Win32 Zlob-bmv

Résolu
rumi Messages postés 62 Statut Membre -  
 Utilisateur anonyme -
Bonjour,
mon ordinateur n'arrête pas d'affiher des msg comme quoi il est infecté de spyware et il y a à chaque fois des fênetres qui s'ouvrent avec des pubs de tout genre d'antivirus, j'ai également des pop-up qui s'ouvrent tout seul.
Si qlq'un pourrait bien m'aider car je ne sais pas trop quoi faire. merci

voici mon rapport hijackthis :

Logfile of HijackThis v1.99.1
Scan saved at 21:03:16, on 20/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NetProject\scit.exe
C:\Program Files\NetProject\sbmntr.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\NetProject\scm.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\NetProject\sbsm.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HijackThis\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
O2 - BHO: (no name) - {6860A44B-5D3E-433D-A7B5-D517F810D0E7} - C:\Program Files\NetProject\sbmdl.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: InternetProgram - {88C9B3C7-06B6-5C05-CFEC-C09DBC10CC30} - C:\Program Files\InternetProgram\InternetProgram-2.dll
O2 - BHO: (no name) - {8FD66659-A7AF-4641-9999-C56607D3A0AB} - (no file)
O2 - BHO: adzgalore - {994B5FB4-0103-44A6-B6B3-C73572B362BC} - C:\WINDOWS\system32\nsn359.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: cpmsky.biz browser optimizer - {BCA95E31-1FBF-4F84-8F23-1BA653007A1E} - C:\WINDOWS\system32\cpmsky.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SM_IAN] C:\Program Files\AdvancedCleaner Free\ian_monitor.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PostSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\cpmsky.dll" DllStart
O4 - HKLM\..\Run: [VirusHeat 4.3] "C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.exe" /h
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [Registry Helper] "C:\Program Files\Registry Helper\RegistryHelper.Exe" /boot
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bijoy2003.lnk = C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.iefixgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.iefixgate.com/redirect.php (file missing)
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} (3DVista Viewer Control) - http://www.3dvista.com/downloads/viewer3dv.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

40 réponses

Utilisateur anonyme
 
Tu as une belle collection


Bonjour/Bonsoir
• Ne pas surfer ailleurs que sur le site
• Couper MSN ou tout autre connexion hormis celle sur le site
• Appliquer exactement et dans l'ordre les procédures indiquées.
• Au cas ou plusieurs intervenants se manifestent, en choisir un et un seul.

• Rester devant la machine en rafraichissant souvent le forum pour voir les nouvelles réponses.
• Répondre sans attendre à toutes les questions posées dans l'ordre ou elles ont étés posées
• Soyez précis dans vos réponses. Tenez vous en au sujet et rien qu'au sujet.
• A proscrire : le language SMS.

• Ne pas quitter tant qu'il n'est pas dit explicitement que le problème est résolu ou qu'il
dépasse les compétences de celui ou ceux qui vous aident.
• N'ouvrez pas plusieurs discussions sur le même sujet sauf si on vous le demande
(Problème non résolu. Ca arrive)

• Ne pas s'impatienter. L'analyse d'un rapport et la recherche de solutions
appropriées prends un certain temps.
Inutile donc de reposter le même message. Nous ne vous oublions pas,
nous vous cherchons une solution

• Ne pas oublier : nous sommes bénévoles.
Nous mangeons, nous dormons, nous travaillons, nous avons une vie de famille aussi.


Préalable
• Vider la corbeille
• Fermer toutes les applications

================ PareFeu XP - Vista ===================
• Si un autre pare-feu que celui de windows est installé, vérifier qu'il est actif et passer à l'étape CCleaner

• Sinon

pour activer/désactiver le Pare-feu Vista
pour activer/désactiver le Pare-feu Xp le Pare-feu Vista

• Activer le pare-Feu si ce n'est déjà fait

===================== CCLEANER ========================

Nettoyage avec CCleaner
On va commencer par faire un peu le ménage

• Télécharger CCLeaner et l'installer sur le bureau en refusant l'installation de la barre Yahoo.

• Fermer toutes les applications
• Lancer CCLeaner
S'il n'est pas en Français cliquer sur Options, Setting, Language
et sélectionner Français
• cocher dans le menu Nettoyeur - onglet Windows :
Internet Explorer: Fichiers Internet Temporaires, Cookies
• Système: Vider la Poubelle, Fichiers Temporaires, Presse-papiers
• Avancé: Vieilles données du Prefetch
• Décocher dans le menu Options - sous-menu Avancé :
Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures
• Cocher dans le menu Nettoyeur - onglet Applications : Internet: Sun Java
• Cocher , si cela est possible, dans le menu Nettoyeur - onglet Applications :
Firefox/Mozilla: Cache Internet, Cookies
• Click sur Analyse
• Click sur le bouton Lancer le nettoyage dans le menu Nettoyeur.
• Click sur Registre
• Sélectionner tout
• Click sur Chercher des erreurs (En bas)

Une fois le scan terminé sélectionner tout
• Click sur Réparer les erreurs sélectionnées

==================== HIJACKTHIS ======================

Désisntaller la version actuelle qui n'est pas la dernière.

HijackThis

• Télécharger HijackThis
• Installer HijackThis en se laissant guider

• Renommer HijackThis.exe en Monjack.exe <== I M P O R T A N T

• Fermer toutes les applications
• Lancer hitjackthis
• Click sur Do a system scan and save a logfile
• Copier/Coller le rapport dans le prochain message puis
• Attendre la suite
_
0
rumi Messages postés 62 Statut Membre
 
je ne vois pas l'onglet "registre" dans CCleaner, c'est situé où?
0
Utilisateur anonyme
 
Ce n'est pas un onglet, c'est sur la gauche la deuxième icone en partant du haut entre nettoyeur et Outils

_
0
rumi Messages postés 62 Statut Membre
 
Merci. Voici le rapport :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:40:19, on 21/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NetProject\scit.exe
C:\Program Files\NetProject\sbmntr.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\NetProject\scm.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\NetProject\sbsm.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\HPZipm12.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - (no file)
O2 - BHO: (no name) - {6860A44B-5D3E-433D-A7B5-D517F810D0E7} - C:\Program Files\NetProject\sbmdl.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: InternetProgram - {88C9B3C7-06B6-5C05-CFEC-C09DBC10CC30} - C:\Program Files\InternetProgram\InternetProgram-2.dll
O2 - BHO: (no name) - {8FD66659-A7AF-4641-9999-C56607D3A0AB} - (no file)
O2 - BHO: (no name) - {994B5FB4-0103-44A6-B6B3-C73572B362BC} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: cpmsky.biz browser optimizer - {BCA95E31-1FBF-4F84-8F23-1BA653007A1E} - C:\WINDOWS\system32\cpmsky.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PostSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\cpmsky.dll" DllStart
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bijoy2003.lnk = C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.iefixgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.iefixgate.com/redirect.php (file missing)
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} (3DVista Viewer Control) - http://www.3dvista.com/downloads/viewer3dv.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O22 - SharedTaskScheduler: hyperproduction - {9d19a1a9-3cdf-4f15-a5ca-ea3905febded} - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
 
Tu n'as pas fait ça

• Renommer HijackThis.exe en Monjack.exe <== I M P O R T A N T

C'est important car certaines infections se cachent à HJ si celui-ci n'est pas renommé.

Reposte un rapport HitJackThis une fois fait.

_
0
rumi Messages postés 62 Statut Membre
 
Est ce que là c'est bon ? j'essaie de renommer mais il y a tjrs le nom hijackthis qui reste

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:14:57, on 21/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NetProject\scit.exe
C:\Program Files\NetProject\sbmntr.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\NetProject\scm.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\NetProject\sbsm.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\Desktop\Monjack\Monjack.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - (no file)
O2 - BHO: (no name) - {6860A44B-5D3E-433D-A7B5-D517F810D0E7} - C:\Program Files\NetProject\sbmdl.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: InternetProgram - {88C9B3C7-06B6-5C05-CFEC-C09DBC10CC30} - C:\Program Files\InternetProgram\InternetProgram-2.dll
O2 - BHO: (no name) - {8FD66659-A7AF-4641-9999-C56607D3A0AB} - (no file)
O2 - BHO: (no name) - {994B5FB4-0103-44A6-B6B3-C73572B362BC} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: cpmsky.biz browser optimizer - {BCA95E31-1FBF-4F84-8F23-1BA653007A1E} - C:\WINDOWS\system32\cpmsky.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PostSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\cpmsky.dll" DllStart
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bijoy2003.lnk = C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.iefixgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.iefixgate.com/redirect.php (file missing)
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} (3DVista Viewer Control) - http://www.3dvista.com/downloads/viewer3dv.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O22 - SharedTaskScheduler: hyperproduction - {9d19a1a9-3cdf-4f15-a5ca-ea3905febded} - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
0
Utilisateur anonyme
 
C'est bon.

Je regarde et je te dis quoi.

_
0
Utilisateur anonyme
 
(Imprimer la procédure car une partie se fera sans Internet)

=================== SMITFRAUDFIX ======================

Télécharger SmitfraudFix (de S!ri)

Etape 1 : Recherche

• Mettre le fichier SmitfraudFix.exe, téléchargé préalablement, sur le Bureau Windows.
• Double click sur SmitfraudFix.exe pour lancer l'outil.
• Après l'affichage du menu, taper 1 puis faire Entrée pour rechercher les fichiers responsables de l'infection.
Le rapport se trouve à la racine de la partition système (en général il s'agit de C: ) dans le fichier rapport.txt
• Copier/Coller le rapport dans le prochain message

_
Etape 2 : Nettoyage:

• Redémarrer l'ordinateur en mode sans échec (au démarrage de l'ordinateur,
après le test du matériel par le BIOS, alors que l'écran est noir,
tapoter sur la touche de fonction F8 (ou F5 dans certains cas))
• Double click sur SmitfraudFix.exe
• Sélectionner 2 et presser Entrée dans le menu pour supprimer les fichiers responsables de l'infection.
• A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presser Entrée afin de débloquer
le fond d'écran et supprimer les clés de registre de l'infection.
• Le correctif déterminera si le fichier wininet.dll est infecté.
• A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
pour remplacer le fichier corrompu.
• Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage.
Le rapport se trouve à la racine de la partition système (en général il s'agit de C: )
dans le fichier rapport.txt. Le Copier/Coller dans le prochain message + Rapport HJ
0
rumi Messages postés 62 Statut Membre
 
Rapport hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:43:28, on 21/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\Monjack\Monjack.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: InternetProgram - {88C9B3C7-06B6-5C05-CFEC-C09DBC10CC30} - C:\Program Files\InternetProgram\InternetProgram-2.dll
O2 - BHO: (no name) - {8FD66659-A7AF-4641-9999-C56607D3A0AB} - (no file)
O2 - BHO: (no name) - {994B5FB4-0103-44A6-B6B3-C73572B362BC} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: cpmsky.biz browser optimizer - {BCA95E31-1FBF-4F84-8F23-1BA653007A1E} - C:\WINDOWS\system32\cpmsky.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PostSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\cpmsky.dll" DllStart
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bijoy2003.lnk = C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} (3DVista Viewer Control) - http://www.3dvista.com/downloads/viewer3dv.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O22 - SharedTaskScheduler: hyperproduction - {9d19a1a9-3cdf-4f15-a5ca-ea3905febded} - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
0
rumi Messages postés 62 Statut Membre
 
est ce que c'est bon là ?
0
Utilisateur anonyme
 
Well.

Envoie moi un rapport HitJackThis.

_
0
rumi Messages postés 62 Statut Membre
 
voici le nouveau rapport :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:31:20, on 21/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\Monjack\Monjack.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: InternetProgram - {88C9B3C7-06B6-5C05-CFEC-C09DBC10CC30} - C:\Program Files\InternetProgram\InternetProgram-2.dll
O2 - BHO: (no name) - {8FD66659-A7AF-4641-9999-C56607D3A0AB} - (no file)
O2 - BHO: (no name) - {994B5FB4-0103-44A6-B6B3-C73572B362BC} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: cpmsky.biz browser optimizer - {BCA95E31-1FBF-4F84-8F23-1BA653007A1E} - C:\WINDOWS\system32\cpmsky.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PostSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\cpmsky.dll" DllStart
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bijoy2003.lnk = C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} (3DVista Viewer Control) - http://www.3dvista.com/downloads/viewer3dv.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O22 - SharedTaskScheduler: hyperproduction - {9d19a1a9-3cdf-4f15-a5ca-ea3905febded} - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
0
Utilisateur anonyme
 
======================= BT Fix ==========================

• Téléchargez BTFix (par bibi26)
• Décompresser l'archive (clique droit sur l'archive -> extraire tout) sur le Bureau.
Il doit y avoir maintenant un dossier du nom de BTFix.
• Sur le Bureau, ouvrir le dossier BTFix.
• Double-click sur le fichier BTFix.exe.
• Click sur Rechercher
• En fin de procédure il affiche le rapport.
• Copier/Coller le rapport dans le prochain message

-------- Désinfection

• Ouvrir BTFix.
• Cliquer sur Nettoyer.
• Un rapport va apparaître, le copier/coller dans la prochaine réponse.
• Copier/coller un nouveau rapport HijacThis

_
0
rumi Messages postés 62 Statut Membre
 
BTFix 1.088 (par bibi26) - 21/03/2008 17:10:02 - Nettoyage - Mode normal
Lancé depuis C:\Documents and Settings\Administrator\Desktop\BTFix\BTFix\BTFix.exe

---> Fichiers/dossiers supprimés (Première passe)

- Fichiers temporaires effacés
- C:\WINDOWS\system32\WhoisCL.exe
- C:\Program Files\InternetProgram\
- C:\Documents and Settings\Administrator\Application Data\ShoppingReport\cs\db\
- C:\Documents and Settings\Administrator\Application Data\ShoppingReport\cs\dwld\
- C:\Documents and Settings\Administrator\Application Data\ShoppingReport\cs\report\
- C:\Documents and Settings\Administrator\Application Data\ShoppingReport\cs\res1\
- C:\Documents and Settings\Administrator\Application Data\ShoppingReport\cs\
- C:\Documents and Settings\Administrator\Application Data\ShoppingReport\

---> Nettoyage terminé

hijackthis rapport :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:12:34, on 21/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Documents and Settings\Administrator\Desktop\Monjack\Monjack.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8FD66659-A7AF-4641-9999-C56607D3A0AB} - (no file)
O2 - BHO: (no name) - {994B5FB4-0103-44A6-B6B3-C73572B362BC} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: cpmsky.biz browser optimizer - {BCA95E31-1FBF-4F84-8F23-1BA653007A1E} - C:\WINDOWS\system32\cpmsky.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PostSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\cpmsky.dll" DllStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bijoy2003.lnk = C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} (3DVista Viewer Control) - http://www.3dvista.com/downloads/viewer3dv.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O22 - SharedTaskScheduler: hyperproduction - {9d19a1a9-3cdf-4f15-a5ca-ea3905febded} - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
0
Utilisateur anonyme
 
On avance

===================== COMBOFIX ========================

Combofix

Installer ComboFix sur le bureau
Note :
Le serveur de téléchargement peut être en surcharge et renvoyer une page d'erreur. Il faut insister.


• Se déconnecter d'internet
• Désactiver seulement pendant l'utilisation de ComboFix, la protection de l'antivirus et de l'antispyware ceux-ci pouvant entraver le bon fonctionnement de combofix
• Fermer toutes les applications en cours
• Double-click sur l'icône qui s'est installé sur le bureau
• Appuyer sur la touche 1 puis sur entrée:
• Laisser Combofix travailler sans se servir de la machine.
• Si ComboFix a besoin de redémarrer la machine, laisser faire.
• Réactiver la protection de l'antivirus et de l'antispyware

• Copier/Coller le rapport généré dans le bloc-note dans le prochain message
(Ce fichier est automatiquement généré et enregistré sous C:\Combofix.txt) et comme d'habitude + rapport HJ
0
rumi Messages postés 62 Statut Membre
 
ComboFix 08-03-20.5 - Administrator 2008-03-21 17:32:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.514 [GMT 1:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\$VAULT$.AVG\Desktop_.ini
C:\Config.Msi\Desktop_.ini
C:\Documents and Settings\Administrator\Application Data\Adobe\Photoshop\6.0\Adobe Photoshop 6 Settings\ImageReady Actions\Desktop_.ini
C:\Documents and Settings\Administrator\Application Data\AntispywareBot
C:\Documents and Settings\Administrator\Application Data\AntispywareBot\Log\2008 Mar 20 - 06_39_16 PM_187.log
C:\Documents and Settings\Administrator\Application Data\AntispywareBot\Log\2008 Mar 20 - 06_39_19 PM_890.log
C:\Documents and Settings\Administrator\Application Data\AntispywareBot\rs.dat
C:\Documents and Settings\Administrator\Application Data\AntispywareBot\Settings\ScanResults.pie
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Shortcut Bar\Office\Desktop_.ini
C:\Documents and Settings\Administrator\Local Settings\Application Data\Sony Ericsson\MMSComposer\Archive\Animations\Desktop_.ini
C:\Documents and Settings\Administrator\Local Settings\Application Data\Sony Ericsson\MMSComposer\Archive\Backgrounds\Desktop_.ini
C:\Documents and Settings\Administrator\Local Settings\Application Data\Sony Ericsson\MMSComposer\Archive\Pictures\Desktop_.ini
C:\Documents and Settings\Administrator\Local Settings\Application Data\Sony Ericsson\MMSComposer\Archive\Sounds\Desktop_.ini
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\FEUVERT\Desktop_.ini
C:\HEROSOFT\Desktop_.ini
C:\HEROSOFT\HERO2001\CODEC\Desktop_.ini
C:\HEROSOFT\HERO2001\Codecs\Desktop_.ini
C:\HEROSOFT\HERO2001\Common\Desktop_.ini
C:\HEROSOFT\HERO2001\Desktop_.ini
C:\HEROSOFT\HERO2001\dllfile\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEBMP\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEBMP\FACE1\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEBMP\Face2\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEBMP\FACE3\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEBMP\Face4\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEPLUG\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEPLUG\newface\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEPLUG\newface\Skin0\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEPLUG\newface\Skin1\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEPLUG\newface\Skin2\Desktop_.ini
C:\HEROSOFT\HERO2001\LOGO\Desktop_.ini
C:\HEROSOFT\HERO2001\Plugins\Desktop_.ini
C:\HEROSOFT\HERO2001\Plugins\ExtResources\Desktop_.ini
C:\HEROSOFT\HERO2001\STHPLUG\Desktop_.ini
C:\Intel\Desktop_.ini
C:\Intel\Logs\Desktop_.ini
C:\Mes t‚l‚chargements\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Esl\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Help\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Help\ENU\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\CMap\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\PFM\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\LanguageNames\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\Proximity\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig\Desktop_.ini
C:\Program Files\Adobe\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Help\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Help\images\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Helpers\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Helpers\Jump To Graphics Editor\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Helpers\Jump To HTML Editor\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Helpers\Preview In\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Legal\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe ImageReady Only\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe ImageReady Only\File Formats\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe ImageReady Only\Filters\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\Automate\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\Extensions\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\File Formats\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\Filters\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\Import-Export\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Digimarc\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Displacement maps\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Effects\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\File Formats\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Filters\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Filters\Lighting Styles\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Import-Export\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Parser\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Brushes\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Color Swatches\Adobe Photoshop Only\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Color Swatches\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Contours\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Custom Shapes\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Duotones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Duotones\Gray-Black Duotones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Duotones\PANTONE(R) Duotones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Duotones\Process Duotones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Quadtones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Quadtones\Gray Quadtones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Quadtones\PANTONE(R) Quadtones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Quadtones\Process Quadtones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\TRITONE\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\TRITONE\Gray Tritones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\TRITONE\PANTONE(R) Tritones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\TRITONE\Process Tritones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Gradients\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Layouts\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Optimized Colors\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Optimized Output Settings\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Optimized Settings\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Patterns\Adobe ImageReady Only\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Patterns\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Patterns\PostScript Patterns\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Photoshop Actions\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Styles\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Textures\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Horizontal Frame\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Simple\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Table\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Table\images\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Vertical Frame\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Required\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Required\ImageReady Default Actions\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Samples\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Samples\Droplets\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Samples\Droplets\ImageReady Droplets\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Samples\Droplets\Photoshop Droplets\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Samples\ImageReady Animations\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\Legal\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\moxplugins\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\Oem\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\tools\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\caticons\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\authoring_wiz\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\custom_window\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\main_window\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\tag_palette\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\widgets\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\workflow_icons\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\database\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\database\odbc\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\layouts\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\locales\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\locales\fr_fr\bitmaps\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\locales\fr_fr\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\locales\fr_fr\upsell\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\locales\fr_fr\upsell\images\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\Desktop_.ini
C:\Program Files\Ahead\CoverDesigner\Desktop_.ini
C:\Program Files\Ahead\CoverDesigner\Templates\Desktop_.ini
C:\Program Files\Ahead\Desktop_.ini
C:\Program Files\Ahead\ImageDrive\Desktop_.ini
C:\Program Files\Ahead\Nero BackItUp\Desktop_.ini
C:\Program Files\Ahead\Nero SoundTrax\Desktop_.ini
C:\Program Files\Ahead\Nero StartSmart\Desktop_.ini
C:\Program Files\Ahead\Nero Toolkit\Desktop_.ini
C:\Program Files\Ahead\Nero Wave Editor\Desktop_.ini
C:\Program Files\Ahead\Nero Wave Editor\Presets\Desktop_.ini
C:\Program Files\Ahead\Nero\CDI\Desktop_.ini
C:\Program Files\Ahead\Nero\Desktop_.ini
C:\Program Files\Ahead\Nero\Uninstall\Desktop_.ini
C:\Program Files\Ahead\WMPBurn\Desktop_.ini
C:\Program Files\Ananda Computers\Bijoy2003\Desktop_.ini
C:\Program Files\Ananda Computers\Desktop_.ini
C:\Program Files\aod\aol\Desktop_.ini
C:\Program Files\aod\Desktop_.ini
C:\Program Files\aod\soaf\Desktop_.ini
C:\Program Files\ATI Technologies\ATI Catalyst Control Center\Desktop_.ini
C:\Program Files\ATI Technologies\ATI HYDRAVISION\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\64\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-PreInstall\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\de\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\en-US\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\en-US\image\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\en-US\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\en-US\jpg\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\es\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\fr\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ja\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ko\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\pt-BR\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ru\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\zh-CHS\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\zh-CHT\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Previews-Common\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\en-US\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\zh_CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\zh_CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Skins\ATI_Classic\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Skins\ATI_Crimson\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Skins\CATALYST_Quicksilver\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Skins\CATALYST_SteelBlue\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Skins\Desktop_.ini
C:\Program Files\ATI Technologies\Desktop_.ini
C:\Program Files\ATI Technologies\UninstallAll\Desktop_.ini
C:\Program Files\Avira\Desktop_.ini
C:\Program Files\CyberLink\Common\Desktop_.ini
C:\Program Files\CyberLink\Desktop_.ini
C:\Program Files\Desktop_.ini
C:\Program Files\Disc2Phone\da\Desktop_.ini
C:\Program Files\Disc2Phone\de\Desktop_.ini
C:\Program Files\Disc2Phone\Desktop_.ini
C:\Program Files\Disc2Phone\es\Desktop_.ini
C:\Program Files\Disc2Phone\fi\Desktop_.ini
C:\Program Files\Disc2Phone\fr\Desktop_.ini
C:\Program Files\Disc2Phone\it\Desktop_.ini
C:\Program Files\Disc2Phone\nb-NO\Desktop_.ini
C:\Program Files\Disc2Phone\nl\Desktop_.ini
C:\Program Files\Disc2Phone\nn-NO\Desktop_.ini
C:\Program Files\Disc2Phone\no\Desktop_.ini
C:\Program Files\Disc2Phone\pt-BR\Desktop_.ini
C:\Program Files\Disc2Phone\Readme\Desktop_.ini
C:\Program Files\Disc2Phone\Readme\HTML_ASSETS\Desktop_.ini
C:\Program Files\Disc2Phone\sv\Desktop_.ini
C:\Program Files\Disc2Phone\zh-CHS\Desktop_.ini
C:\Program Files\Disc2Phone\zh-CHT\Desktop_.ini
C:\Program Files\DivX\Desktop_.ini
C:\Program Files\DivX\DivX Content Uploader\Desktop_.ini
C:\Program Files\DivX\DivX Converter\Microsoft.VC80.CRT\Desktop_.ini
C:\Program Files\DivX\DivX Converter\Microsoft.VC80.MFC\Desktop_.ini
C:\Program Files\DivX\DivX Player\Skins\Desktop_.ini
C:\Program Files\DivX\DivX Web Player\Desktop_.ini
C:\Program Files\DivX\DivX Web Player\Microsoft.VC80.CRT\Desktop_.ini
C:\Program Files\DivX\DivX Web Player\Skins\Desktop_.ini
C:\Program Files\Google\Common\Desktop_.ini
C:\Program Files\Google\Common\Google Updater\Desktop_.ini
C:\Program Files\Google\Desktop_.ini
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\Desktop_.ini
C:\Program Files\Google\GoogleToolbarNotifier\Desktop_.ini
C:\Program Files\Google\Installers\Desktop_.ini
C:\Program Files\Grisoft\AVG7\Desktop_.ini
C:\Program Files\Grisoft\Desktop_.ini
C:\Program Files\Intel Desktop Board\Desktop_.ini
C:\Program Files\Intel Desktop Board\HECI_allOS_3.0.28.1060_PC\Desktop_.ini
C:\Program Files\Intel Desktop Board\HECI_allOS_3.0.28.1060_PC\HECI\Desktop_.ini
C:\Program Files\Intel Desktop Board\HECI_allOS_3.0.28.1060_PC\x64\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\srvrtm\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\srvrtm\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2k_xp\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2k_xp\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2k3\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2k3\jpn\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2k3\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2ksp4\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2ksp4\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\xpsp1\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\xpsp1\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\xpsp2\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\xpsp2\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\STACGUI\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\WDM\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Desktop_.ini
C:\Program Files\Intel\ANS\Desktop_.ini
C:\Program Files\Intel\Desktop_.ini
C:\Program Files\Intel\DMIX\Desktop_.ini
C:\Program Files\Intel\DMIX\Hlp\Desktop_.ini
C:\Program Files\Intel\DMIX\Resource\Desktop_.ini
C:\Program Files\Intel\DMIX\uninst\Desktop_.ini
C:\Program Files\Intel\InfInst\Desktop_.ini
C:\Program Files\Intel\NCS2\Agent\Desktop_.ini
C:\Program Files\Intel\NCS2\Desktop_.ini
C:\Program Files\Intel\NCS2\WMIProv\Desktop_.ini
C:\Program Files\Intel\NCS2\WMIProv\MOF\Desktop_.ini
C:\Program Files\Microsoft ActiveSync\Desktop_.ini
C:\Program Files\Microsoft Office\Desktop_.ini
C:\Program Files\Microsoft Office\media\cagcat\1033\Desktop_.ini
C:\Program Files\Microsoft Office\media\cagcat\Desktop_.ini
C:\Program Files\Microsoft Office\media\cagcat10\1033\Desktop_.ini
C:\Program Files\Microsoft Office\media\cagcat10\Desktop_.ini
C:\Program Files\Microsoft Office\media\Desktop_.ini
C:\Program Files\Microsoft Office\media\office10\1033\Desktop_.ini
C:\Program Files\Microsoft Office\media\office10\autoshap\Desktop_.ini
C:\Program Files\Microsoft Office\media\office10\bullets\Desktop_.ini
C:\Program Files\Microsoft Office\media\office10\Desktop_.ini
C:\Program Files\Microsoft Office\media\office10\lines\Desktop_.ini
C:\Program Files\Microsoft Office\Office\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office\1034\Desktop_.ini
C:\Program Files\Microsoft Office\Office\1036\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Addins\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Bitmaps\Dbwiz\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Bitmaps\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Bitmaps\Styles\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Borders\Desktop_.ini
C:\Program Files\Microsoft Office\Office\bots\Desktop_.ini
C:\Program Files\Microsoft Office\Office\bots\fpcount\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Convert\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Convert\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Desktop_.ini
C:\Program Files\Microsoft Office\Office\forms\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office\forms\Desktop_.ini
C:\Program Files\Microsoft Office\Office\fpclass\Desktop_.ini
C:\Program Files\Microsoft Office\Office\HTML\Desktop_.ini
C:\Program Files\Microsoft Office\Office\images\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Library\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Queries\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Samples\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Shortcut Bar\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Shortcut Bar\Office\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Startup\Desktop_.ini
C:\Program Files\Microsoft Office\Office\tutorial\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Xlators\Desktop_.ini
C:\Program Files\Microsoft Office\Office\XLStart\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\botstyle\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\DataServices\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\webcomp\bcentral\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\webcomp\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\webcomp\expedia\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\webcomp\msnbc\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1036\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\3082\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\AccessWeb\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Addins\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Bitmaps\Dbwiz\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Bitmaps\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Bitmaps\Styles\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Borders\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\bots\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\bots\fpcount\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Broadcast\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Convert\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Convert\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\forms\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\forms\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\fpclass\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\HTML\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\HTML\XMLLinks\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\HTML\XMLLinks\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\images\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Library\Analysis\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Library\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Library\Solver\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Macros\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Media\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Migration\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Queries\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Samples\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Shortcut Bar\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Shortcut Bar\Office\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Startup\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\VS Runtime\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\VS Runtime\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\VS Runtime\schemas\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\VS Runtime\schemas\html\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\VS Runtime\schemas\xml\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Xlators\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\XLStart\Desktop_.ini
C:\Program Files\Microsoft Office\Stationery\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Stationery\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\arcs.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\bars.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\blocks.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\blueprnt.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\capsules.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\downtown.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\expeditn.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\highway.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\neon.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\normal.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\poetic.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\street.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\sweets.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\DocLibs\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\DocLibs\doclib1.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\DocLibs\doclib2.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\bantoc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\footer.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\footnote.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\header.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\horzsplt.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\navwtoc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\threelev.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\toc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\topdown.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\vertsplt.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\1center.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\1cheads.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\1cleft.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\1cright.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\2ceven.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\2cmenul.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\2cmenur.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\2cstagr.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\3c2stagl.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\3ceven.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\3cmenuc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\3cmenul.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\3csidbar.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\4ccenter.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\4cstagc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\4cstagl.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\biblio.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\confirm.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\faq.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\feedback.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\guestbk.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\normal.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\photo.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\reguser.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\search.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\toc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\vtiform.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\album.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\album.wiz\horizontal\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\album.wiz\montage\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\album.wiz\slideshow\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\album.wiz\vertical\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\custsupp.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\custsupp.tem\images\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\empty.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\msimport.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\normal.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\onet.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\personal.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\personal.tem\images\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\project.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\project.tem\images\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\vtidb.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\vtidisc.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\vtipres.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\MseNewFileItems\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\Presentation Designs\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Common\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Common\IDE\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Common\IDE\IDE98\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Common\IDE\IDE98\MSE\1033\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Common\IDE\IDE98\MSE\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Desktop_.ini
C:\Program Files\Mozilla Firefox\chrome\Desktop_.ini
C:\Program Files\Mozilla Firefox\components\Desktop_.ini
C:\Program Files\Mozilla Firefox\defaults\autoconfig\Desktop_.ini
C:\Program Files\Mozilla Firefox\defaults\Desktop_.ini
C:\Program Files\Mozilla Firefox\defaults\pref\Desktop_.ini
C:\Program Files\Mozilla Firefox\defaults\profile\chrome\Desktop_.ini
C:\Program Files\Mozilla Firefox\defaults\profile\Desktop_.ini
C:\Program Files\Mozilla Firefox\Desktop_.ini
C:\Program Files\Mozilla Firefox\dictionaries\Desktop_.ini
C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\Desktop_.ini
C:\Program Files\Mozilla Firefox\extensions\Desktop_.ini
C:\Program Files\Mozilla Firefox\greprefs\Desktop_.ini
C:\Program Files\Mozilla Firefox\plugins\Desktop_.ini
C:\Program Files\Mozilla Firefox\res\Desktop_.ini
C:\Program Files\Mozilla Firefox\res\dtd\Desktop_.ini
C:\Program Files\Mozilla Firefox\res\entityTables\Desktop_.ini
C:\Program Files\Mozilla Firefox\res\fonts\Desktop_.ini
C:\Program Files\Mozilla Firefox\res\html\Desktop_.ini
C:\Program Files\Mozilla Firefox\uninstall\Desktop_.ini
C:\Program Files\Mozilla Firefox\updates\[u]0[/u]\Desktop_.ini
C:\Program Files\Mozilla Firefox\updates\Desktop_.ini
C:\Program Files\MSN Gaming Zone\Desktop_.ini
C:\Program Files\MSN Messenger\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\10\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\1028\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\1046\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\11\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\12\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\16\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\17\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\18\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\19\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\20\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\22\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\25\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\29\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\31\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\4\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\6\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\7\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\8\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\9\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\Desktop_.ini
C:\Program Files\MSXML 4.0\Desktop_.ini
C:\Program Files\Online Services\Desktop_.ini
C:\Program Files\Real\Desktop_.ini
C:\Program Files\Real\RealPlayer\CDBurning\Desktop_.ini
C:\Program Files\Real\RealPlayer\Desktop_.ini
C:\Program Files\Real\RealPlayer\Devices\Desktop_.ini
C:\Program Files\Real\RealPlayer\Firstrun\Desktop_.ini
C:\Program Files\Real\RealPlayer\Firstrun\localguide_files\Desktop_.ini
C:\Program Files\Real\RealPlayer\lang\Desktop_.ini
C:\Program Files\Real\RealPlayer\library\Desktop_.ini
C:\Program Files\Real\RealPlayer\Netscape6\Desktop_.ini
C:\Program Files\Real\RealPlayer\plugins\Desktop_.ini
C:\Program Files\Real\RealPlayer\producer\Desktop_.ini
C:\Program Files\Real\RealPlayer\producer\plugins\Desktop_.ini
C:\Program Files\Real\RealPlayer\producer\Tools\Desktop_.ini
C:\Program Files\Real\RealPlayer\rpplugins\Desktop_.ini
C:\Program Files\Real\RealPlayer\Setup\accesspoints\Desktop_.ini
C:\Program Files\Real\RealPlayer\Setup\Desktop_.ini
C:\Program Files\Real\RealPlayer\templates\Desktop_.ini
C:\Program Files\Sony Ericsson\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Connection Wizard\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Device Manager\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\File Manager\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Image Editor\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Archive\Animations\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Archive\Backgrounds\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Archive\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Archive\Pictures\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Archive\Sounds\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Help\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\language\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\language\MMSComposer\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Messages\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Skins\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\work\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Mobile Networking Wizard\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Notifier\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\OCS\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Sync Station\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Sync Station\forms\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Telecalib\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Telecalib\Log Settings\Desktop_.ini
C:\Program Files\SopCast\ActiveX\Desktop_.ini
C:\Program Files\SopCast\Desktop_.ini
C:\Program Files\Uninstall Information\Desktop_.ini
C:\Program Files\Winamp\Desktop_.ini
C:\Program Files\Winamp\Plugins\avs\Desktop_.ini
C:\Program Files\Winamp\Plugins\avs\Winamp 5 Picks\Desktop_.ini
C:\Program Files\Winamp\Plugins\Desktop_.ini
C:\Program Files\Winamp\Plugins\DSP_SPS\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\wacs\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\wacs\jpgload\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\about\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\checkbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\combobox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\dropdownlist\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\historyeditbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\menubutton\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\msgbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\pathpicker\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\popupmenu\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\statusbar\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\tabsheet\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\titlebox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\tooltips\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\fonts\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\garbage\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\menu\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\Scripts\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\window\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\groups\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\button\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\editbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\slider\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\standardframe\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\text\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\titlebar\Desktop_.ini
C:\Program Files\Winamp\Plugins\Milkdrop\Desktop_.ini
C:\Program Files\Winamp\Plugins\ml\Desktop_.ini
C:\Program Files\Winamp\Skins\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\about\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\notifier\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\player\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\scripts\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\shade\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\standardframe\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\titlebar\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\window\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\xml\Desktop_.ini
C:\Program Files\WinRAR\Desktop_.ini
C:\Program Files\WinRAR\Formats\Desktop_.ini
C:\Program Files\xerox\Desktop_.ini
C:\Program Files\xerox\nwwia\Desktop_.ini
C:\RECYCLER\Desktop_.ini
C:\TempEI4\Desktop_.ini
C:\WINDOWS\system32\epmworker.exe.exe
C:\WINDOWS\Tasks.\AntiSpywareBot Scheduled Scan.job
E:\RECYCLER\Desktop_.ini

----- BITS: Possible infected sites -----

hxxp://77.91.228.186
.
((((((((((((((((((((((((( Files Created from 2008-02-21 to 2008-03-21 )))))))))))))))))))))))))))))))
.

2008-03-21 12:32 . 2008-03-21 12:36 3,956 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-21 12:31 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-03-21 12:31 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-03-21 12:31 . 2008-03-14 09:09 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-03-21 12:31 . 2008-03-15 17:16 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-03-21 12:31 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-03-21 12:31 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-03-21 12:31 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-03-21 11:37 . 2008-03-21 12:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-21 11:34 . 2008-03-21 11:34 352,092 --a------ C:\cc_20080321_1134.reg
2008-03-21 11:18 . 2008-03-21 11:18 <DIR> d-------- C:\Program Files\CCleaner
2008-03-20 18:47 . 2008-03-20 18:47 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-03-20 17:07 . 2008-03-20 17:07 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\winpcdoctor
2008-03-20 17:01 . 2008-03-20 17:44 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-20 16:12 . 2008-03-20 16:12 261,896 --a------ C:\Documents and Settings\Administrator\Application Data\setup_en[1].exe
2008-03-15 15:36 . 2008-03-15 15:36 80,121 --a------ C:\WINDOWS\system32\adzgalore-remove.exe
2008-03-15 15:36 . 2008-03-15 15:36 40,713 --a------ C:\WINDOWS\system32\cpmsky-uninst.exe
2008-03-07 14:58 . 2008-03-07 14:58 60,416 --a------ C:\WINDOWS\system32\cpmsky.dll
2008-03-05 17:12 . 2003-01-10 10:56 30,921 --a------ C:\WINDOWS\system32\drivers\SQCaptur.sys
2008-03-05 17:12 . 2003-01-10 09:30 25,449 --a------ C:\WINDOWS\system32\drivers\SQCamD.sys
2008-03-02 15:49 . 2008-03-15 16:31 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-02-29 13:01 . 2008-02-29 13:01 244 --ah----- C:\sqmnoopt08.sqm
2008-02-29 13:01 . 2008-02-29 13:01 232 --ah----- C:\sqmdata08.sqm
2008-02-21 03:11 . 2008-02-21 03:11 3,162 --a------ C:\WINDOWS\system32\dtu_fr.qm
2008-02-21 03:05 . 2008-02-21 03:05 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-02-21 03:05 . 2008-02-21 03:05 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-02-21 03:05 . 2008-02-21 03:05 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-02-21 03:05 . 2008-02-21 03:05 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2008-02-21 03:05 . 2008-02-21 03:05 9,878 --a------ C:\WINDOWS\system32\dsm_fr.qm
2008-02-21 03:05 . 2008-02-21 03:05 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2008-02-21 03:03 . 2008-02-21 03:03 630,784 --a------ C:\WINDOWS\system32\divxdec.ax
2008-02-21 03:03 . 2008-02-21 03:03 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
2008-02-21 03:03 . 2008-02-21 03:03 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-21 03:03 . 2008-02-21 03:03 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-02-21 03:03 . 2008-02-21 03:03 8,835 --a------ C:\WINDOWS\system32\dpufr.qm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-21 15:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\OpenOffice.org2
2008-03-21 11:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-20 22:46 --------- d-----w C:\Program Files\NCH Swift Sound
2008-03-20 22:40 --------- d-----w C:\Program Files\Norton Security Scan
2008-03-20 22:38 --------- d-----w C:\Program Files\Accent EXCEL Password Recovery
2008-03-20 18:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-03-20 16:51 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-16 21:36 --------- d-----w C:\Program Files\Java
2008-03-06 17:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-22 12:42 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-20 13:30 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-02-13 11:56 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia Multimedia Player
2008-02-12 15:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Registry Helper
2008-02-12 15:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-02-12 12:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-02-12 12:27 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Suite
2008-02-09 18:51 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2008-02-09 18:50 --------- d-----w C:\Program Files\Windows Media Components
2008-02-09 18:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-02-09 18:49 --------- d-----w C:\Program Files\Ulead Systems
2008-02-09 18:49 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-09 18:39 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-02-09 18:39 --------- d-----w C:\Program Files\Nokia
2008-02-09 18:39 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-02-09 18:39 --------- d-----w C:\Program Files\Common Files\Nokia
2008-02-09 18:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-02-07 20:49 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-03 00:08 414,272 ----a-w C:\WINDOWS\system32\DivXc32f.dll
2008-02-03 00:08 414,272 ----a-w C:\WINDOWS\system32\DivXc32.dll
2008-01-29 00:48 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-28 12:05 --------- d-----w C:\Program Files\Logitech
2008-01-28 12:05 --------- d-----w C:\Program Files\Common Files\FotoWire
2008-01-28 12:05 --------- d-----w C:\Documents and Settings\Administrator\Application Data\FotoWire
2008-01-28 12:03 81,920 ------r C:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2008-01-28 12:03 --------- d-----w C:\Program Files\Common Files\Logitech
2007-09-23 10:40 675,880 ----a-w C:\Documents and Settings\Administrator\avcenter.exe.exe
2007-09-20 10:32 43,314 ----a-w C:\Documents and Settings\Administrator\UninstWA.exe.exe
2007-09-12 11:42 2,457,600 ----a-w C:\Documents and Settings\Administrator\Photoshop Album Starter Edition.exe.exe
2007-09-07 13:44 323,584 ----a-w C:\Documents and Settings\Administrator\ddtester.exe.exe
2007-09-02 17:37 9,164,192 ----a-w C:\Documents and Settings\Administrator\EXCEL.EXE.exe
2007-09-02 17:37 5,974,136 ----a-w C:\Documents and Settings\Administrator\POWERPNT.EXE.exe
2007-08-31 11:10 54,048 ----a-w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2007-08-27 12:33 316,832 ----a-w C:\Documents and Settings\Administrator\SETLANG.EXE.exe
2007-08-26 22:56 837,632 ----a-w C:\Documents and Settings\Administrator\STHSDVD.EXE.exe
2007-08-26 22:56 814,080 ----a-w C:\Documents and Settings\Administrator\STHSVCD.EXE.exe
2007-08-26 22:56 40,448 ----a-w C:\Documents and Settings\Administrator\UNINST32.exe.exe
2007-08-26 22:17 83,360 ----a-w C:\Documents and Settings\Administrator\OSA.EXE.exe
2007-08-26 22:16 2,660,472 ----a-w C:\Documents and Settings\Administrator\FRONTPG.EXE.exe
2007-08-26 17:49 65,536 ----a-w C:\Docume
0
rumi Messages postés 62 Statut Membre
 
je recolle le rapport combofix car j'ai l'impression qu'il manque qlq chose.

ComboFix 08-03-20.5 - Administrator 2008-03-21 17:32:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.514 [GMT 1:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\$VAULT$.AVG\Desktop_.ini
C:\Config.Msi\Desktop_.ini
C:\Documents and Settings\Administrator\Application Data\Adobe\Photoshop\6.0\Adobe Photoshop 6 Settings\ImageReady Actions\Desktop_.ini
C:\Documents and Settings\Administrator\Application Data\AntispywareBot
C:\Documents and Settings\Administrator\Application Data\AntispywareBot\Log\2008 Mar 20 - 06_39_16 PM_187.log
C:\Documents and Settings\Administrator\Application Data\AntispywareBot\Log\2008 Mar 20 - 06_39_19 PM_890.log
C:\Documents and Settings\Administrator\Application Data\AntispywareBot\rs.dat
C:\Documents and Settings\Administrator\Application Data\AntispywareBot\Settings\ScanResults.pie
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Shortcut Bar\Office\Desktop_.ini
C:\Documents and Settings\Administrator\Local Settings\Application Data\Sony Ericsson\MMSComposer\Archive\Animations\Desktop_.ini
C:\Documents and Settings\Administrator\Local Settings\Application Data\Sony Ericsson\MMSComposer\Archive\Backgrounds\Desktop_.ini
C:\Documents and Settings\Administrator\Local Settings\Application Data\Sony Ericsson\MMSComposer\Archive\Pictures\Desktop_.ini
C:\Documents and Settings\Administrator\Local Settings\Application Data\Sony Ericsson\MMSComposer\Archive\Sounds\Desktop_.ini
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\FEUVERT\Desktop_.ini
C:\HEROSOFT\Desktop_.ini
C:\HEROSOFT\HERO2001\CODEC\Desktop_.ini
C:\HEROSOFT\HERO2001\Codecs\Desktop_.ini
C:\HEROSOFT\HERO2001\Common\Desktop_.ini
C:\HEROSOFT\HERO2001\Desktop_.ini
C:\HEROSOFT\HERO2001\dllfile\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEBMP\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEBMP\FACE1\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEBMP\Face2\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEBMP\FACE3\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEBMP\Face4\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEPLUG\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEPLUG\newface\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEPLUG\newface\Skin0\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEPLUG\newface\Skin1\Desktop_.ini
C:\HEROSOFT\HERO2001\FACEPLUG\newface\Skin2\Desktop_.ini
C:\HEROSOFT\HERO2001\LOGO\Desktop_.ini
C:\HEROSOFT\HERO2001\Plugins\Desktop_.ini
C:\HEROSOFT\HERO2001\Plugins\ExtResources\Desktop_.ini
C:\HEROSOFT\HERO2001\STHPLUG\Desktop_.ini
C:\Intel\Desktop_.ini
C:\Intel\Logs\Desktop_.ini
C:\Mes t‚l‚chargements\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Esl\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Help\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Help\ENU\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\CMap\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\PFM\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\LanguageNames\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\Proximity\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig\Desktop_.ini
C:\Program Files\Adobe\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Help\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Help\images\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Helpers\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Helpers\Jump To Graphics Editor\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Helpers\Jump To HTML Editor\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Helpers\Preview In\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Legal\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe ImageReady Only\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe ImageReady Only\File Formats\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe ImageReady Only\Filters\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\Automate\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\Extensions\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\File Formats\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\Filters\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Adobe Photoshop Only\Import-Export\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Digimarc\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Displacement maps\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Effects\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\File Formats\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Filters\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Filters\Lighting Styles\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Import-Export\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Plug-Ins\Parser\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Brushes\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Color Swatches\Adobe Photoshop Only\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Color Swatches\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Contours\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Custom Shapes\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Duotones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Duotones\Gray-Black Duotones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Duotones\PANTONE(R) Duotones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Duotones\Process Duotones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Quadtones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Quadtones\Gray Quadtones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Quadtones\PANTONE(R) Quadtones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\Quadtones\Process Quadtones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\TRITONE\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\TRITONE\Gray Tritones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\TRITONE\PANTONE(R) Tritones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Duotones\TRITONE\Process Tritones\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Gradients\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Layouts\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Optimized Colors\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Optimized Output Settings\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Optimized Settings\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Patterns\Adobe ImageReady Only\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Patterns\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Patterns\PostScript Patterns\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Photoshop Actions\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Styles\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\Textures\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Horizontal Frame\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Simple\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Table\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Table\images\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Presets\WebContactSheet\Vertical Frame\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Required\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Required\ImageReady Default Actions\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Samples\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Samples\Droplets\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Samples\Droplets\ImageReady Droplets\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Samples\Droplets\Photoshop Droplets\Desktop_.ini
C:\Program Files\Adobe\Photoshop 6.0\Samples\ImageReady Animations\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\Legal\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\moxplugins\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\Oem\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Apps\tools\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\caticons\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\authoring_wiz\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\custom_window\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\main_window\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\tag_palette\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\widgets\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\combined_bitmaps\workflow_icons\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\database\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\database\odbc\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\layouts\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\locales\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\locales\fr_fr\bitmaps\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\locales\fr_fr\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\locales\fr_fr\upsell\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\3.0\Shared_Assets\locales\fr_fr\upsell\images\Desktop_.ini
C:\Program Files\Adobe\Photoshop Album Edition D‚couverte\Desktop_.ini
C:\Program Files\Ahead\CoverDesigner\Desktop_.ini
C:\Program Files\Ahead\CoverDesigner\Templates\Desktop_.ini
C:\Program Files\Ahead\Desktop_.ini
C:\Program Files\Ahead\ImageDrive\Desktop_.ini
C:\Program Files\Ahead\Nero BackItUp\Desktop_.ini
C:\Program Files\Ahead\Nero SoundTrax\Desktop_.ini
C:\Program Files\Ahead\Nero StartSmart\Desktop_.ini
C:\Program Files\Ahead\Nero Toolkit\Desktop_.ini
C:\Program Files\Ahead\Nero Wave Editor\Desktop_.ini
C:\Program Files\Ahead\Nero Wave Editor\Presets\Desktop_.ini
C:\Program Files\Ahead\Nero\CDI\Desktop_.ini
C:\Program Files\Ahead\Nero\Desktop_.ini
C:\Program Files\Ahead\Nero\Uninstall\Desktop_.ini
C:\Program Files\Ahead\WMPBurn\Desktop_.ini
C:\Program Files\Ananda Computers\Bijoy2003\Desktop_.ini
C:\Program Files\Ananda Computers\Desktop_.ini
C:\Program Files\aod\aol\Desktop_.ini
C:\Program Files\aod\Desktop_.ini
C:\Program Files\aod\soaf\Desktop_.ini
C:\Program Files\ATI Technologies\ATI Catalyst Control Center\Desktop_.ini
C:\Program Files\ATI Technologies\ATI HYDRAVISION\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\64\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-PreInstall\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\de\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\en-US\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\en-US\image\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\en-US\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\en-US\jpg\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\es\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\fr\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ja\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ko\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\pt-BR\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\ru\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\zh-CHS\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\Welcome\zh-CHT\images\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-Existing\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Full-New\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\zh-CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Light\zh-CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Graphics-Previews-Common\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\cs\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\da\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\de\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\el\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\en-US\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\es\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\fi\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\fr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\hu\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\it\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\ja\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\ko\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\nl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\no\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\pl\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\pt-BR\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\ru\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\sv\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\th\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\tr\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\zh_CHS\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\help\zh_CHT\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Skins\ATI_Classic\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Skins\ATI_Crimson\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Skins\CATALYST_Quicksilver\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Skins\CATALYST_SteelBlue\Desktop_.ini
C:\Program Files\ATI Technologies\ATI.ACE\Skins\Desktop_.ini
C:\Program Files\ATI Technologies\Desktop_.ini
C:\Program Files\ATI Technologies\UninstallAll\Desktop_.ini
C:\Program Files\Avira\Desktop_.ini
C:\Program Files\CyberLink\Common\Desktop_.ini
C:\Program Files\CyberLink\Desktop_.ini
C:\Program Files\Desktop_.ini
C:\Program Files\Disc2Phone\da\Desktop_.ini
C:\Program Files\Disc2Phone\de\Desktop_.ini
C:\Program Files\Disc2Phone\Desktop_.ini
C:\Program Files\Disc2Phone\es\Desktop_.ini
C:\Program Files\Disc2Phone\fi\Desktop_.ini
C:\Program Files\Disc2Phone\fr\Desktop_.ini
C:\Program Files\Disc2Phone\it\Desktop_.ini
C:\Program Files\Disc2Phone\nb-NO\Desktop_.ini
C:\Program Files\Disc2Phone\nl\Desktop_.ini
C:\Program Files\Disc2Phone\nn-NO\Desktop_.ini
C:\Program Files\Disc2Phone\no\Desktop_.ini
C:\Program Files\Disc2Phone\pt-BR\Desktop_.ini
C:\Program Files\Disc2Phone\Readme\Desktop_.ini
C:\Program Files\Disc2Phone\Readme\HTML_ASSETS\Desktop_.ini
C:\Program Files\Disc2Phone\sv\Desktop_.ini
C:\Program Files\Disc2Phone\zh-CHS\Desktop_.ini
C:\Program Files\Disc2Phone\zh-CHT\Desktop_.ini
C:\Program Files\DivX\Desktop_.ini
C:\Program Files\DivX\DivX Content Uploader\Desktop_.ini
C:\Program Files\DivX\DivX Converter\Microsoft.VC80.CRT\Desktop_.ini
C:\Program Files\DivX\DivX Converter\Microsoft.VC80.MFC\Desktop_.ini
C:\Program Files\DivX\DivX Player\Skins\Desktop_.ini
C:\Program Files\DivX\DivX Web Player\Desktop_.ini
C:\Program Files\DivX\DivX Web Player\Microsoft.VC80.CRT\Desktop_.ini
C:\Program Files\DivX\DivX Web Player\Skins\Desktop_.ini
C:\Program Files\Google\Common\Desktop_.ini
C:\Program Files\Google\Common\Google Updater\Desktop_.ini
C:\Program Files\Google\Desktop_.ini
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\Desktop_.ini
C:\Program Files\Google\GoogleToolbarNotifier\Desktop_.ini
C:\Program Files\Google\Installers\Desktop_.ini
C:\Program Files\Grisoft\AVG7\Desktop_.ini
C:\Program Files\Grisoft\Desktop_.ini
C:\Program Files\Intel Desktop Board\Desktop_.ini
C:\Program Files\Intel Desktop Board\HECI_allOS_3.0.28.1060_PC\Desktop_.ini
C:\Program Files\Intel Desktop Board\HECI_allOS_3.0.28.1060_PC\HECI\Desktop_.ini
C:\Program Files\Intel Desktop Board\HECI_allOS_3.0.28.1060_PC\x64\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\srvrtm\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\srvrtm\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2k_xp\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2k_xp\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2k3\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2k3\jpn\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2k3\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2ksp4\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\win2ksp4\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\xpsp1\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\xpsp1\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\xpsp2\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\HDAQFE\xpsp2\us\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\STACGUI\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Audio\DISK1\WDM\Desktop_.ini
C:\Program Files\Intel Desktop Boards\Desktop_.ini
C:\Program Files\Intel\ANS\Desktop_.ini
C:\Program Files\Intel\Desktop_.ini
C:\Program Files\Intel\DMIX\Desktop_.ini
C:\Program Files\Intel\DMIX\Hlp\Desktop_.ini
C:\Program Files\Intel\DMIX\Resource\Desktop_.ini
C:\Program Files\Intel\DMIX\uninst\Desktop_.ini
C:\Program Files\Intel\InfInst\Desktop_.ini
C:\Program Files\Intel\NCS2\Agent\Desktop_.ini
C:\Program Files\Intel\NCS2\Desktop_.ini
C:\Program Files\Intel\NCS2\WMIProv\Desktop_.ini
C:\Program Files\Intel\NCS2\WMIProv\MOF\Desktop_.ini
C:\Program Files\Microsoft ActiveSync\Desktop_.ini
C:\Program Files\Microsoft Office\Desktop_.ini
C:\Program Files\Microsoft Office\media\cagcat\1033\Desktop_.ini
C:\Program Files\Microsoft Office\media\cagcat\Desktop_.ini
C:\Program Files\Microsoft Office\media\cagcat10\1033\Desktop_.ini
C:\Program Files\Microsoft Office\media\cagcat10\Desktop_.ini
C:\Program Files\Microsoft Office\media\Desktop_.ini
C:\Program Files\Microsoft Office\media\office10\1033\Desktop_.ini
C:\Program Files\Microsoft Office\media\office10\autoshap\Desktop_.ini
C:\Program Files\Microsoft Office\media\office10\bullets\Desktop_.ini
C:\Program Files\Microsoft Office\media\office10\Desktop_.ini
C:\Program Files\Microsoft Office\media\office10\lines\Desktop_.ini
C:\Program Files\Microsoft Office\Office\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office\1034\Desktop_.ini
C:\Program Files\Microsoft Office\Office\1036\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Addins\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Bitmaps\Dbwiz\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Bitmaps\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Bitmaps\Styles\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Borders\Desktop_.ini
C:\Program Files\Microsoft Office\Office\bots\Desktop_.ini
C:\Program Files\Microsoft Office\Office\bots\fpcount\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Convert\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Convert\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Desktop_.ini
C:\Program Files\Microsoft Office\Office\forms\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office\forms\Desktop_.ini
C:\Program Files\Microsoft Office\Office\fpclass\Desktop_.ini
C:\Program Files\Microsoft Office\Office\HTML\Desktop_.ini
C:\Program Files\Microsoft Office\Office\images\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Library\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Queries\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Samples\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Shortcut Bar\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Shortcut Bar\Office\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Startup\Desktop_.ini
C:\Program Files\Microsoft Office\Office\tutorial\Desktop_.ini
C:\Program Files\Microsoft Office\Office\Xlators\Desktop_.ini
C:\Program Files\Microsoft Office\Office\XLStart\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\botstyle\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\DataServices\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\webcomp\bcentral\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\webcomp\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\webcomp\expedia\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1033\webcomp\msnbc\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\1036\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\3082\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\AccessWeb\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Addins\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Bitmaps\Dbwiz\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Bitmaps\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Bitmaps\Styles\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Borders\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\bots\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\bots\fpcount\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Broadcast\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Convert\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Convert\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\forms\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\forms\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\fpclass\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\HTML\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\HTML\XMLLinks\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\HTML\XMLLinks\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\images\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Library\Analysis\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Library\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Library\Solver\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Macros\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Media\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Migration\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Queries\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Samples\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Shortcut Bar\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Shortcut Bar\Office\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Startup\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\VS Runtime\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\VS Runtime\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\VS Runtime\schemas\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\VS Runtime\schemas\html\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\VS Runtime\schemas\xml\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\Xlators\Desktop_.ini
C:\Program Files\Microsoft Office\Office10\XLStart\Desktop_.ini
C:\Program Files\Microsoft Office\Stationery\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Stationery\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\arcs.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\bars.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\blocks.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\blueprnt.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\capsules.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\downtown.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\expeditn.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\highway.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\neon.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\normal.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\poetic.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\street.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\css\sweets.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\DocLibs\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\DocLibs\doclib1.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\DocLibs\doclib2.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\bantoc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\footer.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\footnote.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\header.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\horzsplt.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\navwtoc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\threelev.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\toc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\topdown.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Frames\vertsplt.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\1center.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\1cheads.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\1cleft.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\1cright.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\2ceven.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\2cmenul.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\2cmenur.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\2cstagr.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\3c2stagl.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\3ceven.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\3cmenuc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\3cmenul.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\3csidbar.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\4ccenter.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\4cstagc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\4cstagl.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\biblio.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\confirm.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\faq.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\feedback.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\guestbk.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\normal.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\photo.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\reguser.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\search.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\toc.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Pages\vtiform.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\album.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\album.wiz\horizontal\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\album.wiz\montage\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\album.wiz\slideshow\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\album.wiz\vertical\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\custsupp.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\custsupp.tem\images\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\empty.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\msimport.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\normal.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\onet.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\personal.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\personal.tem\images\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\project.tem\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\project.tem\images\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\vtidb.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\vtidisc.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Webs\vtipres.wiz\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\MseNewFileItems\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\Presentation Designs\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Common\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Common\IDE\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Common\IDE\IDE98\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Common\IDE\IDE98\MSE\1033\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Common\IDE\IDE98\MSE\Desktop_.ini
C:\Program Files\Microsoft Visual Studio\Desktop_.ini
C:\Program Files\Mozilla Firefox\chrome\Desktop_.ini
C:\Program Files\Mozilla Firefox\components\Desktop_.ini
C:\Program Files\Mozilla Firefox\defaults\autoconfig\Desktop_.ini
C:\Program Files\Mozilla Firefox\defaults\Desktop_.ini
C:\Program Files\Mozilla Firefox\defaults\pref\Desktop_.ini
C:\Program Files\Mozilla Firefox\defaults\profile\chrome\Desktop_.ini
C:\Program Files\Mozilla Firefox\defaults\profile\Desktop_.ini
C:\Program Files\Mozilla Firefox\Desktop_.ini
C:\Program Files\Mozilla Firefox\dictionaries\Desktop_.ini
C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\Desktop_.ini
C:\Program Files\Mozilla Firefox\extensions\Desktop_.ini
C:\Program Files\Mozilla Firefox\greprefs\Desktop_.ini
C:\Program Files\Mozilla Firefox\plugins\Desktop_.ini
C:\Program Files\Mozilla Firefox\res\Desktop_.ini
C:\Program Files\Mozilla Firefox\res\dtd\Desktop_.ini
C:\Program Files\Mozilla Firefox\res\entityTables\Desktop_.ini
C:\Program Files\Mozilla Firefox\res\fonts\Desktop_.ini
C:\Program Files\Mozilla Firefox\res\html\Desktop_.ini
C:\Program Files\Mozilla Firefox\uninstall\Desktop_.ini
C:\Program Files\Mozilla Firefox\updates\[u]0[/u]\Desktop_.ini
C:\Program Files\Mozilla Firefox\updates\Desktop_.ini
C:\Program Files\MSN Gaming Zone\Desktop_.ini
C:\Program Files\MSN Messenger\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\10\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\1028\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\1046\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\11\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\12\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\16\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\17\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\18\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\19\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\20\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\22\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\25\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\29\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\31\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\4\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\6\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\7\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\8\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\9\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\Desktop_.ini
C:\Program Files\MSXML 4.0\Desktop_.ini
C:\Program Files\Online Services\Desktop_.ini
C:\Program Files\Real\Desktop_.ini
C:\Program Files\Real\RealPlayer\CDBurning\Desktop_.ini
C:\Program Files\Real\RealPlayer\Desktop_.ini
C:\Program Files\Real\RealPlayer\Devices\Desktop_.ini
C:\Program Files\Real\RealPlayer\Firstrun\Desktop_.ini
C:\Program Files\Real\RealPlayer\Firstrun\localguide_files\Desktop_.ini
C:\Program Files\Real\RealPlayer\lang\Desktop_.ini
C:\Program Files\Real\RealPlayer\library\Desktop_.ini
C:\Program Files\Real\RealPlayer\Netscape6\Desktop_.ini
C:\Program Files\Real\RealPlayer\plugins\Desktop_.ini
C:\Program Files\Real\RealPlayer\producer\Desktop_.ini
C:\Program Files\Real\RealPlayer\producer\plugins\Desktop_.ini
C:\Program Files\Real\RealPlayer\producer\Tools\Desktop_.ini
C:\Program Files\Real\RealPlayer\rpplugins\Desktop_.ini
C:\Program Files\Real\RealPlayer\Setup\accesspoints\Desktop_.ini
C:\Program Files\Real\RealPlayer\Setup\Desktop_.ini
C:\Program Files\Real\RealPlayer\templates\Desktop_.ini
C:\Program Files\Sony Ericsson\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Connection Wizard\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Device Manager\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\File Manager\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Image Editor\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Archive\Animations\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Archive\Backgrounds\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Archive\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Archive\Pictures\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Archive\Sounds\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Help\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\language\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\language\MMSComposer\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Messages\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\Skins\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\work\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Mobile Networking Wizard\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Notifier\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\OCS\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Sync Station\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Sync Station\forms\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Telecalib\Desktop_.ini
C:\Program Files\Sony Ericsson\Mobile2\Telecalib\Log Settings\Desktop_.ini
C:\Program Files\SopCast\ActiveX\Desktop_.ini
C:\Program Files\SopCast\Desktop_.ini
C:\Program Files\Uninstall Information\Desktop_.ini
C:\Program Files\Winamp\Desktop_.ini
C:\Program Files\Winamp\Plugins\avs\Desktop_.ini
C:\Program Files\Winamp\Plugins\avs\Winamp 5 Picks\Desktop_.ini
C:\Program Files\Winamp\Plugins\Desktop_.ini
C:\Program Files\Winamp\Plugins\DSP_SPS\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\wacs\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\wacs\jpgload\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\about\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\checkbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\combobox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\dropdownlist\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\historyeditbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\menubutton\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\msgbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\pathpicker\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\popupmenu\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\statusbar\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\tabsheet\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\titlebox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\tooltips\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\fonts\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\garbage\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\menu\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\Scripts\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\window\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\groups\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\button\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\editbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\slider\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\standardframe\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\text\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\titlebar\Desktop_.ini
C:\Program Files\Winamp\Plugins\Milkdrop\Desktop_.ini
C:\Program Files\Winamp\Plugins\ml\Desktop_.ini
C:\Program Files\Winamp\Skins\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\about\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\notifier\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\player\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\scripts\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\shade\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\standardframe\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\titlebar\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\window\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\xml\Desktop_.ini
C:\Program Files\WinRAR\Desktop_.ini
C:\Program Files\WinRAR\Formats\Desktop_.ini
C:\Program Files\xerox\Desktop_.ini
C:\Program Files\xerox\nwwia\Desktop_.ini
C:\RECYCLER\Desktop_.ini
C:\TempEI4\Desktop_.ini
C:\WINDOWS\system32\epmworker.exe.exe
C:\WINDOWS\Tasks.\AntiSpywareBot Scheduled Scan.job
E:\RECYCLER\Desktop_.ini

----- BITS: Possible infected sites -----

hxxp://77.91.228.186
.
((((((((((((((((((((((((( Files Created from 2008-02-21 to 2008-03-21 )))))))))))))))))))))))))))))))
.

2008-03-21 12:32 . 2008-03-21 12:36 3,956 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-21 12:31 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-03-21 12:31 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-03-21 12:31 . 2008-03-14 09:09 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-03-21 12:31 . 2008-03-15 17:16 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-03-21 12:31 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-03-21 12:31 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-03-21 12:31 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-03-21 11:37 . 2008-03-21 12:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-21 11:34 . 2008-03-21 11:34 352,092 --a------ C:\cc_20080321_1134.reg
2008-03-21 11:18 . 2008-03-21 11:18 <DIR> d-------- C:\Program Files\CCleaner
2008-03-20 18:47 . 2008-03-20 18:47 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-03-20 17:07 . 2008-03-20 17:07 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\winpcdoctor
2008-03-20 17:01 . 2008-03-20 17:44 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-20 16:12 . 2008-03-20 16:12 261,896 --a------ C:\Documents and Settings\Administrator\Application Data\setup_en[1].exe
2008-03-15 15:36 . 2008-03-15 15:36 80,121 --a------ C:\WINDOWS\system32\adzgalore-remove.exe
2008-03-15 15:36 . 2008-03-15 15:36 40,713 --a------ C:\WINDOWS\system32\cpmsky-uninst.exe
2008-03-07 14:58 . 2008-03-07 14:58 60,416 --a------ C:\WINDOWS\system32\cpmsky.dll
2008-03-05 17:12 . 2003-01-10 10:56 30,921 --a------ C:\WINDOWS\system32\drivers\SQCaptur.sys
2008-03-05 17:12 . 2003-01-10 09:30 25,449 --a------ C:\WINDOWS\system32\drivers\SQCamD.sys
2008-03-02 15:49 . 2008-03-15 16:31 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-02-29 13:01 . 2008-02-29 13:01 244 --ah----- C:\sqmnoopt08.sqm
2008-02-29 13:01 . 2008-02-29 13:01 232 --ah----- C:\sqmdata08.sqm
2008-02-21 03:11 . 2008-02-21 03:11 3,162 --a------ C:\WINDOWS\system32\dtu_fr.qm
2008-02-21 03:05 . 2008-02-21 03:05 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-02-21 03:05 . 2008-02-21 03:05 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-02-21 03:05 . 2008-02-21 03:05 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-02-21 03:05 . 2008-02-21 03:05 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2008-02-21 03:05 . 2008-02-21 03:05 9,878 --a------ C:\WINDOWS\system32\dsm_fr.qm
2008-02-21 03:05 . 2008-02-21 03:05 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2008-02-21 03:03 . 2008-02-21 03:03 630,784 --a------ C:\WINDOWS\system32\divxdec.ax
2008-02-21 03:03 . 2008-02-21 03:03 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
2008-02-21 03:03 . 2008-02-21 03:03 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-21 03:03 . 2008-02-21 03:03 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-02-21 03:03 . 2008-02-21 03:03 8,835 --a------ C:\WINDOWS\system32\dpufr.qm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-21 15:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\OpenOffice.org2
2008-03-21 11:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-20 22:46 --------- d-----w C:\Program Files\NCH Swift Sound
2008-03-20 22:40 --------- d-----w C:\Program Files\Norton Security Scan
2008-03-20 22:38 --------- d-----w C:\Program Files\Accent EXCEL Password Recovery
2008-03-20 18:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-03-20 16:51 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-16 21:36 --------- d-----w C:\Program Files\Java
2008-03-06 17:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-22 12:42 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-20 13:30 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-02-13 11:56 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia Multimedia Player
2008-02-12 15:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Registry Helper
2008-02-12 15:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-02-12 12:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-02-12 12:27 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Suite
2008-02-09 18:51 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2008-02-09 18:50 --------- d-----w C:\Program Files\Windows Media Components
2008-02-09 18:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-02-09 18:49 --------- d-----w C:\Program Files\Ulead Systems
2008-02-09 18:49 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-09 18:39 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-02-09 18:39 --------- d-----w C:\Program Files\Nokia
2008-02-09 18:39 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-02-09 18:39 --------- d-----w C:\Program Files\Common Files\Nokia
2008-02-09 18:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-02-07 20:49 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-03 00:08 414,272 ----a-w C:\WINDOWS\system32\DivXc32f.dll
2008-02-03 00:08 414,272 ----a-w C:\WINDOWS\system32\DivXc32.dll
2008-01-29 00:48 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-28 12:05 --------- d-----w C:\Program Files\Logitech
2008-01-28 12:05 --------- d-----w C:\Program Files\Common Files\FotoWire
2008-01-28 12:05 --------- d-----w C:\Documents and Settings\Administrator\Application Data\FotoWire
2008-01-28 12:03 81,920 ------r C:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2008-01-28 12:03 --------- d-----w C:\Program Files\Common Files\Logitech
2007-09-23 10:40 675,880 ----a-w C:\Documents and Settings\Administrator\avcenter.exe.exe
2007-09-20 10:32 43,314 ----a-w C:\Documents and Settings\Administrator\UninstWA.exe.exe
2007-09-12 11:42 2,457,600 ----a-w C:\Documents and Settings\Administrator\Photoshop Album Starter Edition.exe.exe
2007-09-07 13:44 323,584 ----a-w C:\Documents and Settings\Administrator\ddtester.exe.exe
2007-09-02 17:37 9,164,192 ----a-w C:\Documents and Settings\Administrator\EXCEL.EXE.exe
2007-09-02 17:37 5,974,136 ----a-w C:\Documents and Settings\Administrator\POWERPNT.EXE.exe
2007-08-31 11:10 54,048 ----a-w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2007-08-27 12:33 316,832 ----a-w C:\Documents and Settings\Administrator\SETLANG.EXE.exe
2007-08-26 22:56 837,632 ----a-w C:\Documents and Settings\Administrator\STHSDVD.EXE.exe
2007-08-26 22:56 814,080 ----a-w C:\Documents and Settings\Administrator\STHSVCD.EXE.exe
2007-08-26 22:56 40,448 ----a-w C:\Documents and Settings\Administrator\UNINST32.exe.exe
2007-08-26 22:17 83,360 ----a-w C:\Documents and Settings\Administrator\OSA.EXE.exe
2007-08-26 22:16 2,660,472 ----
0
rumi Messages postés 62 Statut Membre
 
et voici le rapport hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:44:58, on 21/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Documents and Settings\Administrator\Desktop\Monjack\Monjack.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8FD66659-A7AF-4641-9999-C56607D3A0AB} - (no file)
O2 - BHO: (no name) - {994B5FB4-0103-44A6-B6B3-C73572B362BC} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: cpmsky.biz browser optimizer - {BCA95E31-1FBF-4F84-8F23-1BA653007A1E} - C:\WINDOWS\system32\cpmsky.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [PostSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\cpmsky.dll" DllStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bijoy2003.lnk = C:\Program Files\Ananda Computers\Bijoy2003\Bijoy.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} (3DVista Viewer Control) - http://www.3dvista.com/downloads/viewer3dv.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O22 - SharedTaskScheduler: hyperproduction - {9d19a1a9-3cdf-4f15-a5ca-ea3905febded} - (no file)
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
0
rumi Messages postés 62 Statut Membre
 
je vois sur le forum que vous (boodha) m'avez envoyé un message mais quand je click que je ne vois rien. il y a juste mon dernier message ( le 18ème).
0
Utilisateur anonyme
 
Il faut rafraichir avec la touche F5 ou faire défiler, c'est un bug
0
rumi Messages postés 62 Statut Membre
 
j'ai rafréchi et je ne vois toujours pas le message antérieur à ce message que vous m'avez envoyé.
qu'est ce que je dois faire maintenant ? est ce que je dois attendre ?
merci
0