Mémoire vive utilisée à fond sous vista

Zaf -  
 Zaf -
Bonjour, jusqu'ici très content de Vista familial premium même avec ma config
Processeur Genuine Intel T2250 1,73Go
RAM 1022
je pouvais avoir récemment une douzaine de fenêtres d'ouvertes et 2 logiciels P2P à tourner tout en jouant en réseau sur le net...
Depuis peu ma mémoire vive a explosé et flirt les 92% à 98% même lorsqu'il n'y a rien d'ouvert et le démarrage est lent
Mes disques ne sont pas surchargés, même si on ne peut voir s'ils sont bien fragmentés :( , mon processeur ne galère pas
je viens de changer la résollution de l'affichage et des couleurs, que dalle

y-a-t'il d'autres solutions car la latence sur du traitement de texte ne m'amuse plus ? merc

Ps : ramer dans le sens du courant à toujours fait rire les crocodiles
A voir également:

42 réponses

leim78 Messages postés 56 Statut Membre 2
 
autre rapport
Malwarebytes' Anti-Malware 1.11
Version de la base de données: 705

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 154772
Temps écoulé: 5 hour(s), 19 minute(s), 5 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
0
Utilisateur anonyme
 
Malwarebytes a rien trouvé, c'est une bonne chose..
n'oubli pas de faire les scan en mode sans échec surtout !
0
leim78 Messages postés 56 Statut Membre 2
 
autre rapport
BitDefender Online Scanner - Rapport virus en temps réel

Généré à: Thu, May 01, 2008 - 23:03:49

--------------------------------------------------------------------------------

Info d'analyse

Fichiers scannés
110652

Infectés Fichiers
0

Virus Détectés

Aucun virus trouvé.

--------------------------------------------------------------------------------

Ce sommaire du processus d'analyse sera utilisé par les laboratoires Antivirus BitDefender pour créer des statistiques agréguées sur l'activité des virus dans le monde.
0
leim78 Messages postés 56 Statut Membre 2
 
Version - a-squared Anti-Malware 3.5
Dernière mise à jour : 02/05/2008 08:27:06

Paramètres des balayages :

Éléments : Mémoire, Traces, Cookies, C:\Windows\, C:\Program Files
Balaye dans les archives : Marche
Analyse heuristique : Marche
Balaye dans les ADS : Marche

Début du balayage : 02/05/2008 08:45:03

c:\program files\messengerdiscovery Objets détectés : Trace.Directory.DiscoveryLive
c:\users\hermann\appdata\roaming\adscleaner Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\initfiles Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\exchange Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\input Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\internallog Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\internallog Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles\default Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles\default\hintview Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles\default\listview Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\softinform\adscleaner Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\softinform\adscleaner\internallog Objets détectés : Trace.Directory.AdsCleaner
c:\program files\softinform\adscleaner trial Objets détectés : Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\bannerinfo.dat Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\ads.ver Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\advert.data Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\advert.ind Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\advert.ind.add Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\advert.ind.del Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\initfiles\ads.adl Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\initfiles\adsize.adl Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\pkiller.ind Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\whitepages.ind Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive\runflag.dat Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive\thumbnail.dat Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive\thumbnail.dat.ind Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive\thumbnail.datfra Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive\thumbnail.datfrs Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpcont.dat Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpcont.dat.lbz Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpcont.datfra Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpcont.datfrs Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpindid.dat Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpindurl.dat Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\internallog\rpcsrvlog.txt Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles\default\hintview\default view.htg Objets détectés : Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles\default\listview\default view.stg Objets détectés : Trace.File.AdsCleaner
c:\program files\softinform\adscleaner trial\pakiegui.dll Objets détectés : Trace.File.AdsCleaner
c:\program files\softinform\adscleaner trial\pakieplugins.dll Objets détectés : Trace.File.AdsCleaner
c:\program files\softinform\adscleaner trial\sitts.exe Objets détectés : Trace.File.AdsCleaner
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Downloads --> CollectionPath Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Downloads --> CompletePath Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Downloads --> IncompletePath Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Downloads --> TorrentPath Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Plugins --> {9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646} Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> FirstRun Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> GUIMode Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> Language Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> RatesInBytes Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> Running Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> VerboseMode Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Windows --> CMainWnd.ShowCmd Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza --> UserPath Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\AudioVis --> Mike`s Simple Scopes Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\AudioVis --> Sonique Wrapper Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\AudioVis --> WMP Wrapper Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\DownloadPreview --> .avi Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\DownloadPreview --> .div Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\DownloadPreview --> .mp3 Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\DownloadPreview --> .mpeg Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\DownloadPreview --> .mpg Objets détectés : Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\ballon --> Checksum Objets détectés : Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\ballon --> MaximiseeOuverture Objets détectés : Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\ballon --> PositionOuverture Objets détectés : Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\ballon --> TailleOuverture Objets détectés : Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\choixlangues --> Checksum Objets détectés : Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\choixlangues --> MaximiseeOuverture Objets détectés : Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\choixlangues --> PositionOuverture Objets détectés : Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\choixlangues --> TailleOuverture Objets détectés : Trace.Registry.WinSOS
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> CITY Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> DATE Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> LANGUAGE Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> LAST_SCAN Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> MAIL Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> REGION Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> SAVE Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> SAVE EX Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> SPY Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> TEMP Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> TOTALHD Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> TOTALSAUVE Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> TOTALSPY Objets détectés : Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> TOTALTRACES Objets détectés : Trace.Registry.Winsos 5.0
C:\Users\Hermann\AppData\Roaming\Microsoft\Windows\Cookies\hermann@com[1].txt Objets détectés : Trace.TrackingCookie
C:\Users\Hermann\AppData\Roaming\Microsoft\Windows\Cookies\hermann@weborama[1].txt Objets détectés : Trace.TrackingCookie

Analysé

Fichiers : 115851
Traces : 177636
Cookies : 125
Processus : 18

Objets trouvés

Fichiers : 0
Traces : 88
Cookies : 2
Processus : 0
Clés du Registre : 0

Fin du balayage : 02/05/2008 09:20:34
Temps du balayage : 0:35:31

C:\Users\Hermann\AppData\Roaming\Microsoft\Windows\Cookies\hermann@com[1].txt Objets Supprimés Trace.TrackingCookie
C:\Users\Hermann\AppData\Roaming\Microsoft\Windows\Cookies\hermann@weborama[1].txt Objets Supprimés Trace.TrackingCookie
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> CITY Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> DATE Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> LANGUAGE Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> LAST_SCAN Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> MAIL Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> REGION Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> SAVE Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> SAVE EX Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> SPY Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> TEMP Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> TOTALHD Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> TOTALSAUVE Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> TOTALSPY Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_LOCAL_MACHINE\SOFTWARE\WIN SOS --> TOTALTRACES Objets Supprimés Trace.Registry.Winsos 5.0
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\ballon --> Checksum Objets Supprimés Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\ballon --> MaximiseeOuverture Objets Supprimés Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\ballon --> PositionOuverture Objets Supprimés Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\ballon --> TailleOuverture Objets Supprimés Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\choixlangues --> Checksum Objets Supprimés Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\choixlangues --> MaximiseeOuverture Objets Supprimés Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\choixlangues --> PositionOuverture Objets Supprimés Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\WINSOS\WINSOS\choixlangues --> TailleOuverture Objets Supprimés Trace.Registry.WinSOS
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Downloads --> CollectionPath Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Downloads --> CompletePath Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Downloads --> IncompletePath Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Downloads --> TorrentPath Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Plugins --> {9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646} Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> FirstRun Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> GUIMode Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> Language Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> RatesInBytes Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> Running Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Settings --> VerboseMode Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Windows --> CMainWnd.ShowCmd Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_CURRENT_USER\Software\Shareaza\Shareaza --> UserPath Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\AudioVis --> Mike`s Simple Scopes Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\AudioVis --> Sonique Wrapper Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\AudioVis --> WMP Wrapper Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\DownloadPreview --> .avi Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\DownloadPreview --> .div Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\DownloadPreview --> .mp3 Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\DownloadPreview --> .mpeg Objets Supprimés Trace.Registry.Shareaza Lite
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Shareaza\Shareaza\Plugins\DownloadPreview --> .mpg Objets Supprimés Trace.Registry.Shareaza Lite
c:\users\hermann\appdata\roaming\adscleaner\bannerinfo.dat Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\ads.ver Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\advert.data Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\advert.ind Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\advert.ind.add Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\advert.ind.del Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\initfiles\ads.adl Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\initfiles\adsize.adl Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\pkiller.ind Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\whitepages.ind Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive\runflag.dat Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive\thumbnail.dat Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive\thumbnail.dat.ind Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive\thumbnail.datfra Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive\thumbnail.datfrs Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpcont.dat Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpcont.dat.lbz Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpcont.datfra Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpcont.datfrs Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpindid.dat Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails\dpindurl.dat Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\internallog\rpcsrvlog.txt Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles\default\hintview\default view.htg Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles\default\listview\default view.stg Objets Supprimés Trace.File.AdsCleaner
c:\program files\softinform\adscleaner trial\pakiegui.dll Objets Supprimés Trace.File.AdsCleaner
c:\program files\softinform\adscleaner trial\pakieplugins.dll Objets Supprimés Trace.File.AdsCleaner
c:\program files\softinform\adscleaner trial\sitts.exe Objets Supprimés Trace.File.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\adblocker\initfiles Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\archive Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\diskthumbnails Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\exchange Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\input Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\data\internallog Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\internallog Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles\default Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles\default\hintview Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\adscleaner\profiles\default\listview Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\softinform\adscleaner Objets Supprimés Trace.Directory.AdsCleaner
c:\users\hermann\appdata\roaming\softinform\adscleaner\internallog Objets Supprimés Trace.Directory.AdsCleaner
c:\program files\softinform\adscleaner trial Objets Supprimés Trace.Directory.AdsCleaner
c:\program files\messengerdiscovery Objets Supprimés Trace.Directory.DiscoveryLive

Objets Supprimés

Fichiers : 0
Traces : 88
Cookies : 2
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
leim78 Messages postés 56 Statut Membre 2
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:36:33, on 02/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\svchost.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\system32\WUDFHost.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Windows\system32\schtasks.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\system32\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hp\kbd\kbd.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\ESTsoft\ALZip\ALZip.exe
C:\Windows\explorer.exe
C:\Windows\system32\conime.exe
C:\Users\Hermann\Desktop\MSNFix\MSNFix\incl\catchme.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://gamespace.daemon-tools.cc/fra/home

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F3350D6-BC02-41AA-BC84-E870DD39E6F2}: NameServer = 192.168.1.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
0
leim78 Messages postés 56 Statut Membre 2
 
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-02 09:28:30
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:b1,4c,f9,02,0b,6c,4d,61,52,4a,9c,4f,83,f1,f4,e2,a1,99,77,93,af,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:aa,b7,53,bc,0a,33,29,6e,1c,aa,dd,3f,ff,34,03,d8,1c,86,53,6e,8a,..
"p0"="C:\Program Files\DAEMON Tools Lite\"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,b3,9f,bd,14,59,0d,0f,98,e7,81,16,18,05,51,0c,02,75,..
"khjeh"=hex:77,d4,c2,53,46,04,9b,12,57,dc,96,50,c4,b1,88,d8,0c,49,49,1e,8f,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:28,0e,cb,ea,17,8b,f6,8c,d4,8c,f7,04,d3,8d,44,9a,9a,6d,03,02,36,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:b1,4c,f9,02,0b,6c,4d,61,52,4a,9c,4f,83,f1,f4,e2,a1,99,77,93,af,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:aa,b7,53,bc,0a,33,29,6e,1c,aa,dd,3f,ff,34,03,d8,1c,86,53,6e,8a,..
"p0"="C:\Program Files\DAEMON Tools Lite\"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,b3,9f,bd,14,59,0d,0f,98,e7,81,16,18,05,51,0c,02,75,..
"khjeh"=hex:77,d4,c2,53,46,04,9b,12,57,dc,96,50,c4,b1,88,d8,0c,49,49,1e,8f,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:28,0e,cb,ea,17,8b,f6,8c,d4,8c,f7,04,d3,8d,44,9a,9a,6d,03,02,36,..

scanning hidden registry entries ...

scanning hidden files ...

C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb 65536 bytes

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 217

file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\36\36-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v36-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ( 4640 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\59\159-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v159-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v159-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ( 17418 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\59\159-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v159-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v159-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.1 ( 1960 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\59\59-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v59-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.1 ( 46632 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\59\59-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v59-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.2 ( 5200 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\26\58-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v26-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.2 ( 31746 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\26\58-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v26-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.3 ( 3520 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\27\59-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v27-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.4 ( 5480 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\28\60-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v28-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v60-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.5 ( 4328 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\34\34-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v34-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.6 ( 3920 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\35\35-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v35-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.7 ( 4176 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\37\37-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v37-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.3 ( 39396 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\37\37-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v37-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.8 ( 4336 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\38\38-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v38-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.9 ( 4840 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\39\39-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v39-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v39-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.10 ( 3968 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\40\40-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v40-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v40-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.11 ( 4944 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\41\41-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v41-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.4 ( 50124 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\41\41-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v41-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.12 ( 5608 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\42\42-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v42-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.5 ( 46884 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\42\42-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v42-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.13 ( 5264 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\43\43-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v43-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v43-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.14 ( 5864 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\44\44-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v44-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v44-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.15 ( 5656 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\50\50-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v50-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v50-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.6 ( 35922 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\50\50-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v50-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v50-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.16 ( 4016 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\51\151-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v151-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.7 ( 14556 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\51\151-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v151-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.17 ( 1608 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\51\51-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v51-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v51-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.8 ( 25662 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\51\51-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v51-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v51-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.18 ( 2848 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\52\152-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v152-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v152-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.9 ( 17490 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\52\152-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v152-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v152-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.19 ( 1912 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\52\52-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v52-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v52-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.10 ( 24834 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\52\52-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v52-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v52-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.20 ( 2768 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\53\153-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v153-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.11 ( 17184 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\53\153-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v153-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.21 ( 1928 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\53\53-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v53-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.12 ( 68646 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\53\53-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v53-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.22 ( 7672 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\54\154-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v154-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v154-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.13 ( 12810 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\54\154-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v154-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v154-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.23 ( 1416 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\54\54-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v54-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.14 ( 22908 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\54\54-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v54-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.24 ( 2560 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\55\155-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v155-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.15 ( 16068 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\55\155-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v155-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.25 ( 1768 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\55\55-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v55-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.16 ( 66864 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\55\55-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v55-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.26 ( 7392 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\56\156-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v156-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v156-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.17 ( 13728 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\56\156-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v156-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v156-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.27 ( 1512 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\56\56-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v56-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.18 ( 18768 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\56\56-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v56-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.28 ( 2072 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\57\157-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v157-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.19 ( 16032 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\57\157-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v157-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.29 ( 1800 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\57\57-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v57-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.20 ( 64092 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\57\57-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v57-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.30 ( 7088 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\58\158-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v158-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v158-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.21 ( 17490 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\58\158-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v158-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v158-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.31 ( 1920 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\58\58-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v58-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.22 ( 19254 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\58\58-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v58-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.32 ( 2168 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\60\160-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v160-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.23 ( 31944 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\60\160-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v160-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.33 ( 3552 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\60\60-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v60-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v60-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.24 ( 53364 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\60\60-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v60-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v60-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.34 ( 5944 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\61\161-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v161-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.25 ( 16572 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\61\161-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v161-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.35 ( 1824 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\61\61-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v61-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v61-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.26 ( 22008 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\61\61-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v61-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v61-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.36 ( 2384 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\62\162-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v162-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v162-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.27 ( 16518 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\62\162-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v162-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v162-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.37 ( 1872 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\62\62-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v62-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v62-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.28 ( 98886 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\62\62-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v62-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v62-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.38 ( 11000 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\63\163-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v163-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v163-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.29 ( 15744 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\63\163-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v163-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v163-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.39 ( 1728 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\63\63-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v63-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.30 ( 14934 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\63\63-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v63-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.40 ( 1656 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\64\164-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v164-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v164-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.31 ( 17202 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\64\164-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v164-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v164-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.41 ( 1920 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\64\64-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v64-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v64-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.32 ( 35454 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\64\64-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v64-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v64-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.42 ( 3904 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\65\165-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v165-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v165-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.33 ( 55704 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\65\165-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v165-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v165-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.43 ( 6232 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\65\65-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v65-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v65-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.34 ( 50484 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\65\65-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v65-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v65-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.44 ( 5632 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\66\166-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v166-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v166-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.35 ( 16194 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\66\166-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v166-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v166-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.45 ( 1792 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\66\66-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v66-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v66-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.36 ( 19578 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\66\66-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v66-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v66-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.46 ( 2176 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\67\167-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v167-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v167-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.37 ( 18678 bytes )
read file error: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\67\167-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v167-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v167-Do
0
leim78 Messages postés 56 Statut Membre 2
 
voila les scan
0
Utilisateur anonyme
 
ok tu peus refaire msnfix en mode san echec,
http://www.commentcamarche.net/telecharger/telecharger 34055374 msn fix

fais aussi un coup de combofix en sans echec
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

et enfin tu scan hijackthis en sans echec et tu repost apres un raport ...

Démarrer en mode sans echec, ca sert a rien si non !!))
http://www.commentcamarche.net/faq/sujet 5004 windows xp demarrage en mode sans echec
0
leim78 Messages postés 56 Statut Membre 2
 
voila pour hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:41:19, on 02/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Safe mode

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://gamespace.daemon-tools.cc/fra/home

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F3350D6-BC02-41AA-BC84-E870DD39E6F2}: NameServer = 192.168.1.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
0
leim78 Messages postés 56 Statut Membre 2
 
pour l autre
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-02 17:42:36
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:b1,4c,f9,02,0b,6c,4d,61,52,4a,9c,4f,83,f1,f4,e2,a1,99,77,93,af,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:aa,b7,53,bc,0a,33,29,6e,1c,aa,dd,3f,ff,34,03,d8,1c,86,53,6e,8a,..
"p0"="C:\Program Files\DAEMON Tools Lite\"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,b3,9f,bd,14,59,0d,0f,98,e7,81,16,18,05,51,0c,02,75,..
"khjeh"=hex:77,d4,c2,53,46,04,9b,12,57,dc,96,50,c4,b1,88,d8,0c,49,49,1e,8f,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:8c,e5,3a,47,bb,8e,04,98,f2,05,8c,74,bc,f4,37,7d,9d,19,12,e8,05,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:b1,4c,f9,02,0b,6c,4d,61,52,4a,9c,4f,83,f1,f4,e2,a1,99,77,93,af,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:aa,b7,53,bc,0a,33,29,6e,1c,aa,dd,3f,ff,34,03,d8,1c,86,53,6e,8a,..
"p0"="C:\Program Files\DAEMON Tools Lite\"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,b3,9f,bd,14,59,0d,0f,98,e7,81,16,18,05,51,0c,02,75,..
"khjeh"=hex:77,d4,c2,53,46,04,9b,12,57,dc,96,50,c4,b1,88,d8,0c,49,49,1e,8f,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:28,0e,cb,ea,17,8b,f6,8c,d4,8c,f7,04,d3,8d,44,9a,9a,6d,03,02,36,..

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 216

file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\36\36-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v36-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ( 4640 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\59\159-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v159-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v159-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ( 17418 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\59\159-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v159-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v159-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.1 ( 1960 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\59\59-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v59-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.1 ( 46632 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\59\59-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v59-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.2 ( 5200 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\26\58-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v26-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.2 ( 31746 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\26\58-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v26-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.3 ( 3520 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\27\59-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v27-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.4 ( 5480 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\28\60-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v28-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v60-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.5 ( 4328 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\34\34-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v34-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.6 ( 3920 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\35\35-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v35-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.7 ( 4176 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\37\37-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v37-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.3 ( 39396 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\37\37-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v37-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.8 ( 4336 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\38\38-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v38-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.9 ( 4840 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\39\39-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v39-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v39-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.10 ( 3968 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\40\40-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v40-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v40-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.11 ( 4944 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\41\41-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v41-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.4 ( 50124 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\41\41-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v41-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.12 ( 5608 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\42\42-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v42-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.5 ( 46884 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\42\42-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v42-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.13 ( 5264 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\43\43-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v43-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v43-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.14 ( 5864 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\44\44-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v44-{556FBFC4-C84C-4829-AB7E-96FFA71782BC}-v44-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.15 ( 5656 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\50\50-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v50-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v50-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.6 ( 35922 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\50\50-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v50-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v50-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.16 ( 4016 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\51\151-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v151-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.7 ( 14556 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\51\151-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v151-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.17 ( 1608 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\51\51-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v51-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v51-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.8 ( 25662 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\51\51-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v51-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v51-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.18 ( 2848 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\52\152-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v152-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v152-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.9 ( 17490 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\52\152-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v152-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v152-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.19 ( 1912 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\52\52-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v52-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v52-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.10 ( 24834 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\52\52-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v52-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v52-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.20 ( 2768 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\53\153-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v153-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.11 ( 17184 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\53\153-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v153-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.21 ( 1928 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\53\53-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v53-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.12 ( 68646 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\53\53-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v53-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.22 ( 7672 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\54\154-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v154-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v154-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.13 ( 12810 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\54\154-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v154-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v154-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.23 ( 1416 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\54\54-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v54-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.14 ( 22908 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\54\54-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v54-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.24 ( 2560 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\55\155-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v155-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.15 ( 16068 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\55\155-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v155-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.25 ( 1768 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\55\55-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v55-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.16 ( 66864 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\55\55-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v55-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.26 ( 7392 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\56\156-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v156-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v156-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.17 ( 13728 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\56\156-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v156-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v156-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.27 ( 1512 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\56\56-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v56-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.18 ( 18768 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\56\56-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v56-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.28 ( 2072 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\57\157-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v157-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.19 ( 16032 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\57\157-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v157-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.29 ( 1800 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\57\57-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v57-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.20 ( 64092 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\57\57-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v57-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.30 ( 7088 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\58\158-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v158-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v158-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.21 ( 17490 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\58\158-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v158-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v158-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.31 ( 1920 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\58\58-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v58-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.22 ( 19254 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\58\58-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v58-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.32 ( 2168 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\60\160-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v160-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.23 ( 31944 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\60\160-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v160-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v160-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.33 ( 3552 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\60\60-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v60-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v60-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.24 ( 53364 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\60\60-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v60-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v60-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.34 ( 5944 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\61\161-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v161-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.25 ( 16572 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\61\161-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v161-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.35 ( 1824 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\61\61-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v61-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v61-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.26 ( 22008 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\61\61-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v61-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v61-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.36 ( 2384 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\62\162-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v162-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v162-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.27 ( 16518 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\62\162-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v162-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v162-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.37 ( 1872 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\62\62-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v62-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v62-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.28 ( 98886 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\62\62-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v62-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v62-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.38 ( 11000 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\63\163-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v163-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v163-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.29 ( 15744 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\63\163-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v163-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v163-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.39 ( 1728 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\63\63-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v63-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.30 ( 14934 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\63\63-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v63-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.40 ( 1656 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\64\164-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v164-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v164-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.31 ( 17202 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\64\164-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v164-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v164-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.41 ( 1920 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\64\64-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v64-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v64-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.32 ( 35454 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\64\64-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v64-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v64-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.42 ( 3904 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\65\165-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v165-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v165-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.33 ( 55704 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\65\165-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v165-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v165-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.43 ( 6232 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\65\65-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v65-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v65-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.34 ( 50484 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\65\65-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v65-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v65-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.44 ( 5632 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\66\166-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v166-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v166-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.35 ( 16194 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\66\166-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v166-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v166-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.45 ( 1792 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\66\66-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v66-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v66-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.36 ( 19578 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\66\66-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v66-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v66-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.46 ( 2176 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\67\167-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v167-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v167-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.37 ( 18678 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\67\167-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v167-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v167-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.47 ( 2112 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\67\67-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v67-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v67-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.38 ( 37506 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\67\67-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v67-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v67-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.48 ( 4208 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\68\168-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v168-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v168-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.39 ( 16806 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\68\168-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v168-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v168-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.49 ( 1944 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\68\68-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v68-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v68-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.40 ( 15654 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\68\68-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v68-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v68-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.50 ( 1768 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\69\169-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v169-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v169-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.41 ( 18030 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\69\169-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v169-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v169-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.51 ( 1976 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\69\69-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v69-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v69-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.42 ( 21414 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\69\69-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v69-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v69-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.52 ( 2416 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\70\170-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v170-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v170-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.43 ( 17184 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\70\170-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v170-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v170-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.53 ( 1872 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\70\70-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v70-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v70-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.44 ( 14700 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\70\70-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v70-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v70-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.54 ( 1624 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\71\171-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v171-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v171-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.45 ( 20640 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\71\171-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v171-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v171-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.55 ( 2312 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\71\71-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v71-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.46 ( 14034 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\71\71-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v71-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.56 ( 1592 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\72\172-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v172-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.47 ( 20892 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\72\172-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v172-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v172-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.57 ( 2352 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\72\72-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v72-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v72-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.48 ( 46326 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\72\72-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v72-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v72-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.58 ( 5424 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\73\173-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v173-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.49 ( 16986 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\73\173-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v173-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v173-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.59 ( 1880 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\73\73-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v73-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v73-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.50 ( 15654 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\73\73-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v73-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v73-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.60 ( 1752 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\74\174-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v174-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v174-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.51 ( 16068 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\74\174-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v174-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v174-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.61 ( 1792 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\74\74-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v74-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v74-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.52 ( 18408 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\74\74-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v74-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v74-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.62 ( 2024 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\75\175-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v175-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v175-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.53 ( 16176 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\75\175-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v175-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v175-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.63 ( 1808 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\75\75-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v75-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v75-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.54 ( 13026 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\75\75-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v75-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v75-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.64 ( 1472 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\76\176-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v176-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v176-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.55 ( 14430 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\76\176-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v176-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v176-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.65 ( 1632 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\76\76-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v76-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v76-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.56 ( 16860 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\76\76-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v76-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v76-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.66 ( 1888 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\77\177-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v177-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v177-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.57 ( 17508 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\77\177-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v177-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v177-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.67 ( 1984 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\77\77-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v77-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v77-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.58 ( 17670 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\77\77-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v77-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v77-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.68 ( 1984 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\78\178-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v178-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v178-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.59 ( 16950 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\78\178-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v178-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v178-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.69 ( 1880 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\78\78-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v78-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v78-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.60 ( 23088 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\78\78-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v78-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v78-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.70 ( 2608 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\79\179-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v179-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v179-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.61 ( 19182 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\79\179-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v179-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v179-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.71 ( 2192 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\79\79-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v79-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v79-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.62 ( 34392 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\79\79-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v79-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v79-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.72 ( 4088 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\80\180-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v180-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v180-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.63 ( 16608 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\80\180-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v180-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v180-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.73 ( 1816 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\80\80-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v80-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v80-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.64 ( 17472 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\80\80-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v80-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v80-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.74 ( 1968 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\81\181-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v181-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v181-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.65 ( 16284 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\81\181-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v181-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v181-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.75 ( 1832 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\81\81-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v81-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v81-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.66 ( 13926 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\81\81-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v81-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v81-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS.76 ( 1536 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\82\182-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v182-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v182-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 -> catchme.zip -> {59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1.67 ( 16986 bytes )
file zipped: C:\Users\Hermann\AppData\Local\Microsoft\Messenger\HeRmAnN78@hotmail.fr\SharingMetadata\r-el-malino@hotmail.fr\DFSR\Staging\CS{019C7931-58E5-ACF4-CDEB-D8443060DB6C}\82\182-{431DC53A-8FF5-455F-B5E0-16CF37173E3F}-v182-{431DC53
0
leim78 Messages postés 56 Statut Membre 2
 
et voila le log de combofix
ComboFix 08-05-01.2 - Hermann 2008-05-02 18:21:33.1 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1692 [GMT 2:00]
Endroit: C:\Users\Hermann\Desktop\ComboFix.exe
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Windows\system32\jusched.exe

----- BITS: Possible sites infectés -----

hxxp://ftp.hp.com
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-02 to 2008-05-02 ))))))))))))))))))))))))))))))))))))
.

Pas de nouveau fichier créé dans cet espace de temps

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-02 15:35 --------- d-----w C:\Users\Hermann\AppData\Roaming\uTorrent
2008-05-02 12:28 98,304 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-05-02 12:19 --------- d-----w C:\Users\Hermann\AppData\Roaming\LimeWire
2008-05-02 12:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-02 12:11 --------- d-----w C:\Program Files\Rockstar Games
2008-05-02 09:16 --------- d-----w C:\ProgramData\Spyware Terminator
2008-05-02 09:16 --------- d-----w C:\Program Files\Spyware Terminator
2008-05-02 09:00 --------- d-----w C:\Users\Hermann\AppData\Roaming\Spyware Terminator
2008-05-02 07:55 --------- d-----w C:\Program Files\WinClamAVShield
2008-05-02 07:45 --------- d-----w C:\Program Files\a-squared Anti-Malware
2008-05-02 07:21 --------- d-----w C:\Users\Hermann\AppData\Roaming\SoftInform
2008-05-02 07:21 --------- d-----w C:\Program Files\SoftInform
2008-05-01 14:26 --------- d-----w C:\Users\Hermann\AppData\Roaming\Malwarebytes
2008-05-01 14:26 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-05-01 14:25 --------- d-----w C:\ProgramData\Malwarebytes
2008-05-01 14:19 --------- d-----w C:\Program Files\Trend Micro
2008-05-01 11:50 712 ----a-w C:\Users\Hermann\AppData\Roaming\wklnhst.dat
2008-04-29 16:27 --------- d-----w C:\Users\Hermann\AppData\Roaming\Talkback
2008-04-29 13:23 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-04-29 12:57 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com
2008-04-29 12:56 --------- d-----w C:\Users\Hermann\AppData\Roaming\SUPERAntiSpyware.com
2008-04-29 12:06 --------- d-----w C:\Program Files\directx
2008-04-29 11:04 --------- d-----w C:\Program Files\Warcraft III
2008-04-28 19:13 --------- d-----w C:\Program Files\Microsoft Works
2008-04-24 16:26 --------- d-----w C:\Users\Hermann\AppData\Roaming\Apple Computer
2008-04-24 16:25 --------- d-----w C:\ProgramData\Apple Computer
2008-04-24 16:25 --------- d-----w C:\Program Files\iTunes
2008-04-24 16:25 --------- d-----w C:\Program Files\iPod
2008-04-24 16:24 --------- d-----w C:\Program Files\QuickTime
2008-04-24 16:23 --------- d-----w C:\Program Files\Apple Software Update
2008-04-24 16:21 --------- d-----w C:\ProgramData\Apple
2008-04-24 16:21 --------- d-----w C:\Program Files\Common Files\Apple
2008-04-23 20:07 --------- d-----w C:\Program Files\free-downloads.net
2008-04-23 20:06 2,560 ----a-w C:\Windows\_MSRSTRT.EXE
2008-04-16 05:55 --------- d-----w C:\Program Files\Common Files\LogiShrd
2008-04-16 05:52 --------- d-----w C:\ProgramData\LogiShrd
2008-04-16 05:52 --------- d-----w C:\Program Files\Logitech
2008-04-11 19:50 138,752 ----a-w C:\Windows\system32\drivers\sp_rsdrv2.sys
2008-04-11 19:42 --------- d-----w C:\ProgramData\Lavasoft
2008-04-10 17:06 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2008-04-09 14:45 --------- d-----w C:\Program Files\Ubisoft
2008-04-09 09:42 --------- d-----w C:\Program Files\Yahoo!
2008-04-09 09:24 --------- d-----w C:\Program Files\Windows Mail
2008-04-07 15:28 --------- d-----w C:\Program Files\EA GAMES
2008-04-06 07:08 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-04-06 07:03 717,296 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-04-05 11:34 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-04-05 07:26 --------- d-----w C:\Program Files\uTorrent
2008-04-04 16:10 174 --sha-w C:\Program Files\desktop.ini
2008-04-04 16:03 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-04 16:03 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-04-04 16:03 --------- d-----w C:\Program Files\Windows Journal
2008-04-04 16:03 --------- d-----w C:\Program Files\Windows Defender
2008-04-04 16:03 --------- d-----w C:\Program Files\Windows Collaboration
2008-04-04 16:03 --------- d-----w C:\Program Files\Windows Calendar
2008-04-04 15:45 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-04-04 15:45 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-04-01 20:15 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-03-31 11:05 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-03-31 11:05 --------- d-----w C:\Program Files\Realtek
2008-03-31 10:55 --------- d-----w C:\Users\Hermann\AppData\Roaming\WinBatch
2008-03-29 17:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-03-23 09:17 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-16 10:26 --------- d-----w C:\Program Files\Windows Live
2008-03-11 11:27 --------- d-----w C:\Program Files\VideoLAN
2008-03-09 12:25 --------- d-----w C:\Users\Hermann\AppData\Roaming\vlc
2008-03-04 10:26 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-03 17:45 2,829 ----a-w C:\Windows\War3Unin.pif
2008-03-03 17:45 139,264 ----a-w C:\Windows\War3Unin.exe
2008-02-29 19:37 21,840 ----atw C:\Windows\System32\SIntfNT.dll
2008-02-29 19:37 17,212 ----atw C:\Windows\System32\SIntf32.dll
2008-02-29 19:37 12,067 ----atw C:\Windows\System32\SIntf16.dll
2008-02-29 07:14 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 07:11 988,216 ----a-w C:\Windows\System32\winload.exe
2008-02-29 07:11 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-02-29 06:53 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-02-29 06:53 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:53 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 04:21 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-02-29 04:12 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 04:12 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-22 05:05 615,992 ----a-w C:\Windows\System32\ci.dll
2008-02-22 05:01 826,880 ----a-w C:\Windows\System32\wininet.dll
2008-02-22 04:57 295,936 ----a-w C:\Windows\System32\gdi32.dll
2008-01-18 20:09 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-01-18 20:09 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-01-18 20:09 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2008-03-24 11:48 5724184]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-19 09:38 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 17:01 65536]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 18:16 65536]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 13:59 118784]
"StartCCC"="c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 11:26 4874240 C:\Windows\RtHDVCpl.exe]
"HP Health Check Scheduler"="c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 13:13 71176]
"SunJavaUpdateReg"="C:\Windows\system32\jureg.exe" [2007-04-07 02:56 54936]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 22:52 49152]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 11:22 517768]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-09 12:23 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-04-11 21:50 2957824]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2008-05-02 08:26 1962128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
"GrpConv"="grpconv -o" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2008-03-24 11:48 5724184]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 22:40:10 210520]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-01-13 19:12:18 67128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E4FCBFAC-19EF-44E5-A036-485CB0BE127D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{27FB6ED0-6CFA-4800-805B-7B8B9904D797}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{134071CE-D8E7-432B-B06F-8CE33EE9B8EE}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{5E4F2BEC-E7C2-4E87-956B-60CFCDE21B07}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{18ED7BA4-FEF1-4DCB-835B-C982EB7678C4}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{92B9E409-B6DC-44EB-9579-4BBFB1004E9B}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{40EDABA8-B681-4A4B-92F7-DE3539BB296A}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{DFE5295C-3BCA-4E2E-8F45-854F498AE586}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{6E7E50F5-D6DC-424E-A805-EC922C71E5DC}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{440C66E8-5E04-4239-A21E-F301781C0CDF}C:\\program files\\windows sidebar\\sidebar.exe"= UDP:C:\program files\windows sidebar\sidebar.exe:Volet Windows
"UDP Query User{5D43A5EB-3BA4-413E-98B2-4AA29B0171E9}C:\\program files\\windows sidebar\\sidebar.exe"= TCP:C:\program files\windows sidebar\sidebar.exe:Volet Windows
"{911162BB-27A8-4385-9022-F5BBCD3D7BD7}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{3827976E-8FE6-4A45-A319-47BE1B83589E}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{ADE4CAA0-430A-452C-BBBD-A1332AC66E8E}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{027A7669-15DB-45E5-9E69-345122661B6E}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"TCP Query User{11EBCDAC-4D32-4BA3-93B5-6379988F0B20}C:\\program files\\logitech\\desktop messenger\\8876480\\program\\logitechdesktopmessenger.exe"= UDP:C:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe:Logitech Desktop Messenger
"UDP Query User{807B5A2F-2761-4A54-8191-03B4203F471F}C:\\program files\\logitech\\desktop messenger\\8876480\\program\\logitechdesktopmessenger.exe"= TCP:C:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe:Logitech Desktop Messenger
"{9C7CAD32-6269-467D-A087-17DC48D54170}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{99609E9D-9528-4B68-9A96-51E681C4C6A2}C:\\program files\\bitdownload\\bitdownload.exe"= UDP:C:\program files\bitdownload\bitdownload.exe:BitDownload
"UDP Query User{E4AB56DC-8DBC-425A-A30F-6D3155E38485}C:\\program files\\bitdownload\\bitdownload.exe"= TCP:C:\program files\bitdownload\bitdownload.exe:BitDownload
"TCP Query User{E4CA437C-12AB-42A0-A9BF-ADFD68F6A5CD}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{ED0C63DB-1846-4A57-9509-F5B33DC6EED0}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{DDD4114F-3540-4631-B49C-5FF2CDE0242B}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{75D799C1-57CF-497D-AF46-4E94C49EAE8D}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{0F305B92-0BF1-4664-9A99-7731C1F7BEF0}C:\\program files\\windows sidebar\\sidebar.exe"= UDP:C:\program files\windows sidebar\sidebar.exe:Volet Windows
"UDP Query User{76BAEAC6-50B2-4D8F-AA3E-C159511524CD}C:\\program files\\windows sidebar\\sidebar.exe"= TCP:C:\program files\windows sidebar\sidebar.exe:Volet Windows
"TCP Query User{2A739031-2B90-4B7A-980A-F4D27C7FCEBC}C:\\program files\\warcraft iii\\war3.exe"= UDP:C:\program files\warcraft iii\war3.exe:Warcraft III
"UDP Query User{4C614532-9F24-4DE0-B23B-356324074D09}C:\\program files\\warcraft iii\\war3.exe"= TCP:C:\program files\warcraft iii\war3.exe:Warcraft III
"TCP Query User{D07AE4D1-3FC8-411D-A055-C9C29223461E}C:\\program files\\warcraft iii\\war3.exe"= UDP:C:\program files\warcraft iii\war3.exe:Warcraft III
"UDP Query User{89E4115C-2E53-47A0-AE1E-5B471AC62F71}C:\\program files\\warcraft iii\\war3.exe"= TCP:C:\program files\warcraft iii\war3.exe:Warcraft III
"TCP Query User{1D57DB06-6391-413D-9A58-694D57724CFA}C:\\program files\\screamer radio\\screamer.exe"= UDP:C:\program files\screamer radio\screamer.exe:Screamer Radio
"UDP Query User{B0AEDEE1-2D70-48D7-8AEB-5F144B858416}C:\\program files\\screamer radio\\screamer.exe"= TCP:C:\program files\screamer radio\screamer.exe:Screamer Radio
"TCP Query User{17D8812F-2851-4E6A-B77F-AC63F72397B0}C:\\users\\hermann\\wow-2.0.0-frfr-installer-downloader.exe"= Disabled:UDP:C:\users\hermann\wow-2.0.0-frfr-installer-downloader.exe:wow-2.0.0-frfr-installer-downloader.exe
"UDP Query User{CDAC9B03-9B6B-4B5E-B0E5-19790477FF29}C:\\users\\hermann\\wow-2.0.0-frfr-installer-downloader.exe"= Disabled:TCP:C:\users\hermann\wow-2.0.0-frfr-installer-downloader.exe:wow-2.0.0-frfr-installer-downloader.exe
"TCP Query User{527506DE-F120-4D61-9430-BA3478A7AB7C}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{6ACFDFC2-C8A0-434C-9A97-B98A079CD5C9}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{D814659E-A13F-4358-9DCD-B9282F271A57}C:\\users\\hermann\\desktop\\utorrent.exe"= UDP:C:\users\hermann\desktop\utorrent.exe:utorrent.exe
"UDP Query User{9A5FDE96-3822-43D1-AB6E-1BE755E31915}C:\\users\\hermann\\desktop\\utorrent.exe"= TCP:C:\users\hermann\desktop\utorrent.exe:utorrent.exe
"TCP Query User{5B4D5CF4-328A-42A7-9627-78A60F3D5942}C:\\users\\hermann\\program files\\utorrent\\utorrent.exe"= UDP:C:\users\hermann\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{931E2520-DB3F-4E66-91D0-CF9DA3291817}C:\\users\\hermann\\program files\\utorrent\\utorrent.exe"= TCP:C:\users\hermann\program files\utorrent\utorrent.exe:utorrent.exe
"TCP Query User{B4B54935-FC39-40E4-BF51-DC06B13BA4A3}C:\\users\\hermann\\program files\\utorrent\\utorrent.exe"= UDP:C:\users\hermann\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{F3644E2F-4588-455E-A77C-781C0713D947}C:\\users\\hermann\\program files\\utorrent\\utorrent.exe"= TCP:C:\users\hermann\program files\utorrent\utorrent.exe:utorrent.exe
"TCP Query User{22487B17-FB20-4A26-8435-03B100C7D2E4}C:\\program files\\world of warcraft\\wow-1.12.0-frfr-downloader.exe"= UDP:C:\program files\world of warcraft\wow-1.12.0-frfr-downloader.exe:Blizzard Downloader
"UDP Query User{2A9ACB70-1338-41EC-B567-99C79B05501E}C:\\program files\\world of warcraft\\wow-1.12.0-frfr-downloader.exe"= TCP:C:\program files\world of warcraft\wow-1.12.0-frfr-downloader.exe:Blizzard Downloader
"TCP Query User{010E3F87-C804-4965-B78D-2DAD78578C1C}C:\\users\\hermann\\desktop\\torrent\\worms 4 mayhem\\crack\\rld-w4m\\worms 4 mayhem.exe"= UDP:C:\users\hermann\desktop\torrent\worms 4 mayhem\crack\rld-w4m\worms 4 mayhem.exe:worms 4 mayhem.exe
"UDP Query User{6CC0445A-2B28-4B83-9CEE-8AFBC47E5EF3}C:\\users\\hermann\\desktop\\torrent\\worms 4 mayhem\\crack\\rld-w4m\\worms 4 mayhem.exe"= TCP:C:\users\hermann\desktop\torrent\worms 4 mayhem\crack\rld-w4m\worms 4 mayhem.exe:worms 4 mayhem.exe
"{EEE4C71F-60B9-4427-9627-5DAF42239118}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{CA0AC3A5-5555-47D8-BF4B-F83A828F1D1F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{63E03C36-5125-4B73-BC7F-BFB2B4D9174C}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 0 (0x0)

S1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-03-29 19:31]
S1 sp_rsdrv2;Spyware Terminator Driver 2;C:\Windows\system32\drivers\sp_rsdrv2.sys [2008-04-11 21:50]
S2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
S2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32]
S3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-08-14 00:07]
S3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2008-02-19 10:13]
S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\Windows\system32\DRIVERS\WlanBZXP.sys [2006-03-21 17:28]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

*Newly Created Service* - ECACHE
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-01 16:29:04 C:\Windows\Tasks\User_Feed_Synchronization-{7AEDADEC-69AE-44A0-8785-6A3A89907BEA}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-02 18:24:19
Windows 6.0.6001 Service Pack 1 NTFS

Balayage processus cachés ...

Balayage caché autostart entries ...

Balayage des fichiers cachés ...

Scan terminé avec succès
Les fichiers cachés: 0

**************************************************************************
.
Temps d'accomplissement: 2008-05-02 18:24:56
ComboFix-quarantined-files.txt 2008-05-02 16:24:46

Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.

241 --- E O F --- 2008-05-02 03:05:08
0
Utilisateur anonyme
 
je crois que combofix l'a eu, reposte un raport hijackthis tout neuf stp...
0
leim78 Messages postés 56 Statut Membre 2
 
voila
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:38:47, on 02/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Safe mode

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://gamespace.daemon-tools.cc/fra/home

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F3350D6-BC02-41AA-BC84-E870DD39E6F2}: NameServer = 192.168.1.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
0
Utilisateur anonyme
 
Tu peus cocher et fixer cette ligne, elle est inutile
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

télacharge aussi sdfix et suis en ce tuto pour son l'utilisation
https://www.malekal.com/slenfbot-still-an-other-irc-bot/

Ensuite une fois que tu as fais ca tu refais un raport HIjackthi ...
0
leim78 Messages postés 56 Statut Membre 2
 
voila
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:07:06, on 02/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Safe mode

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://gamespace.daemon-tools.cc/fra/home

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F3350D6-BC02-41AA-BC84-E870DD39E6F2}: NameServer = 192.168.1.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
0
Utilisateur anonyme
 
slaut

bon ca m'as pas l'air pas mal ca mais je pas sure a 100% que c'est completement propre
tu as toujours des problemes avec ton ordi ou c'est terminé?
éxplique comment c'est maintenant...
0
leim78 Messages postés 56 Statut Membre 2
 
c est bon sa fonctionne normalement le problème est résolu merci a toi blablate je ne sait pas se que j aurais fait sans toi merci encore
0
Utilisateur anonyme
 
a bien tant mieux mais attend c'est pas fini..

1 ) il faudrait que tu recréer un point de restauration tout neuf pour pas que ça réapparaisse
dans menu démarrer/ordinateur/propriété system/parametres systeme avancés/protection du systèm
a point de restauration tu décoches tes disques, puis appliquer/ok et tu redémarre,
une fois redémarré tu rechoche pour réactiver la restauration de ton système

2) télécharge tools cleaner , ça va enlever les traces des logiciels de désinfection, si tu n'es pas sure de se que ca affiche avant d'éffacer poste le raport
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

3) installe ccleaner et fait un nettoyage et une réparation avec, n'hesite pas non plus a l'utiliser tout les soir avant d'éteindre
https://www.ccleaner.com/

3) installe un vrai parefeu aussi..
http://www.commentcamarche.net/telecharger/logiciel 38 firewall

4:) tu peus cocher et fixer ces lignes dans hijackthis

R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

et n'utilise pas trop internet explorer si tu veus être tranquille, il vaut mieux utiliser firefox...
0
leim78 Messages postés 56 Statut Membre 2
 
c est bon j ai fait tout ce que tu a dit et maintenant c est terminer ?
il y aurai pas un patch pour mettre le pare feu comodo en français
0
Utilisateur anonyme
 
salut
oui lol ca devrais etre bon maintenant et non c'est dommage il n'y a pas encore comodo 3 en francais...
La verssion 2 disponible sur leut site est en francais elle si tu veus
http://www.personalfirewall.comodo.com/download_firewall.html

Il faudrait aussi que tu évite d'utiliser pas ta cession administrateur, utilise une cession limité plutot avec de bon mot de passe alphanumérique et tu serras tranquille...
ta consommation de mémoire est revenu a combien?
0
galaxie245
 
slt tout a fait normal la memoire est utiliser pour le cache disque quand une applic demande le cache est reduit voila
0