-12-25 10:11]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"NvMediaCenter"="RunDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"Local Security Authority Service"="C:\WINDOWS\System32\lssas.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuvsrq]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
S2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 10:21]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 06:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 07:08]
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 18:21:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-25 18:24:08
C:\ComboFix2.txt ... 2007-12-25 11:19
C:\ComboFix3.txt ... 2007-12-23 22:20
.
2007-12-23 19:00:59 --- E O F ---
En tout cas, un grand merci pour ton aide et ta disponibilité.
Sophie
Voici les rapports de ce que j'ai executé sur ton conseil :
J'ai tout analysé avec le site Virus Total...
--------------------------------------------------------------------------------------------------------------
Résultats de OTMovit :
C:\WINDOWS\system32\sexfvf.exe moved successfully.
C:\WINDOWS\system32\hnqhx.exe moved successfully.
Created on 12/25/2007 18:04:21
------------------------------------------------------------------------------------------------
Rapport hitjackhis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:08:55, on 25/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: {8e67a85c-e1d4-eca9-1f94-519271e0c874} - {478c0e17-2915-49f1-9ace-4d1ec58a76e8} - C:\WINDOWS\System32\cwbkwlxw.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {86BE360E-D40E-4212-B495-307A65FBAA89} - C:\WINDOWS\System32\ddcyy.dll (file missing)
O2 - BHO: (no name) - {97E2CE47-CA37-4E19-9780-7C15B780F4AA} - C:\WINDOWS\System32\ddcca.dll (file missing)
O2 - BHO: (no name) - {F9C77AE8-BC56-4554-9A70-FB2C975521F6} - C:\WINDOWS\System32\jkhfe.dll (file missing)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O20 - Winlogon Notify: wvuvsrq - C:\WINDOWS\
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
-----------------------------------------------------------------------
Le rapport combofix :
ComboFix 07-12-21.4 - Propriétaire 2007-12-25 18:13:25.5 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.78 [GMT 1:00]
Running from: C:\Documents and Settings\Propriétaire\Bureau\Programmes desinfectionvirus\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-11-25 to 2007-12-25 ))))))))))))))))))))))))))))))))))))
.
2007-12-23 22:48 . 2007-12-23 22:48 <REP> d-------- C:\Program Files\Avira
2007-12-23 22:48 . 2007-12-23 22:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-12-23 21:08 . 2007-12-23 21:09 <REP> d-------- C:\Program Files\Panda Security
2007-12-23 20:41 . 2007-12-23 20:41 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-12-23 20:37 . 2007-12-25 12:32 <REP> d-------- C:\VundoFix Backups
2007-12-23 20:12 . 2007-12-23 20:12 <REP> d-------- C:\Documents and Settings\LocalService\Menu Démarrer
2007-12-23 18:00 . 2004-08-20 00:09 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-12-23 17:50 . 2007-12-23 17:50 <REP> d-------- C:\WINDOWS\provisioning
2007-12-23 17:50 . 2007-12-23 17:50 <REP> d-------- C:\WINDOWS\peernet
2007-12-23 17:42 . 2007-12-23 17:42 <REP> d-------- C:\WINDOWS\ServicePackFiles
2007-12-23 17:20 . 2007-12-23 17:20 <REP> d-------- C:\WINDOWS\EHome
2007-12-23 16:47 . 2007-12-23 16:47 <REP> d-------- C:\Program Files\TresorNet
2007-12-23 16:46 . 2007-12-23 16:47 1,429,032 --a------ C:\WINDOWS\system32\Noël Cadeaux.scr
2007-12-23 15:25 . 2002-04-15 21:11 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2007-12-23 15:25 . 2004-08-19 16:10 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
2007-12-23 15:25 . 2004-08-02 14:20 7,208 --------- C:\WINDOWS\system32\secupd.sig
2007-12-23 15:25 . 2004-08-02 14:20 4,569 --------- C:\WINDOWS\system32\secupd.dat
2007-12-23 13:58 . 2004-08-20 00:09 614,912 --a------ C:\WINDOWS\system32\h323msp.dll
2007-12-23 13:58 . 2004-08-20 00:09 332,800 --a------ C:\WINDOWS\system32\ipnathlp.dll
2007-12-23 13:58 . 2004-08-20 00:10 266,752 --a------ C:\WINDOWS\system32\h323.tsp
2007-12-23 13:58 . 2004-03-30 02:49 40,960 -----c--- C:\WINDOWS\system32\dllcache\evtgprov.dll
2007-12-23 13:07 . 2003-02-28 16:34 313,856 --a------ C:\WINDOWS\system32\dx3j.dll
2007-12-23 13:07 . 2003-02-28 18:26 171,280 --a------ C:\WINDOWS\system32\jit.dll
2007-12-23 13:07 . 2003-02-28 18:26 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2007-12-23 13:07 . 2003-02-28 18:26 46,352 --a------ C:\WINDOWS\setdebug.exe
2007-12-23 13:07 . 2003-02-28 16:54 7,315 --a------ C:\WINDOWS\system32\javasup.vxd
2007-12-23 13:07 . 2003-02-28 16:35 6,550 --a------ C:\WINDOWS\jautoexp.dat
2007-12-23 09:59 . 2007-12-23 09:59 118 --a------ C:\WINDOWS\system32\wujjdpch.bat
2007-12-23 09:46 . 2007-12-23 13:26 <REP> d-------- C:\Program Files\a-squared Free
2007-12-22 22:52 . 2007-12-22 22:52 121 --a------ C:\WINDOWS\system32\wcamd.bat
2007-12-22 22:40 . 2007-12-22 22:40 123 --a------ C:\WINDOWS\system32\qqydyjm.bat
2007-12-22 22:31 . 2007-12-22 22:31 128 --a------ C:\WINDOWS\system32\mtcdqq.bat
2007-12-22 22:31 . 2007-12-22 22:31 124 --a------ C:\WINDOWS\system32\htrfx.bat
2007-12-22 21:55 . 2007-12-23 22:07 52,736 --a------ C:\WINDOWS\system\hpsysdrv .exe
2007-12-22 21:55 . 2007-12-23 23:54 181 --a------ C:\WINDOWS\system\hpsysdrv .DAT
2007-12-22 21:35 . 2007-12-22 21:35 16,308 --ah----- C:\WINDOWS\system32\nippom.exe
2007-12-22 21:19 . 2007-12-22 21:19 0 --ah----- C:\WINDOWS\system32\yedh.exe
2007-12-22 21:18 . 2007-12-22 21:18 127 --a------ C:\WINDOWS\system32\yyiwk.bat
2007-12-22 21:18 . 2007-12-22 21:18 118 --a------ C:\WINDOWS\system32\ixfwg.bat
2007-12-22 20:01 . 2005-10-20 23:25 1,097,728 --a------ C:\WINDOWS\system32\esent.dll
2007-12-22 13:13 . 2007-12-22 13:13 <REP> d-------- C:\Program Files\Trend Micro
2007-12-22 13:04 . 2007-12-22 13:04 <REP> d-------- C:\WINDOWS\system32\bits
2007-12-22 13:01 . 2007-12-25 11:23 <REP> d--h----- C:\WINDOWS\$hf_mig$
2007-12-22 13:01 . 2005-06-28 09:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-12-22 12:55 . 2004-08-20 00:09 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2007-12-22 12:55 . 2004-08-20 00:09 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-12-22 12:55 . 2004-08-20 00:09 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2007-12-22 12:55 . 2004-08-20 00:09 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2007-12-22 10:54 . 2007-12-22 10:57 256 --a------ C:\WINDOWS\wininit.ini
2007-12-21 17:16 . 2007-12-21 17:17 714 ---hs---- C:\WINDOWS\system32\iffruoww.ini
2007-12-19 20:17 . 2007-12-21 17:08 654 ---hs---- C:\WINDOWS\system32\ijlhiqto.ini
2007-12-19 14:18 . 2007-12-19 14:19 <REP> d-------- C:\Program Files\pfoc
2007-12-18 20:15 . 2007-12-19 20:15 474 ---hs---- C:\WINDOWS\system32\boxxabdd.ini
2007-12-18 18:59 . 2007-12-18 18:59 482 --a------ C:\WINDOWS\Disney.ini
2007-12-18 18:58 . 2007-12-18 18:58 <REP> d-------- C:\Program Files\Disney Interactive
2007-12-17 20:13 . 2007-12-18 20:13 354 ---hs---- C:\WINDOWS\system32\ofihltxw.ini
2007-12-16 10:47 . 2007-12-22 18:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-16 10:47 . 2007-12-16 10:47 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-14 20:10 . 2007-12-15 20:13 354 ---hs---- C:\WINDOWS\system32\imvlpwmp.ini
2007-12-14 19:57 . 2007-12-14 19:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-12-14 19:49 . 2007-12-25 16:46 88,566 --a------ C:\WINDOWS\system32\nvapps.xml
2007-12-14 19:47 . 2006-10-22 12:22 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-12-14 19:47 . 2006-10-22 12:22 17,056 --a------ C:\WINDOWS\system32\nvdisp.nvu
2007-12-14 19:46 . 2006-10-22 15:06 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-12-14 19:38 . 2007-12-14 19:54 <REP> d-------- C:\WINDOWS\nview
2007-12-14 18:49 . 2007-12-14 18:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
2007-12-13 21:03 . 2007-12-14 20:11 8 --a------ C:\WINDOWS\system32\nvModes.dat
2007-12-13 20:33 . 2007-12-13 20:33 <REP> d-------- C:\NVIDIA
2007-12-13 20:03 . 2007-12-13 20:03 294 ---hs---- C:\WINDOWS\system32\saipnoks.ini
2007-12-12 20:06 . 2007-12-12 20:06 1,409 --a------ C:\WINDOWS\system32\tmp2DBDD.FOT
2007-12-12 19:58 . 2007-12-12 19:58 714 ---hs---- C:\WINDOWS\system32\bjrsofky.ini
2007-12-12 19:31 . 2007-07-30 19:19 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-12-12 19:31 . 2007-07-30 19:19 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-12-12 19:31 . 2007-07-30 19:19 216,408 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2007-12-12 19:31 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-12-12 19:31 . 2007-07-30 19:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2007-12-12 19:31 . 2007-07-30 19:18 33,624 --a------ C:\WINDOWS\system32\wups.dll
2007-12-12 19:31 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2007-12-12 19:31 . 2007-07-30 19:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2007-12-12 19:31 . 2007-07-30 19:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2007-12-12 19:27 . 2007-12-12 19:27 <REP> d---s---- C:\Documents and Settings\Propriétaire\UserData
2007-12-12 19:27 . 2007-12-12 19:27 <REP> d---s---- C:\Documents and Settings\Propriétaire\UserData
2007-12-12 12:29 . 2007-12-12 12:29 <REP> d-------- C:\Program Files\Avery Dennison
2007-12-12 12:29 . 2007-12-12 12:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avery
2007-12-11 20:00 . 2007-12-12 12:17 654 ---hs---- C:\WINDOWS\system32\uvkxqfom.ini
2007-12-11 18:33 . 2007-12-11 18:33 1,409 --a------ C:\WINDOWS\system32\tmp72774.FOT
2007-12-10 20:46 . 2007-12-10 20:46 <REP> d-------- C:\Documents and Settings\Propriétaire\Application Data\Avanquest
2007-12-10 20:46 . 2007-12-10 20:46 <REP> d-------- C:\Documents and Settings\Propriétaire\Application Data\Avanquest
2007-12-10 20:46 . 2007-12-10 20:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avanquest
2007-12-10 20:00 . 2007-12-11 17:39 414 ---hs---- C:\WINDOWS\system32\cuigirqx.ini
2007-12-10 19:26 . 2007-12-10 19:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2007-12-10 19:24 . 2007-12-10 19:24 <REP> dr-hs---- C:\_Backup.RC
2007-12-10 19:24 . 2007-12-23 10:48 <REP> d--h----- C:\_Backup
2007-12-10 19:20 . 2007-12-10 19:20 <REP> d-------- C:\Documents and Settings\Propriétaire\Application Data\VCOM
2007-12-10 19:20 . 2007-12-10 19:20 <REP> d-------- C:\Documents and Settings\Propriétaire\Application Data\VCOM
2007-12-10 19:17 . 2007-12-10 19:17 <REP> d-------- C:\Program Files\VCOM
2007-12-09 19:07 . 1994-09-21 01:00 12,800 --a------ C:\WINDOWS\system32\WING32.DLL
2007-12-09 19:06 . 2007-12-09 19:06 <REP> d-------- C:\TLCWIN
2007-12-09 11:19 . 2002-09-27 08:56 249,136 -r-hs---- C:\cmldr
2007-12-09 11:19 . 2007-11-18 02:56 184 -rahs---- C:\BOOT.BAK
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 17:06 --------- d-----w C:\Program Files\Mozilla Thunderbird
2007-12-25 10:44 1,503 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2007-12-23 22:33 --------- d---a-w C:\Program Files\USB Storage RW
2007-12-19 18:30 --------- d-----w C:\Program Files\eMule
2007-12-12 11:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-12 11:27 --------- d---a-w C:\Program Files\Fichiers communs\InstallShield
2007-11-20 21:59 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\vlc
2007-11-20 21:59 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\vlc
2007-11-20 19:01 --------- d-----w C:\Program Files\QuickTime
2007-11-20 19:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2007-11-20 18:23 --------- d---a-w C:\Program Files\Fichiers communs\Adobe
2007-11-20 13:08 --------- d-----w C:\Program Files\EPSON
2007-11-18 20:27 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Grisoft
2007-11-18 20:21 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Grisoft
2007-11-18 20:21 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Grisoft
2007-11-18 20:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-18 09:45 --------- d-----w C:\Program Files\Java
2007-11-18 09:43 --------- d-----w C:\Program Files\Fichiers communs\Java
2007-11-18 09:12 --------- d-----w C:\Program Files\VideoLAN
2007-11-18 08:56 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Thunderbird
2007-11-18 08:56 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Thunderbird
2007-11-18 08:52 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Talkback
2007-11-18 08:52 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Talkback
2007-11-18 08:47 --------- d-----w C:\Program Files\Sunbelt Software
2007-11-18 08:35 17,920 ----a-w C:\WINDOWS\system32\tftp.exe
2007-11-18 08:32 --------- d-----w C:\Program Files\Alwil Software
2007-11-17 22:22 --------- d---a-w C:\Program Files\InterVideo
2007-11-17 22:22 --------- d---a-w C:\Documents and Settings\Propriétaire\Application Data\VERITAS
2007-11-17 22:22 --------- d---a-w C:\Documents and Settings\Propriétaire\Application Data\VERITAS
2007-11-17 22:21 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\InterVideo
2007-11-17 22:21 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\InterVideo
2007-11-17 22:04 65,308 ---ha-w C:\WINDOWS\system32\hekpkpz.exe
2007-11-17 21:59 --------- d---a-w C:\Program Files\Symantec
2007-11-17 21:59 --------- d---a-w C:\Program Files\Fichiers communs\Symantec Shared
2007-11-17 21:59 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-17 21:48 3,458 --sha-r C:\WINDOWS\system32\drivers\HP_DF101A-ABF 415_YC_Pavi_QCZB318_E32FRheBLF2_4_IKM266-8235_S_V_BAM37312_T030317_W1_L40C_M256_J40_7AMD_8Athlon XP 2000+_91,66_1_N10EC8139_P_Z14F12F00_K_A11063059_U11063038_G10DE0172.MRK
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{478c0e17-2915-49f1-9ace-4d1ec58a76e8}]
C:\WINDOWS\System32\cwbkwlxw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86BE360E-D40E-4212-B495-307A65FBAA89}]
C:\WINDOWS\System32\ddcyy.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97E2CE47-CA37-4E19-9780-7C15B780F4AA}]
C:\WINDOWS\System32\ddcca.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9C77AE8-BC56-4554-9A70-FB2C975521F6}]
C:\WINDOWS\System32\jkhfe.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" []
"KYE_Showicon"="C:\Program Files\USB Storage RW\shwicon.exe" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" [2007-12-25 10:11]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"NvMediaCenter"="RunDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"Local Security Authority Service"="C:\WINDOWS\System32\lssas.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuvsrq]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
S2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 10:21]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 06:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 07:08]
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 18:21:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-25 18:24:08
C:\ComboFix2.txt ... 2007-12-25 11:19
C:\ComboFix3.txt ... 2007-12-23 22:20
.
2007-12-23 19:00:59 --- E O F ---
En tout cas, un grand merci pour ton aide et ta disponibilité.
Sophie
jlpjlp
Messages postés
51580
Date d'inscription
vendredi 18 mai 2007
Statut
Contributeur sécurité
Dernière intervention
3 mai 2022
5 040
25 déc. 2007 à 21:08
25 déc. 2007 à 21:08
lance hijackhtis et fix ces lignes:
O2 - BHO: {8e67a85c-e1d4-eca9-1f94-519271e0c874} - {478c0e17-2915-49f1-9ace-4d1ec58a76e8} - C:\WINDOWS\System32\cwbkwlxw.dll (file missing)
O2 - BHO: (no name) - {86BE360E-D40E-4212-B495-307A65FBAA89} - C:\WINDOWS\System32\ddcyy.dll (file missing)
O2 - BHO: (no name) - {97E2CE47-CA37-4E19-9780-7C15B780F4AA} - C:\WINDOWS\System32\ddcca.dll (file missing)
O2 - BHO: (no name) - {F9C77AE8-BC56-4554-9A70-FB2C975521F6} - C:\WINDOWS\System32\jkhfe.dll (file missing)
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O20 - Winlogon Notify: wvuvsrq - C:\WINDOWS\
______________________________
Ouvre le bloc-notes (click droit sur le bureau > dans l´arborescence choisie nouveau et nouveau fichier texte) et fais un copier coller de ce qui est en citation ci-dessous (copie tout d'un trait-sans les barres(X)) :
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{478c0e17-2915-49f1-9ace-4d1ec58a76e8}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86BE360E-D40E-4212-B495-307A65FBAA89}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97E2CE47-CA37-4E19-9780-7C15B780F4AA}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9C77AE8-BC56-4554-9A70-FB2C975521F6}]
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX X
note : regedit4 doit etre sur la premiere ligne dans le bloc note et a la fin il y a une ligne blanche
Puis click sur "fichier"/"enregistrer sous" :
dans : sur le bureau
Nom du fichier : fix.reg
Type de fichier : "tous les fichiers"
clique sur "enregistrer"
ca doit ressembler a ca une fois enrregistré :
http://img520.imageshack.us/img520/4251/screenshot005ps2.png
quitte internet et double clique sur fix.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
Si c'est bien le cas, clique sur "oui"
_________________________
nettoie ton registre avec regcleaner
http://manuelsdaide.com/RegCleaner/RegCleaner.htm
________________________
installe:
SPYWAREBLASTER pour immuniser le système contre vundo notamment(l'infection que tu avais) mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)
________________________
colle le rapport d'un scan avec antivir et un rapport hijackthis
O2 - BHO: {8e67a85c-e1d4-eca9-1f94-519271e0c874} - {478c0e17-2915-49f1-9ace-4d1ec58a76e8} - C:\WINDOWS\System32\cwbkwlxw.dll (file missing)
O2 - BHO: (no name) - {86BE360E-D40E-4212-B495-307A65FBAA89} - C:\WINDOWS\System32\ddcyy.dll (file missing)
O2 - BHO: (no name) - {97E2CE47-CA37-4E19-9780-7C15B780F4AA} - C:\WINDOWS\System32\ddcca.dll (file missing)
O2 - BHO: (no name) - {F9C77AE8-BC56-4554-9A70-FB2C975521F6} - C:\WINDOWS\System32\jkhfe.dll (file missing)
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O20 - Winlogon Notify: wvuvsrq - C:\WINDOWS\
______________________________
Ouvre le bloc-notes (click droit sur le bureau > dans l´arborescence choisie nouveau et nouveau fichier texte) et fais un copier coller de ce qui est en citation ci-dessous (copie tout d'un trait-sans les barres(X)) :
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{478c0e17-2915-49f1-9ace-4d1ec58a76e8}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86BE360E-D40E-4212-B495-307A65FBAA89}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97E2CE47-CA37-4E19-9780-7C15B780F4AA}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9C77AE8-BC56-4554-9A70-FB2C975521F6}]
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX X
note : regedit4 doit etre sur la premiere ligne dans le bloc note et a la fin il y a une ligne blanche
Puis click sur "fichier"/"enregistrer sous" :
dans : sur le bureau
Nom du fichier : fix.reg
Type de fichier : "tous les fichiers"
clique sur "enregistrer"
ca doit ressembler a ca une fois enrregistré :
http://img520.imageshack.us/img520/4251/screenshot005ps2.png
quitte internet et double clique sur fix.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
Si c'est bien le cas, clique sur "oui"
_________________________
nettoie ton registre avec regcleaner
http://manuelsdaide.com/RegCleaner/RegCleaner.htm
________________________
installe:
SPYWAREBLASTER pour immuniser le système contre vundo notamment(l'infection que tu avais) mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)
________________________
colle le rapport d'un scan avec antivir et un rapport hijackthis
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
bluael
Messages postés
37
Date d'inscription
lundi 19 novembre 2007
Statut
Membre
Dernière intervention
27 avril 2011
25 déc. 2007 à 21:55
25 déc. 2007 à 21:55
Alors, j'en suis à fixer le registre et j'ai le message, "impossible d'importer c:\..... Erreur d'accès au registre"
J'ai pourtant tout suivi pas à pas, je ne vois pas où j'ai foiré le truc ?
J'ai pourtant tout suivi pas à pas, je ne vois pas où j'ai foiré le truc ?
jlpjlp
Messages postés
51580
Date d'inscription
vendredi 18 mai 2007
Statut
Contributeur sécurité
Dernière intervention
3 mai 2022
5 040
25 déc. 2007 à 22:48
25 déc. 2007 à 22:48
ok passe a la suite:
_________________________
nettoie ton registre avec regcleaner
http://manuelsdaide.com/RegCleaner/RegCleaner.htm
________________________
installe:
SPYWAREBLASTER pour immuniser le système contre vundo notamment(l'infection que tu avais) mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)
________________________
colle le rapport d'un scan avec antivir et un rapport hijackthis
_________________________
nettoie ton registre avec regcleaner
http://manuelsdaide.com/RegCleaner/RegCleaner.htm
________________________
installe:
SPYWAREBLASTER pour immuniser le système contre vundo notamment(l'infection que tu avais) mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)
________________________
colle le rapport d'un scan avec antivir et un rapport hijackthis
bluael
Messages postés
37
Date d'inscription
lundi 19 novembre 2007
Statut
Membre
Dernière intervention
27 avril 2011
26 déc. 2007 à 18:46
26 déc. 2007 à 18:46
Alors !!!!
________________________________________________________________________________________
Le rapport d'anitivir est nickel, pas d'infection décelée. je ne le poste pas, car il fait au minimun 50 pages!!!!
__________________________________________________________________________________________
Le rapport Hitjackhis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:44:07, on 26/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
_____________________________________________________________________________________________________
Je laisse à JlpJlp le soin de marquer "Résolu" si c''est le cas, dans le cas contraire et bien on continue !!!!
Et je le remercie encore beaucoup pour son aide patiente !!!
Bonsn soirée.
Sophie
________________________________________________________________________________________
Le rapport d'anitivir est nickel, pas d'infection décelée. je ne le poste pas, car il fait au minimun 50 pages!!!!
__________________________________________________________________________________________
Le rapport Hitjackhis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:44:07, on 26/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
_____________________________________________________________________________________________________
Je laisse à JlpJlp le soin de marquer "Résolu" si c''est le cas, dans le cas contraire et bien on continue !!!!
Et je le remercie encore beaucoup pour son aide patiente !!!
Bonsn soirée.
Sophie
jlpjlp
Messages postés
51580
Date d'inscription
vendredi 18 mai 2007
Statut
Contributeur sécurité
Dernière intervention
3 mai 2022
5 040
26 déc. 2007 à 19:01
26 déc. 2007 à 19:01
Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe
_________________
télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
Citation :
C:\WINDOWS\System32\lssas.exe
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
___________________
mets a jour internet explorer:
https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html
___________________
recolle un rapport hiajckhtis et dis tes soucis
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe
_________________
télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
Citation :
C:\WINDOWS\System32\lssas.exe
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
___________________
mets a jour internet explorer:
https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html
___________________
recolle un rapport hiajckhtis et dis tes soucis
bluael
Messages postés
37
Date d'inscription
lundi 19 novembre 2007
Statut
Membre
Dernière intervention
27 avril 2011
26 déc. 2007 à 20:10
26 déc. 2007 à 20:10
Alors, le rapport OTmoveit :
File/Folder C:\WINDOWS\System32\lssas.exe not found.
Created on 12/26/2007 19:15:54
_________________________
Mise à jour internet effectuée...
_________________________
Et le rapport Hitjackhis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:09:06, on 26/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
Tout à l'air de bien se passer sur le comportement général du PC.
Sophie.
File/Folder C:\WINDOWS\System32\lssas.exe not found.
Created on 12/26/2007 19:15:54
_________________________
Mise à jour internet effectuée...
_________________________
Et le rapport Hitjackhis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:09:06, on 26/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
Tout à l'air de bien se passer sur le comportement général du PC.
Sophie.
jlpjlp
Messages postés
51580
Date d'inscription
vendredi 18 mai 2007
Statut
Contributeur sécurité
Dernière intervention
3 mai 2022
5 040
26 déc. 2007 à 20:48
26 déc. 2007 à 20:48
ok c'est bon pour toi!!
tu peux cocher resolu au dessus de ton premier message enfin
pour protéger gratos ton ordi
http://www.commentcamarche.net/telecharger/logiciel 4 securite
mettre un antivirus
AVAST en français ou ANTIVIR (en anglais mais très efficace)
https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
-------------
des anti-espions :
AD AWARE + SPYBOT +/- si tea timer non active de spybot: WINDOWS DEFENDER (si ordi avec au moins 1g de ram)
+/-
SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...
Rq : spybot et ad-aware on sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
--------
un pare feu :
celui de Windows ou mieux KERIO/ sunbelt ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)
https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm
-----------
CCLEANER pour effacer les traces de surf
tu peux cocher resolu au dessus de ton premier message enfin
pour protéger gratos ton ordi
http://www.commentcamarche.net/telecharger/logiciel 4 securite
mettre un antivirus
AVAST en français ou ANTIVIR (en anglais mais très efficace)
https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
-------------
des anti-espions :
AD AWARE + SPYBOT +/- si tea timer non active de spybot: WINDOWS DEFENDER (si ordi avec au moins 1g de ram)
+/-
SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...
Rq : spybot et ad-aware on sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
--------
un pare feu :
celui de Windows ou mieux KERIO/ sunbelt ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)
https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm
-----------
CCLEANER pour effacer les traces de surf
bluael
Messages postés
37
Date d'inscription
lundi 19 novembre 2007
Statut
Membre
Dernière intervention
27 avril 2011
26 déc. 2007 à 20:54
26 déc. 2007 à 20:54
MERCI !!!!!!!
Je ne me permet pas de récapituler la solution , parce que je n'ai pas tout bien compris !!!!!
Je ne me permet pas de récapituler la solution , parce que je n'ai pas tout bien compris !!!!!
jlpjlp
Messages postés
51580
Date d'inscription
vendredi 18 mai 2007
Statut
Contributeur sécurité
Dernière intervention
3 mai 2022
5 040
27 déc. 2007 à 10:10
27 déc. 2007 à 10:10
ok
bonne continuation!
bonne continuation!
Bonjour tt le monde!
J'ai le même virus!
Je télécharge tous les programmes (vundo, combofix etc) Je fais les scans et je colle les rapports!!
Et j'ai le mm problème que toi Jerome_J !!! L'icône de mon disque local dans le poste de travail est une croix rouge!!
J'ai le même virus!
Je télécharge tous les programmes (vundo, combofix etc) Je fais les scans et je colle les rapports!!
Et j'ai le mm problème que toi Jerome_J !!! L'icône de mon disque local dans le poste de travail est une croix rouge!!
Alors j'ai éxécuté vundofix... Et voici les rapports:
---------------------------------------------------------------------------------------------------------
---------------------------------------------------------------------------------------------------------
VirtumondoBeGone:
[01/13/2008, 13:06:53] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\RAPHAEL\Bureau\VirtumundoBeGone.exe" )
[01/13/2008, 13:07:07] - Detected System Information:
[01/13/2008, 13:07:07] - Windows Version: 5.1.2600, Service Pack 2
[01/13/2008, 13:07:07] - Current Username: RAPHAEL (Admin)
[01/13/2008, 13:07:07] - Windows is in NORMAL mode.
[01/13/2008, 13:07:07] - Searching for Browser Helper Objects:
[01/13/2008, 13:07:07] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[01/13/2008, 13:07:07] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[01/13/2008, 13:07:07] - BHO 3: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[01/13/2008, 13:07:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/13/2008, 13:07:07] - No filename found. Continuing.
[01/13/2008, 13:07:07] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
[01/13/2008, 13:07:07] - BHO 5: {c199d92d-00a2-4617-93fe-5ef6170d9edb} ()
[01/13/2008, 13:07:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/13/2008, 13:07:07] - Checking for HKLM\...\Winlogon\Notify\lisnfsat
[01/13/2008, 13:07:07] - Key not found: HKLM\...\Winlogon\Notify\lisnfsat, continuing.
[01/13/2008, 13:07:07] - BHO 6: {C2C57D64-905C-4139-ABDF-8AA2CE269263} ()
[01/13/2008, 13:07:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/13/2008, 13:07:07] - Checking for HKLM\...\Winlogon\Notify\mljge
[01/13/2008, 13:07:07] - Key not found: HKLM\...\Winlogon\Notify\mljge, continuing.
[01/13/2008, 13:07:07] - BHO 7: {E1759A31-E627-4758-9562-6899DF36C9C2} ()
[01/13/2008, 13:07:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/13/2008, 13:07:07] - Checking for HKLM\...\Winlogon\Notify\urqnkjh
[01/13/2008, 13:07:07] - Key not found: HKLM\...\Winlogon\Notify\urqnkjh, continuing.
[01/13/2008, 13:07:07] - BHO 8: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[01/13/2008, 13:07:07] - Finished Searching Browser Helper Objects
[01/13/2008, 13:07:07] - Finishing up...
[01/13/2008, 13:07:07] - Nothing found! Exiting...
-------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------
Combofix:
ComboFix 08-01-13.1 - RAPHAEL 2008-01-13 13:14:11.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.615 [GMT 1:00]
Running from: C:\Documents and Settings\RAPHAEL\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\storageprotector
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\ac
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\em
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\oid
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\user
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\StorageProtector
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\StorageProtector\Contact Customer Service.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\StorageProtector\StorageProtector.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\StorageProtector\Uninstall StorageProtector.lnk
C:\Documents and Settings\RAPHAEL\Application Data\setup_en[1].exe
C:\Documents and Settings\RAPHAEL\Application Data\storageprotector
C:\Documents and Settings\RAPHAEL\Application Data\storageprotector\Logs\update.log
C:\pos10.tmp
C:\pos100.tmp
C:\pos101.tmp
C:\pos102.tmp
C:\pos103.tmp
C:\pos104.tmp
C:\pos105.tmp
C:\pos106.tmp
C:\pos107.tmp
C:\pos108.tmp
C:\pos109.tmp
C:\pos10A.tmp
C:\pos10B.tmp
C:\pos10C.tmp
C:\pos10D.tmp
C:\pos10E.tmp
C:\pos10F.tmp
C:\pos11.tmp
C:\pos110.tmp
C:\pos111.tmp
C:\pos112.tmp
C:\pos113.tmp
C:\pos114.tmp
C:\pos115.tmp
C:\pos116.tmp
C:\pos117.tmp
C:\pos118.tmp
C:\pos119.tmp
C:\pos11A.tmp
C:\pos11B.tmp
C:\pos11C.tmp
C:\pos11D.tmp
C:\pos11E.tmp
C:\pos11F.tmp
C:\pos12.tmp
C:\pos120.tmp
C:\pos121.tmp
C:\pos122.tmp
C:\pos123.tmp
C:\pos124.tmp
C:\pos125.tmp
C:\pos126.tmp
C:\pos127.tmp
C:\pos128.tmp
C:\pos129.tmp
C:\pos12A.tmp
C:\pos12B.tmp
C:\pos12C.tmp
C:\pos12D.tmp
C:\pos12E.tmp
C:\pos12F.tmp
C:\pos13.tmp
C:\pos130.tmp
C:\pos131.tmp
C:\pos132.tmp
C:\pos133.tmp
C:\pos134.tmp
C:\pos135.tmp
C:\pos136.tmp
C:\pos137.tmp
C:\pos138.tmp
C:\pos139.tmp
C:\pos13A.tmp
C:\pos13B.tmp
C:\pos13C.tmp
C:\pos13D.tmp
C:\pos13E.tmp
C:\pos13F.tmp
C:\pos14.tmp
C:\pos140.tmp
C:\pos141.tmp
C:\pos142.tmp
C:\pos143.tmp
C:\pos144.tmp
C:\pos145.tmp
C:\pos146.tmp
C:\pos147.tmp
C:\pos148.tmp
C:\pos149.tmp
C:\pos14A.tmp
C:\pos14B.tmp
C:\pos14C.tmp
C:\pos14D.tmp
C:\pos14E.tmp
C:\pos14F.tmp
C:\pos15.tmp
C:\pos150.tmp
C:\pos151.tmp
C:\pos152.tmp
C:\pos153.tmp
C:\pos154.tmp
C:\pos155.tmp
C:\pos156.tmp
C:\pos157.tmp
C:\pos158.tmp
C:\pos159.tmp
C:\pos15A.tmp
C:\pos15B.tmp
C:\pos15C.tmp
C:\pos15D.tmp
C:\pos15E.tmp
C:\pos15F.tmp
C:\pos16.tmp
C:\pos160.tmp
C:\pos161.tmp
C:\pos162.tmp
C:\pos163.tmp
C:\pos164.tmp
C:\pos165.tmp
C:\pos166.tmp
C:\pos167.tmp
C:\pos168.tmp
C:\pos169.tmp
C:\pos16A.tmp
C:\pos16B.tmp
C:\pos16C.tmp
C:\pos16D.tmp
C:\pos16E.tmp
C:\pos16F.tmp
C:\pos17.tmp
C:\pos170.tmp
C:\pos171.tmp
C:\pos172.tmp
C:\pos173.tmp
C:\pos174.tmp
C:\pos175.tmp
C:\pos176.tmp
C:\pos177.tmp
C:\pos178.tmp
C:\pos179.tmp
C:\pos17A.tmp
C:\pos17B.tmp
C:\pos17C.tmp
C:\pos17D.tmp
C:\pos17E.tmp
C:\pos17F.tmp
C:\pos18.tmp
C:\pos180.tmp
C:\pos181.tmp
C:\pos182.tmp
C:\pos183.tmp
C:\pos184.tmp
C:\pos185.tmp
C:\pos186.tmp
C:\pos187.tmp
C:\pos188.tmp
C:\pos189.tmp
C:\pos18A.tmp
C:\pos18B.tmp
C:\pos18C.tmp
C:\pos18D.tmp
C:\pos18E.tmp
C:\pos18F.tmp
C:\pos19.tmp
C:\pos190.tmp
C:\pos191.tmp
C:\pos192.tmp
C:\pos193.tmp
C:\pos194.tmp
C:\pos195.tmp
C:\pos196.tmp
C:\pos197.tmp
C:\pos198.tmp
C:\pos199.tmp
C:\pos19A.tmp
C:\pos19B.tmp
C:\pos19C.tmp
C:\pos19D.tmp
C:\pos19E.tmp
C:\pos19F.tmp
C:\pos1A.tmp
C:\pos1A0.tmp
C:\pos1A1.tmp
C:\pos1A2.tmp
C:\pos1A3.tmp
C:\pos1A4.tmp
C:\pos1A5.tmp
C:\pos1A6.tmp
C:\pos1A7.tmp
C:\pos1A8.tmp
C:\pos1A9.tmp
C:\pos1AA.tmp
C:\pos1AB.tmp
C:\pos1AC.tmp
C:\pos1AD.tmp
C:\pos1AE.tmp
C:\pos1AF.tmp
C:\pos1B.tmp
C:\pos1B0.tmp
C:\pos1B1.tmp
C:\pos1B2.tmp
C:\pos1B3.tmp
C:\pos1B4.tmp
C:\pos1B5.tmp
C:\pos1B6.tmp
C:\pos1B7.tmp
C:\pos1B8.tmp
C:\pos1B9.tmp
C:\pos1BA.tmp
C:\pos1BB.tmp
C:\pos1BC.tmp
C:\pos1BD.tmp
C:\pos1BE.tmp
C:\pos1BF.tmp
C:\pos1C.tmp
C:\pos1C0.tmp
C:\pos1C1.tmp
C:\pos1C2.tmp
C:\pos1C3.tmp
C:\pos1C4.tmp
C:\pos1C5.tmp
C:\pos1C6.tmp
C:\pos1C7.tmp
C:\pos1C8.tmp
C:\pos1C9.tmp
C:\pos1CA.tmp
C:\pos1CB.tmp
C:\pos1CC.tmp
C:\pos1CD.tmp
C:\pos1CE.tmp
C:\pos1CF.tmp
C:\pos1D.tmp
C:\pos1D0.tmp
C:\pos1D1.tmp
C:\pos1D2.tmp
C:\pos1D3.tmp
C:\pos1D4.tmp
C:\pos1D5.tmp
C:\pos1D6.tmp
C:\pos1D7.tmp
C:\pos1D8.tmp
C:\pos1D9.tmp
C:\pos1DA.tmp
C:\pos1DB.tmp
C:\pos1DC.tmp
C:\pos1DD.tmp
C:\pos1DE.tmp
C:\pos1DF.tmp
C:\pos1E.tmp
C:\pos1E0.tmp
C:\pos1E1.tmp
C:\pos1E2.tmp
C:\pos1E3.tmp
C:\pos1E4.tmp
C:\pos1E5.tmp
C:\pos1E6.tmp
C:\pos1E7.tmp
C:\pos1E8.tmp
C:\pos1E9.tmp
C:\pos1EA.tmp
C:\pos1EB.tmp
C:\pos1EC.tmp
C:\pos1ED.tmp
C:\pos1EE.tmp
C:\pos1EF.tmp
C:\pos1F.tmp
C:\pos1F0.tmp
C:\pos1F1.tmp
C:\pos1F2.tmp
C:\pos1F2A.tmp
C:\pos1F2B.tmp
C:\pos1F2D.tmp
C:\pos1F2E.tmp
C:\pos1F2F.tmp
C:\pos1F3.tmp
C:\pos1F30.tmp
C:\pos1F31.tmp
C:\pos1F33.tmp
C:\pos1F34.tmp
C:\pos1F35.tmp
C:\pos1F36.tmp
C:\pos1F37.tmp
C:\pos1F38.tmp
C:\pos1F39.tmp
C:\pos1F3A.tmp
C:\pos1F3B.tmp
C:\pos1F3C.tmp
C:\pos1F3D.tmp
C:\pos1F3E.tmp
C:\pos1F3F.tmp
C:\pos1F4.tmp
C:\pos1F40.tmp
C:\pos1F41.tmp
C:\pos1F42.tmp
C:\pos1F43.tmp
C:\pos1F44.tmp
C:\pos1F45.tmp
C:\pos1F46.tmp
C:\pos1F47.tmp
C:\pos1F48.tmp
C:\pos1F49.tmp
C:\pos1F4A.tmp
C:\pos1F4B.tmp
C:\pos1F4C.tmp
C:\pos1F4E.tmp
C:\pos1F5.tmp
C:\pos1F50.tmp
C:\pos1F51.tmp
C:\pos1F52.tmp
C:\pos1F53.tmp
C:\pos1F54.tmp
C:\pos1F55.tmp
C:\pos1F56.tmp
C:\pos1F57.tmp
C:\pos1F58.tmp
C:\pos1F59.tmp
C:\pos1F5A.tmp
C:\pos1F5B.tmp
C:\pos1F5C.tmp
C:\pos1F5D.tmp
C:\pos1F5E.tmp
C:\pos1F5F.tmp
C:\pos1F6.tmp
C:\pos1F60.tmp
C:\pos1F61.tmp
C:\pos1F62.tmp
C:\pos1F63.tmp
C:\pos1F64.tmp
C:\pos1F65.tmp
C:\pos1F66.tmp
C:\pos1F67.tmp
C:\pos1F68.tmp
C:\pos1F69.tmp
C:\pos1F6A.tmp
C:\pos1F6B.tmp
C:\pos1F6C.tmp
C:\pos1F6D.tmp
C:\pos1F6E.tmp
C:\pos1F6F.tmp
C:\pos1F7.tmp
C:\pos1F70.tmp
C:\pos1F71.tmp
C:\pos1F72.tmp
C:\pos1F73.tmp
C:\pos1F74.tmp
C:\pos1F75.tmp
C:\pos1F76.tmp
C:\pos1F77.tmp
C:\pos1F78.tmp
C:\pos1F79.tmp
C:\pos1F7A.tmp
C:\pos1F7B.tmp
C:\pos1F7C.tmp
C:\pos1F7D.tmp
C:\pos1F7E.tmp
C:\pos1F7F.tmp
C:\pos1F8.tmp
C:\pos1F80.tmp
C:\pos1F81.tmp
C:\pos1F82.tmp
C:\pos1F83.tmp
C:\pos1F84.tmp
C:\pos1F85.tmp
C:\pos1F86.tmp
C:\pos1F87.tmp
C:\pos1F88.tmp
C:\pos1F89.tmp
C:\pos1F8A.tmp
C:\pos1F8B.tmp
C:\pos1F8C.tmp
C:\pos1F8D.tmp
C:\pos1F8E.tmp
C:\pos1F8F.tmp
C:\pos1F9.tmp
C:\pos1F90.tmp
C:\pos1F91.tmp
C:\pos1F92.tmp
C:\pos1F93.tmp
C:\pos1F94.tmp
C:\pos1F95.tmp
C:\pos1F96.tmp
C:\pos1F97.tmp
C:\pos1F98.tmp
C:\pos1F99.tmp
C:\pos1F9A.tmp
C:\pos1F9B.tmp
C:\pos1F9C.tmp
C:\pos1F9D.tmp
C:\pos1F9E.tmp
C:\pos1F9F.tmp
C:\pos1FA.tmp
C:\pos1FA0.tmp
C:\pos1FA1.tmp
C:\pos1FA2.tmp
C:\pos1FA3.tmp
C:\pos1FA4.tmp
C:\pos1FA5.tmp
C:\pos1FA6.tmp
C:\pos1FA7.tmp
C:\pos1FA8.tmp
C:\pos1FA9.tmp
C:\pos1FAA.tmp
C:\pos1FAB.tmp
C:\pos1FAC.tmp
C:\pos1FAD.tmp
C:\pos1FAE.tmp
C:\pos1FAF.tmp
C:\pos1FB.tmp
C:\pos1FB0.tmp
C:\pos1FB1.tmp
C:\pos1FB2.tmp
C:\pos1FB3.tmp
C:\pos1FB4.tmp
C:\pos1FB5.tmp
C:\pos1FB6.tmp
C:\pos1FB7.tmp
C:\pos1FB8.tmp
C:\pos1FB9.tmp
C:\pos1FBA.tmp
C:\pos1FBB.tmp
C:\pos1FBC.tmp
C:\pos1FBD.tmp
C:\pos1FBE.tmp
C:\pos1FBF.tmp
C:\pos1FC.tmp
C:\pos1FC0.tmp
C:\pos1FC1.tmp
C:\pos1FC2.tmp
C:\pos1FC3.tmp
C:\pos1FC4.tmp
C:\pos1FC5.tmp
C:\pos1FC6.tmp
C:\pos1FC7.tmp
C:\pos1FC8.tmp
C:\pos1FC9.tmp
C:\pos1FCA.tmp
C:\pos1FCB.tmp
C:\pos1FCC.tmp
C:\pos1FCD.tmp
C:\pos1FCE.tmp
C:\pos1FCF.tmp
C:\pos1FD.tmp
C:\pos1FD0.tmp
C:\pos1FD1.tmp
C:\pos1FD2.tmp
C:\pos1FD3.tmp
C:\pos1FD4.tmp
C:\pos1FD5.tmp
C:\pos1FD6.tmp
C:\pos1FD7.tmp
C:\pos1FD8.tmp
C:\pos1FD9.tmp
C:\pos1FDA.tmp
C:\pos1FDB.tmp
C:\pos1FDC.tmp
C:\pos1FDD.tmp
C:\pos1FDE.tmp
C:\pos1FDF.tmp
C:\pos1FE.tmp
C:\pos1FE0.tmp
C:\pos1FE1.tmp
C:\pos1FE2.tmp
C:\pos1FE3.tmp
C:\pos1FE4.tmp
C:\pos1FE5.tmp
C:\pos1FE6.tmp
C:\pos1FE7.tmp
C:\pos1FE8.tmp
C:\pos1FE9.tmp
C:\pos1FEA.tmp
C:\pos1FEB.tmp
C:\pos1FEC.tmp
C:\pos1FED.tmp
C:\pos1FEE.tmp
C:\pos1FEF.tmp
C:\pos1FF.tmp
C:\pos1FF0.tmp
C:\pos1FF1.tmp
C:\pos1FF2.tmp
C:\pos1FF3.tmp
C:\pos1FF4.tmp
C:\pos1FF5.tmp
C:\pos1FF6.tmp
C:\pos1FF7.tmp
C:\pos1FF8.tmp
C:\pos1FF9.tmp
C:\pos1FFA.tmp
C:\pos1FFB.tmp
C:\pos1FFC.tmp
C:\pos1FFD.tmp
C:\pos1FFE.tmp
C:\pos1FFF.tmp
C:\pos20.tmp
C:\pos200.tmp
C:\pos2000.tmp
C:\pos2001.tmp
C:\pos2002.tmp
C:\pos2003.tmp
C:\pos2004.tmp
C:\pos2005.tmp
C:\pos2006.tmp
C:\pos2007.tmp
C:\pos2008.tmp
C:\pos2009.tmp
C:\pos200A.tmp
C:\pos200B.tmp
C:\pos200C.tmp
C:\pos200D.tmp
C:\pos200E.tmp
C:\pos200F.tmp
C:\pos201.tmp
C:\pos2010.tmp
C:\pos2011.tmp
C:\pos2012.tmp
C:\pos2013.tmp
C:\pos2014.tmp
C:\pos2015.tmp
C:\pos2016.tmp
C:\pos2017.tmp
C:\pos2018.tmp
C:\pos2019.tmp
C:\pos201A.tmp
C:\pos201B.tmp
C:\pos201C.tmp
C:\pos201D.tmp
C:\pos201E.tmp
C:\pos201F.tmp
C:\pos202.tmp
C:\pos2020.tmp
C:\pos2021.tmp
C:\pos2022.tmp
C:\pos2023.tmp
C:\pos2024.tmp
C:\pos2025.tmp
C:\pos2026.tmp
C:\pos2027.tmp
C:\pos2028.tmp
C:\pos2029.tmp
C:\pos202A.tmp
C:\pos202B.tmp
C:\pos202C.tmp
C:\pos202D.tmp
C:\pos202E.tmp
C:\pos202F.tmp
C:\pos203.tmp
C:\pos2030.tmp
C:\pos2031.tmp
C:\pos2032.tmp
C:\pos2033.tmp
C:\pos2034.tmp
C:\pos2035.tmp
C:\pos2036.tmp
C:\pos2037.tmp
C:\pos2038.tmp
C:\pos2039.tmp
C:\pos203A.tmp
C:\pos203B.tmp
C:\pos203C.tmp
C:\pos203D.tmp
C:\pos203E.tmp
C:\pos203F.tmp
C:\pos204.tmp
C:\pos2040.tmp
C:\pos2041.tmp
C:\pos2042.tmp
C:\pos2043.tmp
C:\pos2044.tmp
C:\pos2045.tmp
C:\pos2046.tmp
C:\pos2047.tmp
C:\pos2048.tmp
C:\pos2049.tmp
C:\pos204A.tmp
C:\pos204B.tmp
C:\pos204C.tmp
C:\pos204D.tmp
C:\pos204E.tmp
C:\pos204F.tmp
C:\pos205.tmp
C:\pos2050.tmp
C:\pos2051.tmp
C:\pos2052.tmp
C:\pos2053.tmp
C:\pos2054.tmp
C:\pos2055.tmp
C:\pos2056.tmp
C:\pos2057.tmp
C:\pos2058.tmp
C:\pos2059.tmp
C:\pos205A.tmp
C:\pos205B.tmp
C:\pos205C.tmp
C:\pos205D.tmp
C:\pos205E.tmp
C:\pos205F.tmp
C:\pos206.tmp
C:\pos2060.tmp
C:\pos2061.tmp
C:\pos2062.tmp
C:\pos2063.tmp
C:\pos2064.tmp
C:\pos2065.tmp
C:\pos2066.tmp
C:\pos2067.tmp
C:\pos2068.tmp
C:\pos2069.tmp
C:\pos206A.tmp
C:\pos206B.tmp
C:\pos206C.tmp
C:\pos206D.tmp
C:\pos206E.tmp
C:\pos206F.tmp
C:\pos207.tmp
C:\pos2070.tmp
C:\pos2071.tmp
C:\pos2072.tmp
C:\pos2073.tmp
C:\pos2074.tmp
C:\pos2075.tmp
C:\pos2076.tmp
C:\pos2077.tmp
C:\pos2078.tmp
C:\pos2079.tmp
C:\pos207A.tmp
C:\pos207B.tmp
C:\pos207C.tmp
C:\pos207D.tmp
C:\pos207E.tmp
C:\pos207F.tmp
C:\pos208.tmp
C:\pos2080.tmp
C:\pos2081.tmp
C:\pos2082.tmp
C:\pos2083.tmp
C:\pos2084.tmp
C:\pos2085.tmp
C:\pos2086.tmp
C:\pos2087.tmp
C:\pos2088.tmp
C:\pos2089.tmp
C:\pos208A.tmp
C:\pos208B.tmp
C:\pos208C.tmp
C:\pos208D.tmp
C:\pos208E.tmp
C:\pos208F.tmp
C:\pos209.tmp
C:\pos2090.tmp
C:\pos2091.tmp
C:\pos2092.tmp
C:\pos2093.tmp
C:\pos2094.tmp
C:\pos2095.tmp
C:\pos2096.tmp
C:\pos2097.tmp
C:\pos2098.tmp
C:\pos2099.tmp
C:\pos209A.tmp
C:\pos209B.tmp
C:\pos209C.tmp
C:\pos209D.tmp
C:\pos209E.tmp
C:\pos209F.tmp
C:\pos20A.tmp
C:\pos20A0.tmp
C:\pos20A1.tmp
C:\pos20A2.tmp
C:\pos20A3.tmp
C:\pos20A4.tmp
C:\pos20A5.tmp
C:\pos20A6.tmp
C:\pos20A7.tmp
C:\pos20A8.tmp
C:\pos20A9.tmp
C:\pos20AA.tmp
C:\pos20AB.tmp
C:\pos20AC.tmp
C:\pos20AD.tmp
C:\pos20AE.tmp
C:\pos20AF.tmp
C:\pos20B.tmp
C:\pos20B0.tmp
C:\pos20B1.tmp
C:\pos20B2.tmp
C:\pos20B3.tmp
C:\pos20B4.tmp
C:\pos20B5.tmp
C:\pos20B6.tmp
C:\pos20B7.tmp
C:\pos20B8.tmp
C:\pos20B9.tmp
C:\pos20BA.tmp
C:\pos20BB.tmp
C:\pos20BC.tmp
C:\pos20BD.tmp
C:\pos20BE.tmp
C:\pos20BF.tmp
C:\pos20C.tmp
C:\pos20C0.tmp
C:\pos20C1.tmp
C:\pos20C2.tmp
C:\pos20C3.tmp
C:\pos20C4.tmp
C:\pos20C5.tmp
C:\pos20C6.tmp
C:\pos20C7.tmp
C:\pos20C8.tmp
C:\pos20C9.tmp
C:\pos20CA.tmp
C:\pos20CB.tmp
C:\pos20CC.tmp
C:\pos20CD.tmp
C:\pos20CE.tmp
C:\pos20CF.tmp
C:\pos20D.tmp
C:\pos20D0.tmp
C:\pos20D1.tmp
C:\pos20D2.tmp
C:\pos20D3.tmp
C:\pos20D4.tmp
C:\pos20D5.tmp
C:\pos20D6.tmp
C:\pos20D7.tmp
C:\pos20D8.tmp
C:\pos20D9.tmp
C:\pos20DA.tmp
C:\pos20DB.tmp
C:\pos20DC.tmp
C:\pos20DD.tmp
C:\pos20DE.tmp
C:\pos20DF.tmp
C:\pos20E.tmp
C:\pos20E0.tmp
C:\pos20E1.tmp
C:\pos20E2.tmp
C:\pos20E3.tmp
C:\pos20E4.tmp
C:\pos20E5.tmp
C:\pos20E6.tmp
C:\pos20E7.tmp
C:\pos20E8.tmp
C:\pos20E9.tmp
C:\pos20EA.tmp
C:\pos20EB.tmp
C:\pos20EC.tmp
C:\pos20ED.tmp
C:\pos20EE.tmp
C:\pos20EF.tmp
C:\pos20F.tmp
C:\pos20F0.tmp
C:\pos20F1.tmp
C:\pos20F2.tmp
C:\pos20F3.tmp
C:\pos20F4.tmp
C:\pos20F5.tmp
C:\pos20F6.tmp
C:\pos20F7.tmp
C:\pos20F8.tmp
C:\pos20F9.tmp
C:\pos20FA.tmp
C:\pos20FB.tmp
C:\pos20FC.tmp
C:\pos20FD.tmp
C:\pos20FE.tmp
C:\pos20FF.tmp
C:\pos21.tmp
C:\pos210.tmp
C:\pos2100.tmp
C:\pos2101.tmp
C:\pos2102.tmp
C:\pos2103.tmp
C:\pos2104.tmp
C:\pos2105.tmp
C:\pos2106.tmp
C:\pos2107.tmp
C:\pos2108.tmp
C:\pos2109.tmp
C:\pos210A.tmp
C:\pos210B.tmp
C:\pos210C.tmp
C:\pos210D.tmp
C:\pos210E.tmp
C:\pos210F.tmp
C:\pos211.tmp
C:\pos2110.tmp
C:\pos2111.tmp
C:\pos2112.tmp
C:\pos2113.tmp
C:\pos2114.tmp
C:\pos2115.tmp
C:\pos2116.tmp
C:\pos2117.tmp
C:\pos2118.tmp
C:\pos2119.tmp
C:\pos211A.tmp
C:\pos211B.tmp
C:\pos211C.tmp
C:\pos211D.tmp
C:\pos211E.tmp
C:\pos211F.tmp
C:\pos212.tmp
C:\pos2120.tmp
C:\pos2121.tmp
C:\pos213.tmp
C:\pos214.tmp
C:\pos215.tmp
C:\pos216.tmp
C:\pos217.tmp
C:\pos218.tmp
C:\pos219.tmp
C:\pos21A.tmp
C:\pos21B.tmp
C:\pos21C.tmp
C:\pos21D.tmp
C:\pos21E.tmp
C:\pos21F.tmp
C:\pos22.tmp
C:\pos220.tmp
C:\pos221.tmp
C:\pos222.tmp
C:\pos223.tmp
C:\pos224.tmp
C:\pos225.tmp
C:\pos226.tmp
C:\pos227.tmp
C:\pos228.tmp
C:\pos229.tmp
C:\pos22A.tmp
C:\pos22B.tmp
C:\pos22C.tmp
C:\pos22D.tmp
C:\pos22E.tmp
C:\pos22F.tmp
C:\pos23.tmp
C:\pos230.tmp
C:\pos231.tmp
C:\pos232.tmp
C:\pos233.tmp
C:\pos234.tmp
C:\pos235.tmp
C:\pos236.tmp
C:\pos237.tmp
C:\pos238.tmp
C:\pos239.tmp
C:\pos23A.tmp
C:\pos23B.tmp
C:\pos23C.tmp
C:\pos23D.tmp
C:\pos23E.tmp
C:\pos23F.tmp
C:\pos24.tmp
C:\pos240.tmp
C:\pos241.tmp
C:\pos242.tmp
C:\pos243.tmp
C:\pos244.tmp
C:\pos245.tmp
C:\pos246.tmp
C:\pos247.tmp
C:\pos248.tmp
C:\pos249.tmp
C:\pos24A.tmp
C:\pos24B.tmp
C:\pos24C.tmp
C:\pos24D.tmp
C:\pos24E.tmp
C:\pos24F.tmp
C:\pos24F1.tmp
C:\pos24F2.tmp
C:\pos24F3.tmp
C:\pos24F4.tmp
C:\pos24F5.tmp
C:\pos24F6.tmp
C:\pos24F7.tmp
C:\pos24F8.tmp
C:\pos24F9.tmp
C:\pos24FA.tmp
C:\pos24FB.tmp
C:\pos24FD.tmp
C:\pos24FE.tmp
C:\pos24FF.tmp
C:\pos25.tmp
C:\pos250.tmp
C:\pos2500.tmp
C:\pos2501.tmp
C:\pos2502.tmp
C:\pos2503.tmp
C:\pos2504.tmp
C:\pos2505.tmp
C:\pos2506.tmp
C:\pos2507.tmp
C:\pos2508.tmp
C:\pos2509.tmp
C:\pos250A.tmp
C:\pos250B.tmp
C:\pos250C.tmp
C:\pos250D.tmp
C:\pos250E.tmp
C:\pos250F.tmp
C:\pos251.tmp
C:\pos2510.tmp
C:\pos2511.tmp
C:\pos2512.tmp
C:\pos2513.tmp
C:\pos2514.tmp
C:\pos2515.tmp
C:\pos2516.tmp
C:\pos2517.tmp
C:\pos2518.tmp
C:\pos2519.tmp
C:\pos251A.tmp
C:\pos251B.tmp
C:\pos251C.tmp
C:\pos251F.tmp
C:\pos252.tmp
C:\pos2520.tmp
C:\pos2521.tmp
C:\pos2522.tmp
C:\pos2523.tmp
C:\pos2524.tmp
C:\pos2525.tmp
C:\pos2526.tmp
C:\pos2527.tmp
C:\pos2528.tmp
C:\pos2529.tmp
C:\pos252A.tmp
C:\pos252B.tmp
C:\pos252C.tmp
C:\pos252E.tmp
C:\pos253.tmp
C:\pos2530.tmp
C:\pos2531.tmp
C:\pos2532.tmp
C:\pos2533.tmp
C:\pos2534.tmp
C:\pos2535.tmp
C:\pos2536.tmp
C:\pos2537.tmp
C:\pos2538.tmp
C:\pos2539.tmp
C:\pos253A.tmp
C:\pos253B.tmp
C:\pos253C.tmp
C:\pos253D.tmp
C:\pos253E.tmp
C:\pos253F.tmp
C:\pos254.tmp
C:\pos2540.tmp
C:\pos2541.tmp
C:\pos2542.tmp
C:\pos2543.tmp
C:\pos2544.tmp
C:\pos2545.tmp
C:\pos2546.tmp
C:\pos2547.tmp
C:\pos2548.tmp
C:\pos2549.tmp
C:\pos254A.tmp
C:\pos254B.tmp
C:\pos254C.tmp
C:\pos254D.tmp
C:\pos254E.tmp
C:\pos254F.tmp
C:\pos255.tmp
C:\pos2550.tmp
C:\pos2551.tmp
C:\pos2552.tmp
C:\pos2553.tmp
C:\pos2554.tmp
C:\pos2555.tmp
C:\pos2556.tmp
C:\pos2557.tmp
C:\pos2558.tmp
C:\pos2559.tmp
C:\pos255A.tmp
C:\pos255B.tmp
C:\pos255C.tmp
C:\pos255D.tmp
C:\pos255E.tmp
C:\pos255F.tmp
C:\pos256.tmp
C:\pos2560.tmp
C:\pos2561.tmp
C:\pos2562.tmp
C:\pos2563.tmp
C:\pos2564.tmp
C:\pos2565.tmp
C:\pos2566.tmp
C:\pos2567.tmp
C:\pos2568.tmp
C:\pos2569.tmp
C:\pos256A.tmp
C:\pos256B.tmp
C:\pos256C.tmp
C:\pos256D.tmp
C:\pos256E.tmp
C:\pos256F.tmp
C:\pos257.tmp
C:\pos2570.tmp
C:\pos2571.tmp
C:\pos2572.tmp
C:\pos2573.tmp
C:\pos2574.tmp
C:\pos2575.tmp
C:\pos2576.tmp
C:\pos2577.tmp
C:\pos2578.tmp
C:\pos2579.tmp
C:\pos257A.tmp
C:\pos257B.tmp
C:\pos257C.tmp
C:\pos257D.tmp
C:\pos257E.tmp
C:\pos257F.tmp
C:\pos258.tmp
C:\pos2580.tmp
C:\pos2581.tmp
C:\pos2582.tmp
C:\pos2583.tmp
C:\pos2584.tmp
C:\pos2585.tmp
C:\pos2586.tmp
C:\pos2587.tmp
C:\pos2588.tmp
C:\pos2589.tmp
C:\pos258A.tmp
C:\pos258B.tmp
C:\pos258C.tmp
C:\pos258D.tmp
C:\pos258E.tmp
C:\pos258F.tmp
C:\pos259.tmp
C:\pos2590.tmp
C:\pos2591.tmp
C:\pos2592.tmp
C:\pos2593.tmp
C:\pos2594.tmp
C:\pos2595.tmp
C:\pos2596.tmp
C:\pos2597.tmp
C:\pos2598.tmp
C:\pos2599.tmp
C:\pos259A.tmp
C:\pos259B.tmp
C:\pos259C.tmp
C:\pos259D.tmp
C:\pos259E.tmp
C:\pos259F.tmp
C:\pos25A.tmp
C:\pos25A0.tmp
C:\pos25A1.tmp
C:\pos25A2.tmp
C:\pos25A3.tmp
C:\pos25A4.tmp
C:\pos25A5.tmp
C:\pos25A6.tmp
C:\pos25A7.tmp
C:\pos25A8.tmp
C:\pos25A9.tmp
C:\pos25AA.tmp
C:\pos25AB.tmp
C:\pos25AC.tmp
C:\pos25AD.tmp
C:\pos25AE.tmp
C:\pos25AF.tmp
C:\pos25B.tmp
C:\pos25B0.tmp
C:\pos25B1.tmp
C:\pos25B2.tmp
C:\pos25B3.tmp
C:\pos25B4.tmp
C:\pos25B5.tmp
C:\pos25B6.tmp
C:\pos25B7.tmp
C:\pos25B8.tmp
C:\pos25B9.tmp
C:\pos25BA.tmp
C:\pos25BB.tmp
C:\pos25BC.tmp
C:\pos25BD.tmp
C:\pos25BE.tmp
C:\pos25BF.tmp
C:\pos25C.tmp
C:\pos25C0.tmp
C:\pos25C1.tmp
C:\pos25C2.tmp
C:\pos25C3.tmp
C:\pos25C4.tmp
C:\pos25C5.tmp
C:\pos25C6.tmp
C:\pos25C7.tmp
C:\pos25C8.tmp
C:\pos25C9.tmp
C:\pos25CA.tmp
C:\pos25CB.tmp
C:\pos25CC.tmp
C:\pos25CD.tmp
C:\pos25CE.tmp
C:\pos25CF.tmp
C:\pos25D.tmp
C:\pos25D0.tmp
C:\pos25D1.tmp
C:\pos25D2.tmp
C:\pos25D3.tmp
C:\pos25D4.tmp
C:\pos25D5.tmp
C:\pos25D6.tmp
C:\pos25D7.tmp
C:\pos25D8.tmp
C:\pos25D9.tmp
C:\pos25DA.tmp
C:\pos25DB.tmp
C:\pos25DC.tmp
C:\pos25DD.tmp
C:\pos25DE.tmp
C:\pos25DF.tmp
C:\pos25E.tmp
C:\pos25E0.tmp
C:\pos25E1.tmp
C:\pos25E2.tmp
C:\pos25E3.tmp
C:\pos25E4.tmp
C:\pos25E5.tmp
C:\pos25E6.tmp
C:\pos25E7.tmp
C:\pos25E8.tmp
C:\pos25E9.tmp
C:\pos25EA.tmp
C:\pos25EB.tmp
C:\pos25EC.tmp
C:\pos25ED.tmp
C:\pos25EE.tmp
C:\pos25EF.tmp
C:\pos25F.tmp
C:\pos25F0.tmp
C:\pos25F1.tmp
C:\pos25F2.tmp
C:\pos25F3.tmp
C:\pos25F4.tmp
C:\pos25F5.tmp
C:\pos25F6.tmp
C:\pos25F7.tmp
C:\pos25F8.tmp
C:\pos25F9.tmp
C:\pos25FA.tmp
C:\pos25FB.tmp
C:\pos25FC.tmp
C:\pos25FD.tmp
C:\pos25FE.tmp
C:\pos25FF.tmp
C:\pos26.tmp
C:\pos260.tmp
C:\pos2600.tmp
C:\pos2601.tmp
C:\pos2602.tmp
C:\pos2603.tmp
C:\pos2604.tmp
C:\pos2605.tmp
C:\pos2606.tmp
C:\pos2607.tmp
C:\pos2608.tmp
C:\pos2609.tmp
C:\pos260A.tmp
C:\pos260B.tmp
C:\pos260C.tmp
C:\pos260D.tmp
C:\pos260E.tmp
C:\pos260F.tmp
C:\pos261.tmp
C:\pos2610.tmp
C:\pos2611.tmp
C:\pos2612.tmp
C:\pos2613.tmp
C:\pos2614.tmp
C:\pos2615.tmp
C:\pos2616.tmp
C:\pos2617.tmp
C:\pos2618.tmp
C:\pos2619.tmp
C:\pos261A.tmp
C:\pos261B.tmp
C:\pos261C.tmp
C:\pos261D.tmp
C:\pos261E.tmp
C:\pos261F.tmp
C:\pos262.tmp
C:\pos2620.tmp
C:\pos2621.tmp
C:\pos2622.tmp
C:\pos2623.tmp
C:\pos2624.tmp
C:\pos2625.tmp
C:\pos2626.tmp
C:\pos2627.tmp
C:\pos2628.tmp
C:\pos2629.tmp
C:\pos262A.tmp
C:\pos262B.tmp
C:\pos262C.tmp
C:\pos262D.tmp
C:\pos262E.tmp
C:\pos262F.tmp
C:\pos263.tmp
C:\pos2630.tmp
C:\pos2631.tmp
C:\pos2632.tmp
C:\pos2633.tmp
C:\pos2634.tmp
C:\pos2635.tmp
C:\pos2636.tmp
C:\pos2637.tmp
C:\pos2638.tmp
C:\pos2639.tmp
C:\pos263A.tmp
C:\pos263B.tmp
C:\pos263C.tmp
C:\pos263D.tmp
C:\pos263E.tmp
C:\pos263F.tmp
C:\pos264.tmp
C:\pos2640.tmp
C:\pos2641.tmp
C:\pos2642.tmp
C:\pos2643.tmp
C:\pos2644.tmp
C:\pos2645.tmp
C:\pos2646.tmp
C:\pos2647.tmp
C:\pos2648.tmp
C:\pos2649.tmp
C:\pos264A.tmp
C:\pos264B.tmp
C:\pos264C.tmp
C:\pos264D.tmp
C:\pos264E.tmp
C:\pos264F.tmp
C:\pos265.tmp
C:\pos2650.tmp
C:\pos2651.tmp
C:\pos2652.tmp
C:\pos2653.tmp
C:\pos2654.tmp
C:\pos2655.tmp
C:\pos2656.tmp
C:\pos2657.tmp
C:\pos2658.tmp
C:\pos2659.tmp
C:\pos265A.tmp
C:\pos265B.tmp
C:\pos265C.tmp
C:\pos265D.tmp
C:\pos265E.tmp
C:\pos265F.tmp
C:\pos266.tmp
C:\pos2660.tmp
C:\pos2661.tmp
C:\pos2662.tmp
C:\pos2663.tmp
C:\pos2664.tmp
C:\pos2665.tmp
C:\pos2666.tmp
C:\pos2667.tmp
C:\pos2668.tmp
C:\pos2669.tmp
C:\pos266A.tmp
C:\pos266B.tmp
C:\pos266C.tmp
C:\pos266D.tmp
C:\pos266E.tmp
C:\pos266F.tmp
C:\pos267.tmp
C:\pos2670.tmp
C:\pos2671.tmp
C:\pos2672.tmp
C:\pos2673.tmp
C:\pos2674.tmp
C:\pos2675.tmp
C:\pos2676.tmp
C:\pos2677.tmp
C:\pos2678.tmp
C:\pos2679.tmp
C:\pos267A.tmp
C:\pos267B.tmp
C:\pos267C.tmp
C:\pos267D.tmp
C:\pos267E.tmp
C:\pos267F.tmp
C:\pos268.tmp
C:\pos2680.tmp
C:\pos2681.tmp
C:\pos2682.tmp
C:\pos2683.tmp
C:\pos2684.tmp
C:\pos2685.tmp
C:\pos2686.tmp
C:\pos2687.tmp
C:\pos2688.tmp
C:\pos2689.tmp
C:\pos268A.tmp
C:\pos268B.tmp
C:\pos268C.tmp
C:\pos268D.tmp
C:\pos268E.tmp
C:\pos268F.tmp
C:\pos269.tmp
C:\pos2690.tmp
C:\pos2691.tmp
C:\pos2692.tmp
C:\pos2693.tmp
C:\pos2694.tmp
C:\pos2695.tmp
C:\pos2696.tmp
C:\pos2697.tmp
C:\pos2698.tmp
C:\pos2699.tmp
C:\pos269A.tmp
C:\pos269B.tmp
C:\pos269C.tmp
C:\pos269D.tmp
C:\pos269E.tmp
C:\pos269F.tmp
C:\pos26A.tmp
C:\pos26A0.tmp
C:\pos26A1.tmp
C:\pos26A2.tmp
C:\pos26A3.tmp
C:\pos26A4.tmp
C:\pos26A5.tmp
C:\pos26A6.tmp
C:\pos26A7.tmp
C:\pos26A8.tmp
C:\pos26A9.tmp
C:\pos26AA.tmp
C:\pos26AB.tmp
C:\pos26AC.tmp
C:\pos26AD.tmp
C:\pos26AE.tmp
C:\pos26AF.tmp
C:\pos26B.tmp
C:\pos26B0.tmp
C:\pos26B1.tmp
C:\pos26B2.tmp
C:\pos26B3.tmp
C:\pos26B4.tmp
C:\pos26B5.tmp
C:\pos26B6.tmp
C:\pos26B7.tmp
C:\pos26B8.tmp
C:\pos26B9.tmp
C:\pos26BA.tmp
C:\pos26BB.tmp
C:\pos26BC.tmp
C:\pos26BD.tmp
C:\pos26BE.tmp
C:\pos26BF.tmp
C:\pos26C.tmp
C:\pos26C0.tmp
C:\pos26C1.tmp
C:\pos26C2.tmp
C:\pos26C3.tmp
C:\pos26C4.tmp
C:\pos26C5.tmp
C:\pos26C6.tmp
C:\pos26C7.tmp
C:\pos26C8.tmp
C:\pos26C9.tmp
C:\pos26CA.tmp
C:\pos26CB.tmp
C:\pos26CC.tmp
C:\pos26CD.tmp
C:\pos26CE.tmp
C:\pos26CF.tmp
C:\pos26D.tmp
C:\pos26D0.tmp
C:\pos26D1.tmp
C:\pos26D2.tmp
C:\pos26D3.tmp
C:\pos26D4.tmp
C:\pos26D5.tmp
C:\pos26D6.tmp
C:\pos26D7.tmp
C:\pos26D8.tmp
C:\pos26D9.tmp
C:\pos26DA.tmp
C:\pos26DB.tmp
C:\pos26DC.tmp
C:\pos26DD.tmp
C:\pos26DE.tmp
C:\pos26DF.tmp
C:\pos26E.tmp
C:\pos26E0.tmp
C:\pos26E1.tmp
C:\pos26E2.tmp
C:\pos26E3.tmp
C:\pos26E4.tmp
C:\pos26E5.tmp
C:\pos26E6.tmp
C:\pos26E7.tmp
C:\pos26E8.tmp
C:\pos26E9.tmp
C:\pos26F.tmp
C:\pos27.tmp
C:\pos270.tmp
C:\pos271.tmp
C:\pos272.tmp
C:\pos273.tmp
C:\pos274.tmp
C:\pos275.tmp
C:\pos276.tmp
C:\pos277.tmp
C:\pos278.tmp
C:\pos279.tmp
C:\pos27A.tmp
C:\pos27B.tmp
C:\pos27C.tmp
C:\pos27D.tmp
C:\pos27E.tmp
C:\pos27F.tmp
C:\pos28.tmp
C:\pos280.tmp
C:\pos281.tmp
C:\pos282.tmp
C:\pos283.tmp
C:\pos284.tmp
C:\pos285.tmp
C:\pos286.tmp
C:\pos287.tmp
C:\pos288.tmp
C:\pos289.tmp
C:\pos28A.tmp
C:\pos28B.tmp
C:\pos28C.tmp
C:\pos28D.tmp
C:\pos28E.tmp
C:\pos28F.tmp
C:\pos29.tmp
C:\pos290.tmp
C:\pos291.tmp
C:\pos292.tmp
C:\pos293.tmp
C:\pos294.tmp
C:\pos295.tmp
C:\pos296.tmp
C:\pos297.tmp
C:\pos298.tmp
C:\pos299.tmp
C:\pos29A.tmp
C:\pos29B.tmp
C:\pos29C.tmp
C:\pos29D.tmp
C:\pos29E.tmp
C:\pos29F.tmp
C:\pos2A.tmp
C:\pos2A0.tmp
C:\pos2A1.tmp
C:\pos2A2.tmp
C:\pos2A3.tmp
C:\pos2A4.tmp
C:\pos2A5.tmp
C:\pos2A6.tmp
C:\pos2A7.tmp
C:\pos2A8.tmp
C:\pos2A9.tmp
C:\pos2AA.tmp
C:\pos2AB.tmp
C:\pos2AC.tmp
C:\pos2AD.tmp
C:\pos2AE.tmp
C:\pos2AF.tmp
C:\pos2B.tmp
C:\pos2B0.tmp
C:\pos2B1.tmp
C:\pos2B2.tmp
C:\pos2B3.tmp
C:\pos2B4.tmp
C:\pos2B5.tmp
C:\pos2B6.tmp
C:\pos2B7.tmp
C:\pos2B8.tmp
C:\pos2B9.tmp
C:\pos2BA.tmp
C:\pos2BB.tmp
C:\pos2BC.tmp
C:\pos2BD.tmp
C:\pos2BE.tmp
C:\pos2BF.tmp
C:\pos2C.tmp
C:\pos2C0.tmp
C:\pos2C1.tmp
C:\pos2C2.tmp
C:\pos2C3.tmp
C:\pos2C4.tmp
C:\pos2C5.tmp
C:\pos2C6.tmp
C:\pos2C7.tmp
C:\pos2C8.tmp
C:\pos2C9.tmp
C:\pos2CA.tmp
C:\pos2CB.tmp
C:\pos2CC.tmp
C:\pos2CD.tmp
C:\pos2CE.tmp
C:\pos2CF.tmp
C:\pos2D.tmp
C:\pos2D0.tmp
C:\pos2D1.tmp
C:\pos2D2.tmp
C:\pos2D3.tmp
C:\pos2D4.tmp
C:\pos2D5.tmp
C:\pos2D6.tmp
C:\pos2D7.tmp
C:\pos2D8.tmp
C:\pos2D9.tmp
C:\pos2DA.tmp
C:\pos2DB.tmp
C:\pos2DC.tmp
C:\pos2DD.tmp
C:\pos2DE.tmp
C:\pos2DF.tmp
C:\pos2E.tmp
C:\pos2E0.tmp
C:\pos2E1.tmp
C:\pos2E2.tmp
C:\pos2E3.tmp
C:\pos2E4.tmp
C:\pos2E5.tmp
C:\pos2E6.tmp
C:\pos2E7.tmp
C:\pos2E8.tmp
C:\pos2E9.tmp
C:\pos2EA.tmp
C:\pos2EB.tmp
C:\pos2EC.tmp
C:\pos2ED.tmp
C:\pos2EE.tmp
C:\pos2EF.tmp
C:\pos2F.tmp
C:\pos2F0.tmp
C:\pos2F1.tmp
C:\pos2F2.tmp
C:\pos2F3.tmp
C:\pos2F4.tmp
C:\pos2F5.tmp
C:\pos2F6.tmp
C:\pos2F7.tmp
C:\pos2F8.tmp
C:\pos2F9.tmp
C:\pos2FA.tmp
C:\pos2FB.tmp
C:\pos2FC.tmp
C:\pos2FD.tmp
C:\pos2FE.tmp
C:\pos2FF.tmp
C:\pos3.tmp
C:\pos30.tmp
C:\pos300.tmp
C:\pos301.tmp
C:\pos302.tmp
C:\pos303.tmp
C:\pos304.tmp
C:\pos305.tmp
C:\pos306.tmp
C:\pos307.tmp
C:\pos308.tmp
C:\pos309.tmp
C:\pos30A.tmp
C:\pos30B.tmp
C:\pos30C.tmp
C:\pos30D.tmp
C:\pos30E.tmp
C:\pos30F.tmp
C:\pos31.tmp
C:\pos310.tmp
C:\pos311.tmp
C:\pos312.tmp
C:\pos313.tmp
C:\pos314.tmp
C:\pos315.tmp
C:\pos316.tmp
C:\pos317.tmp
C:\pos318.tmp
C:\pos319.tmp
C:\pos31A.tmp
C:\pos31B.tmp
C:\pos31C.tmp
C:\pos31D.tmp
C:\pos31E.tmp
C:\pos31F.tmp
C:\pos32.tmp
C:\pos320.tmp
C:\pos321.tmp
C:\pos322.tmp
C:\pos323.tmp
C:\pos324.tmp
C:\pos325.tmp
C:\pos326.tmp
C:\pos327.tmp
C:\pos328.tmp
C:\pos329.tmp
C:\pos32A.tmp
C:\pos32B.tmp
C:\pos32C.tmp
C:\pos32D.tmp
C:\pos32E.tmp
C:\pos32F.tmp
C:\pos33.tmp
C:\pos330.tmp
C:\pos331.tmp
C:\pos332.tmp
C:\pos333.tmp
C:\pos334.tmp
C:\pos335.tmp
C:\pos336.tmp
C:\pos337.tmp
C:\pos338.tmp
C:\pos339.tmp
C:\pos33A.tmp
C:\pos33B.tmp
C:\pos33C.tmp
C:\pos33D.tmp
C:\pos33E.tmp
C:\pos33F.tmp
C:\pos34.tmp
C:\pos340.tmp
C:\pos341.tmp
C:\pos342.tmp
C:\pos343.tmp
C:\pos344.tmp
C:\pos345.tmp
C:\pos346.tmp
C:\pos347.tmp
C:\pos348.tmp
C:\pos349.tmp
C:\pos34A.tmp
C:\pos34B.tmp
C:\pos34C.tmp
C:\pos34D.tmp
C:\pos34E.tmp
C:\pos34F.tmp
C:\pos35.tmp
C:\pos350.tmp
C:\pos351.tmp
C:\pos352.tmp
C:\pos353.tmp
C:\pos354.tmp
C:\pos355.tmp
C:\pos356.tmp
C:\pos357.tmp
C:\pos358.tmp
C:\pos359.tmp
C:\pos35A.tmp
C:\pos35B.tmp
C:\pos35C.tmp
C:\pos35D.tmp
C:\pos35E.tmp
C:\pos35F.tmp
C:\pos36.tmp
C:\pos360.tmp
C:\pos361.tmp
C:\pos362.tmp
C:\pos363.tmp
C:\pos364.tmp
C:\pos365.tmp
C:\pos366.tmp
C:\pos367.tmp
C:\pos368.tmp
C:\pos369.tmp
C:\pos36A.tmp
C:\pos36B.tmp
C:\pos36C.tmp
C:\pos36D.tmp
C:\pos36E.tmp
C:\pos36F.tmp
C:\pos37.tmp
C:\pos370.tmp
C:\pos371.tmp
C:\pos372.tmp
C:\pos373.tmp
C:\pos374.tmp
C:\pos375.tmp
C:\pos376.tmp
C:\pos377.tmp
C:\pos378.tmp
C:\pos379.tmp
C:\pos37A.tmp
C:\pos37B.tmp
C:\pos37C.tmp
C:\pos37D.tmp
C:\pos37E.tmp
C:\pos37F.tmp
C:\pos38.tmp
C:\pos380.tmp
C:\pos381.tmp
C:\pos382.tmp
C:\pos383.tmp
C:\pos384.tmp
C:\pos385.tmp
C:\pos386.tmp
C:\pos387.tmp
C:\pos388.tmp
C:\pos389.tmp
C:\pos38A.tmp
C:\pos38B.tmp
C:\pos38C.tmp
C:\pos38D.tmp
C:\pos38E.tmp
C:\pos38F.tmp
C:\pos39.tmp
C:\pos390.tmp
C:\pos391.tmp
C:\pos392.tmp
C:\pos393.tmp
C:\pos394.tmp
C:\pos395.tmp
C:\pos396.tmp
C:\pos397.tmp
C:\pos398.tmp
C:\pos399.tmp
C:\pos39A.tmp
C:\pos39B.tmp
C:\pos39C.tmp
C:\pos39D.tmp
C:\pos39E.tmp
C:\pos39F.tmp
C:\pos3A.tmp
C:\pos3A0.tmp
C:\pos3A1.tmp
C:\pos3A2.tmp
C:\pos3A3.tmp
C:\pos3A4.tmp
C:\pos3A5.tmp
C:\pos3A6.tmp
C:\pos3A7.tmp
C:\pos3A8.tmp
C:\pos3A9.tmp
C:\pos3AA.tmp
C:\pos3AB.tmp
C:\pos3AC.tmp
C:\pos3AD.tmp
C:\pos3AE.tmp
C:\pos3AF.tmp
C:\pos3B.tmp
C:\pos3B0.tmp
C:\pos3B1.tmp
C:\pos3B2.tmp
C:\pos3B3.tmp
C:\pos3B4.tmp
C:\pos3B5.tmp
C:\pos3B6.tmp
C:\pos3B7.tmp
C:\pos3B8.tmp
C:\pos3B9.tmp
C:\pos3BA.tmp
C:\pos3BB.tmp
C:\pos3BC.tmp
C:\pos3BD.tmp
C:\pos3BE.tmp
C:\pos3BF.tmp
C:\pos3C.tmp
C:\pos3C0.tmp
C:\pos3C1.tmp
C:\pos3C2.tmp
C:\pos3C3.tmp
C:\pos3C4.tmp
C:\pos3C5.tmp
C:\pos3C6.tmp
C:\pos3C7.tmp
C:\pos3C8.tmp
C:\pos3C9.tmp
C:\pos3CA.tmp
C:\pos3CB.tmp
C:\pos3CC.tmp
C:\pos3CD.tmp
C:\pos3CE.tmp
C:\pos3CF.tmp
C:\pos3D.tmp
C:\pos3D0.tmp
C:\pos3D1.tmp
C:\pos3D2.tmp
C:\pos3D3.tmp
C:\pos3D4.tmp
C:\pos3D5.tmp
C:\pos3D6.tmp
C:\pos3D7.tmp
C:\pos3D8.tmp
C:\pos3D9.tmp
C:\pos3DA.tmp
C:\pos3DB.tmp
C:\pos3DC.tmp
C:\pos3DD.tmp
C:\pos3DE.tmp
C:\pos3DF.tmp
C:\pos3E.tmp
C:\pos3E0.tmp
C:\pos3E1.tmp
C:\pos3E2.tmp
C:\pos3E3.tmp
C:\pos3E4.tmp
C:\pos3E5.tmp
C:\pos3E6.tmp
C:\pos3E7.tmp
C:\pos3E8.tmp
C:\pos3E9.tmp
C:\pos3EA.tmp
C:\pos3EB.tmp
C:\pos3EC.tmp
C:\pos3ED.tmp
C:\pos3EE.tmp
C:\pos3EF.tmp
C:\pos3F.tmp
C:\pos3F0.tmp
C:\pos3F1.tmp
C:\pos3F2.tmp
C:\pos3F3.tmp
C:\pos3F4.tmp
C:\pos3F5.tmp
C:\pos3F6.tmp
C:\pos3F7.tmp
C:\pos3F8.tmp
C:\pos3F9.tmp
C:\pos3FA.tmp
C:\pos3FB.tmp
C:\pos3FC.tmp
C:\pos3FD.tmp
C:\pos3FE.tmp
C:\pos3FF.tmp
C:\pos4.tmp
C:\pos40.tmp
C:\pos400.tmp
C:\pos401.tmp
C:\pos402.tmp
C:\pos403.tmp
C:\pos404.tmp
C:\pos405.tmp
C:\pos406.tmp
C:\pos407.tmp
C:\pos408.tmp
C:\pos409.tmp
C:\pos40A.tmp
C:\pos40B.tmp
C:\pos40C.tmp
C:\pos40D.tmp
C:\pos40E.tmp
C:\pos40F.tmp
C:\pos41.tmp
C:\pos410.tmp
C:\pos411.tmp
C:\pos412.tmp
C:\pos413.tmp
C:\pos414.tmp
C:\pos415.tmp
C:\pos416.tmp
C:\pos417.tmp
C:\pos418.tmp
C:\pos419.tmp
C:\pos41A.tmp
C:\pos41B.tmp
C:\pos41C.tmp
C:\pos41D.tmp
C:\pos41E.tmp
C:\pos41F.tmp
C:\pos42.tmp
C:\pos420.tmp
C:\pos421.tmp
C:\pos422.tmp
C:\pos423.tmp
C:\pos424.tmp
C:\pos425.tmp
C:\pos426.tmp
C:\pos427.tmp
C:\pos428.tmp
C:\pos429.tmp
C:\pos42A.tmp
C:\pos42B.tmp
C:\pos42C.tmp
C:\pos42D.tmp
C:\pos42E.tmp
C:\pos42F.tmp
C:\pos43.tmp
C:\pos430.tmp
C:\pos431.tmp
C:\pos432.tmp
C:\pos433.tmp
C:\pos434.tmp
C:\pos435.tmp
C:\pos436.tmp
C:\pos437.tmp
C:\pos438.tmp
C:\pos439.tmp
C:\pos43A.tmp
C:\pos43B.tmp
C:\pos43C.tmp
C:\pos43D.tmp
C:\pos43E.tmp
C:\pos43F.tmp
C:\pos44.tmp
C:\pos440.tmp
C:\pos441.tmp
C:\pos442.tmp
C:\pos443.tmp
C:\pos444.tmp
C:\pos445.tmp
C:\pos446.tmp
C:\pos447.tmp
C:\pos448.tmp
C:\pos449.tmp
C:\pos44A.tmp
C:\pos44B.tmp
C:\pos44C.tmp
C:\pos44D.tmp
C:\pos44E.tmp
C:\pos44F.tmp
C:\pos45.tmp
C:\pos450.tmp
C:\pos451.tmp
C:\pos452.tmp
C:\pos453.tmp
C:\pos454.tmp
C:\pos455.tmp
C:\pos456.tmp
C:\pos457.tmp
C:\pos458.tmp
C:\pos459.tmp
C:\pos45A.tmp
C:\pos45B.tmp
C:\pos45C.tmp
C:\pos45D.tmp
C:\pos45E.tmp
C:\pos45F.tmp
C:\pos46.tmp
C:\pos460.tmp
C:\pos461.tmp
C:\pos462.tmp
C:\pos463.tmp
C:\pos464.tmp
C:\pos465.tmp
C:\pos466.tmp
C:\pos467.tmp
C:\pos468.tmp
C:\pos469.tmp
C:\pos46A.tmp
C:\pos46B.tmp
C:\pos46C.tmp
C:\pos46D.tmp
C:\pos46E.tmp
C:\pos46F.tmp
C:\pos47.tmp
C:\pos470.tmp
C:\pos471.tmp
C:\pos472.tmp
C:\pos473.tmp
C:\pos474.tmp
C:\pos475.tmp
C:\pos476.tmp
C:\pos477.tmp
C:\pos478.tmp
C:\pos479.tmp
C:\pos47A.tmp
C:\pos47B.tmp
C:\pos47C.tmp
C:\pos47D.tmp
C:\pos47E.tmp
C:\pos47F.tmp
C:\pos48.tmp
C:\pos480.tmp
C:\pos481.tmp
C:\pos482.tmp
C:\pos483.tmp
C:\pos484.tmp
C:\pos485.tmp
C:\pos486.tmp
C:\pos487.tmp
C:\pos488.tmp
C:\pos489.tmp
C:\pos48A.tmp
C:\pos48B.tmp
C:\pos48C.tmp
C:\pos48D.tmp
C:\pos48E.tmp
C:\pos48F.tmp
C:\pos49.tmp
C:\pos490.tmp
C:\pos491.tmp
C:\pos492.tmp
C:\pos493.tmp
C:\pos494.tmp
C:\pos495.tmp
C:\pos496.tmp
C:\pos497.tmp
C:\pos498.tmp
C:\pos499.tmp
C:\pos49A.tmp
C:\pos49B.tmp
C:\pos49C.tmp
C:\pos49D.tmp
C:\pos49E.tmp
C:\pos49F.tmp
C:\pos4A.tmp
C:\pos4A0.tmp
C:\pos4A1.tmp
C:\pos4A2.tmp
C:\pos4A3.tmp
C:\pos4A4.tmp
C:\pos4A5.tmp
C:\pos4A6.tmp
C:\pos4A7.tmp
C:\pos4A8.tmp
C:\pos4A9.tmp
C:\pos4AA.tmp
C:\pos4AB.tmp
C:\pos4AC.tmp
C:\pos4AD.tmp
C:\pos4AE.tmp
C:\pos4AF.tmp
C:\pos4B.tmp
C:\pos4B0.tmp
C:\pos4B1.tmp
C:\pos4B2.tmp
C:\pos4B3.tmp
C:\pos4B4.tmp
C:\pos4B5.tmp
C:\pos4B6.tmp
C:\pos4B7.tmp
C:\pos4B8.tmp
C:\pos4B9.tmp
C:\pos4BA.tmp
C:\pos4BB.tmp
C:\pos4BC.tmp
C:\pos4BD.tmp
C:\pos4BE.tmp
C:\pos4BF.tmp
C:\pos4C.tmp
C:\pos4C0.tmp
C:\pos4C1.tmp
C:\pos4C2.tmp
C:\pos4C3.tmp
C:\pos4C4.tmp
C:\pos4C5.tmp
C:\pos4C6.tmp
C:\pos4C7.tmp
C:\pos4C8.tmp
C:\pos4C9.tmp
C:\pos4CA.tmp
C:\pos4CB.tmp
C:\pos4CC.tmp
C:\pos4CD.tmp
C:\pos4CE.tmp
C:\pos4CF.tmp
C:\pos4D.tmp
C:\pos4D0.tmp
C:\pos4D1.tmp
C:\pos4D2.tmp
C:\pos4D3.tmp
C:\pos4D4.tmp
C:\pos4D5.tmp
C:\pos4D6.tmp
C:\pos4D7.tmp
C:\pos4D8.tmp
C:\pos4D9.tmp
C:\pos4DA.tmp
C:\pos4DB.tmp
C:\pos4DC.tmp
C:\pos4DD.tmp
C:\pos4DE.tmp
C:\pos4DF.tmp
C:\pos4E.tmp
C:\pos4E0.tmp
C:\pos4E1.tmp
C:\pos4E2.tmp
C:\pos4E3.tmp
C:\pos4E4.tmp
C:\pos4E5.tmp
C:\pos4E6.tmp
C:\pos4E7.tmp
C:\pos4E8.tmp
C:\pos4E9.tmp
C:\pos4EA.tmp
C:\pos4EB.tmp
C:\pos4EC.tmp
C:\pos4ED.tmp
C:\pos4EE.tmp
C:\pos4EF.tmp
C:\pos4F.tmp
C:\pos4F0.tmp
C:\pos4F1.tmp
C:\pos4F2.tmp
C:\pos4F3.tmp
C:\pos4F4.tmp
C:\pos4F5.tmp
C:\pos4F6.tmp
C:\pos4F7.tmp
C:\pos4F8.tmp
C:\pos4F9.tmp
C:\pos4FA.tmp
C:\pos4FB.tmp
C:\pos4FC.tmp
C:\pos4FD.tmp
C:\pos4FE.tmp
C:\pos4FF.tmp
C:\pos5.tmp
C:\pos50.tmp
C:\pos500.tmp
C:\pos501.tmp
C:\pos502.tmp
C:\pos503.tmp
C:\pos504.tmp
C:\pos505.tmp
C:\pos506.tmp
C:\pos507.tmp
C:\pos508.tmp
C:\pos509.tmp
C:\pos50A.tmp
C:\pos50B.tmp
C:\pos50C.tmp
C:\pos50D.tmp
C:\pos50E.tmp
C:\pos50F.tmp
C:\pos51.tmp
C:\pos510.tmp
C:\pos511.tmp
C:\pos512.tmp
C:\pos513.tmp
C:\pos514.tmp
C:\pos515.tmp
C:\pos516.tmp
C:\pos517.tmp
C:\pos518.tmp
C:\pos519.tmp
C:\pos51A.tmp
C:\pos51B.tmp
C:\pos51C.tmp
C:\pos51D.tmp
C:\pos51E.tmp
C:\pos51F.tmp
C:\pos52.tmp
C:\pos520.tmp
C:\pos521.tmp
C:\pos522.tmp
C:\pos523.tmp
C:\pos524.tmp
C:\pos525.tmp
C:\pos526.tmp
C:\pos527.tmp
C:\pos528.tmp
C:\pos529.tmp
C:\pos52A.tmp
C:\pos52B.tmp
C:\pos52C.tmp
C:\pos52D.tmp
C:\pos52E.tmp
C:\pos52F.tmp
C:\pos53.tmp
C:\pos530.tmp
C:\pos531.tmp
C:\pos532.tmp
C:\pos533.tmp
C:\pos534.tmp
C:\pos535.tmp
C:\pos536.tmp
C:\pos537.tmp
C:\pos538.tmp
C:\pos539.tmp
C:\pos53A.tmp
C:\pos53B.tmp
C:\pos53C.tmp
C:\pos53D.tmp
C:\pos53E.tmp
C:\pos53F.tmp
C:\pos54.tmp
C:\pos540.tmp
C:\pos541.tmp
C:\pos542.tmp
C:\pos543.tmp
C:\pos544.tmp
C:\pos545.tmp
C:\pos546.tmp
C:\pos547.tmp
C:\pos548.tmp
C:\pos549.tmp
C:\pos54A.tmp
C:\pos54B.tmp
C:\pos54C.tmp
C:\pos54D.tmp
C:\pos54E.tmp
C:\pos54F.tmp
C:\pos55.tmp
C:\pos550.tmp
C:\pos551.tmp
C:\pos552.tmp
C:\pos553.tmp
C:\pos554.tmp
C:\pos555.tmp
C:\pos556.tmp
C:\pos557.tmp
C:\pos558.tmp
C:\pos559.tmp
C:\pos55A.tmp
C:\pos55B.tmp
C:\pos55C.tmp
C:\pos55D.tmp
C:\pos55E.tmp
C:\pos55F.tmp
C:\pos56.tmp
C:\pos560.tmp
C:\pos561.tmp
C:\pos562.tmp
C:\pos563.tmp
C:\pos564.tmp
C:\pos565.tmp
C:\pos566.tmp
C:\pos567.tmp
C:\pos568.tmp
C:\pos569.tmp
C:\pos56A.tmp
C:\pos56B.tmp
C:\pos56C.tmp
C:\pos56D.tmp
C:\pos56E.tmp
C:\pos56F.tmp
C:\pos57.tmp
C:\pos570.tmp
C:\pos571.tmp
C:\pos572.tmp
C:\pos573.tmp
C:\pos574.tmp
C:\pos575.tmp
C:\pos576.tmp
C:\pos577.tmp
C:\pos578.tmp
C:\pos579.tmp
C:\pos57A.tmp
C:\pos57B.tmp
C:\pos57C.tmp
C:\pos57D.tmp
C:\pos57E.tmp
C:\pos57F.tmp
C:\pos58.tmp
C:\pos580.tmp
C:\pos581.tmp
C:\pos582.tmp
C:\pos583.tmp
C:\pos584.tmp
C:\pos585.tmp
C:\pos586.tmp
C:\pos587.tmp
C:\pos588.tmp
C:\pos589.tmp
C:\pos58A.tmp
C:\pos58B.tmp
C:\pos58C.tmp
C:\pos58D.tmp
C:\pos58E.tmp
C:\pos58F.tmp
C:\pos59.tmp
C:\pos590.tmp
C:\pos591.tmp
C:\pos592.tmp
C:\pos593.tmp
C:\pos594.tmp
C:\pos595.tmp
C:\pos596.tmp
C:\pos597.tmp
C:\pos598.tmp
C:\pos599.tmp
C:\pos59A.tmp
C:\pos59B.tmp
C:\pos59C.tmp
C:\pos59D.tmp
C:\pos59E.tmp
C:\pos59F.tmp
C:\pos5A.tmp
C:\pos5A0.tmp
C:\pos5A1.tmp
C:\pos5A2.tmp
C:\pos5A3.tmp
C:\pos5A4.tmp
C:\pos5A5.tmp
C:\pos5A6.tmp
C:\pos5A7.tmp
C:\pos5A8.tmp
C:\pos5A9.tmp
C:\pos5AA.tmp
C:\pos5AB.tmp
C:\pos5AC.tmp
C:\pos5AD.tmp
C:\pos5AE.tmp
C:\pos5AF.tmp
C:\pos5B.tmp
C:\pos5B0.tmp
C:\pos5B1.tmp
C:\pos5B2.tmp
C:\pos5B3.tmp
C:\pos5B4.tmp
C:\pos5B5.tmp
C:\pos5B6.tmp
C:\pos5B7.tmp
C:\pos5B8.tmp
C:\pos5B9.tmp
C:\pos5BA.tmp
C:\pos5BB.tmp
C:\pos5BC.tmp
C:\pos5BD.tmp
C:\pos5BE.tmp
C:\pos5BF.tmp
C:\pos5C.tmp
C:\pos5C0.tmp
C:\pos5C1.tmp
C:\pos5C2.tmp
C:\pos5C3.tmp
C:\pos5C4.tmp
C:\pos5C5.tmp
C:\pos5C6.tmp
C:\pos5C7.tmp
C:\pos5C8.tmp
C:\pos5C9.tmp
C:\pos5CA.tmp
C:\pos5CB.tmp
C:\pos5CC.tmp
C:\pos5CD.tmp
C:\pos5CE.tmp
C:\pos5CF.tmp
C:\pos5D.tmp
C:\pos5D0.tmp
C:\pos5D1.tmp
C:\pos5D2.tmp
C:\pos5D3.tmp
C:\pos5D4.tmp
C:\pos5D5.tmp
C:\pos5D6.tmp
C:\pos5D7.tmp
C:\pos5D8.tmp
C:\pos5D9.tmp
C:\pos5DA.tmp
C:\pos5DB.tmp
C:\pos5DC.tmp
C:\pos5DD.tmp
C:\pos5DE.tmp
C:\pos5E.tmp
C:\pos5F.tmp
C:\pos6.tmp
C:\pos60.tmp
C:\pos61.tmp
C:\pos62.tmp
C:\pos63.tmp
C:\pos64.tmp
C:\pos65.tmp
C:\pos66.tmp
C:\pos67.tmp
C:\pos68.tmp
C:\pos69.tmp
C:\pos6A.tmp
C:\pos6B.tmp
C:\pos6C.tmp
C:\pos6D.tmp
C:\pos6E.tmp
C:\pos6F.tmp
C:\pos7.tmp
C:\pos70.tmp
C:\pos71.tmp
C:\pos72.tmp
C:\pos73.tmp
C:\pos74.tmp
C:\pos75.tmp
C:\pos76.tmp
C:\pos77.tmp
C:\pos77B.tmp
C:\pos77C.tmp
C:\pos77D.tmp
C:\pos77E.tmp
C:\pos77F.tmp
C:\pos78.tmp
C:\pos780.tmp
C:\pos781.tmp
C:\pos782.tmp
C:\pos783.tmp
C:\pos784.tmp
C:\pos785.tmp
C:\pos786.tmp
C:\pos787.tmp
C:\pos788.tmp
C:\pos789.tmp
C:\pos78A.tmp
C:\pos78B.tmp
C:\pos78C.tmp
C:\pos78D.tmp
C:\pos78E.tmp
C:\pos78F.tmp
C:\pos79.tmp
C:\pos790.tmp
C:\pos791.tmp
C:\pos792.tmp
C:\pos793.tmp
C:\pos794.tmp
C:\pos795.tmp
C:\pos796.tmp
C:\pos797.tmp
C:\pos798.tmp
C:\pos799.tmp
C:\pos79A.tmp
C:\pos79B.tmp
C:\pos79C.tmp
C:\pos79D.tmp
C:\pos79E.tmp
C:\pos79F.tmp
C:\pos7A.tmp
C:\pos7A0.tmp
C:\pos7A1.tmp
C:\pos7A2.tmp
C:\pos7A3.tmp
C:\pos7A4.tmp
C:\pos7A5.tmp
C:\pos7A6.tmp
C:\pos7A7.tmp
C:\pos7A8.tmp
C:\pos7A9.tmp
C:\pos7AA.tmp
C:\pos7AB.tmp
C:\pos7AC.tmp
C:\pos7AD.tmp
C:\pos7AE.tmp
C:\pos7AF.tmp
C:\pos7B.tmp
C:\pos7B0.tmp
C:\pos7B1.tmp
C:\pos7B2.tmp
C:\pos7B3.tmp
C:\pos7B4.tmp
C:\pos7B5.tmp
C:\pos7B6.tmp
C:\pos7B7.tmp
C:\pos7B8.tmp
C:\pos7B9.tmp
C:\pos7BA.tmp
C:\pos7BB.tmp
C:\pos7BC.tmp
C:\pos7BD.tmp
C:\pos7BE.tmp
C:\pos7BF.tmp
C:\pos7C.tmp
C:\pos7C0.tmp
C:\pos7C1.tmp
C:\pos7C2.tmp
C:\pos7C3.tmp
C:\pos7C4.tmp
C:\pos7C5.tmp
C:\pos7C6.tmp
C:\pos7C7.tmp
C:\pos7C8.tmp
C:\pos7C9.tmp
C:\pos7CA.tmp
C:\pos7CB.tmp
C:\pos7CC.tmp
C:\pos7CD.tmp
C:\pos7CE.tmp
C:\pos7CF.tmp
C:\pos7D.tmp
C:\pos7D0.tmp
C:\pos7D1.tmp
C:\pos7D2.tmp
C:\pos7D3.tmp
C:\pos7D4.tmp
C:\pos7D5.tmp
C:\pos7D6.tmp
C:\pos7D7.tmp
C:\pos7D8.tmp
C:\pos7D9.tmp
C:\pos7DA.tmp
C:\pos7DB.tmp
C:\pos7DC.tmp
C:\pos7DD.tmp
C:\pos7DE.tmp
C:\pos7DF.tmp
C:\pos7E.tmp
C:\pos7E0.tmp
C:\pos7E1.tmp
C:\pos7E2.tmp
C:\pos7E3.tmp
C:\pos7E4.tmp
C:\pos7E5.tmp
C:\pos7E6.tmp
C:\pos7E7.tmp
C:\pos7E8.tmp
C:\pos7E9.tmp
C:\pos7EA.tmp
C:\pos7EB.tmp
C:\pos7EC.tmp
C:\pos7ED.tmp
C:\pos7EE.tmp
C:\pos7EF.tmp
C:\pos7F.tmp
C:\pos7F0.tmp
C:\pos7F1.tmp
C:\pos7F2.tmp
C:\pos7F3.tmp
C:\pos7F4.tmp
C:\pos7F5.tmp
C:\pos7F6.tmp
C:\pos7F7.tmp
C:\pos7F8.tmp
C:\pos7F9.tmp
C:\pos7FA.tmp
C:\pos7FB.tmp
C:\pos7FC.tmp
C:\pos7FD.tmp
C:\pos7FE.tmp
C:\pos7FF.tmp
C:\pos8.tmp
C:\pos80.tmp
C:\pos800.tmp
C:\pos801.tmp
C:\pos802.tmp
C:\pos803.tmp
C:\pos804.tmp
C:\pos805.tmp
C:\pos806.tmp
C:\pos807.tmp
C:\pos808.tmp
C:\pos809.tmp
C:\pos80A.tmp
C:\pos80B.tmp
C:\pos80C.tmp
C:\pos80D.tmp
C:\pos80E.tmp
C:\pos80F.tmp
C:\pos81.tmp
C:\pos810.tmp
C:\pos811.tmp
C:\pos812.tmp
C:\pos813.tmp
C:\pos814.tmp
C:\pos815.tmp
C:\pos816.tmp
C:\pos817.tmp
C:\pos818.tmp
C:\pos819.tmp
C:\pos81A.tmp
C:\pos81B.tmp
C:\pos81C.tmp
C:\pos81D.tmp
C:\pos81E.tmp
C:\pos81F.tmp
C:\pos82.tmp
C:\pos820.tmp
C:\pos821.tmp
C:\pos822.tmp
C:\pos823.tmp
C:\pos824.tmp
C:\pos825.tmp
C:\pos826.tmp
C:\pos827.tmp
C:\pos828.tmp
C:\pos829.tmp
C:\pos82A.tmp
C:\pos82B.tmp
C:\pos82C.tmp
C:\pos82D.tmp
C:\pos82E.tmp
C:\pos82F.tmp
C:\pos83.tmp
C:\pos830.tmp
C:\pos831.tmp
C:\pos832.tmp
C:\pos833.tmp
C:\pos834.tmp
C:\pos835.tmp
C:\pos836.tmp
C:\pos837.tmp
C:\pos838.tmp
C:\pos839.tmp
C:\pos83A.tmp
C:\pos83B.tmp
C:\pos83C.tmp
C:\pos83D.tmp
C:\pos83E.tmp
C:\pos83F.tmp
C:\pos84.tmp
C:\pos840.tmp
C:\pos841.tmp
C:\pos842.tmp
C:\pos843.tmp
C:\pos844.tmp
C:\pos845.tmp
C:\pos846.tmp
C:\pos847.tmp
C:\pos848.tmp
C:\pos849.tmp
C:\pos84A.tmp
C:\pos84B.tmp
C:\pos84C.tmp
C:\pos84D.tmp
C:\pos84E.tmp
C:\pos84F.tmp
C:\pos85.tmp
C:\pos850.tmp
C:\pos851.tmp
C:\pos852.tmp
C:\pos853.tmp
C:\pos854.tmp
C:\pos855.tmp
C:\pos856.tmp
C:\pos857.tmp
C:\pos858.tmp
C:\pos859.tmp
C:\pos85A.tmp
C:\pos85B.tmp
C:\pos85C.tmp
C:\pos85D.tmp
C:\pos85E.tmp
C:\pos85F.tmp
C:\pos86.tmp
C:\pos860.tmp
C:\pos861.tmp
C:\pos862.tmp
C:\pos863.tmp
C:\pos864.tmp
C:\pos865.tmp
C:\pos866.tmp
C:\pos867.tmp
C:\pos868.tmp
C:\pos869.tmp
C:\pos86A.tmp
C:\pos86B.tmp
C:\pos86C.tmp
C:\pos86D.tmp
C:\pos86E.tmp
C:\pos86F.tmp
C:\pos87.tmp
C:\pos870.tmp
C:\pos871.tmp
C:\pos872.tmp
C:\pos873.tmp
C:\pos874.tmp
C:\pos875.tmp
C:\pos876.tmp
C:\pos877.tmp
C:\pos878.tmp
C:\pos879.tmp
C:\pos87A.tmp
C:\pos87B.tmp
C:\pos87C.tmp
C:\pos87D.tmp
C:\pos87E.tmp
C:\pos87F.tmp
C:\pos88.tmp
C:\pos880.tmp
C:\pos881.tmp
C:\pos882.tmp
C:\pos883.tmp
C:\pos884.tmp
C:\pos885.tmp
C:\pos886.tmp
C:\pos887.tmp
C:\pos888.tmp
C:\pos889.tmp
C:\pos88A.tmp
C:\pos88B.tmp
C:\pos88C.tmp
C:\pos88D.tmp
C:\pos88E.tmp
C:\pos88F.tmp
C:\pos89.tmp
C:\pos890.tmp
C:\pos891.tmp
C:\pos892.tmp
C:\pos893.tmp
C:\pos894.tmp
C:\pos895.tmp
C:\pos896.tmp
C:\pos897.tmp
C:\pos898.tmp
C:\pos899.tmp
C:\pos89A.tmp
C:\pos89B.tmp
C:\pos89C.tmp
C:\pos89D.tmp
C:\pos89E.tmp
C:\pos89F.tmp
C:\pos8A.tmp
C:\pos8A0.tmp
C:\pos8A1.tmp
C:\pos8A2.tmp
C:\pos8A3.tmp
C:\pos8A4.tmp
C:\pos8A5.tmp
C:\pos8A6.tmp
C:\pos8A7.tmp
C:\pos8A8.tmp
C:\pos8A9.tmp
C:\pos8AA.tmp
C:\pos8AB.tmp
C:\pos8AC.tmp
C:\pos8AD.tmp
C:\pos8AE.tmp
C:\pos8AF.tmp
C:\pos8B.tmp
C:\pos8B0.tmp
C:\pos8B1.tmp
C:\pos8B2.tmp
C:\pos8B3.tmp
C:\pos8B4.tmp
C:\pos8B5.tmp
C:\pos8B6.tmp
C:\pos8B7.tmp
C:\pos8B8.tmp
C:\pos8B9.tmp
C:\pos8BA.tmp
C:\pos8BB.tmp
C:\pos8BC.tmp
C:\pos8BD.tmp
C:\pos8BE.tmp
C:\pos8BF.tmp
C:\pos8C.tmp
C:\pos8C0.tmp
C:\pos8C1.tmp
C:\pos8C2.tmp
C:\pos8C3.tmp
C:\pos8C4.tmp
C:\pos8C5.tmp
C:\pos8C6.tmp
C:\pos8C7.tmp
C:\pos8C8.tmp
C:\pos8C9.tmp
C:\pos8CA.tmp
C:\pos8CB.tmp
C:\pos8CC.tmp
C:\pos8CD.tmp
C:\pos8CE.tmp
C:\pos8CF.tmp
C:\pos8D.tmp
C:\pos8D0.tmp
C:\pos8D1.tmp
C:\pos8D2.tmp
C:\pos8D3.tmp
C:\pos8D4.tmp
C:\pos8D5.tmp
C:\pos8D6.tmp
C:\pos8D7.tmp
C:\pos8D8.tmp
C:\pos8D9.tmp
C:\pos8DA.tmp
C:\pos8DB.tmp
C:\pos8DC.tmp
C:\pos8DD.tmp
C:\pos8DE.tmp
C:\pos8DF.tmp
C:\pos8E.tmp
C:\pos8E0.tmp
C:\pos8E1.tmp
C:\pos8E2.tmp
C:\pos8E3.tmp
C:\pos8E4.tmp
C:\pos8E5.tmp
C:\pos8E6.tmp
C:\pos8E7.tmp
C:\pos8E8.tmp
C:\pos8E9.tmp
C:\pos8EA.tmp
C:\pos8EB.tmp
C:\pos8EC.tmp
C:\pos8ED.tmp
C:\pos8EE.tmp
C:\pos8EF.tmp
C:\pos8F.tmp
C:\pos8F0.tmp
C:\pos8F1.tmp
C:\pos8F2.tmp
C:\pos8F3.tmp
C:\pos8F4.tmp
C:\pos8F5.tmp
C:\pos8F6.tmp
C:\pos8F7.tmp
C:\pos8F8.tmp
C:\pos8F9.tmp
C:\pos8FA.tmp
C:\pos8FB.tmp
C:\pos8FC.tmp
C:\pos8FD.tmp
C:\pos8FE.tmp
C:\pos8FF.tmp
C:\pos9.tmp
C:\pos90.tmp
C:\pos900.tmp
C:\pos901.tmp
C:\pos902.tmp
C:\pos903.tmp
C:\pos904.tmp
C:\pos905.tmp
C:\pos906.tmp
C:\pos907.tmp
C:\pos908.tmp
C:\pos909.tmp
C:\pos90A.tmp
C:\pos90B.tmp
C:\pos90C.tmp
C:\pos90D.tmp
C:\pos90E.tmp
C:\pos90F.tmp
C:\pos91.tmp
C:\pos910.tmp
C:\pos911.tmp
C:\pos912.tmp
C:\pos913.tmp
C:\pos914.tmp
C:\pos915.tmp
C:\pos916.tmp
C:\pos917.tmp
C:\pos918.tmp
C:\pos919.tmp
C:\pos91A.tmp
C:\pos91B.tmp
C:\pos91C.tmp
C:\pos91D.tmp
C:\pos91E.tmp
C:\pos91F.tmp
C:\pos92.tmp
C:\pos920.tmp
C:\pos921.tmp
C:\pos922.tmp
C:\pos923.tmp
C:\pos924.tmp
C:\pos925.tmp
C:\pos926.tmp
C:\pos927.tmp
C:\pos928.tmp
C:\pos929.tmp
C:\pos92A.tmp
C:\pos92B.tmp
C:\pos92C.tmp
C:\pos92D.tmp
C:\pos92E.tmp
C:\pos92F.tmp
C:\pos93.tmp
C:\pos930.tmp
C:\pos931.tmp
C:\pos932.tmp
C:\pos933.tmp
C:\pos934.tmp
C:\pos935.tmp
C:\pos936.tmp
C:\pos937.tmp
C:\pos938.tmp
C:\pos939.tmp
C:\pos93A.tmp
C:\pos93B.tmp
C:\pos93C.tmp
C:\pos93D.tmp
C:\pos93E.tmp
C:\pos93F.tmp
C:\pos94.tmp
C:\pos940.tmp
C:\pos941.tmp
C:\pos942.tmp
C:\pos943.tmp
C:\pos944.tmp
C:\pos945.tmp
C:\pos946.tmp
C:\pos947.tmp
C:\pos948.tmp
C:\pos949.tmp
C:\pos94A.tmp
C:\pos94B.tmp
C:\pos94C.tmp
C:\pos94D.tmp
C:\pos94E.tmp
C:\pos94F.tmp
C:\pos95.tmp
C:\pos950.tmp
C:\pos951.tmp
C:\pos952.tmp
C:\pos953.tmp
C:\pos954.tmp
C:\pos955.tmp
C:\pos956.tmp
C:\pos957.tmp
C:\pos958.tmp
C:\pos959.tmp
C:\pos95A.tmp
C:\pos95B.tmp
C:\pos95C.tmp
C:\pos95D.tmp
C:\pos95E.tmp
C:\pos95F.tmp
C:\pos96.tmp
C:\pos960.tmp
C:\pos961.tmp
C:\pos962.tmp
C:\pos963.tmp
C:\pos964.tmp
C:\pos965.tmp
C:\pos966.tmp
C:\pos967.tmp
C:\pos968.tmp
C:\pos969.tmp
C:\pos96A.tmp
C:\pos96B.tmp
C:\pos96C.tmp
C:\pos96D.tmp
C:\pos96E.tmp
C:\pos97.tmp
C:\pos98.tmp
C:\pos99.tmp
C:\pos9A.tmp
C:\pos9B.tmp
C:\pos9C.tmp
C:\pos9D.tmp
C:\pos9E.tmp
C:\pos9F.tmp
C:\posA.tmp
C:\posA0.tmp
C:\posA1.tmp
C:\posA2.tmp
C:\posA3.tmp
C:\posA4.tmp
C:\posA5.tmp
C:\posA6.tmp
C:\posA7.tmp
C:\posA8.tmp
C:\posA9.tmp
C:\posAA.tmp
C:\posAB.tmp
C:\posAC.tmp
C:\posAD.tmp
C:\posAE.tmp
C:\posAF.tmp
C:\posB.tmp
C:\posB0.tmp
C:\posB1.tmp
C:\posB2.tmp
C:\posB3.tmp
C:\posB4.tmp
C:\posB5.tmp
C:\posB6.tmp
C:\posB7.tmp
C:\posB8.tmp
C:\posB9.tmp
C:\posBA.tmp
C:\posBB.tmp
C:\posBC.tmp
C:\posBD.tmp
C:\posBE.tmp
C:\posBF.tmp
C:\posC.tmp
C:\posC0.tmp
C:\posC1.tmp
C:\posC2.tmp
C:\posC3.tmp
C:\posC4.tmp
C:\posC5.tmp
C:\posC6.tmp
C:\posC7.tmp
C:\posC8.tmp
C:\posC9.tmp
C:\posCA.tmp
C:\posCB.tmp
C:\posCC.tmp
C:\posCD.tmp
C:\posCE.tmp
C:\posCF.tmp
C:\posD.tmp
C:\posD0.tmp
C:\posD1.tmp
C:\posD2.tmp
C:\posD3.tmp
C:\posD4.tmp
C:\posD5.tmp
C:\posD6.tmp
C:\posD7.tmp
C:\posD8.tmp
C:\posD9.tmp
C:\posDA.tmp
C:\posDB.tmp
C:\posDC.tmp
C:\posDD.tmp
C:\posDE.tmp
C:\posDF.tmp
C:\posE.tmp
C:\posE0.tmp
C:\posE1.tmp
C:\posE2.tmp
C:\posE3.tmp
C:\posE4.tmp
C:\posE5.tmp
C:\posE6.tmp
C:\posE7.tmp
C:\posE8.tmp
C:\posE9.tmp
C:\posEA.tmp
C:\posEB.tmp
C:\posEC.tmp
C:\posED.tmp
C:\posEE.tmp
C:\posEF.tmp
C:\posF.tmp
C:\posF0.tmp
C:\posF1.tmp
C:\posF2.tmp
C:\posF3.tmp
C:\posF4.tmp
C:\posF5.tmp
C:\posF6.tmp
C:\posF7.tmp
C:\posF8.tmp
C:\posF9.tmp
C:\posFA.tmp
C:\posFB.tmp
C:\posFC.tmp
C:\posFD.tmp
C:\posFE.tmp
C:\posFF.tmp
C:\Program Files\Fichiers communs\StorageProtector
C:\Program Files\StorageProtector
C:\Program Files\StorageProtector\atl71.dll
C:\Program Files\StorageProtector\License.rtf
C:\Program Files\StorageProtector\mfc71.dll
C:\Program Files\StorageProtector\msvcp71.dll
C:\Program Files\StorageProtector\msvcr71.dll
C:\Program Files\StorageProtector\Readme.rtf
C:\Program Files\StorageProtector\Res\Main.ico
C:\Program Files\StorageProtector\Res\RecycleBin.ico
C:\Program Files\StorageProtector\rm.url
C:\Program Files\StorageProtector\sr.log
C:\Program Files\StorageProtector\swupd.log
C:\Program Files\StorageProtector\SysRep.exe.cer
C:\Program Files\StorageProtector\SysRep.exe.Log
C:\Program Files\StorageProtector\SysRep.exe.xml
C:\Program Files\StorageProtector\SysRep.url
C:\Program Files\StorageProtector\transpaid.exe
C:\Program Files\StorageProtector\unins000.dat
C:\Program Files\StorageProtector\unins000.exe
C:\Program Files\StorageProtector\urls.ini
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\geebb.dll
C:\WINDOWS\system32\urqnkjh.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-12-13 to 2008-01-13 ))))))))))))))))))))))))))))))))))))
.
2008-01-13 13:12 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 12:48 . 2008-01-13 12:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-13 12:46 . 2008-01-13 13:03 <REP> d-------- C:\VundoFix Backups
2008-01-13 12:43 . 2008-01-13 12:43 <REP> d-------- C:\Program Files\Trend Micro
2008-01-13 12:29 . 2008-01-13 12:33 <REP> d-------- C:\Program Files\OmniBack
2008-01-12 12:16 . 2008-01-12 12:16 268 --ah----- C:\sqmdata10.sqm
2008-01-12 12:16 . 2008-01-12 12:16 244 --ah----- C:\sqmnoopt10.sqm
2008-01-10 01:06 . 2008-01-10 01:08 32,764 --a------ C:\WINDOWS\17PHolmes572.exe
2008-01-10 00:15 . 2004-08-04 00:54 83,968 --a------ C:\WINDOWS\system32\CNBJMON2.DLL
2008-01-10 00:15 . 2001-08-23 15:46 58,276 --a------ C:\WINDOWS\system32\CNBJHLP2.HLP
2008-01-10 00:15 . 2001-08-23 15:46 1,312 --a------ C:\WINDOWS\system32\CNBJHLP2.CNT
2008-01-09 21:47 . 2008-01-09 21:47 <REP> d-------- C:\Program Files\Valve
2008-01-09 18:02 . 2008-01-09 18:02 <REP> d-------- C:\Program Files\ImTOO
2008-01-09 16:07 . 2008-01-09 16:07 <REP> d-------- C:\Documents and Settings\RAPHAEL\Application Data\AdobeUM
2008-01-08 20:03 . 2008-01-08 20:03 <REP> d-------- C:\Program Files\RapidSolution
2008-01-08 20:03 . 2008-01-08 20:15 <REP> d-------- C:\Documents and Settings\RAPHAEL\Application Data\Tunebite
2008-01-08 20:03 . 2008-01-08 20:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\RapidSolution
2008-01-08 20:03 . 2007-12-11 09:52 26,784 --a------ C:\WINDOWS\system32\drivers\tbhsd.sys
2008-01-06 22:23 . 2008-01-06 22:24 <REP> d-------- C:\Program Files\Everest Poker
2008-01-03 19:53 . 2008-01-03 19:57 <REP> d-------- C:\Documents and Sett
---------------------------------------------------------------------------------------------------------
---------------------------------------------------------------------------------------------------------
VirtumondoBeGone:
[01/13/2008, 13:06:53] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\RAPHAEL\Bureau\VirtumundoBeGone.exe" )
[01/13/2008, 13:07:07] - Detected System Information:
[01/13/2008, 13:07:07] - Windows Version: 5.1.2600, Service Pack 2
[01/13/2008, 13:07:07] - Current Username: RAPHAEL (Admin)
[01/13/2008, 13:07:07] - Windows is in NORMAL mode.
[01/13/2008, 13:07:07] - Searching for Browser Helper Objects:
[01/13/2008, 13:07:07] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[01/13/2008, 13:07:07] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[01/13/2008, 13:07:07] - BHO 3: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[01/13/2008, 13:07:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/13/2008, 13:07:07] - No filename found. Continuing.
[01/13/2008, 13:07:07] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
[01/13/2008, 13:07:07] - BHO 5: {c199d92d-00a2-4617-93fe-5ef6170d9edb} ()
[01/13/2008, 13:07:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/13/2008, 13:07:07] - Checking for HKLM\...\Winlogon\Notify\lisnfsat
[01/13/2008, 13:07:07] - Key not found: HKLM\...\Winlogon\Notify\lisnfsat, continuing.
[01/13/2008, 13:07:07] - BHO 6: {C2C57D64-905C-4139-ABDF-8AA2CE269263} ()
[01/13/2008, 13:07:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/13/2008, 13:07:07] - Checking for HKLM\...\Winlogon\Notify\mljge
[01/13/2008, 13:07:07] - Key not found: HKLM\...\Winlogon\Notify\mljge, continuing.
[01/13/2008, 13:07:07] - BHO 7: {E1759A31-E627-4758-9562-6899DF36C9C2} ()
[01/13/2008, 13:07:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/13/2008, 13:07:07] - Checking for HKLM\...\Winlogon\Notify\urqnkjh
[01/13/2008, 13:07:07] - Key not found: HKLM\...\Winlogon\Notify\urqnkjh, continuing.
[01/13/2008, 13:07:07] - BHO 8: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[01/13/2008, 13:07:07] - Finished Searching Browser Helper Objects
[01/13/2008, 13:07:07] - Finishing up...
[01/13/2008, 13:07:07] - Nothing found! Exiting...
-------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------
Combofix:
ComboFix 08-01-13.1 - RAPHAEL 2008-01-13 13:14:11.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.615 [GMT 1:00]
Running from: C:\Documents and Settings\RAPHAEL\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\storageprotector
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\ac
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\em
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\oid
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\user
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\StorageProtector
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\StorageProtector\Contact Customer Service.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\StorageProtector\StorageProtector.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\StorageProtector\Uninstall StorageProtector.lnk
C:\Documents and Settings\RAPHAEL\Application Data\setup_en[1].exe
C:\Documents and Settings\RAPHAEL\Application Data\storageprotector
C:\Documents and Settings\RAPHAEL\Application Data\storageprotector\Logs\update.log
C:\pos10.tmp
C:\pos100.tmp
C:\pos101.tmp
C:\pos102.tmp
C:\pos103.tmp
C:\pos104.tmp
C:\pos105.tmp
C:\pos106.tmp
C:\pos107.tmp
C:\pos108.tmp
C:\pos109.tmp
C:\pos10A.tmp
C:\pos10B.tmp
C:\pos10C.tmp
C:\pos10D.tmp
C:\pos10E.tmp
C:\pos10F.tmp
C:\pos11.tmp
C:\pos110.tmp
C:\pos111.tmp
C:\pos112.tmp
C:\pos113.tmp
C:\pos114.tmp
C:\pos115.tmp
C:\pos116.tmp
C:\pos117.tmp
C:\pos118.tmp
C:\pos119.tmp
C:\pos11A.tmp
C:\pos11B.tmp
C:\pos11C.tmp
C:\pos11D.tmp
C:\pos11E.tmp
C:\pos11F.tmp
C:\pos12.tmp
C:\pos120.tmp
C:\pos121.tmp
C:\pos122.tmp
C:\pos123.tmp
C:\pos124.tmp
C:\pos125.tmp
C:\pos126.tmp
C:\pos127.tmp
C:\pos128.tmp
C:\pos129.tmp
C:\pos12A.tmp
C:\pos12B.tmp
C:\pos12C.tmp
C:\pos12D.tmp
C:\pos12E.tmp
C:\pos12F.tmp
C:\pos13.tmp
C:\pos130.tmp
C:\pos131.tmp
C:\pos132.tmp
C:\pos133.tmp
C:\pos134.tmp
C:\pos135.tmp
C:\pos136.tmp
C:\pos137.tmp
C:\pos138.tmp
C:\pos139.tmp
C:\pos13A.tmp
C:\pos13B.tmp
C:\pos13C.tmp
C:\pos13D.tmp
C:\pos13E.tmp
C:\pos13F.tmp
C:\pos14.tmp
C:\pos140.tmp
C:\pos141.tmp
C:\pos142.tmp
C:\pos143.tmp
C:\pos144.tmp
C:\pos145.tmp
C:\pos146.tmp
C:\pos147.tmp
C:\pos148.tmp
C:\pos149.tmp
C:\pos14A.tmp
C:\pos14B.tmp
C:\pos14C.tmp
C:\pos14D.tmp
C:\pos14E.tmp
C:\pos14F.tmp
C:\pos15.tmp
C:\pos150.tmp
C:\pos151.tmp
C:\pos152.tmp
C:\pos153.tmp
C:\pos154.tmp
C:\pos155.tmp
C:\pos156.tmp
C:\pos157.tmp
C:\pos158.tmp
C:\pos159.tmp
C:\pos15A.tmp
C:\pos15B.tmp
C:\pos15C.tmp
C:\pos15D.tmp
C:\pos15E.tmp
C:\pos15F.tmp
C:\pos16.tmp
C:\pos160.tmp
C:\pos161.tmp
C:\pos162.tmp
C:\pos163.tmp
C:\pos164.tmp
C:\pos165.tmp
C:\pos166.tmp
C:\pos167.tmp
C:\pos168.tmp
C:\pos169.tmp
C:\pos16A.tmp
C:\pos16B.tmp
C:\pos16C.tmp
C:\pos16D.tmp
C:\pos16E.tmp
C:\pos16F.tmp
C:\pos17.tmp
C:\pos170.tmp
C:\pos171.tmp
C:\pos172.tmp
C:\pos173.tmp
C:\pos174.tmp
C:\pos175.tmp
C:\pos176.tmp
C:\pos177.tmp
C:\pos178.tmp
C:\pos179.tmp
C:\pos17A.tmp
C:\pos17B.tmp
C:\pos17C.tmp
C:\pos17D.tmp
C:\pos17E.tmp
C:\pos17F.tmp
C:\pos18.tmp
C:\pos180.tmp
C:\pos181.tmp
C:\pos182.tmp
C:\pos183.tmp
C:\pos184.tmp
C:\pos185.tmp
C:\pos186.tmp
C:\pos187.tmp
C:\pos188.tmp
C:\pos189.tmp
C:\pos18A.tmp
C:\pos18B.tmp
C:\pos18C.tmp
C:\pos18D.tmp
C:\pos18E.tmp
C:\pos18F.tmp
C:\pos19.tmp
C:\pos190.tmp
C:\pos191.tmp
C:\pos192.tmp
C:\pos193.tmp
C:\pos194.tmp
C:\pos195.tmp
C:\pos196.tmp
C:\pos197.tmp
C:\pos198.tmp
C:\pos199.tmp
C:\pos19A.tmp
C:\pos19B.tmp
C:\pos19C.tmp
C:\pos19D.tmp
C:\pos19E.tmp
C:\pos19F.tmp
C:\pos1A.tmp
C:\pos1A0.tmp
C:\pos1A1.tmp
C:\pos1A2.tmp
C:\pos1A3.tmp
C:\pos1A4.tmp
C:\pos1A5.tmp
C:\pos1A6.tmp
C:\pos1A7.tmp
C:\pos1A8.tmp
C:\pos1A9.tmp
C:\pos1AA.tmp
C:\pos1AB.tmp
C:\pos1AC.tmp
C:\pos1AD.tmp
C:\pos1AE.tmp
C:\pos1AF.tmp
C:\pos1B.tmp
C:\pos1B0.tmp
C:\pos1B1.tmp
C:\pos1B2.tmp
C:\pos1B3.tmp
C:\pos1B4.tmp
C:\pos1B5.tmp
C:\pos1B6.tmp
C:\pos1B7.tmp
C:\pos1B8.tmp
C:\pos1B9.tmp
C:\pos1BA.tmp
C:\pos1BB.tmp
C:\pos1BC.tmp
C:\pos1BD.tmp
C:\pos1BE.tmp
C:\pos1BF.tmp
C:\pos1C.tmp
C:\pos1C0.tmp
C:\pos1C1.tmp
C:\pos1C2.tmp
C:\pos1C3.tmp
C:\pos1C4.tmp
C:\pos1C5.tmp
C:\pos1C6.tmp
C:\pos1C7.tmp
C:\pos1C8.tmp
C:\pos1C9.tmp
C:\pos1CA.tmp
C:\pos1CB.tmp
C:\pos1CC.tmp
C:\pos1CD.tmp
C:\pos1CE.tmp
C:\pos1CF.tmp
C:\pos1D.tmp
C:\pos1D0.tmp
C:\pos1D1.tmp
C:\pos1D2.tmp
C:\pos1D3.tmp
C:\pos1D4.tmp
C:\pos1D5.tmp
C:\pos1D6.tmp
C:\pos1D7.tmp
C:\pos1D8.tmp
C:\pos1D9.tmp
C:\pos1DA.tmp
C:\pos1DB.tmp
C:\pos1DC.tmp
C:\pos1DD.tmp
C:\pos1DE.tmp
C:\pos1DF.tmp
C:\pos1E.tmp
C:\pos1E0.tmp
C:\pos1E1.tmp
C:\pos1E2.tmp
C:\pos1E3.tmp
C:\pos1E4.tmp
C:\pos1E5.tmp
C:\pos1E6.tmp
C:\pos1E7.tmp
C:\pos1E8.tmp
C:\pos1E9.tmp
C:\pos1EA.tmp
C:\pos1EB.tmp
C:\pos1EC.tmp
C:\pos1ED.tmp
C:\pos1EE.tmp
C:\pos1EF.tmp
C:\pos1F.tmp
C:\pos1F0.tmp
C:\pos1F1.tmp
C:\pos1F2.tmp
C:\pos1F2A.tmp
C:\pos1F2B.tmp
C:\pos1F2D.tmp
C:\pos1F2E.tmp
C:\pos1F2F.tmp
C:\pos1F3.tmp
C:\pos1F30.tmp
C:\pos1F31.tmp
C:\pos1F33.tmp
C:\pos1F34.tmp
C:\pos1F35.tmp
C:\pos1F36.tmp
C:\pos1F37.tmp
C:\pos1F38.tmp
C:\pos1F39.tmp
C:\pos1F3A.tmp
C:\pos1F3B.tmp
C:\pos1F3C.tmp
C:\pos1F3D.tmp
C:\pos1F3E.tmp
C:\pos1F3F.tmp
C:\pos1F4.tmp
C:\pos1F40.tmp
C:\pos1F41.tmp
C:\pos1F42.tmp
C:\pos1F43.tmp
C:\pos1F44.tmp
C:\pos1F45.tmp
C:\pos1F46.tmp
C:\pos1F47.tmp
C:\pos1F48.tmp
C:\pos1F49.tmp
C:\pos1F4A.tmp
C:\pos1F4B.tmp
C:\pos1F4C.tmp
C:\pos1F4E.tmp
C:\pos1F5.tmp
C:\pos1F50.tmp
C:\pos1F51.tmp
C:\pos1F52.tmp
C:\pos1F53.tmp
C:\pos1F54.tmp
C:\pos1F55.tmp
C:\pos1F56.tmp
C:\pos1F57.tmp
C:\pos1F58.tmp
C:\pos1F59.tmp
C:\pos1F5A.tmp
C:\pos1F5B.tmp
C:\pos1F5C.tmp
C:\pos1F5D.tmp
C:\pos1F5E.tmp
C:\pos1F5F.tmp
C:\pos1F6.tmp
C:\pos1F60.tmp
C:\pos1F61.tmp
C:\pos1F62.tmp
C:\pos1F63.tmp
C:\pos1F64.tmp
C:\pos1F65.tmp
C:\pos1F66.tmp
C:\pos1F67.tmp
C:\pos1F68.tmp
C:\pos1F69.tmp
C:\pos1F6A.tmp
C:\pos1F6B.tmp
C:\pos1F6C.tmp
C:\pos1F6D.tmp
C:\pos1F6E.tmp
C:\pos1F6F.tmp
C:\pos1F7.tmp
C:\pos1F70.tmp
C:\pos1F71.tmp
C:\pos1F72.tmp
C:\pos1F73.tmp
C:\pos1F74.tmp
C:\pos1F75.tmp
C:\pos1F76.tmp
C:\pos1F77.tmp
C:\pos1F78.tmp
C:\pos1F79.tmp
C:\pos1F7A.tmp
C:\pos1F7B.tmp
C:\pos1F7C.tmp
C:\pos1F7D.tmp
C:\pos1F7E.tmp
C:\pos1F7F.tmp
C:\pos1F8.tmp
C:\pos1F80.tmp
C:\pos1F81.tmp
C:\pos1F82.tmp
C:\pos1F83.tmp
C:\pos1F84.tmp
C:\pos1F85.tmp
C:\pos1F86.tmp
C:\pos1F87.tmp
C:\pos1F88.tmp
C:\pos1F89.tmp
C:\pos1F8A.tmp
C:\pos1F8B.tmp
C:\pos1F8C.tmp
C:\pos1F8D.tmp
C:\pos1F8E.tmp
C:\pos1F8F.tmp
C:\pos1F9.tmp
C:\pos1F90.tmp
C:\pos1F91.tmp
C:\pos1F92.tmp
C:\pos1F93.tmp
C:\pos1F94.tmp
C:\pos1F95.tmp
C:\pos1F96.tmp
C:\pos1F97.tmp
C:\pos1F98.tmp
C:\pos1F99.tmp
C:\pos1F9A.tmp
C:\pos1F9B.tmp
C:\pos1F9C.tmp
C:\pos1F9D.tmp
C:\pos1F9E.tmp
C:\pos1F9F.tmp
C:\pos1FA.tmp
C:\pos1FA0.tmp
C:\pos1FA1.tmp
C:\pos1FA2.tmp
C:\pos1FA3.tmp
C:\pos1FA4.tmp
C:\pos1FA5.tmp
C:\pos1FA6.tmp
C:\pos1FA7.tmp
C:\pos1FA8.tmp
C:\pos1FA9.tmp
C:\pos1FAA.tmp
C:\pos1FAB.tmp
C:\pos1FAC.tmp
C:\pos1FAD.tmp
C:\pos1FAE.tmp
C:\pos1FAF.tmp
C:\pos1FB.tmp
C:\pos1FB0.tmp
C:\pos1FB1.tmp
C:\pos1FB2.tmp
C:\pos1FB3.tmp
C:\pos1FB4.tmp
C:\pos1FB5.tmp
C:\pos1FB6.tmp
C:\pos1FB7.tmp
C:\pos1FB8.tmp
C:\pos1FB9.tmp
C:\pos1FBA.tmp
C:\pos1FBB.tmp
C:\pos1FBC.tmp
C:\pos1FBD.tmp
C:\pos1FBE.tmp
C:\pos1FBF.tmp
C:\pos1FC.tmp
C:\pos1FC0.tmp
C:\pos1FC1.tmp
C:\pos1FC2.tmp
C:\pos1FC3.tmp
C:\pos1FC4.tmp
C:\pos1FC5.tmp
C:\pos1FC6.tmp
C:\pos1FC7.tmp
C:\pos1FC8.tmp
C:\pos1FC9.tmp
C:\pos1FCA.tmp
C:\pos1FCB.tmp
C:\pos1FCC.tmp
C:\pos1FCD.tmp
C:\pos1FCE.tmp
C:\pos1FCF.tmp
C:\pos1FD.tmp
C:\pos1FD0.tmp
C:\pos1FD1.tmp
C:\pos1FD2.tmp
C:\pos1FD3.tmp
C:\pos1FD4.tmp
C:\pos1FD5.tmp
C:\pos1FD6.tmp
C:\pos1FD7.tmp
C:\pos1FD8.tmp
C:\pos1FD9.tmp
C:\pos1FDA.tmp
C:\pos1FDB.tmp
C:\pos1FDC.tmp
C:\pos1FDD.tmp
C:\pos1FDE.tmp
C:\pos1FDF.tmp
C:\pos1FE.tmp
C:\pos1FE0.tmp
C:\pos1FE1.tmp
C:\pos1FE2.tmp
C:\pos1FE3.tmp
C:\pos1FE4.tmp
C:\pos1FE5.tmp
C:\pos1FE6.tmp
C:\pos1FE7.tmp
C:\pos1FE8.tmp
C:\pos1FE9.tmp
C:\pos1FEA.tmp
C:\pos1FEB.tmp
C:\pos1FEC.tmp
C:\pos1FED.tmp
C:\pos1FEE.tmp
C:\pos1FEF.tmp
C:\pos1FF.tmp
C:\pos1FF0.tmp
C:\pos1FF1.tmp
C:\pos1FF2.tmp
C:\pos1FF3.tmp
C:\pos1FF4.tmp
C:\pos1FF5.tmp
C:\pos1FF6.tmp
C:\pos1FF7.tmp
C:\pos1FF8.tmp
C:\pos1FF9.tmp
C:\pos1FFA.tmp
C:\pos1FFB.tmp
C:\pos1FFC.tmp
C:\pos1FFD.tmp
C:\pos1FFE.tmp
C:\pos1FFF.tmp
C:\pos20.tmp
C:\pos200.tmp
C:\pos2000.tmp
C:\pos2001.tmp
C:\pos2002.tmp
C:\pos2003.tmp
C:\pos2004.tmp
C:\pos2005.tmp
C:\pos2006.tmp
C:\pos2007.tmp
C:\pos2008.tmp
C:\pos2009.tmp
C:\pos200A.tmp
C:\pos200B.tmp
C:\pos200C.tmp
C:\pos200D.tmp
C:\pos200E.tmp
C:\pos200F.tmp
C:\pos201.tmp
C:\pos2010.tmp
C:\pos2011.tmp
C:\pos2012.tmp
C:\pos2013.tmp
C:\pos2014.tmp
C:\pos2015.tmp
C:\pos2016.tmp
C:\pos2017.tmp
C:\pos2018.tmp
C:\pos2019.tmp
C:\pos201A.tmp
C:\pos201B.tmp
C:\pos201C.tmp
C:\pos201D.tmp
C:\pos201E.tmp
C:\pos201F.tmp
C:\pos202.tmp
C:\pos2020.tmp
C:\pos2021.tmp
C:\pos2022.tmp
C:\pos2023.tmp
C:\pos2024.tmp
C:\pos2025.tmp
C:\pos2026.tmp
C:\pos2027.tmp
C:\pos2028.tmp
C:\pos2029.tmp
C:\pos202A.tmp
C:\pos202B.tmp
C:\pos202C.tmp
C:\pos202D.tmp
C:\pos202E.tmp
C:\pos202F.tmp
C:\pos203.tmp
C:\pos2030.tmp
C:\pos2031.tmp
C:\pos2032.tmp
C:\pos2033.tmp
C:\pos2034.tmp
C:\pos2035.tmp
C:\pos2036.tmp
C:\pos2037.tmp
C:\pos2038.tmp
C:\pos2039.tmp
C:\pos203A.tmp
C:\pos203B.tmp
C:\pos203C.tmp
C:\pos203D.tmp
C:\pos203E.tmp
C:\pos203F.tmp
C:\pos204.tmp
C:\pos2040.tmp
C:\pos2041.tmp
C:\pos2042.tmp
C:\pos2043.tmp
C:\pos2044.tmp
C:\pos2045.tmp
C:\pos2046.tmp
C:\pos2047.tmp
C:\pos2048.tmp
C:\pos2049.tmp
C:\pos204A.tmp
C:\pos204B.tmp
C:\pos204C.tmp
C:\pos204D.tmp
C:\pos204E.tmp
C:\pos204F.tmp
C:\pos205.tmp
C:\pos2050.tmp
C:\pos2051.tmp
C:\pos2052.tmp
C:\pos2053.tmp
C:\pos2054.tmp
C:\pos2055.tmp
C:\pos2056.tmp
C:\pos2057.tmp
C:\pos2058.tmp
C:\pos2059.tmp
C:\pos205A.tmp
C:\pos205B.tmp
C:\pos205C.tmp
C:\pos205D.tmp
C:\pos205E.tmp
C:\pos205F.tmp
C:\pos206.tmp
C:\pos2060.tmp
C:\pos2061.tmp
C:\pos2062.tmp
C:\pos2063.tmp
C:\pos2064.tmp
C:\pos2065.tmp
C:\pos2066.tmp
C:\pos2067.tmp
C:\pos2068.tmp
C:\pos2069.tmp
C:\pos206A.tmp
C:\pos206B.tmp
C:\pos206C.tmp
C:\pos206D.tmp
C:\pos206E.tmp
C:\pos206F.tmp
C:\pos207.tmp
C:\pos2070.tmp
C:\pos2071.tmp
C:\pos2072.tmp
C:\pos2073.tmp
C:\pos2074.tmp
C:\pos2075.tmp
C:\pos2076.tmp
C:\pos2077.tmp
C:\pos2078.tmp
C:\pos2079.tmp
C:\pos207A.tmp
C:\pos207B.tmp
C:\pos207C.tmp
C:\pos207D.tmp
C:\pos207E.tmp
C:\pos207F.tmp
C:\pos208.tmp
C:\pos2080.tmp
C:\pos2081.tmp
C:\pos2082.tmp
C:\pos2083.tmp
C:\pos2084.tmp
C:\pos2085.tmp
C:\pos2086.tmp
C:\pos2087.tmp
C:\pos2088.tmp
C:\pos2089.tmp
C:\pos208A.tmp
C:\pos208B.tmp
C:\pos208C.tmp
C:\pos208D.tmp
C:\pos208E.tmp
C:\pos208F.tmp
C:\pos209.tmp
C:\pos2090.tmp
C:\pos2091.tmp
C:\pos2092.tmp
C:\pos2093.tmp
C:\pos2094.tmp
C:\pos2095.tmp
C:\pos2096.tmp
C:\pos2097.tmp
C:\pos2098.tmp
C:\pos2099.tmp
C:\pos209A.tmp
C:\pos209B.tmp
C:\pos209C.tmp
C:\pos209D.tmp
C:\pos209E.tmp
C:\pos209F.tmp
C:\pos20A.tmp
C:\pos20A0.tmp
C:\pos20A1.tmp
C:\pos20A2.tmp
C:\pos20A3.tmp
C:\pos20A4.tmp
C:\pos20A5.tmp
C:\pos20A6.tmp
C:\pos20A7.tmp
C:\pos20A8.tmp
C:\pos20A9.tmp
C:\pos20AA.tmp
C:\pos20AB.tmp
C:\pos20AC.tmp
C:\pos20AD.tmp
C:\pos20AE.tmp
C:\pos20AF.tmp
C:\pos20B.tmp
C:\pos20B0.tmp
C:\pos20B1.tmp
C:\pos20B2.tmp
C:\pos20B3.tmp
C:\pos20B4.tmp
C:\pos20B5.tmp
C:\pos20B6.tmp
C:\pos20B7.tmp
C:\pos20B8.tmp
C:\pos20B9.tmp
C:\pos20BA.tmp
C:\pos20BB.tmp
C:\pos20BC.tmp
C:\pos20BD.tmp
C:\pos20BE.tmp
C:\pos20BF.tmp
C:\pos20C.tmp
C:\pos20C0.tmp
C:\pos20C1.tmp
C:\pos20C2.tmp
C:\pos20C3.tmp
C:\pos20C4.tmp
C:\pos20C5.tmp
C:\pos20C6.tmp
C:\pos20C7.tmp
C:\pos20C8.tmp
C:\pos20C9.tmp
C:\pos20CA.tmp
C:\pos20CB.tmp
C:\pos20CC.tmp
C:\pos20CD.tmp
C:\pos20CE.tmp
C:\pos20CF.tmp
C:\pos20D.tmp
C:\pos20D0.tmp
C:\pos20D1.tmp
C:\pos20D2.tmp
C:\pos20D3.tmp
C:\pos20D4.tmp
C:\pos20D5.tmp
C:\pos20D6.tmp
C:\pos20D7.tmp
C:\pos20D8.tmp
C:\pos20D9.tmp
C:\pos20DA.tmp
C:\pos20DB.tmp
C:\pos20DC.tmp
C:\pos20DD.tmp
C:\pos20DE.tmp
C:\pos20DF.tmp
C:\pos20E.tmp
C:\pos20E0.tmp
C:\pos20E1.tmp
C:\pos20E2.tmp
C:\pos20E3.tmp
C:\pos20E4.tmp
C:\pos20E5.tmp
C:\pos20E6.tmp
C:\pos20E7.tmp
C:\pos20E8.tmp
C:\pos20E9.tmp
C:\pos20EA.tmp
C:\pos20EB.tmp
C:\pos20EC.tmp
C:\pos20ED.tmp
C:\pos20EE.tmp
C:\pos20EF.tmp
C:\pos20F.tmp
C:\pos20F0.tmp
C:\pos20F1.tmp
C:\pos20F2.tmp
C:\pos20F3.tmp
C:\pos20F4.tmp
C:\pos20F5.tmp
C:\pos20F6.tmp
C:\pos20F7.tmp
C:\pos20F8.tmp
C:\pos20F9.tmp
C:\pos20FA.tmp
C:\pos20FB.tmp
C:\pos20FC.tmp
C:\pos20FD.tmp
C:\pos20FE.tmp
C:\pos20FF.tmp
C:\pos21.tmp
C:\pos210.tmp
C:\pos2100.tmp
C:\pos2101.tmp
C:\pos2102.tmp
C:\pos2103.tmp
C:\pos2104.tmp
C:\pos2105.tmp
C:\pos2106.tmp
C:\pos2107.tmp
C:\pos2108.tmp
C:\pos2109.tmp
C:\pos210A.tmp
C:\pos210B.tmp
C:\pos210C.tmp
C:\pos210D.tmp
C:\pos210E.tmp
C:\pos210F.tmp
C:\pos211.tmp
C:\pos2110.tmp
C:\pos2111.tmp
C:\pos2112.tmp
C:\pos2113.tmp
C:\pos2114.tmp
C:\pos2115.tmp
C:\pos2116.tmp
C:\pos2117.tmp
C:\pos2118.tmp
C:\pos2119.tmp
C:\pos211A.tmp
C:\pos211B.tmp
C:\pos211C.tmp
C:\pos211D.tmp
C:\pos211E.tmp
C:\pos211F.tmp
C:\pos212.tmp
C:\pos2120.tmp
C:\pos2121.tmp
C:\pos213.tmp
C:\pos214.tmp
C:\pos215.tmp
C:\pos216.tmp
C:\pos217.tmp
C:\pos218.tmp
C:\pos219.tmp
C:\pos21A.tmp
C:\pos21B.tmp
C:\pos21C.tmp
C:\pos21D.tmp
C:\pos21E.tmp
C:\pos21F.tmp
C:\pos22.tmp
C:\pos220.tmp
C:\pos221.tmp
C:\pos222.tmp
C:\pos223.tmp
C:\pos224.tmp
C:\pos225.tmp
C:\pos226.tmp
C:\pos227.tmp
C:\pos228.tmp
C:\pos229.tmp
C:\pos22A.tmp
C:\pos22B.tmp
C:\pos22C.tmp
C:\pos22D.tmp
C:\pos22E.tmp
C:\pos22F.tmp
C:\pos23.tmp
C:\pos230.tmp
C:\pos231.tmp
C:\pos232.tmp
C:\pos233.tmp
C:\pos234.tmp
C:\pos235.tmp
C:\pos236.tmp
C:\pos237.tmp
C:\pos238.tmp
C:\pos239.tmp
C:\pos23A.tmp
C:\pos23B.tmp
C:\pos23C.tmp
C:\pos23D.tmp
C:\pos23E.tmp
C:\pos23F.tmp
C:\pos24.tmp
C:\pos240.tmp
C:\pos241.tmp
C:\pos242.tmp
C:\pos243.tmp
C:\pos244.tmp
C:\pos245.tmp
C:\pos246.tmp
C:\pos247.tmp
C:\pos248.tmp
C:\pos249.tmp
C:\pos24A.tmp
C:\pos24B.tmp
C:\pos24C.tmp
C:\pos24D.tmp
C:\pos24E.tmp
C:\pos24F.tmp
C:\pos24F1.tmp
C:\pos24F2.tmp
C:\pos24F3.tmp
C:\pos24F4.tmp
C:\pos24F5.tmp
C:\pos24F6.tmp
C:\pos24F7.tmp
C:\pos24F8.tmp
C:\pos24F9.tmp
C:\pos24FA.tmp
C:\pos24FB.tmp
C:\pos24FD.tmp
C:\pos24FE.tmp
C:\pos24FF.tmp
C:\pos25.tmp
C:\pos250.tmp
C:\pos2500.tmp
C:\pos2501.tmp
C:\pos2502.tmp
C:\pos2503.tmp
C:\pos2504.tmp
C:\pos2505.tmp
C:\pos2506.tmp
C:\pos2507.tmp
C:\pos2508.tmp
C:\pos2509.tmp
C:\pos250A.tmp
C:\pos250B.tmp
C:\pos250C.tmp
C:\pos250D.tmp
C:\pos250E.tmp
C:\pos250F.tmp
C:\pos251.tmp
C:\pos2510.tmp
C:\pos2511.tmp
C:\pos2512.tmp
C:\pos2513.tmp
C:\pos2514.tmp
C:\pos2515.tmp
C:\pos2516.tmp
C:\pos2517.tmp
C:\pos2518.tmp
C:\pos2519.tmp
C:\pos251A.tmp
C:\pos251B.tmp
C:\pos251C.tmp
C:\pos251F.tmp
C:\pos252.tmp
C:\pos2520.tmp
C:\pos2521.tmp
C:\pos2522.tmp
C:\pos2523.tmp
C:\pos2524.tmp
C:\pos2525.tmp
C:\pos2526.tmp
C:\pos2527.tmp
C:\pos2528.tmp
C:\pos2529.tmp
C:\pos252A.tmp
C:\pos252B.tmp
C:\pos252C.tmp
C:\pos252E.tmp
C:\pos253.tmp
C:\pos2530.tmp
C:\pos2531.tmp
C:\pos2532.tmp
C:\pos2533.tmp
C:\pos2534.tmp
C:\pos2535.tmp
C:\pos2536.tmp
C:\pos2537.tmp
C:\pos2538.tmp
C:\pos2539.tmp
C:\pos253A.tmp
C:\pos253B.tmp
C:\pos253C.tmp
C:\pos253D.tmp
C:\pos253E.tmp
C:\pos253F.tmp
C:\pos254.tmp
C:\pos2540.tmp
C:\pos2541.tmp
C:\pos2542.tmp
C:\pos2543.tmp
C:\pos2544.tmp
C:\pos2545.tmp
C:\pos2546.tmp
C:\pos2547.tmp
C:\pos2548.tmp
C:\pos2549.tmp
C:\pos254A.tmp
C:\pos254B.tmp
C:\pos254C.tmp
C:\pos254D.tmp
C:\pos254E.tmp
C:\pos254F.tmp
C:\pos255.tmp
C:\pos2550.tmp
C:\pos2551.tmp
C:\pos2552.tmp
C:\pos2553.tmp
C:\pos2554.tmp
C:\pos2555.tmp
C:\pos2556.tmp
C:\pos2557.tmp
C:\pos2558.tmp
C:\pos2559.tmp
C:\pos255A.tmp
C:\pos255B.tmp
C:\pos255C.tmp
C:\pos255D.tmp
C:\pos255E.tmp
C:\pos255F.tmp
C:\pos256.tmp
C:\pos2560.tmp
C:\pos2561.tmp
C:\pos2562.tmp
C:\pos2563.tmp
C:\pos2564.tmp
C:\pos2565.tmp
C:\pos2566.tmp
C:\pos2567.tmp
C:\pos2568.tmp
C:\pos2569.tmp
C:\pos256A.tmp
C:\pos256B.tmp
C:\pos256C.tmp
C:\pos256D.tmp
C:\pos256E.tmp
C:\pos256F.tmp
C:\pos257.tmp
C:\pos2570.tmp
C:\pos2571.tmp
C:\pos2572.tmp
C:\pos2573.tmp
C:\pos2574.tmp
C:\pos2575.tmp
C:\pos2576.tmp
C:\pos2577.tmp
C:\pos2578.tmp
C:\pos2579.tmp
C:\pos257A.tmp
C:\pos257B.tmp
C:\pos257C.tmp
C:\pos257D.tmp
C:\pos257E.tmp
C:\pos257F.tmp
C:\pos258.tmp
C:\pos2580.tmp
C:\pos2581.tmp
C:\pos2582.tmp
C:\pos2583.tmp
C:\pos2584.tmp
C:\pos2585.tmp
C:\pos2586.tmp
C:\pos2587.tmp
C:\pos2588.tmp
C:\pos2589.tmp
C:\pos258A.tmp
C:\pos258B.tmp
C:\pos258C.tmp
C:\pos258D.tmp
C:\pos258E.tmp
C:\pos258F.tmp
C:\pos259.tmp
C:\pos2590.tmp
C:\pos2591.tmp
C:\pos2592.tmp
C:\pos2593.tmp
C:\pos2594.tmp
C:\pos2595.tmp
C:\pos2596.tmp
C:\pos2597.tmp
C:\pos2598.tmp
C:\pos2599.tmp
C:\pos259A.tmp
C:\pos259B.tmp
C:\pos259C.tmp
C:\pos259D.tmp
C:\pos259E.tmp
C:\pos259F.tmp
C:\pos25A.tmp
C:\pos25A0.tmp
C:\pos25A1.tmp
C:\pos25A2.tmp
C:\pos25A3.tmp
C:\pos25A4.tmp
C:\pos25A5.tmp
C:\pos25A6.tmp
C:\pos25A7.tmp
C:\pos25A8.tmp
C:\pos25A9.tmp
C:\pos25AA.tmp
C:\pos25AB.tmp
C:\pos25AC.tmp
C:\pos25AD.tmp
C:\pos25AE.tmp
C:\pos25AF.tmp
C:\pos25B.tmp
C:\pos25B0.tmp
C:\pos25B1.tmp
C:\pos25B2.tmp
C:\pos25B3.tmp
C:\pos25B4.tmp
C:\pos25B5.tmp
C:\pos25B6.tmp
C:\pos25B7.tmp
C:\pos25B8.tmp
C:\pos25B9.tmp
C:\pos25BA.tmp
C:\pos25BB.tmp
C:\pos25BC.tmp
C:\pos25BD.tmp
C:\pos25BE.tmp
C:\pos25BF.tmp
C:\pos25C.tmp
C:\pos25C0.tmp
C:\pos25C1.tmp
C:\pos25C2.tmp
C:\pos25C3.tmp
C:\pos25C4.tmp
C:\pos25C5.tmp
C:\pos25C6.tmp
C:\pos25C7.tmp
C:\pos25C8.tmp
C:\pos25C9.tmp
C:\pos25CA.tmp
C:\pos25CB.tmp
C:\pos25CC.tmp
C:\pos25CD.tmp
C:\pos25CE.tmp
C:\pos25CF.tmp
C:\pos25D.tmp
C:\pos25D0.tmp
C:\pos25D1.tmp
C:\pos25D2.tmp
C:\pos25D3.tmp
C:\pos25D4.tmp
C:\pos25D5.tmp
C:\pos25D6.tmp
C:\pos25D7.tmp
C:\pos25D8.tmp
C:\pos25D9.tmp
C:\pos25DA.tmp
C:\pos25DB.tmp
C:\pos25DC.tmp
C:\pos25DD.tmp
C:\pos25DE.tmp
C:\pos25DF.tmp
C:\pos25E.tmp
C:\pos25E0.tmp
C:\pos25E1.tmp
C:\pos25E2.tmp
C:\pos25E3.tmp
C:\pos25E4.tmp
C:\pos25E5.tmp
C:\pos25E6.tmp
C:\pos25E7.tmp
C:\pos25E8.tmp
C:\pos25E9.tmp
C:\pos25EA.tmp
C:\pos25EB.tmp
C:\pos25EC.tmp
C:\pos25ED.tmp
C:\pos25EE.tmp
C:\pos25EF.tmp
C:\pos25F.tmp
C:\pos25F0.tmp
C:\pos25F1.tmp
C:\pos25F2.tmp
C:\pos25F3.tmp
C:\pos25F4.tmp
C:\pos25F5.tmp
C:\pos25F6.tmp
C:\pos25F7.tmp
C:\pos25F8.tmp
C:\pos25F9.tmp
C:\pos25FA.tmp
C:\pos25FB.tmp
C:\pos25FC.tmp
C:\pos25FD.tmp
C:\pos25FE.tmp
C:\pos25FF.tmp
C:\pos26.tmp
C:\pos260.tmp
C:\pos2600.tmp
C:\pos2601.tmp
C:\pos2602.tmp
C:\pos2603.tmp
C:\pos2604.tmp
C:\pos2605.tmp
C:\pos2606.tmp
C:\pos2607.tmp
C:\pos2608.tmp
C:\pos2609.tmp
C:\pos260A.tmp
C:\pos260B.tmp
C:\pos260C.tmp
C:\pos260D.tmp
C:\pos260E.tmp
C:\pos260F.tmp
C:\pos261.tmp
C:\pos2610.tmp
C:\pos2611.tmp
C:\pos2612.tmp
C:\pos2613.tmp
C:\pos2614.tmp
C:\pos2615.tmp
C:\pos2616.tmp
C:\pos2617.tmp
C:\pos2618.tmp
C:\pos2619.tmp
C:\pos261A.tmp
C:\pos261B.tmp
C:\pos261C.tmp
C:\pos261D.tmp
C:\pos261E.tmp
C:\pos261F.tmp
C:\pos262.tmp
C:\pos2620.tmp
C:\pos2621.tmp
C:\pos2622.tmp
C:\pos2623.tmp
C:\pos2624.tmp
C:\pos2625.tmp
C:\pos2626.tmp
C:\pos2627.tmp
C:\pos2628.tmp
C:\pos2629.tmp
C:\pos262A.tmp
C:\pos262B.tmp
C:\pos262C.tmp
C:\pos262D.tmp
C:\pos262E.tmp
C:\pos262F.tmp
C:\pos263.tmp
C:\pos2630.tmp
C:\pos2631.tmp
C:\pos2632.tmp
C:\pos2633.tmp
C:\pos2634.tmp
C:\pos2635.tmp
C:\pos2636.tmp
C:\pos2637.tmp
C:\pos2638.tmp
C:\pos2639.tmp
C:\pos263A.tmp
C:\pos263B.tmp
C:\pos263C.tmp
C:\pos263D.tmp
C:\pos263E.tmp
C:\pos263F.tmp
C:\pos264.tmp
C:\pos2640.tmp
C:\pos2641.tmp
C:\pos2642.tmp
C:\pos2643.tmp
C:\pos2644.tmp
C:\pos2645.tmp
C:\pos2646.tmp
C:\pos2647.tmp
C:\pos2648.tmp
C:\pos2649.tmp
C:\pos264A.tmp
C:\pos264B.tmp
C:\pos264C.tmp
C:\pos264D.tmp
C:\pos264E.tmp
C:\pos264F.tmp
C:\pos265.tmp
C:\pos2650.tmp
C:\pos2651.tmp
C:\pos2652.tmp
C:\pos2653.tmp
C:\pos2654.tmp
C:\pos2655.tmp
C:\pos2656.tmp
C:\pos2657.tmp
C:\pos2658.tmp
C:\pos2659.tmp
C:\pos265A.tmp
C:\pos265B.tmp
C:\pos265C.tmp
C:\pos265D.tmp
C:\pos265E.tmp
C:\pos265F.tmp
C:\pos266.tmp
C:\pos2660.tmp
C:\pos2661.tmp
C:\pos2662.tmp
C:\pos2663.tmp
C:\pos2664.tmp
C:\pos2665.tmp
C:\pos2666.tmp
C:\pos2667.tmp
C:\pos2668.tmp
C:\pos2669.tmp
C:\pos266A.tmp
C:\pos266B.tmp
C:\pos266C.tmp
C:\pos266D.tmp
C:\pos266E.tmp
C:\pos266F.tmp
C:\pos267.tmp
C:\pos2670.tmp
C:\pos2671.tmp
C:\pos2672.tmp
C:\pos2673.tmp
C:\pos2674.tmp
C:\pos2675.tmp
C:\pos2676.tmp
C:\pos2677.tmp
C:\pos2678.tmp
C:\pos2679.tmp
C:\pos267A.tmp
C:\pos267B.tmp
C:\pos267C.tmp
C:\pos267D.tmp
C:\pos267E.tmp
C:\pos267F.tmp
C:\pos268.tmp
C:\pos2680.tmp
C:\pos2681.tmp
C:\pos2682.tmp
C:\pos2683.tmp
C:\pos2684.tmp
C:\pos2685.tmp
C:\pos2686.tmp
C:\pos2687.tmp
C:\pos2688.tmp
C:\pos2689.tmp
C:\pos268A.tmp
C:\pos268B.tmp
C:\pos268C.tmp
C:\pos268D.tmp
C:\pos268E.tmp
C:\pos268F.tmp
C:\pos269.tmp
C:\pos2690.tmp
C:\pos2691.tmp
C:\pos2692.tmp
C:\pos2693.tmp
C:\pos2694.tmp
C:\pos2695.tmp
C:\pos2696.tmp
C:\pos2697.tmp
C:\pos2698.tmp
C:\pos2699.tmp
C:\pos269A.tmp
C:\pos269B.tmp
C:\pos269C.tmp
C:\pos269D.tmp
C:\pos269E.tmp
C:\pos269F.tmp
C:\pos26A.tmp
C:\pos26A0.tmp
C:\pos26A1.tmp
C:\pos26A2.tmp
C:\pos26A3.tmp
C:\pos26A4.tmp
C:\pos26A5.tmp
C:\pos26A6.tmp
C:\pos26A7.tmp
C:\pos26A8.tmp
C:\pos26A9.tmp
C:\pos26AA.tmp
C:\pos26AB.tmp
C:\pos26AC.tmp
C:\pos26AD.tmp
C:\pos26AE.tmp
C:\pos26AF.tmp
C:\pos26B.tmp
C:\pos26B0.tmp
C:\pos26B1.tmp
C:\pos26B2.tmp
C:\pos26B3.tmp
C:\pos26B4.tmp
C:\pos26B5.tmp
C:\pos26B6.tmp
C:\pos26B7.tmp
C:\pos26B8.tmp
C:\pos26B9.tmp
C:\pos26BA.tmp
C:\pos26BB.tmp
C:\pos26BC.tmp
C:\pos26BD.tmp
C:\pos26BE.tmp
C:\pos26BF.tmp
C:\pos26C.tmp
C:\pos26C0.tmp
C:\pos26C1.tmp
C:\pos26C2.tmp
C:\pos26C3.tmp
C:\pos26C4.tmp
C:\pos26C5.tmp
C:\pos26C6.tmp
C:\pos26C7.tmp
C:\pos26C8.tmp
C:\pos26C9.tmp
C:\pos26CA.tmp
C:\pos26CB.tmp
C:\pos26CC.tmp
C:\pos26CD.tmp
C:\pos26CE.tmp
C:\pos26CF.tmp
C:\pos26D.tmp
C:\pos26D0.tmp
C:\pos26D1.tmp
C:\pos26D2.tmp
C:\pos26D3.tmp
C:\pos26D4.tmp
C:\pos26D5.tmp
C:\pos26D6.tmp
C:\pos26D7.tmp
C:\pos26D8.tmp
C:\pos26D9.tmp
C:\pos26DA.tmp
C:\pos26DB.tmp
C:\pos26DC.tmp
C:\pos26DD.tmp
C:\pos26DE.tmp
C:\pos26DF.tmp
C:\pos26E.tmp
C:\pos26E0.tmp
C:\pos26E1.tmp
C:\pos26E2.tmp
C:\pos26E3.tmp
C:\pos26E4.tmp
C:\pos26E5.tmp
C:\pos26E6.tmp
C:\pos26E7.tmp
C:\pos26E8.tmp
C:\pos26E9.tmp
C:\pos26F.tmp
C:\pos27.tmp
C:\pos270.tmp
C:\pos271.tmp
C:\pos272.tmp
C:\pos273.tmp
C:\pos274.tmp
C:\pos275.tmp
C:\pos276.tmp
C:\pos277.tmp
C:\pos278.tmp
C:\pos279.tmp
C:\pos27A.tmp
C:\pos27B.tmp
C:\pos27C.tmp
C:\pos27D.tmp
C:\pos27E.tmp
C:\pos27F.tmp
C:\pos28.tmp
C:\pos280.tmp
C:\pos281.tmp
C:\pos282.tmp
C:\pos283.tmp
C:\pos284.tmp
C:\pos285.tmp
C:\pos286.tmp
C:\pos287.tmp
C:\pos288.tmp
C:\pos289.tmp
C:\pos28A.tmp
C:\pos28B.tmp
C:\pos28C.tmp
C:\pos28D.tmp
C:\pos28E.tmp
C:\pos28F.tmp
C:\pos29.tmp
C:\pos290.tmp
C:\pos291.tmp
C:\pos292.tmp
C:\pos293.tmp
C:\pos294.tmp
C:\pos295.tmp
C:\pos296.tmp
C:\pos297.tmp
C:\pos298.tmp
C:\pos299.tmp
C:\pos29A.tmp
C:\pos29B.tmp
C:\pos29C.tmp
C:\pos29D.tmp
C:\pos29E.tmp
C:\pos29F.tmp
C:\pos2A.tmp
C:\pos2A0.tmp
C:\pos2A1.tmp
C:\pos2A2.tmp
C:\pos2A3.tmp
C:\pos2A4.tmp
C:\pos2A5.tmp
C:\pos2A6.tmp
C:\pos2A7.tmp
C:\pos2A8.tmp
C:\pos2A9.tmp
C:\pos2AA.tmp
C:\pos2AB.tmp
C:\pos2AC.tmp
C:\pos2AD.tmp
C:\pos2AE.tmp
C:\pos2AF.tmp
C:\pos2B.tmp
C:\pos2B0.tmp
C:\pos2B1.tmp
C:\pos2B2.tmp
C:\pos2B3.tmp
C:\pos2B4.tmp
C:\pos2B5.tmp
C:\pos2B6.tmp
C:\pos2B7.tmp
C:\pos2B8.tmp
C:\pos2B9.tmp
C:\pos2BA.tmp
C:\pos2BB.tmp
C:\pos2BC.tmp
C:\pos2BD.tmp
C:\pos2BE.tmp
C:\pos2BF.tmp
C:\pos2C.tmp
C:\pos2C0.tmp
C:\pos2C1.tmp
C:\pos2C2.tmp
C:\pos2C3.tmp
C:\pos2C4.tmp
C:\pos2C5.tmp
C:\pos2C6.tmp
C:\pos2C7.tmp
C:\pos2C8.tmp
C:\pos2C9.tmp
C:\pos2CA.tmp
C:\pos2CB.tmp
C:\pos2CC.tmp
C:\pos2CD.tmp
C:\pos2CE.tmp
C:\pos2CF.tmp
C:\pos2D.tmp
C:\pos2D0.tmp
C:\pos2D1.tmp
C:\pos2D2.tmp
C:\pos2D3.tmp
C:\pos2D4.tmp
C:\pos2D5.tmp
C:\pos2D6.tmp
C:\pos2D7.tmp
C:\pos2D8.tmp
C:\pos2D9.tmp
C:\pos2DA.tmp
C:\pos2DB.tmp
C:\pos2DC.tmp
C:\pos2DD.tmp
C:\pos2DE.tmp
C:\pos2DF.tmp
C:\pos2E.tmp
C:\pos2E0.tmp
C:\pos2E1.tmp
C:\pos2E2.tmp
C:\pos2E3.tmp
C:\pos2E4.tmp
C:\pos2E5.tmp
C:\pos2E6.tmp
C:\pos2E7.tmp
C:\pos2E8.tmp
C:\pos2E9.tmp
C:\pos2EA.tmp
C:\pos2EB.tmp
C:\pos2EC.tmp
C:\pos2ED.tmp
C:\pos2EE.tmp
C:\pos2EF.tmp
C:\pos2F.tmp
C:\pos2F0.tmp
C:\pos2F1.tmp
C:\pos2F2.tmp
C:\pos2F3.tmp
C:\pos2F4.tmp
C:\pos2F5.tmp
C:\pos2F6.tmp
C:\pos2F7.tmp
C:\pos2F8.tmp
C:\pos2F9.tmp
C:\pos2FA.tmp
C:\pos2FB.tmp
C:\pos2FC.tmp
C:\pos2FD.tmp
C:\pos2FE.tmp
C:\pos2FF.tmp
C:\pos3.tmp
C:\pos30.tmp
C:\pos300.tmp
C:\pos301.tmp
C:\pos302.tmp
C:\pos303.tmp
C:\pos304.tmp
C:\pos305.tmp
C:\pos306.tmp
C:\pos307.tmp
C:\pos308.tmp
C:\pos309.tmp
C:\pos30A.tmp
C:\pos30B.tmp
C:\pos30C.tmp
C:\pos30D.tmp
C:\pos30E.tmp
C:\pos30F.tmp
C:\pos31.tmp
C:\pos310.tmp
C:\pos311.tmp
C:\pos312.tmp
C:\pos313.tmp
C:\pos314.tmp
C:\pos315.tmp
C:\pos316.tmp
C:\pos317.tmp
C:\pos318.tmp
C:\pos319.tmp
C:\pos31A.tmp
C:\pos31B.tmp
C:\pos31C.tmp
C:\pos31D.tmp
C:\pos31E.tmp
C:\pos31F.tmp
C:\pos32.tmp
C:\pos320.tmp
C:\pos321.tmp
C:\pos322.tmp
C:\pos323.tmp
C:\pos324.tmp
C:\pos325.tmp
C:\pos326.tmp
C:\pos327.tmp
C:\pos328.tmp
C:\pos329.tmp
C:\pos32A.tmp
C:\pos32B.tmp
C:\pos32C.tmp
C:\pos32D.tmp
C:\pos32E.tmp
C:\pos32F.tmp
C:\pos33.tmp
C:\pos330.tmp
C:\pos331.tmp
C:\pos332.tmp
C:\pos333.tmp
C:\pos334.tmp
C:\pos335.tmp
C:\pos336.tmp
C:\pos337.tmp
C:\pos338.tmp
C:\pos339.tmp
C:\pos33A.tmp
C:\pos33B.tmp
C:\pos33C.tmp
C:\pos33D.tmp
C:\pos33E.tmp
C:\pos33F.tmp
C:\pos34.tmp
C:\pos340.tmp
C:\pos341.tmp
C:\pos342.tmp
C:\pos343.tmp
C:\pos344.tmp
C:\pos345.tmp
C:\pos346.tmp
C:\pos347.tmp
C:\pos348.tmp
C:\pos349.tmp
C:\pos34A.tmp
C:\pos34B.tmp
C:\pos34C.tmp
C:\pos34D.tmp
C:\pos34E.tmp
C:\pos34F.tmp
C:\pos35.tmp
C:\pos350.tmp
C:\pos351.tmp
C:\pos352.tmp
C:\pos353.tmp
C:\pos354.tmp
C:\pos355.tmp
C:\pos356.tmp
C:\pos357.tmp
C:\pos358.tmp
C:\pos359.tmp
C:\pos35A.tmp
C:\pos35B.tmp
C:\pos35C.tmp
C:\pos35D.tmp
C:\pos35E.tmp
C:\pos35F.tmp
C:\pos36.tmp
C:\pos360.tmp
C:\pos361.tmp
C:\pos362.tmp
C:\pos363.tmp
C:\pos364.tmp
C:\pos365.tmp
C:\pos366.tmp
C:\pos367.tmp
C:\pos368.tmp
C:\pos369.tmp
C:\pos36A.tmp
C:\pos36B.tmp
C:\pos36C.tmp
C:\pos36D.tmp
C:\pos36E.tmp
C:\pos36F.tmp
C:\pos37.tmp
C:\pos370.tmp
C:\pos371.tmp
C:\pos372.tmp
C:\pos373.tmp
C:\pos374.tmp
C:\pos375.tmp
C:\pos376.tmp
C:\pos377.tmp
C:\pos378.tmp
C:\pos379.tmp
C:\pos37A.tmp
C:\pos37B.tmp
C:\pos37C.tmp
C:\pos37D.tmp
C:\pos37E.tmp
C:\pos37F.tmp
C:\pos38.tmp
C:\pos380.tmp
C:\pos381.tmp
C:\pos382.tmp
C:\pos383.tmp
C:\pos384.tmp
C:\pos385.tmp
C:\pos386.tmp
C:\pos387.tmp
C:\pos388.tmp
C:\pos389.tmp
C:\pos38A.tmp
C:\pos38B.tmp
C:\pos38C.tmp
C:\pos38D.tmp
C:\pos38E.tmp
C:\pos38F.tmp
C:\pos39.tmp
C:\pos390.tmp
C:\pos391.tmp
C:\pos392.tmp
C:\pos393.tmp
C:\pos394.tmp
C:\pos395.tmp
C:\pos396.tmp
C:\pos397.tmp
C:\pos398.tmp
C:\pos399.tmp
C:\pos39A.tmp
C:\pos39B.tmp
C:\pos39C.tmp
C:\pos39D.tmp
C:\pos39E.tmp
C:\pos39F.tmp
C:\pos3A.tmp
C:\pos3A0.tmp
C:\pos3A1.tmp
C:\pos3A2.tmp
C:\pos3A3.tmp
C:\pos3A4.tmp
C:\pos3A5.tmp
C:\pos3A6.tmp
C:\pos3A7.tmp
C:\pos3A8.tmp
C:\pos3A9.tmp
C:\pos3AA.tmp
C:\pos3AB.tmp
C:\pos3AC.tmp
C:\pos3AD.tmp
C:\pos3AE.tmp
C:\pos3AF.tmp
C:\pos3B.tmp
C:\pos3B0.tmp
C:\pos3B1.tmp
C:\pos3B2.tmp
C:\pos3B3.tmp
C:\pos3B4.tmp
C:\pos3B5.tmp
C:\pos3B6.tmp
C:\pos3B7.tmp
C:\pos3B8.tmp
C:\pos3B9.tmp
C:\pos3BA.tmp
C:\pos3BB.tmp
C:\pos3BC.tmp
C:\pos3BD.tmp
C:\pos3BE.tmp
C:\pos3BF.tmp
C:\pos3C.tmp
C:\pos3C0.tmp
C:\pos3C1.tmp
C:\pos3C2.tmp
C:\pos3C3.tmp
C:\pos3C4.tmp
C:\pos3C5.tmp
C:\pos3C6.tmp
C:\pos3C7.tmp
C:\pos3C8.tmp
C:\pos3C9.tmp
C:\pos3CA.tmp
C:\pos3CB.tmp
C:\pos3CC.tmp
C:\pos3CD.tmp
C:\pos3CE.tmp
C:\pos3CF.tmp
C:\pos3D.tmp
C:\pos3D0.tmp
C:\pos3D1.tmp
C:\pos3D2.tmp
C:\pos3D3.tmp
C:\pos3D4.tmp
C:\pos3D5.tmp
C:\pos3D6.tmp
C:\pos3D7.tmp
C:\pos3D8.tmp
C:\pos3D9.tmp
C:\pos3DA.tmp
C:\pos3DB.tmp
C:\pos3DC.tmp
C:\pos3DD.tmp
C:\pos3DE.tmp
C:\pos3DF.tmp
C:\pos3E.tmp
C:\pos3E0.tmp
C:\pos3E1.tmp
C:\pos3E2.tmp
C:\pos3E3.tmp
C:\pos3E4.tmp
C:\pos3E5.tmp
C:\pos3E6.tmp
C:\pos3E7.tmp
C:\pos3E8.tmp
C:\pos3E9.tmp
C:\pos3EA.tmp
C:\pos3EB.tmp
C:\pos3EC.tmp
C:\pos3ED.tmp
C:\pos3EE.tmp
C:\pos3EF.tmp
C:\pos3F.tmp
C:\pos3F0.tmp
C:\pos3F1.tmp
C:\pos3F2.tmp
C:\pos3F3.tmp
C:\pos3F4.tmp
C:\pos3F5.tmp
C:\pos3F6.tmp
C:\pos3F7.tmp
C:\pos3F8.tmp
C:\pos3F9.tmp
C:\pos3FA.tmp
C:\pos3FB.tmp
C:\pos3FC.tmp
C:\pos3FD.tmp
C:\pos3FE.tmp
C:\pos3FF.tmp
C:\pos4.tmp
C:\pos40.tmp
C:\pos400.tmp
C:\pos401.tmp
C:\pos402.tmp
C:\pos403.tmp
C:\pos404.tmp
C:\pos405.tmp
C:\pos406.tmp
C:\pos407.tmp
C:\pos408.tmp
C:\pos409.tmp
C:\pos40A.tmp
C:\pos40B.tmp
C:\pos40C.tmp
C:\pos40D.tmp
C:\pos40E.tmp
C:\pos40F.tmp
C:\pos41.tmp
C:\pos410.tmp
C:\pos411.tmp
C:\pos412.tmp
C:\pos413.tmp
C:\pos414.tmp
C:\pos415.tmp
C:\pos416.tmp
C:\pos417.tmp
C:\pos418.tmp
C:\pos419.tmp
C:\pos41A.tmp
C:\pos41B.tmp
C:\pos41C.tmp
C:\pos41D.tmp
C:\pos41E.tmp
C:\pos41F.tmp
C:\pos42.tmp
C:\pos420.tmp
C:\pos421.tmp
C:\pos422.tmp
C:\pos423.tmp
C:\pos424.tmp
C:\pos425.tmp
C:\pos426.tmp
C:\pos427.tmp
C:\pos428.tmp
C:\pos429.tmp
C:\pos42A.tmp
C:\pos42B.tmp
C:\pos42C.tmp
C:\pos42D.tmp
C:\pos42E.tmp
C:\pos42F.tmp
C:\pos43.tmp
C:\pos430.tmp
C:\pos431.tmp
C:\pos432.tmp
C:\pos433.tmp
C:\pos434.tmp
C:\pos435.tmp
C:\pos436.tmp
C:\pos437.tmp
C:\pos438.tmp
C:\pos439.tmp
C:\pos43A.tmp
C:\pos43B.tmp
C:\pos43C.tmp
C:\pos43D.tmp
C:\pos43E.tmp
C:\pos43F.tmp
C:\pos44.tmp
C:\pos440.tmp
C:\pos441.tmp
C:\pos442.tmp
C:\pos443.tmp
C:\pos444.tmp
C:\pos445.tmp
C:\pos446.tmp
C:\pos447.tmp
C:\pos448.tmp
C:\pos449.tmp
C:\pos44A.tmp
C:\pos44B.tmp
C:\pos44C.tmp
C:\pos44D.tmp
C:\pos44E.tmp
C:\pos44F.tmp
C:\pos45.tmp
C:\pos450.tmp
C:\pos451.tmp
C:\pos452.tmp
C:\pos453.tmp
C:\pos454.tmp
C:\pos455.tmp
C:\pos456.tmp
C:\pos457.tmp
C:\pos458.tmp
C:\pos459.tmp
C:\pos45A.tmp
C:\pos45B.tmp
C:\pos45C.tmp
C:\pos45D.tmp
C:\pos45E.tmp
C:\pos45F.tmp
C:\pos46.tmp
C:\pos460.tmp
C:\pos461.tmp
C:\pos462.tmp
C:\pos463.tmp
C:\pos464.tmp
C:\pos465.tmp
C:\pos466.tmp
C:\pos467.tmp
C:\pos468.tmp
C:\pos469.tmp
C:\pos46A.tmp
C:\pos46B.tmp
C:\pos46C.tmp
C:\pos46D.tmp
C:\pos46E.tmp
C:\pos46F.tmp
C:\pos47.tmp
C:\pos470.tmp
C:\pos471.tmp
C:\pos472.tmp
C:\pos473.tmp
C:\pos474.tmp
C:\pos475.tmp
C:\pos476.tmp
C:\pos477.tmp
C:\pos478.tmp
C:\pos479.tmp
C:\pos47A.tmp
C:\pos47B.tmp
C:\pos47C.tmp
C:\pos47D.tmp
C:\pos47E.tmp
C:\pos47F.tmp
C:\pos48.tmp
C:\pos480.tmp
C:\pos481.tmp
C:\pos482.tmp
C:\pos483.tmp
C:\pos484.tmp
C:\pos485.tmp
C:\pos486.tmp
C:\pos487.tmp
C:\pos488.tmp
C:\pos489.tmp
C:\pos48A.tmp
C:\pos48B.tmp
C:\pos48C.tmp
C:\pos48D.tmp
C:\pos48E.tmp
C:\pos48F.tmp
C:\pos49.tmp
C:\pos490.tmp
C:\pos491.tmp
C:\pos492.tmp
C:\pos493.tmp
C:\pos494.tmp
C:\pos495.tmp
C:\pos496.tmp
C:\pos497.tmp
C:\pos498.tmp
C:\pos499.tmp
C:\pos49A.tmp
C:\pos49B.tmp
C:\pos49C.tmp
C:\pos49D.tmp
C:\pos49E.tmp
C:\pos49F.tmp
C:\pos4A.tmp
C:\pos4A0.tmp
C:\pos4A1.tmp
C:\pos4A2.tmp
C:\pos4A3.tmp
C:\pos4A4.tmp
C:\pos4A5.tmp
C:\pos4A6.tmp
C:\pos4A7.tmp
C:\pos4A8.tmp
C:\pos4A9.tmp
C:\pos4AA.tmp
C:\pos4AB.tmp
C:\pos4AC.tmp
C:\pos4AD.tmp
C:\pos4AE.tmp
C:\pos4AF.tmp
C:\pos4B.tmp
C:\pos4B0.tmp
C:\pos4B1.tmp
C:\pos4B2.tmp
C:\pos4B3.tmp
C:\pos4B4.tmp
C:\pos4B5.tmp
C:\pos4B6.tmp
C:\pos4B7.tmp
C:\pos4B8.tmp
C:\pos4B9.tmp
C:\pos4BA.tmp
C:\pos4BB.tmp
C:\pos4BC.tmp
C:\pos4BD.tmp
C:\pos4BE.tmp
C:\pos4BF.tmp
C:\pos4C.tmp
C:\pos4C0.tmp
C:\pos4C1.tmp
C:\pos4C2.tmp
C:\pos4C3.tmp
C:\pos4C4.tmp
C:\pos4C5.tmp
C:\pos4C6.tmp
C:\pos4C7.tmp
C:\pos4C8.tmp
C:\pos4C9.tmp
C:\pos4CA.tmp
C:\pos4CB.tmp
C:\pos4CC.tmp
C:\pos4CD.tmp
C:\pos4CE.tmp
C:\pos4CF.tmp
C:\pos4D.tmp
C:\pos4D0.tmp
C:\pos4D1.tmp
C:\pos4D2.tmp
C:\pos4D3.tmp
C:\pos4D4.tmp
C:\pos4D5.tmp
C:\pos4D6.tmp
C:\pos4D7.tmp
C:\pos4D8.tmp
C:\pos4D9.tmp
C:\pos4DA.tmp
C:\pos4DB.tmp
C:\pos4DC.tmp
C:\pos4DD.tmp
C:\pos4DE.tmp
C:\pos4DF.tmp
C:\pos4E.tmp
C:\pos4E0.tmp
C:\pos4E1.tmp
C:\pos4E2.tmp
C:\pos4E3.tmp
C:\pos4E4.tmp
C:\pos4E5.tmp
C:\pos4E6.tmp
C:\pos4E7.tmp
C:\pos4E8.tmp
C:\pos4E9.tmp
C:\pos4EA.tmp
C:\pos4EB.tmp
C:\pos4EC.tmp
C:\pos4ED.tmp
C:\pos4EE.tmp
C:\pos4EF.tmp
C:\pos4F.tmp
C:\pos4F0.tmp
C:\pos4F1.tmp
C:\pos4F2.tmp
C:\pos4F3.tmp
C:\pos4F4.tmp
C:\pos4F5.tmp
C:\pos4F6.tmp
C:\pos4F7.tmp
C:\pos4F8.tmp
C:\pos4F9.tmp
C:\pos4FA.tmp
C:\pos4FB.tmp
C:\pos4FC.tmp
C:\pos4FD.tmp
C:\pos4FE.tmp
C:\pos4FF.tmp
C:\pos5.tmp
C:\pos50.tmp
C:\pos500.tmp
C:\pos501.tmp
C:\pos502.tmp
C:\pos503.tmp
C:\pos504.tmp
C:\pos505.tmp
C:\pos506.tmp
C:\pos507.tmp
C:\pos508.tmp
C:\pos509.tmp
C:\pos50A.tmp
C:\pos50B.tmp
C:\pos50C.tmp
C:\pos50D.tmp
C:\pos50E.tmp
C:\pos50F.tmp
C:\pos51.tmp
C:\pos510.tmp
C:\pos511.tmp
C:\pos512.tmp
C:\pos513.tmp
C:\pos514.tmp
C:\pos515.tmp
C:\pos516.tmp
C:\pos517.tmp
C:\pos518.tmp
C:\pos519.tmp
C:\pos51A.tmp
C:\pos51B.tmp
C:\pos51C.tmp
C:\pos51D.tmp
C:\pos51E.tmp
C:\pos51F.tmp
C:\pos52.tmp
C:\pos520.tmp
C:\pos521.tmp
C:\pos522.tmp
C:\pos523.tmp
C:\pos524.tmp
C:\pos525.tmp
C:\pos526.tmp
C:\pos527.tmp
C:\pos528.tmp
C:\pos529.tmp
C:\pos52A.tmp
C:\pos52B.tmp
C:\pos52C.tmp
C:\pos52D.tmp
C:\pos52E.tmp
C:\pos52F.tmp
C:\pos53.tmp
C:\pos530.tmp
C:\pos531.tmp
C:\pos532.tmp
C:\pos533.tmp
C:\pos534.tmp
C:\pos535.tmp
C:\pos536.tmp
C:\pos537.tmp
C:\pos538.tmp
C:\pos539.tmp
C:\pos53A.tmp
C:\pos53B.tmp
C:\pos53C.tmp
C:\pos53D.tmp
C:\pos53E.tmp
C:\pos53F.tmp
C:\pos54.tmp
C:\pos540.tmp
C:\pos541.tmp
C:\pos542.tmp
C:\pos543.tmp
C:\pos544.tmp
C:\pos545.tmp
C:\pos546.tmp
C:\pos547.tmp
C:\pos548.tmp
C:\pos549.tmp
C:\pos54A.tmp
C:\pos54B.tmp
C:\pos54C.tmp
C:\pos54D.tmp
C:\pos54E.tmp
C:\pos54F.tmp
C:\pos55.tmp
C:\pos550.tmp
C:\pos551.tmp
C:\pos552.tmp
C:\pos553.tmp
C:\pos554.tmp
C:\pos555.tmp
C:\pos556.tmp
C:\pos557.tmp
C:\pos558.tmp
C:\pos559.tmp
C:\pos55A.tmp
C:\pos55B.tmp
C:\pos55C.tmp
C:\pos55D.tmp
C:\pos55E.tmp
C:\pos55F.tmp
C:\pos56.tmp
C:\pos560.tmp
C:\pos561.tmp
C:\pos562.tmp
C:\pos563.tmp
C:\pos564.tmp
C:\pos565.tmp
C:\pos566.tmp
C:\pos567.tmp
C:\pos568.tmp
C:\pos569.tmp
C:\pos56A.tmp
C:\pos56B.tmp
C:\pos56C.tmp
C:\pos56D.tmp
C:\pos56E.tmp
C:\pos56F.tmp
C:\pos57.tmp
C:\pos570.tmp
C:\pos571.tmp
C:\pos572.tmp
C:\pos573.tmp
C:\pos574.tmp
C:\pos575.tmp
C:\pos576.tmp
C:\pos577.tmp
C:\pos578.tmp
C:\pos579.tmp
C:\pos57A.tmp
C:\pos57B.tmp
C:\pos57C.tmp
C:\pos57D.tmp
C:\pos57E.tmp
C:\pos57F.tmp
C:\pos58.tmp
C:\pos580.tmp
C:\pos581.tmp
C:\pos582.tmp
C:\pos583.tmp
C:\pos584.tmp
C:\pos585.tmp
C:\pos586.tmp
C:\pos587.tmp
C:\pos588.tmp
C:\pos589.tmp
C:\pos58A.tmp
C:\pos58B.tmp
C:\pos58C.tmp
C:\pos58D.tmp
C:\pos58E.tmp
C:\pos58F.tmp
C:\pos59.tmp
C:\pos590.tmp
C:\pos591.tmp
C:\pos592.tmp
C:\pos593.tmp
C:\pos594.tmp
C:\pos595.tmp
C:\pos596.tmp
C:\pos597.tmp
C:\pos598.tmp
C:\pos599.tmp
C:\pos59A.tmp
C:\pos59B.tmp
C:\pos59C.tmp
C:\pos59D.tmp
C:\pos59E.tmp
C:\pos59F.tmp
C:\pos5A.tmp
C:\pos5A0.tmp
C:\pos5A1.tmp
C:\pos5A2.tmp
C:\pos5A3.tmp
C:\pos5A4.tmp
C:\pos5A5.tmp
C:\pos5A6.tmp
C:\pos5A7.tmp
C:\pos5A8.tmp
C:\pos5A9.tmp
C:\pos5AA.tmp
C:\pos5AB.tmp
C:\pos5AC.tmp
C:\pos5AD.tmp
C:\pos5AE.tmp
C:\pos5AF.tmp
C:\pos5B.tmp
C:\pos5B0.tmp
C:\pos5B1.tmp
C:\pos5B2.tmp
C:\pos5B3.tmp
C:\pos5B4.tmp
C:\pos5B5.tmp
C:\pos5B6.tmp
C:\pos5B7.tmp
C:\pos5B8.tmp
C:\pos5B9.tmp
C:\pos5BA.tmp
C:\pos5BB.tmp
C:\pos5BC.tmp
C:\pos5BD.tmp
C:\pos5BE.tmp
C:\pos5BF.tmp
C:\pos5C.tmp
C:\pos5C0.tmp
C:\pos5C1.tmp
C:\pos5C2.tmp
C:\pos5C3.tmp
C:\pos5C4.tmp
C:\pos5C5.tmp
C:\pos5C6.tmp
C:\pos5C7.tmp
C:\pos5C8.tmp
C:\pos5C9.tmp
C:\pos5CA.tmp
C:\pos5CB.tmp
C:\pos5CC.tmp
C:\pos5CD.tmp
C:\pos5CE.tmp
C:\pos5CF.tmp
C:\pos5D.tmp
C:\pos5D0.tmp
C:\pos5D1.tmp
C:\pos5D2.tmp
C:\pos5D3.tmp
C:\pos5D4.tmp
C:\pos5D5.tmp
C:\pos5D6.tmp
C:\pos5D7.tmp
C:\pos5D8.tmp
C:\pos5D9.tmp
C:\pos5DA.tmp
C:\pos5DB.tmp
C:\pos5DC.tmp
C:\pos5DD.tmp
C:\pos5DE.tmp
C:\pos5E.tmp
C:\pos5F.tmp
C:\pos6.tmp
C:\pos60.tmp
C:\pos61.tmp
C:\pos62.tmp
C:\pos63.tmp
C:\pos64.tmp
C:\pos65.tmp
C:\pos66.tmp
C:\pos67.tmp
C:\pos68.tmp
C:\pos69.tmp
C:\pos6A.tmp
C:\pos6B.tmp
C:\pos6C.tmp
C:\pos6D.tmp
C:\pos6E.tmp
C:\pos6F.tmp
C:\pos7.tmp
C:\pos70.tmp
C:\pos71.tmp
C:\pos72.tmp
C:\pos73.tmp
C:\pos74.tmp
C:\pos75.tmp
C:\pos76.tmp
C:\pos77.tmp
C:\pos77B.tmp
C:\pos77C.tmp
C:\pos77D.tmp
C:\pos77E.tmp
C:\pos77F.tmp
C:\pos78.tmp
C:\pos780.tmp
C:\pos781.tmp
C:\pos782.tmp
C:\pos783.tmp
C:\pos784.tmp
C:\pos785.tmp
C:\pos786.tmp
C:\pos787.tmp
C:\pos788.tmp
C:\pos789.tmp
C:\pos78A.tmp
C:\pos78B.tmp
C:\pos78C.tmp
C:\pos78D.tmp
C:\pos78E.tmp
C:\pos78F.tmp
C:\pos79.tmp
C:\pos790.tmp
C:\pos791.tmp
C:\pos792.tmp
C:\pos793.tmp
C:\pos794.tmp
C:\pos795.tmp
C:\pos796.tmp
C:\pos797.tmp
C:\pos798.tmp
C:\pos799.tmp
C:\pos79A.tmp
C:\pos79B.tmp
C:\pos79C.tmp
C:\pos79D.tmp
C:\pos79E.tmp
C:\pos79F.tmp
C:\pos7A.tmp
C:\pos7A0.tmp
C:\pos7A1.tmp
C:\pos7A2.tmp
C:\pos7A3.tmp
C:\pos7A4.tmp
C:\pos7A5.tmp
C:\pos7A6.tmp
C:\pos7A7.tmp
C:\pos7A8.tmp
C:\pos7A9.tmp
C:\pos7AA.tmp
C:\pos7AB.tmp
C:\pos7AC.tmp
C:\pos7AD.tmp
C:\pos7AE.tmp
C:\pos7AF.tmp
C:\pos7B.tmp
C:\pos7B0.tmp
C:\pos7B1.tmp
C:\pos7B2.tmp
C:\pos7B3.tmp
C:\pos7B4.tmp
C:\pos7B5.tmp
C:\pos7B6.tmp
C:\pos7B7.tmp
C:\pos7B8.tmp
C:\pos7B9.tmp
C:\pos7BA.tmp
C:\pos7BB.tmp
C:\pos7BC.tmp
C:\pos7BD.tmp
C:\pos7BE.tmp
C:\pos7BF.tmp
C:\pos7C.tmp
C:\pos7C0.tmp
C:\pos7C1.tmp
C:\pos7C2.tmp
C:\pos7C3.tmp
C:\pos7C4.tmp
C:\pos7C5.tmp
C:\pos7C6.tmp
C:\pos7C7.tmp
C:\pos7C8.tmp
C:\pos7C9.tmp
C:\pos7CA.tmp
C:\pos7CB.tmp
C:\pos7CC.tmp
C:\pos7CD.tmp
C:\pos7CE.tmp
C:\pos7CF.tmp
C:\pos7D.tmp
C:\pos7D0.tmp
C:\pos7D1.tmp
C:\pos7D2.tmp
C:\pos7D3.tmp
C:\pos7D4.tmp
C:\pos7D5.tmp
C:\pos7D6.tmp
C:\pos7D7.tmp
C:\pos7D8.tmp
C:\pos7D9.tmp
C:\pos7DA.tmp
C:\pos7DB.tmp
C:\pos7DC.tmp
C:\pos7DD.tmp
C:\pos7DE.tmp
C:\pos7DF.tmp
C:\pos7E.tmp
C:\pos7E0.tmp
C:\pos7E1.tmp
C:\pos7E2.tmp
C:\pos7E3.tmp
C:\pos7E4.tmp
C:\pos7E5.tmp
C:\pos7E6.tmp
C:\pos7E7.tmp
C:\pos7E8.tmp
C:\pos7E9.tmp
C:\pos7EA.tmp
C:\pos7EB.tmp
C:\pos7EC.tmp
C:\pos7ED.tmp
C:\pos7EE.tmp
C:\pos7EF.tmp
C:\pos7F.tmp
C:\pos7F0.tmp
C:\pos7F1.tmp
C:\pos7F2.tmp
C:\pos7F3.tmp
C:\pos7F4.tmp
C:\pos7F5.tmp
C:\pos7F6.tmp
C:\pos7F7.tmp
C:\pos7F8.tmp
C:\pos7F9.tmp
C:\pos7FA.tmp
C:\pos7FB.tmp
C:\pos7FC.tmp
C:\pos7FD.tmp
C:\pos7FE.tmp
C:\pos7FF.tmp
C:\pos8.tmp
C:\pos80.tmp
C:\pos800.tmp
C:\pos801.tmp
C:\pos802.tmp
C:\pos803.tmp
C:\pos804.tmp
C:\pos805.tmp
C:\pos806.tmp
C:\pos807.tmp
C:\pos808.tmp
C:\pos809.tmp
C:\pos80A.tmp
C:\pos80B.tmp
C:\pos80C.tmp
C:\pos80D.tmp
C:\pos80E.tmp
C:\pos80F.tmp
C:\pos81.tmp
C:\pos810.tmp
C:\pos811.tmp
C:\pos812.tmp
C:\pos813.tmp
C:\pos814.tmp
C:\pos815.tmp
C:\pos816.tmp
C:\pos817.tmp
C:\pos818.tmp
C:\pos819.tmp
C:\pos81A.tmp
C:\pos81B.tmp
C:\pos81C.tmp
C:\pos81D.tmp
C:\pos81E.tmp
C:\pos81F.tmp
C:\pos82.tmp
C:\pos820.tmp
C:\pos821.tmp
C:\pos822.tmp
C:\pos823.tmp
C:\pos824.tmp
C:\pos825.tmp
C:\pos826.tmp
C:\pos827.tmp
C:\pos828.tmp
C:\pos829.tmp
C:\pos82A.tmp
C:\pos82B.tmp
C:\pos82C.tmp
C:\pos82D.tmp
C:\pos82E.tmp
C:\pos82F.tmp
C:\pos83.tmp
C:\pos830.tmp
C:\pos831.tmp
C:\pos832.tmp
C:\pos833.tmp
C:\pos834.tmp
C:\pos835.tmp
C:\pos836.tmp
C:\pos837.tmp
C:\pos838.tmp
C:\pos839.tmp
C:\pos83A.tmp
C:\pos83B.tmp
C:\pos83C.tmp
C:\pos83D.tmp
C:\pos83E.tmp
C:\pos83F.tmp
C:\pos84.tmp
C:\pos840.tmp
C:\pos841.tmp
C:\pos842.tmp
C:\pos843.tmp
C:\pos844.tmp
C:\pos845.tmp
C:\pos846.tmp
C:\pos847.tmp
C:\pos848.tmp
C:\pos849.tmp
C:\pos84A.tmp
C:\pos84B.tmp
C:\pos84C.tmp
C:\pos84D.tmp
C:\pos84E.tmp
C:\pos84F.tmp
C:\pos85.tmp
C:\pos850.tmp
C:\pos851.tmp
C:\pos852.tmp
C:\pos853.tmp
C:\pos854.tmp
C:\pos855.tmp
C:\pos856.tmp
C:\pos857.tmp
C:\pos858.tmp
C:\pos859.tmp
C:\pos85A.tmp
C:\pos85B.tmp
C:\pos85C.tmp
C:\pos85D.tmp
C:\pos85E.tmp
C:\pos85F.tmp
C:\pos86.tmp
C:\pos860.tmp
C:\pos861.tmp
C:\pos862.tmp
C:\pos863.tmp
C:\pos864.tmp
C:\pos865.tmp
C:\pos866.tmp
C:\pos867.tmp
C:\pos868.tmp
C:\pos869.tmp
C:\pos86A.tmp
C:\pos86B.tmp
C:\pos86C.tmp
C:\pos86D.tmp
C:\pos86E.tmp
C:\pos86F.tmp
C:\pos87.tmp
C:\pos870.tmp
C:\pos871.tmp
C:\pos872.tmp
C:\pos873.tmp
C:\pos874.tmp
C:\pos875.tmp
C:\pos876.tmp
C:\pos877.tmp
C:\pos878.tmp
C:\pos879.tmp
C:\pos87A.tmp
C:\pos87B.tmp
C:\pos87C.tmp
C:\pos87D.tmp
C:\pos87E.tmp
C:\pos87F.tmp
C:\pos88.tmp
C:\pos880.tmp
C:\pos881.tmp
C:\pos882.tmp
C:\pos883.tmp
C:\pos884.tmp
C:\pos885.tmp
C:\pos886.tmp
C:\pos887.tmp
C:\pos888.tmp
C:\pos889.tmp
C:\pos88A.tmp
C:\pos88B.tmp
C:\pos88C.tmp
C:\pos88D.tmp
C:\pos88E.tmp
C:\pos88F.tmp
C:\pos89.tmp
C:\pos890.tmp
C:\pos891.tmp
C:\pos892.tmp
C:\pos893.tmp
C:\pos894.tmp
C:\pos895.tmp
C:\pos896.tmp
C:\pos897.tmp
C:\pos898.tmp
C:\pos899.tmp
C:\pos89A.tmp
C:\pos89B.tmp
C:\pos89C.tmp
C:\pos89D.tmp
C:\pos89E.tmp
C:\pos89F.tmp
C:\pos8A.tmp
C:\pos8A0.tmp
C:\pos8A1.tmp
C:\pos8A2.tmp
C:\pos8A3.tmp
C:\pos8A4.tmp
C:\pos8A5.tmp
C:\pos8A6.tmp
C:\pos8A7.tmp
C:\pos8A8.tmp
C:\pos8A9.tmp
C:\pos8AA.tmp
C:\pos8AB.tmp
C:\pos8AC.tmp
C:\pos8AD.tmp
C:\pos8AE.tmp
C:\pos8AF.tmp
C:\pos8B.tmp
C:\pos8B0.tmp
C:\pos8B1.tmp
C:\pos8B2.tmp
C:\pos8B3.tmp
C:\pos8B4.tmp
C:\pos8B5.tmp
C:\pos8B6.tmp
C:\pos8B7.tmp
C:\pos8B8.tmp
C:\pos8B9.tmp
C:\pos8BA.tmp
C:\pos8BB.tmp
C:\pos8BC.tmp
C:\pos8BD.tmp
C:\pos8BE.tmp
C:\pos8BF.tmp
C:\pos8C.tmp
C:\pos8C0.tmp
C:\pos8C1.tmp
C:\pos8C2.tmp
C:\pos8C3.tmp
C:\pos8C4.tmp
C:\pos8C5.tmp
C:\pos8C6.tmp
C:\pos8C7.tmp
C:\pos8C8.tmp
C:\pos8C9.tmp
C:\pos8CA.tmp
C:\pos8CB.tmp
C:\pos8CC.tmp
C:\pos8CD.tmp
C:\pos8CE.tmp
C:\pos8CF.tmp
C:\pos8D.tmp
C:\pos8D0.tmp
C:\pos8D1.tmp
C:\pos8D2.tmp
C:\pos8D3.tmp
C:\pos8D4.tmp
C:\pos8D5.tmp
C:\pos8D6.tmp
C:\pos8D7.tmp
C:\pos8D8.tmp
C:\pos8D9.tmp
C:\pos8DA.tmp
C:\pos8DB.tmp
C:\pos8DC.tmp
C:\pos8DD.tmp
C:\pos8DE.tmp
C:\pos8DF.tmp
C:\pos8E.tmp
C:\pos8E0.tmp
C:\pos8E1.tmp
C:\pos8E2.tmp
C:\pos8E3.tmp
C:\pos8E4.tmp
C:\pos8E5.tmp
C:\pos8E6.tmp
C:\pos8E7.tmp
C:\pos8E8.tmp
C:\pos8E9.tmp
C:\pos8EA.tmp
C:\pos8EB.tmp
C:\pos8EC.tmp
C:\pos8ED.tmp
C:\pos8EE.tmp
C:\pos8EF.tmp
C:\pos8F.tmp
C:\pos8F0.tmp
C:\pos8F1.tmp
C:\pos8F2.tmp
C:\pos8F3.tmp
C:\pos8F4.tmp
C:\pos8F5.tmp
C:\pos8F6.tmp
C:\pos8F7.tmp
C:\pos8F8.tmp
C:\pos8F9.tmp
C:\pos8FA.tmp
C:\pos8FB.tmp
C:\pos8FC.tmp
C:\pos8FD.tmp
C:\pos8FE.tmp
C:\pos8FF.tmp
C:\pos9.tmp
C:\pos90.tmp
C:\pos900.tmp
C:\pos901.tmp
C:\pos902.tmp
C:\pos903.tmp
C:\pos904.tmp
C:\pos905.tmp
C:\pos906.tmp
C:\pos907.tmp
C:\pos908.tmp
C:\pos909.tmp
C:\pos90A.tmp
C:\pos90B.tmp
C:\pos90C.tmp
C:\pos90D.tmp
C:\pos90E.tmp
C:\pos90F.tmp
C:\pos91.tmp
C:\pos910.tmp
C:\pos911.tmp
C:\pos912.tmp
C:\pos913.tmp
C:\pos914.tmp
C:\pos915.tmp
C:\pos916.tmp
C:\pos917.tmp
C:\pos918.tmp
C:\pos919.tmp
C:\pos91A.tmp
C:\pos91B.tmp
C:\pos91C.tmp
C:\pos91D.tmp
C:\pos91E.tmp
C:\pos91F.tmp
C:\pos92.tmp
C:\pos920.tmp
C:\pos921.tmp
C:\pos922.tmp
C:\pos923.tmp
C:\pos924.tmp
C:\pos925.tmp
C:\pos926.tmp
C:\pos927.tmp
C:\pos928.tmp
C:\pos929.tmp
C:\pos92A.tmp
C:\pos92B.tmp
C:\pos92C.tmp
C:\pos92D.tmp
C:\pos92E.tmp
C:\pos92F.tmp
C:\pos93.tmp
C:\pos930.tmp
C:\pos931.tmp
C:\pos932.tmp
C:\pos933.tmp
C:\pos934.tmp
C:\pos935.tmp
C:\pos936.tmp
C:\pos937.tmp
C:\pos938.tmp
C:\pos939.tmp
C:\pos93A.tmp
C:\pos93B.tmp
C:\pos93C.tmp
C:\pos93D.tmp
C:\pos93E.tmp
C:\pos93F.tmp
C:\pos94.tmp
C:\pos940.tmp
C:\pos941.tmp
C:\pos942.tmp
C:\pos943.tmp
C:\pos944.tmp
C:\pos945.tmp
C:\pos946.tmp
C:\pos947.tmp
C:\pos948.tmp
C:\pos949.tmp
C:\pos94A.tmp
C:\pos94B.tmp
C:\pos94C.tmp
C:\pos94D.tmp
C:\pos94E.tmp
C:\pos94F.tmp
C:\pos95.tmp
C:\pos950.tmp
C:\pos951.tmp
C:\pos952.tmp
C:\pos953.tmp
C:\pos954.tmp
C:\pos955.tmp
C:\pos956.tmp
C:\pos957.tmp
C:\pos958.tmp
C:\pos959.tmp
C:\pos95A.tmp
C:\pos95B.tmp
C:\pos95C.tmp
C:\pos95D.tmp
C:\pos95E.tmp
C:\pos95F.tmp
C:\pos96.tmp
C:\pos960.tmp
C:\pos961.tmp
C:\pos962.tmp
C:\pos963.tmp
C:\pos964.tmp
C:\pos965.tmp
C:\pos966.tmp
C:\pos967.tmp
C:\pos968.tmp
C:\pos969.tmp
C:\pos96A.tmp
C:\pos96B.tmp
C:\pos96C.tmp
C:\pos96D.tmp
C:\pos96E.tmp
C:\pos97.tmp
C:\pos98.tmp
C:\pos99.tmp
C:\pos9A.tmp
C:\pos9B.tmp
C:\pos9C.tmp
C:\pos9D.tmp
C:\pos9E.tmp
C:\pos9F.tmp
C:\posA.tmp
C:\posA0.tmp
C:\posA1.tmp
C:\posA2.tmp
C:\posA3.tmp
C:\posA4.tmp
C:\posA5.tmp
C:\posA6.tmp
C:\posA7.tmp
C:\posA8.tmp
C:\posA9.tmp
C:\posAA.tmp
C:\posAB.tmp
C:\posAC.tmp
C:\posAD.tmp
C:\posAE.tmp
C:\posAF.tmp
C:\posB.tmp
C:\posB0.tmp
C:\posB1.tmp
C:\posB2.tmp
C:\posB3.tmp
C:\posB4.tmp
C:\posB5.tmp
C:\posB6.tmp
C:\posB7.tmp
C:\posB8.tmp
C:\posB9.tmp
C:\posBA.tmp
C:\posBB.tmp
C:\posBC.tmp
C:\posBD.tmp
C:\posBE.tmp
C:\posBF.tmp
C:\posC.tmp
C:\posC0.tmp
C:\posC1.tmp
C:\posC2.tmp
C:\posC3.tmp
C:\posC4.tmp
C:\posC5.tmp
C:\posC6.tmp
C:\posC7.tmp
C:\posC8.tmp
C:\posC9.tmp
C:\posCA.tmp
C:\posCB.tmp
C:\posCC.tmp
C:\posCD.tmp
C:\posCE.tmp
C:\posCF.tmp
C:\posD.tmp
C:\posD0.tmp
C:\posD1.tmp
C:\posD2.tmp
C:\posD3.tmp
C:\posD4.tmp
C:\posD5.tmp
C:\posD6.tmp
C:\posD7.tmp
C:\posD8.tmp
C:\posD9.tmp
C:\posDA.tmp
C:\posDB.tmp
C:\posDC.tmp
C:\posDD.tmp
C:\posDE.tmp
C:\posDF.tmp
C:\posE.tmp
C:\posE0.tmp
C:\posE1.tmp
C:\posE2.tmp
C:\posE3.tmp
C:\posE4.tmp
C:\posE5.tmp
C:\posE6.tmp
C:\posE7.tmp
C:\posE8.tmp
C:\posE9.tmp
C:\posEA.tmp
C:\posEB.tmp
C:\posEC.tmp
C:\posED.tmp
C:\posEE.tmp
C:\posEF.tmp
C:\posF.tmp
C:\posF0.tmp
C:\posF1.tmp
C:\posF2.tmp
C:\posF3.tmp
C:\posF4.tmp
C:\posF5.tmp
C:\posF6.tmp
C:\posF7.tmp
C:\posF8.tmp
C:\posF9.tmp
C:\posFA.tmp
C:\posFB.tmp
C:\posFC.tmp
C:\posFD.tmp
C:\posFE.tmp
C:\posFF.tmp
C:\Program Files\Fichiers communs\StorageProtector
C:\Program Files\StorageProtector
C:\Program Files\StorageProtector\atl71.dll
C:\Program Files\StorageProtector\License.rtf
C:\Program Files\StorageProtector\mfc71.dll
C:\Program Files\StorageProtector\msvcp71.dll
C:\Program Files\StorageProtector\msvcr71.dll
C:\Program Files\StorageProtector\Readme.rtf
C:\Program Files\StorageProtector\Res\Main.ico
C:\Program Files\StorageProtector\Res\RecycleBin.ico
C:\Program Files\StorageProtector\rm.url
C:\Program Files\StorageProtector\sr.log
C:\Program Files\StorageProtector\swupd.log
C:\Program Files\StorageProtector\SysRep.exe.cer
C:\Program Files\StorageProtector\SysRep.exe.Log
C:\Program Files\StorageProtector\SysRep.exe.xml
C:\Program Files\StorageProtector\SysRep.url
C:\Program Files\StorageProtector\transpaid.exe
C:\Program Files\StorageProtector\unins000.dat
C:\Program Files\StorageProtector\unins000.exe
C:\Program Files\StorageProtector\urls.ini
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\geebb.dll
C:\WINDOWS\system32\urqnkjh.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-12-13 to 2008-01-13 ))))))))))))))))))))))))))))))))))))
.
2008-01-13 13:12 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 12:48 . 2008-01-13 12:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-13 12:46 . 2008-01-13 13:03 <REP> d-------- C:\VundoFix Backups
2008-01-13 12:43 . 2008-01-13 12:43 <REP> d-------- C:\Program Files\Trend Micro
2008-01-13 12:29 . 2008-01-13 12:33 <REP> d-------- C:\Program Files\OmniBack
2008-01-12 12:16 . 2008-01-12 12:16 268 --ah----- C:\sqmdata10.sqm
2008-01-12 12:16 . 2008-01-12 12:16 244 --ah----- C:\sqmnoopt10.sqm
2008-01-10 01:06 . 2008-01-10 01:08 32,764 --a------ C:\WINDOWS\17PHolmes572.exe
2008-01-10 00:15 . 2004-08-04 00:54 83,968 --a------ C:\WINDOWS\system32\CNBJMON2.DLL
2008-01-10 00:15 . 2001-08-23 15:46 58,276 --a------ C:\WINDOWS\system32\CNBJHLP2.HLP
2008-01-10 00:15 . 2001-08-23 15:46 1,312 --a------ C:\WINDOWS\system32\CNBJHLP2.CNT
2008-01-09 21:47 . 2008-01-09 21:47 <REP> d-------- C:\Program Files\Valve
2008-01-09 18:02 . 2008-01-09 18:02 <REP> d-------- C:\Program Files\ImTOO
2008-01-09 16:07 . 2008-01-09 16:07 <REP> d-------- C:\Documents and Settings\RAPHAEL\Application Data\AdobeUM
2008-01-08 20:03 . 2008-01-08 20:03 <REP> d-------- C:\Program Files\RapidSolution
2008-01-08 20:03 . 2008-01-08 20:15 <REP> d-------- C:\Documents and Settings\RAPHAEL\Application Data\Tunebite
2008-01-08 20:03 . 2008-01-08 20:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\RapidSolution
2008-01-08 20:03 . 2007-12-11 09:52 26,784 --a------ C:\WINDOWS\system32\drivers\tbhsd.sys
2008-01-06 22:23 . 2008-01-06 22:24 <REP> d-------- C:\Program Files\Everest Poker
2008-01-03 19:53 . 2008-01-03 19:57 <REP> d-------- C:\Documents and Sett