Probleme de pages de pub

Résolu
cocovani -  
g!rly Messages postés 18462 Statut Contributeur -
Bonjour,
j'ai des pages qui s'ouvrent, me demandant de telecharger virus effaceur et d'autres programmes pour securiser mon pc, ainsi que des pages de pub pour gladiatus, casino,etc
j'ai passé un coup de c cleaner, spybot mais rien y fait ca apparait toujours
si quelqu'un pouvait m'aider, ce serait cool; parce que là je ne trouve pas de solutions.
merci d'avance
je post un rapport hickjack, a tout hasard
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:18:37, on 01/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\HP_Administrateur\Mes documents\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: Shell=
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [java] system.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [40b74df8] rundll32.exe "C:\WINDOWS\system32\cmrqemsk.dll",b
O4 - HKLM\..\Run: [BM43847e64] Rundll32.exe "C:\WINDOWS\system32\gwvwjrbl.dll",s
O4 - HKLM\..\RunServices: [java] system.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Barre d'état système d'ATI CATALYST.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.3.5.cab
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
A voir également:

12 réponses

g!rly Messages postés 18462 Statut Contributeur 406
 
salut,

belle infection !

1

Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
http://www.atribune.org/ccount/click.php?id=4
* Double-clique VundoFix.exe afin de le lancer
* Clique sur le bouton Scan for Vundo
* Lorsque le scan est complété, clique sur le bouton Remove Vundo
* Une invite te demandera si tu veux supprimer les fichiers, clique YES
* Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
* Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK
* Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse

Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".

2

Télécharge combofix.exe (par sUBs) sur ton Bureau.

-> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

-> Double clique combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

NOTE : Le rapport se trouve également ici : C:\Combofix.txt

Avant d'utiliser ComboFix :

-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

Une fois fait, sur ton bureau double-clic sur Combofix.exe.

- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

-> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

Repost egalement un nouveau rapport hijack this stp

@+
0
cocovani
 
ah,merci. ca a lair de mieux marcher donc, je dois te poster les rapports
rapport fix vundo
Symantec Trojan.Vundo Removal Tool 1.5.1
The process "iexplore.exe" might be affected by the threat. It has been suspended.
The process "iexplore.exe" might be affected by the threat. It has been suspended.
The process "iexplore.exe" might be affected by the threat. It has been terminated.
The process "iexplore.exe" might be affected by the threat. It has been terminated.

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine: (not scanned)
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp: (not scanned)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\01\81-{407BF39B-4D65-259F-8465-326B1AABD0EA}-v1-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v81-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\82\25-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v82-{3FBD0880-DA6B-41EF-A959-454BA2F2E894}-v25-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\83\31-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v83-{3FBD0880-DA6B-41EF-A959-454BA2F2E894}-v31-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\84\84-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v84-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v84-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\85\85-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v85-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v85-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\86\86-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v86-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v86-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\87\35-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v87-{3FBD0880-DA6B-41EF-A959-454BA2F2E894}-v35-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\88\88-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v88-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v88-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\89\89-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v89-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v89-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\90\90-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v90-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v90-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\91\91-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v91-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v91-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\92\92-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v92-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v92-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\93\93-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v93-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v93-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\94\94-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v94-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v94-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\95\95-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v95-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v95-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\96\96-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v96-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v96-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\97\51-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v97-{3FBD0880-DA6B-41EF-A959-454BA2F2E894}-v51-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\98\98-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v98-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v98-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\juanalauz@hotmail.fr\DFSR\Staging\CS{407BF39B-4D65-259F-8465-326B1AABD0EA}\99\55-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v99-{3FBD0880-DA6B-41EF-A959-454BA2F2E894}-v55-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\00\1022-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v900-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1022-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\00\1072-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1000-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1072-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\01\1024-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v901-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1024-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\01\1073-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1001-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1073-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\01\15-{B84BBF74-3066-DA79-6CA7-D83180BBE95D}-v1-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v15-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\02\1026-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v902-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1026-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\02\1074-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1002-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1074-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\03\1028-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v903-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1028-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\03\1075-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1003-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1075-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\03\1110-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1103-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1110-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\04\1030-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v904-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1030-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\04\1076-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1004-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1076-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\04\1111-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1104-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1111-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\05\1032-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v905-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1032-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\05\1077-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1005-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1077-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\06\1034-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v906-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1034-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\06\1078-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1006-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1078-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\07\1036-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v907-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1036-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\08\1038-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v908-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1038-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\09\1040-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v909-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1040-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\10\1042-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v910-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1042-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\11\1044-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v911-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1044-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\12\1045-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v912-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1045-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\17\1047-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v917-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1047-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\17\1080-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1017-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1080-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\18\1049-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v918-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1049-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\18\1081-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1018-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1081-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\19\1082-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1019-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1082-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\20\1051-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v920-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1051-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\20\1083-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1020-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1083-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\21\1084-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1021-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1084-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\22\1085-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1022-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1085-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\23\1086-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1023-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1086-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\24\1087-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1024-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1087-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\25\1088-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1025-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1088-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\26\1089-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1026-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1089-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\27\1090-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1027-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1090-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\28\1091-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1028-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1091-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\29\1053-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v929-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1053-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\29\1092-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1029-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1092-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\30\1055-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v930-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1055-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\31\1057-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v931-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1057-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\42\1093-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1042-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1093-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\48\1094-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1048-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1094-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\50\1095-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1050-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1095-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\51\1096-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1051-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1096-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\52\1097-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1052-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1097-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\53\1098-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1053-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1098-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\54\1099-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1054-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1099-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\54\1119-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1454-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1119-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\55\1100-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1055-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1100-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\55\1112-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1455-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1112-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\56\1101-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1056-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1101-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\56\1113-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1456-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1113-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\57\1102-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1057-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1102-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\57\1114-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1457-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1114-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\58\1103-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1058-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1103-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\58\1109-{78AEC0C3-0A3D-4DF9-94B2-7E5943846B24}-v558-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1109-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\58\1122-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1458-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1122-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\59\1104-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1059-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1104-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\59\1115-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1459-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1115-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\60\1105-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1060-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1105-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\60\1116-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1460-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1116-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\61\1106-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1061-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1106-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\61\1117-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1461-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1117-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\62\1107-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1062-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1107-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\62\1118-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1462-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1118-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\63\1108-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1063-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1108-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\63\1120-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1463-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1120-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\64\1121-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1464-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1121-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\69\1079-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1069-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1079-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\87\1059-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v987-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1059-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\88\1060-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v988-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1060-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\89\1061-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v989-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1061-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\90\1062-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v990-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1062-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\91\1063-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v991-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1063-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\91\1123-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1491-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1123-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\92\1064-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v992-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1064-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\92\1124-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1492-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1124-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\93\1065-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v993-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1065-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\93\1125-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1493-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1125-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\94\1066-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v994-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1066-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\94\1126-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1494-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1126-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\95\1067-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v995-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1067-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\95\1127-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1495-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1127-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\96\1058-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v896-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1058-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\96\1068-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v996-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1068-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\96\1128-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v1496-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1128-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\97\1016-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v897-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1016-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\97\1069-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v997-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1069-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\98\1018-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v898-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1018-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\98\1070-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v998-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1070-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\99\1020-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v899-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1020-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\lolamego@hotmail.fr\DFSR\Staging\CS{B84BBF74-3066-DA79-6CA7-D83180BBE95D}\99\1071-{446D3418-FCC9-4DDE-B47E-183E59C1B8E3}-v999-{7F3BCA44-6712-4D6A-8CF4-44898CED6414}-v1071-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\01\11-{E385BA45-78FF-0EFC-89E9-10299AF1F153}-v1-{0645B2E8-AB17-4964-BFA4-FF014415DFCF}-v11-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\29\429-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v429-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v429-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\30\430-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v430-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v430-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\31\431-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v431-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v431-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\32\432-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v432-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v432-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\33\433-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v433-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v433-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\34\434-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v434-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v434-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\35\435-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v435-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v435-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\36\436-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v436-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v436-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\37\437-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v437-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v437-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\38\438-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v438-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v438-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\39\439-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v439-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v439-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\40\440-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v440-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v440-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\41\448-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v441-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v448-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\42\449-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v442-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v449-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\43\443-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v443-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v443-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\44\444-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v444-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v444-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\45\445-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v445-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v445-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\46\446-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v446-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v446-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\47\447-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v447-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v447-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\50\450-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v450-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v450-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\51\451-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v451-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v451-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\52\452-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v452-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v452-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\53\453-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v453-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v453-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\54\454-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v454-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v454-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\55\455-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v455-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v455-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\56\456-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v456-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v456-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\57\457-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v457-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v457-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\58\458-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v458-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v458-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\59\459-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v459-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v459-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\60\460-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v460-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v460-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\61\461-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v461-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v461-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\62\462-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v462-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v462-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\63\463-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v463-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v463-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\64\464-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v464-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v464-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\65\465-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v465-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v465-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\66\466-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v466-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v466-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\67\467-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v467-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v467-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\68\468-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v468-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v468-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\69\469-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v469-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v469-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\70\470-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v470-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v470-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\71\471-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v471-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v471-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\72\472-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v472-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v472-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\73\473-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v473-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v473-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\74\474-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v474-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v474-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\75\475-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v475-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v475-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\76\476-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v476-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v476-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\77\477-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v477-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v477-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\78\478-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v478-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v478-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\79\479-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v479-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v479-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\80\480-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v480-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v480-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\81\481-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v481-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v481-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\82\482-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v482-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v482-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\83\483-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v483-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v483-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\84\484-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v484-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v484-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\85\485-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v485-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v485-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\86\486-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v486-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v486-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\87\487-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v487-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v487-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\88\488-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v488-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v488-Downloaded.frx (WARNING: not scanned, path to long)
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Messenger\wildhonney@hotmail.fr\SharingMetadata\luneloise@hotmail.com\DFSR\Staging\CS{E385BA45-78FF-0EFC-89E9-10299AF1F153}\89\489-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v489-{DFE74152-9D12-45A2-AE4E-D78CA0D2704A}-v489-Downloaded.frx (WARNING: not sca
0
g!rly Messages postés 18462 Statut Contributeur 406
 
re,

je t´ai jamais dit de passer le removal tool de chez symantec

oui post les rapports que je t´avais demandés stp

@+
0
cocovani
 
j'en etais sur de mon etourderie
donc le vundofix ma dit qu'il navait rien trouvé
voici le rappoet combofix
ComboFix 08-06-01.6 - HP_Administrateur 2008-06-02 19:06:48.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.405 [GMT 2:00]
Endroit: C:\Documents and Settings\HP_Administrateur\Bureau\ComboFix.exe
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Menu Démarrer\Online Security Guide.url
.
---- Previous Run -------
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\BM43847e64.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\asvuiuba.dll
C:\WINDOWS\system32\cmrqemsk.dll
C:\WINDOWS\system32\cxgsoiqs.ini
C:\WINDOWS\system32\ddcYsTnK.dll
C:\WINDOWS\system32\fwoembfd.dll
C:\WINDOWS\system32\gwvwjrbl.dll
C:\WINDOWS\system32\iifdbCVo.dll
C:\WINDOWS\system32\jwoupaol.dll
C:\WINDOWS\system32\ksmeqrmc.ini
C:\WINDOWS\system32\loapuowj.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mueogucf.dll
C:\WINDOWS\system32\oVCbdfii.ini
C:\WINDOWS\system32\oVCbdfii.ini2
C:\WINDOWS\system32\pfbypsgr.dll
C:\WINDOWS\system32\puisyans.dll
C:\WINDOWS\system32\pWEfOXyb.ini
C:\WINDOWS\system32\pWEfOXyb.ini2
C:\WINDOWS\system32\qapnvjcr.dll
C:\WINDOWS\system32\qomlMfgD.dll
C:\WINDOWS\system32\rcjvnpaq.ini
C:\WINDOWS\system32\skbkxvvr.dll
C:\WINDOWS\system32\snaysiup.ini
C:\WINDOWS\system32\wDLlmnnn.ini
C:\WINDOWS\system32\wDLlmnnn.ini2
C:\WINDOWS\system32\ycmpffyv.dll
C:\WINDOWS\system32\yvlpnrff.dll
C:\WINDOWS\tmlpcert2007
D:\Autorun.inf

.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-02 to 2008-06-02 ))))))))))))))))))))))))))))))))))))
.

2008-06-01 22:21 . 2008-06-01 22:21 <REP> d--hs---- C:\found.000
2008-06-01 20:09 . 2008-06-01 20:09 <REP> d-------- C:\Documents and Settings\HP_Administrateur\Application Data\Grisoft
2008-06-01 20:09 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-05-19 20:57 . 2008-05-19 20:57 <REP> d-------- C:\VundoFix Backups
2008-05-09 00:05 . 2008-05-09 00:05 <REP> d-------- C:\Documents and Settings\HP_Administrateur\Application Data\Sonic
2008-05-08 20:35 . 2008-05-08 21:28 65 --a------ C:\WINDOWS\3DWarehouseClient.INI
2008-05-04 19:16 . 2008-05-04 19:47 <REP> d-------- C:\Documents and Settings\HP_Administrateur\Application Data\Download Manager
2008-05-03 10:51 . 2003-11-07 01:41 14,604 --a------ C:\WINDOWS\system32\drivers\pfc.sys

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-02 16:15 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\WTablet
2008-06-02 16:13 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-06-01 20:14 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-01 20:14 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-06-01 20:14 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-06-01 20:14 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-01 20:14 --------- d-----w C:\Program Files\Symantec
2008-05-31 22:02 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\uTorrent
2008-05-31 06:36 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-05-19 19:46 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-05-12 22:35 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\AdobeUM
2008-05-09 19:12 --------- d-----w C:\Program Files\adslTV
2008-05-09 11:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-09 10:55 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-03 09:39 --------- d-----w C:\Program Files\Yahoo!
2008-05-03 08:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-01 11:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-25 23:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2008-04-23 15:59 --------- d-----w C:\Program Files\RightMark Memory Analyzer
2008-04-22 20:45 --------- d-----w C:\Program Files\Windows Live
2008-04-21 21:37 --------- d-----w C:\Program Files\CCleaner
2008-04-21 20:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-21 19:50 --------- d-----w C:\Program Files\Any Video Converter Professional
2008-04-21 17:21 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\MyPhoneExplorer
2008-04-21 16:25 --------- d-----w C:\Program Files\ImTOO
2008-04-21 15:55 --------- d-----w C:\Program Files\Fichiers communs\Adobe Systems Shared
2008-04-21 15:21 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\HP
2008-04-20 11:08 --------- d-----w C:\Program Files\MyPhoneExplorer
2008-04-20 00:45 --------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
2008-04-19 23:33 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Leadertech
2008-04-19 21:25 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-19 19:44 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Sony Setup
2008-04-19 19:43 --------- d-----w C:\Program Files\Sony Setup
2008-04-19 17:07 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Teleca
2008-04-19 17:02 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Sony Ericsson
2008-04-19 00:05 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2008-04-19 00:05 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-04-18 23:59 --------- d-----w C:\Program Files\Java
2008-04-18 08:15 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\ma-config.com
2008-04-17 16:32 --------- d-----w C:\Program Files\eMule
2008-04-17 16:32 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\eMule
2008-04-15 19:07 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Apple Computer
2008-04-15 19:04 --------- d-----w C:\Program Files\iTunes
2008-04-15 18:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-13 14:06 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\vlc
2008-04-11 19:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-11 19:22 --------- d-----w C:\Program Files\Lavasoft
2008-04-11 19:21 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-04-11 15:03 --------- d-----w C:\Program Files\Norton Internet Security
2008-04-10 17:36 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Symantec
2008-04-10 17:32 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-09 19:12 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\HPQ
2008-04-08 19:11 --------- d-----w C:\Program Files\InstantStorm
2008-04-08 18:52 --------- d-----w C:\Program Files\QuickTime
2008-04-08 18:27 --------- d-----w C:\Program Files\Replay Converter
2008-04-08 18:25 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-04-08 18:25 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\GetRightToGo
2008-04-08 18:15 --------- d-----w C:\Program Files\KeepV Converter
2008-04-06 10:30 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Ambient Design
2008-04-06 10:23 --------- d-----w C:\Program Files\Ambient Design
2008-04-06 10:09 --------- d-----w C:\Program Files\Tablet
2008-04-04 01:29 --------- d-----w C:\Program Files\Micro Application
2008-04-04 00:01 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\InterVideo
2008-04-03 23:35 --------- d-----w C:\Program Files\Active Data Recovery Services
2008-04-03 19:09 --------- d-----w C:\Program Files\Ontrack
2008-04-03 15:45 --------- d-----w C:\Program Files\ImageShackToolbar
2008-04-02 21:04 --------- d-----w C:\Program Files\Common Files
2008-04-02 19:30 --------- d-----w C:\Program Files\ESTsoft
2008-04-02 19:30 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\ESTsoft
2008-04-02 17:20 --------- d-----w C:\Program Files\FILERECOVERY DEMO
2008-04-02 17:08 286,720 ----a-w C:\WINDOWS\iun507.exe
2008-04-02 16:57 --------- d-----w C:\Program Files\SoftLogica
2008-03-29 11:02 3,532 ----a-w C:\drmHeader.bin
2008-03-26 21:20 558 ---ha-w C:\os466477.bin
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2007-03-09 14:11 119 ----a-w C:\Program Files\satsukidecodersettings.ini
2007-03-09 14:10 3,972 ----a-w C:\Program Files\ffdssetts.reg
2007-03-09 14:10 3,240 ----a-w C:\Program Files\ffdsasetts.reg
2007-03-09 10:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2006-05-04 17:58 251 -c--a-w C:\Program Files\wt3d.ini
2006-05-16 07:39 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
2007-03-09 07:12 27,648 --sha-w C:\WINDOWS\system32\AVSredirect.dll
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-02-06 22:05 349552 --a------ C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-04-10 19:32 116088 --a------ C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E03E4D5-0F28-4427-A975-A6F21E627323}]
C:\WINDOWS\system32\nnnmlLDw.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9CF21E9-812E-4341-ACFE-D9CB2A611AA9}]
C:\WINDOWS\system32\byXOfEWp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll" [2008-02-06 22:05 349552]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2008-02-06 22:05 349552]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 19:37 68856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-10-15 02:51 14864384 C:\WINDOWS\RTHDCPL.EXE]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 23:14 237568]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2004-10-26 00:17 90112]
"PCDrProfiler"="" []
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2008-02-07 00:49 718704]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-03 01:44 61440]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 20:30 139264]
"ftutil2"="ftutil2.dll" [2004-06-07 22:05 106496 C:\WINDOWS\system32\ftutil2.dll]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 21:34 64512]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-01-25 19:47 51048]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-10-02 09:13 57344]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 03:15 77312 C:\WINDOWS\arpwrmsg.exe]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-04-19 02:04 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04 52736]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 08:35 49152]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 07:12 49152]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]

C:\Documents and Settings\Invit‚\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2005-01-01 17:16:33 27136]

C:\Documents and Settings\HP_Administrateur\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 21:16:50 113664]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Barre d'‚tat systŠme d'ATI CATALYST.lnk - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe [2005-10-02 09:13:42 57344]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 07:23:26 282624]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2006-05-14 19:27:00 118784]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2006-08-11 23:53:12 124912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.iac2"= C:\PROGRA~1\REPLAY~1\iac25_32.ax
"vidc.yv12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-10-03 22:57]
R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-10 21:00]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 21:12]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 20:30]
R3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 19:44]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 s816bus;Sony Ericsson Device 816 driver (WDM);C:\WINDOWS\system32\DRIVERS\s816bus.sys [2007-06-19 09:51]
S3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s816mdfl.sys [2007-06-19 09:51]
S3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s816mdm.sys [2007-06-19 09:51]
S3 s816mgmt;Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s816mgmt.sys [2007-06-19 09:51]
S3 s816nd5;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS);C:\WINDOWS\system32\DRIVERS\s816nd5.sys [2007-06-19 09:51]
S3 s816obex;Sony Ericsson Device 816 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s816obex.sys [2007-06-19 09:51]
S3 s816unic;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM);C:\WINDOWS\system32\DRIVERS\s816unic.sys [2007-06-19 09:51]
S3 WN5401;Liteon Wireless LAN PCI 802.11 a/b/g adapter WN5401A;C:\WINDOWS\system32\DRIVERS\wn5401.sys [2005-01-07 02:08]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

*Newly Created Service* - COMHOST
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-20 18:49:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-21 15:49:50 C:\WINDOWS\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- c:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\Main\Mediahub.exe;Sched HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0
"2006-06-11 20:28:19 C:\WINDOWS\Tasks\HubTask 1 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- C:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\Main\Mediahub.exe;Sched HubTask 1 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0
"2008-05-27 14:44:48 C:\WINDOWS\Tasks\Norton Internet Security - Effectuer une analyse complète du système - HP_Administrateur.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
"2008-06-02 17:10:01 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-02 19:08:27
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cachés ...

Balayage caché autostart entries ...

Balayage des fichiers cachés ...


**************************************************************************
.
Temps d'accomplissement: 2008-06-02 19:14:00
ComboFix-quarantined-files.txt 2008-06-02 17:12:57

Pre-Run: 150,043,844,608 octets libres
Post-Run: 150,027,857,920 octets libres

281 --- E O F --- 2008-04-16 21:21:40
0
cocovani > cocovani
 
et le rapport hijack qui a suivi le rapport combofix
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:35:38, on 02/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Documents and Settings\HP_Administrateur\Mes documents\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {0CF5D165-517E-48B6-B3C7-3054A24F8BF6} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: (no name) - {8E03E4D5-0F28-4427-A975-A6F21E627323} - C:\WINDOWS\system32\nnnmlLDw.dll (file missing)
O2 - BHO: (no name) - {F9CF21E9-812E-4341-ACFE-D9CB2A611AA9} - C:\WINDOWS\system32\byXOfEWp.dll (file missing)
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Barre d'état système d'ATI CATALYST.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.3.5.cab
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
0
g!rly Messages postés 18462 Statut Contributeur 406
 
ok

pas grave ;-)

ca a l´air mieux en effet

Fais un scan avec cet antispyware :

Telecharge malwarebytes + tutoriel :

-> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

Tu l´instale; le programme va se mettre automatiquement a jour.

Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

Puis click sur "rechercher".

Laisse le scanner le pc...

Si des elements on ete trouvés > click sur supprimer la selection.

si il t´es demandé de redemarrer > click sur "yes".

A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

Copie et colle le rapport stp.

@+
0
cocovani
 
c'est ennervant de faire des chose sans arriver a comprendre en clair ce qui m'est arrivé mais en tout cas j'etais bien infecté merci encor
voici le rapport
Malwarebytes' Anti-Malware 1.14
Version de la base de données: 815

22:29:29 02/06/2008
mbam-log-6-2-2008 (22-29-29).txt

Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
Eléments examinés: 190737
Temps écoulé: 48 minute(s), 57 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 4
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 23

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0cf5d165-517e-48b6-b3c7-3054a24f8bf6} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\40b74df8 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM43847e64 (Trojan.Agent) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\asvuiuba.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\cmrqemsk.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcYsTnK.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\iifdbCVo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\jwoupaol.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\pfbypsgr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\puisyans.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\qapnvjcr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\qomlMfgD.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\skbkxvvr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\yvlpnrff.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP62\A0035235.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP63\A0036288.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039340.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039341.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039342.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039344.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039345.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039347.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039348.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039349.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039351.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
0
g!rly Messages postés 18462 Statut Contributeur 406
 
ok

repost un nouveau rapport hijack this stp
0
cocovani
 
rapport hicjack this
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:01:30, on 02/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\HP_Administrateur\Mes documents\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: (no name) - {8E03E4D5-0F28-4427-A975-A6F21E627323} - C:\WINDOWS\system32\nnnmlLDw.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {F9CF21E9-812E-4341-ACFE-D9CB2A611AA9} - C:\WINDOWS\system32\byXOfEWp.dll (file missing)
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [java] system.exe
O4 - HKLM\..\RunServices: [java] system.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingC7805] cmd /c del "C:\WINDOWS\system32\byXOfEWp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1993] command /c del "C:\WINDOWS\system32\nnnmlLDw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC943] cmd /c del "C:\WINDOWS\system32\nnnmlLDw.dll_old"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Barre d'état système d'ATI CATALYST.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.3.5.cab
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
g!rly Messages postés 18462 Statut Contributeur 406
 
l´infection c´est developpée...

desinstale spybot puis passe a nouveau combofix et post son rapport stp avec un nouveau rapport hijack this.

@+
0
cocovani
 
ca concorde, car j avais des fenetre de spybot qui s'ouvraient et qui parlaient de modif
ComboFix 08-06-01.6 - HP_Administrateur 2008-06-03 0:05:14.4 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.469 [GMT 2:00]
Endroit: C:\Documents and Settings\HP_Administrateur\Bureau\ComboFix.exe
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

J:\Autorun.inf

.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-02 to 2008-06-02 ))))))))))))))))))))))))))))))))))))
.

2008-06-02 21:30 . 2008-06-02 22:29 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-02 21:30 . 2008-06-02 21:30 <REP> d-------- C:\Documents and Settings\HP_Administrateur\Application Data\Malwarebytes
2008-06-02 21:30 . 2008-06-02 21:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-02 21:30 . 2008-05-30 01:06 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-02 21:30 . 2008-05-30 01:06 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-01 22:21 . 2008-06-01 22:21 <REP> d--hs---- C:\found.000
2008-06-01 20:09 . 2008-06-01 20:09 <REP> d-------- C:\Documents and Settings\HP_Administrateur\Application Data\Grisoft
2008-06-01 20:09 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-05-19 20:57 . 2008-05-19 20:57 <REP> d-------- C:\VundoFix Backups
2008-05-09 00:05 . 2008-05-09 00:05 <REP> d-------- C:\Documents and Settings\HP_Administrateur\Application Data\Sonic
2008-05-08 20:35 . 2008-05-08 21:28 65 --a------ C:\WINDOWS\3DWarehouseClient.INI
2008-05-04 19:16 . 2008-05-04 19:47 <REP> d-------- C:\Documents and Settings\HP_Administrateur\Application Data\Download Manager
2008-05-03 10:51 . 2003-11-07 01:41 14,604 --a------ C:\WINDOWS\system32\drivers\pfc.sys

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-02 21:56 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\WTablet
2008-06-02 21:52 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-02 21:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-02 21:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-02 20:51 --------- d-----w C:\Program Files\Google
2008-06-02 20:50 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-06-02 20:29 --------- d-----w C:\Program Files\MSN Messenger
2008-06-01 20:14 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-01 20:14 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-06-01 20:14 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-06-01 20:14 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-01 20:14 --------- d-----w C:\Program Files\Symantec
2008-05-31 22:02 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\uTorrent
2008-05-31 06:36 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-05-19 19:46 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-05-12 22:35 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\AdobeUM
2008-05-09 19:12 --------- d-----w C:\Program Files\adslTV
2008-05-03 09:39 --------- d-----w C:\Program Files\Yahoo!
2008-05-03 08:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-01 11:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-25 23:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2008-04-23 15:59 --------- d-----w C:\Program Files\RightMark Memory Analyzer
2008-04-22 20:45 --------- d-----w C:\Program Files\Windows Live
2008-04-21 21:37 --------- d-----w C:\Program Files\CCleaner
2008-04-21 20:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-21 19:50 --------- d-----w C:\Program Files\Any Video Converter Professional
2008-04-21 17:21 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\MyPhoneExplorer
2008-04-21 16:25 --------- d-----w C:\Program Files\ImTOO
2008-04-21 15:55 --------- d-----w C:\Program Files\Fichiers communs\Adobe Systems Shared
2008-04-21 15:21 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\HP
2008-04-20 11:08 --------- d-----w C:\Program Files\MyPhoneExplorer
2008-04-20 00:45 --------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
2008-04-19 23:33 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Leadertech
2008-04-19 21:25 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-19 19:44 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Sony Setup
2008-04-19 19:43 --------- d-----w C:\Program Files\Sony Setup
2008-04-19 17:07 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Teleca
2008-04-19 17:02 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Sony Ericsson
2008-04-19 00:05 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2008-04-19 00:05 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-04-18 23:59 --------- d-----w C:\Program Files\Java
2008-04-18 08:15 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\ma-config.com
2008-04-17 16:32 --------- d-----w C:\Program Files\eMule
2008-04-17 16:32 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\eMule
2008-04-15 19:07 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Apple Computer
2008-04-15 19:04 --------- d-----w C:\Program Files\iTunes
2008-04-15 18:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-13 14:06 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\vlc
2008-04-11 19:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-11 19:22 --------- d-----w C:\Program Files\Lavasoft
2008-04-11 19:21 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-04-11 15:03 --------- d-----w C:\Program Files\Norton Internet Security
2008-04-10 17:36 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Symantec
2008-04-10 17:32 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-09 19:12 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\HPQ
2008-04-08 19:11 --------- d-----w C:\Program Files\InstantStorm
2008-04-08 18:52 --------- d-----w C:\Program Files\QuickTime
2008-04-08 18:27 --------- d-----w C:\Program Files\Replay Converter
2008-04-08 18:25 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-04-08 18:25 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\GetRightToGo
2008-04-08 18:15 --------- d-----w C:\Program Files\KeepV Converter
2008-04-06 10:30 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\Ambient Design
2008-04-06 10:23 --------- d-----w C:\Program Files\Ambient Design
2008-04-06 10:09 --------- d-----w C:\Program Files\Tablet
2008-04-04 01:29 --------- d-----w C:\Program Files\Micro Application
2008-04-04 00:01 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\InterVideo
2008-04-03 23:35 --------- d-----w C:\Program Files\Active Data Recovery Services
2008-04-03 19:09 --------- d-----w C:\Program Files\Ontrack
2008-04-03 15:45 --------- d-----w C:\Program Files\ImageShackToolbar
2008-04-02 21:04 --------- d-----w C:\Program Files\Common Files
2008-04-02 19:30 --------- d-----w C:\Program Files\ESTsoft
2008-04-02 19:30 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\ESTsoft
2008-04-02 17:20 --------- d-----w C:\Program Files\FILERECOVERY DEMO
2008-04-02 17:08 286,720 ----a-w C:\WINDOWS\iun507.exe
2008-04-02 16:57 --------- d-----w C:\Program Files\SoftLogica
2008-03-29 11:02 3,532 ----a-w C:\drmHeader.bin
2008-03-26 21:20 558 ---ha-w C:\os466477.bin
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2007-03-09 14:11 119 ----a-w C:\Program Files\satsukidecodersettings.ini
2007-03-09 14:10 3,972 ----a-w C:\Program Files\ffdssetts.reg
2007-03-09 14:10 3,240 ----a-w C:\Program Files\ffdsasetts.reg
2007-03-09 10:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2006-05-04 17:58 251 -c--a-w C:\Program Files\wt3d.ini
2006-05-16 07:39 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
2007-03-09 07:12 27,648 --sha-w C:\WINDOWS\system32\AVSredirect.dll
.

((((((((((((((((((((((((((((( snapshot@2008-06-02_18.44.08.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-02 16:15:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-02 21:56:12 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-02-06 22:05 349552 --a------ C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-04-10 19:32 116088 --a------ C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E03E4D5-0F28-4427-A975-A6F21E627323}]
C:\WINDOWS\system32\nnnmlLDw.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9CF21E9-812E-4341-ACFE-D9CB2A611AA9}]
C:\WINDOWS\system32\byXOfEWp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll" [2008-02-06 22:05 349552]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2008-02-06 22:05 349552]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 19:37 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-10-15 02:51 14864384 C:\WINDOWS\RTHDCPL.EXE]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 23:14 237568]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2004-10-26 00:17 90112]
"PCDrProfiler"="" []
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2008-02-07 00:49 718704]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-03 01:44 61440]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 20:30 139264]
"ftutil2"="ftutil2.dll" [2004-06-07 22:05 106496 C:\WINDOWS\system32\ftutil2.dll]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 21:34 64512]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-01-25 19:47 51048]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-10-02 09:13 57344]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 03:15 77312 C:\WINDOWS\arpwrmsg.exe]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-04-19 02:04 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04 52736]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 08:35 49152]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 07:12 49152]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]

C:\Documents and Settings\Invit‚\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2005-01-01 17:16:33 27136]

C:\Documents and Settings\HP_Administrateur\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 21:16:50 113664]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Barre d'‚tat systŠme d'ATI CATALYST.lnk - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe [2005-10-02 09:13:42 57344]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 07:23:26 282624]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2006-05-14 19:27:00 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.iac2"= C:\PROGRA~1\REPLAY~1\iac25_32.ax
"vidc.yv12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-10-03 22:57]
R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-10 21:00]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 21:12]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 20:30]
R3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 19:44]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 s816bus;Sony Ericsson Device 816 driver (WDM);C:\WINDOWS\system32\DRIVERS\s816bus.sys [2007-06-19 09:51]
S3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s816mdfl.sys [2007-06-19 09:51]
S3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s816mdm.sys [2007-06-19 09:51]
S3 s816mgmt;Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s816mgmt.sys [2007-06-19 09:51]
S3 s816nd5;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS);C:\WINDOWS\system32\DRIVERS\s816nd5.sys [2007-06-19 09:51]
S3 s816obex;Sony Ericsson Device 816 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s816obex.sys [2007-06-19 09:51]
S3 s816unic;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM);C:\WINDOWS\system32\DRIVERS\s816unic.sys [2007-06-19 09:51]
S3 WN5401;Liteon Wireless LAN PCI 802.11 a/b/g adapter WN5401A;C:\WINDOWS\system32\DRIVERS\wn5401.sys [2005-01-07 02:08]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

*Newly Created Service* - COMHOST
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-20 18:49:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-21 15:49:50 C:\WINDOWS\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- c:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\Main\Mediahub.exe;Sched HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0
"2006-06-11 20:28:19 C:\WINDOWS\Tasks\HubTask 1 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- C:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\Main\Mediahub.exe;Sched HubTask 1 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0
"2008-06-02 21:54:07 C:\WINDOWS\Tasks\Norton Internet Security - Effectuer une analyse complète du système - HP_Administrateur.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
"2008-06-02 22:10:00 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-03 00:11:11
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cachés ...

Balayage caché autostart entries ...

Balayage des fichiers cachés ...

Scan terminé avec succès
Les fichiers cachés: 0

**************************************************************************
.
Temps d'accomplissement: 2008-06-03 0:17:58
ComboFix-quarantined-files.txt 2008-06-02 22:17:13
ComboFix2.txt 2008-06-02 17:14:01

Pre-Run: 153,598,709,760 octets libres
Post-Run: 153,625,120,768 octets libres

257 --- E O F --- 2008-04-16 21:21:40


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:26:06, on 03/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\HP_Administrateur\Mes documents\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: (no name) - {8E03E4D5-0F28-4427-A975-A6F21E627323} - C:\WINDOWS\system32\nnnmlLDw.dll (file missing)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {F9CF21E9-812E-4341-ACFE-D9CB2A611AA9} - C:\WINDOWS\system32\byXOfEWp.dll (file missing)
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Barre d'état système d'ATI CATALYST.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.3.5.cab
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
0
g!rly Messages postés 18462 Statut Contributeur 406
 
Salut cocovani,

passe ceci stp

Télécharge Clean:

-> http://www.malekal.com/download/clean.zip

-> Dézippe tout le contenu dans un dossier que tu auras cré au préalable (sur ton bureau par exemple). Double clic sur clean ou clean.cmd choisie l'option 1.

Un rapport va s'ouvrir, copie et colle le contenu sur le forum.

-> pour ceux ou celles qui auraient un doute sur comment deziper un fichier :

http://www.tutopat.com/viewtopic.php?t=933&sid=34215b238376bfb22ef9e8eca9995914

@+
0
cocovani
 
salut,
voici le rapport. et cela me demande d'envoyer un fichier sur un site; mais le site me dit que je n'ai pas choisi de fichier.
est ce important?
merci
C:\WINDOWS\System32\clkcnt.txt -->02/06/2008 17:45:55
C:\WINDOWS\System32\wpa.dbl -->01/06/2008 23:50:30
C:\WINDOWS\System32\S32EVNT1.DLL -->01/06/2008 22:14:20
C:\WINDOWS\System32\MRT.exe -->09/05/2008 23:35:04
C:\WINDOWS\System32\PerfStringBackup.INI -->23/04/2008 17:04:46
C:\WINDOWS\System32\perfh00C.dat -->23/04/2008 17:04:46
C:\WINDOWS\System32\perfh009.dat -->23/04/2008 17:04:46
C:\WINDOWS\System32\perfc00C.dat -->23/04/2008 17:04:46
C:\WINDOWS\System32\perfc009.dat -->23/04/2008 17:04:46
C:\WINDOWS\System32\FNTCACHE.DAT -->20/04/2008 01:38:14
C:\WINDOWS\System32\rmoc3260.dll -->19/04/2008 02:05:03
C:\WINDOWS\System32\pndx5032.dll -->19/04/2008 02:04:52
C:\WINDOWS\System32\pndx5016.dll -->19/04/2008 02:04:52
C:\WINDOWS\System32\pncrt.dll -->19/04/2008 02:04:47
C:\WINDOWS\System32\jupdate-1.6.0_05-b13.log -->19/04/2008 01:59:51
C:\WINDOWS\System32\nscompat.tlb -->15/04/2008 23:25:50
C:\WINDOWS\System32\amcompat.tlb -->15/04/2008 23:25:50
C:\WINDOWS\System32\FLASH.OCX -->11/04/2008 17:14:37
C:\WINDOWS\System32\BASSMOD.dll -->02/04/2008 23:02:49
C:\WINDOWS\System32\TZLog.log -->02/04/2008 06:56:02
C:\WINDOWS\System32\$winnt$.inf -->01/04/2008 19:00:35
C:\WINDOWS\System32\QuickTimeVR.qtx -->28/03/2008 23:37:26
C:\WINDOWS\System32\QuickTime.qts -->28/03/2008 23:37:26
C:\WINDOWS\System32\win32k.sys -->20/03/2008 10:09:22
C:\WINDOWS\System32\mshtml.dll -->01/03/2008 18:28:10

C:\WINDOWS\WindowsUpdate.log -->03/06/2008 17:28:32
C:\WINDOWS\KB950749.log -->03/06/2008 17:23:30
C:\WINDOWS\KB932823-v3.log -->03/06/2008 17:23:16
C:\WINDOWS\wiadebug.log -->03/06/2008 17:16:33
C:\WINDOWS\wiaservc.log -->03/06/2008 17:16:31
C:\WINDOWS\0.log -->03/06/2008 17:15:28
C:\WINDOWS\QTFont.qfn -->03/06/2008 17:14:49
C:\WINDOWS\bootstat.dat -->03/06/2008 17:14:37
C:\WINDOWS\SchedLgU.Txt -->03/06/2008 01:08:33
C:\WINDOWS\system.ini -->03/06/2008 00:11:09
C:\WINDOWS\setupapi.log -->03/06/2008 00:04:30
C:\WINDOWS\BM43847e64.txt -->02/06/2008 17:54:06
C:\WINDOWS\ntbtlog.txt -->01/06/2008 21:41:53
C:\WINDOWS\WININIT.INI -->01/06/2008 18:58:18
C:\WINDOWS\3DWarehouseClient.INI -->08/05/2008 21:28:07
0
g!rly Messages postés 18462 Statut Contributeur 406
 
Tu n´est pas le seul a qui cela arrive...

laisse tomber...

fais ce scan en ligne et post le rapport stp

Fais un scan en ligne Kaspersky avec Internet Explorer :
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
-> Click sur Démarrer Online-Scanner
-> Click maintenant sur J'accepte.
-> Valide l'installation d'un ou de plusieurs ActiveX si c'est nécessaire.
-> Patiente pendant l'installation des Mises à jour.
-> Choisis par la suite l'analyse du Poste de travail.
-> Sauvegarde puis colle le rapport généré en fin d'analyse.

C´est long, mais...

@+
0
cocovani
 
re salut
eh ben , ca fait peur
le rapport
0
cocovani
 
voici le rapport comme il est immense
je t'en envois une partie
Paramètres d'analyse
Analyser avec la base antivirus suivante standard
Analyser les archives vrai
Analyser les bases de messagerie vrai

Cible de l'analyse Poste de travail
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Statistiques de l'analyse
Total d'objets analysés 150392
Nombre de virus trouvés 5
Nombre d'objets infectés 7 / 0
Nombre d'objets suspects 0
Durée de l'analyse 02:52:14

est ce que je dois t'envoyer tout les reste comme ceci:
C:\USERDATA\Application Data\Adobe\Updater\Data\estoolkit1_meta.txt L'objet est verrouillé ignoré

C:\USERDATA\Application Data\Adobe\Updater\Data\helpcenter2.aum L'objet est verrouillé ignoré

C:\USERDATA\Application Data\Adobe\Updater\Data\helpcenter2_meta.txt L'objet est verrouillé ignoré

C:\USERDATA\Application Data\Adobe\Updater\Data\photoshop9-fr_FR-RET.aum L'objet est verrouillé ignoré

C:\USERDATA\Application Data\Adobe\Updater\Data\photoshop9-fr_FR-RET_meta.txt L'objet est verrouillé ignoré

C:\USERDATA\Application Data\Adobe\Workflow\editing.xml L'objet est verrouillé ignoré

C:\USERDATA\Application Data\Adobe\Workflow\projects.xml L'objet est verrouillé ignoré

C:\USERDATA\Application Data\Adobe\Workflow\settings.xml L'objet est verrouillé ignoré

C:\USERDATA\Application Data\Adobe\XMP\FileInfoLibPrefs.txt L'objet est verrouillé ignoré

C:\USERDATA\Application Data\AdobeUM\AcRdB7_0_9.sta L'objet est verrouillé ignoré

parce que y en a 8799 ko mais il sont tous verouillé
là je commence a plus rien comprendre
mais toujours confiance
0
g!rly Messages postés 18462 Statut Contributeur 406
 
Salut,

kaspersky a trouvés des fichiers infectés (5), post le rapport entier, comme ca on va pouvoir les supprimer car lui ne le fait pas...

@+
0
cocovani
 
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, June 04, 2008 10:18:27 PM
Système d'exploitation : Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version : 5.0.83.0
Dernière mise à jour de la base antivirus Kaspersky : 4/06/2008
Enregistrements dans la base antivirus Kaspersky : 736986


Paramètres d'analyse
Analyser avec la base antivirus suivante standard
Analyser les archives vrai
Analyser les bases de messagerie vrai

Cible de l'analyse Poste de travail
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Statistiques de l'analyse
Total d'objets analysés 145576
Nombre de virus trouvés 5
Nombre d'objets infectés 19 / 0
Nombre d'objets suspects 0
Durée de l'analyse 02:44:00

Nom de l'objet infecté Nom du virus Dernière action
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\01 - Morceau 1.mp3.445b7b85.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\02 - Morceau 2.mp3.445b7ba6.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\03 - Morceau 3.mp3.445b7bcc.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\04 - Morceau 4.mp3.445b7bed.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\05 - Morceau 5.mp3.445b7c11.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\06 - Morceau 6.mp3.445b7c27.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\06 - Morceau 6.mp3.44636ad4.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\07 - Morceau 7.mp3.445b7c40.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\08 - Morceau 8.mp3.445b7c5b.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\09 - Morceau 9.mp3.445b7c6e.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\09 - Morceau 9.mp3.44636e56.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\10 - Morceau 10.mp3.445b7c85.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\11 - Morceau 11.mp3.445b7c9a.mmd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0592.JPG.4391706c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0593.JPG.439171b4.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0594.JPG.439171c2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0595.JPG.4391b3b4.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0596.JPG.4391b3e2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0597.JPG.4391b3f6.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0598.JPG.4391b3fa.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0599.JPG.4391b428.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0600.JPG.4391b436.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0601.JPG.4391b456.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0602.JPG.4391b45a.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0603.JPG.4391b480.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0604.JPG.4391b4c0.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0605.JPG.4391b4e2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0608.JPG.43a0553e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0609.JPG.43a05546.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0610.JPG.43a07f4e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0611.JPG.43a07f76.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0613.JPG.43a0801e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0614.JPG.43a0820c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0616.JPG.43a08256.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0617.JPG.43a0827a.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0618.JPG.43a09d6a.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0619.JPG.43a09d82.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0620.JPG.43a09d9c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0625.JPG.43a2af90.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0626.JPG.43a2b194.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0627.JPG.43a2e516.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0628.JPG.43a2e534.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0629.JPG.43a2e8c2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0630.JPG.43a2e8d2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0631.JPG.43a2e8e2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0631_modifiée.JPG.43a2e8e2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0632.JPG.43a2e90e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0633.JPG.43a2e924.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0634.JPG.43a30008.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0635.JPG.43a30058.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0636.JPG.43a3009e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0637.JPG.43a31200.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0639.JPG.43a31cb6.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0640.JPG.43a49fec.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0641.JPG.43a49ffe.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0643.JPG.43a4ae56.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0644.JPG.43a4aea6.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0645.JPG.43a4aee2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0646.JPG.43a4aefe.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0647.JPG.43a4af78.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0648.JPG.43a4b028.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0649.JPG.43a4b110.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0650.JPG.43a55e34.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0661.JPG.43a7ceae.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0662.JPG.43a7cec0.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0666.JPG.43a7daaa.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0667.JPG.43a7dab4.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0668.JPG.43a7dade.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0669.JPG.43a7e190.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0670.JPG.43a7e196.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0672.JPG.43a7e1a2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0673.JPG.43a7e1e4.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0674.JPG.43a7e206.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0675.JPG.43a7e240.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0676.JPG.43a7e26e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0677.JPG.43a7e2b6.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0678.JPG.43a7ea10.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0679.JPG.43a7ea1c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0680.JPG.43a7ea48.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0681.JPG.43a7ea82.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0682.JPG.43a7eab6.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0683.JPG.43a7eaca.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0684.JPG.43a7ead2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0686.JPG.43a7f2ea.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0687.JPG.43a7f30e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0688.JPG.43a7f35e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0689.JPG.43a7f39c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0690.JPG.43a7f3ce.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0691.JPG.43a7f3d4.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0692.JPG.43a80328.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0707.JPG.43abc89e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0709.JPG.43abc990.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0710.JPG.43abc9d0.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0711.JPG.43abca02.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0712.JPG.43abca12.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0713.JPG.43abd070.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0725.JPG.43ac1c74.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0726.JPG.43ad1d50.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0727.JPG.43ad1d7c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0730.JPG.43ad2050.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0731.JPG.43ad2112.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0732.JPG.43ad25f0.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0735.JPG.43ad269e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0736.JPG.43ad26aa.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0737.JPG.43ad26d2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0738.JPG.43ad26de.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0741.JPG.43ad27ec.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0744.JPG.43ad2c02.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0745.JPG.43ad2d52.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0746.JPG.43ad2d60.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0747.JPG.43ad2e0e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0748.JPG.43ad2e3e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0749.JPG.43ad2e4c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0750.JPG.43ad2e54.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0755.JPG.43ad6c62.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0756.JPG.43ad6c74.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0757.JPG.43ad6c90.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0758.JPG.43ad6e14.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0760.JPG.43ae71ce.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0761.JPG.43ae72e8.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0763.JPG.43ae7328.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0764.JPG.43ae7368.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0765.JPG.43ae7390.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0767.JPG.43ae9c64.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0768.JPG.43ae9c7c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0769.JPG.43ae9cac.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0771.JPG.43ae9eb0.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0772.JPG.43aebf64.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0774.JPG.43aec060.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0776.JPG.43b1976e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0777.JPG.43b198fa.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0779.JPG.43b2686e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0781.JPG.43b271c6.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0782.JPG.43b271ee.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0783.JPG.43b2725c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0784.JPG.43b2726c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0785.JPG.43b27288.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0786.JPG.43b27298.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0787.JPG.43b272ca.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0788.JPG.43b272dc.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0789.JPG.43b272f2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0793.JPG.43b2ea62.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0794.JPG.43b2ea78.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0795.JPG.43b2ea90.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0796.JPG.43b2eab4.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0797.JPG.43b2eabc.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0798.JPG.43b2ead6.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0799.JPG.43b2eaf4.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0800.JPG.43b2eb00.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0805.JPG.43b58af8.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0807.JPG.43b58bfc.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0808.JPG.43b5a442.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0809.JPG.43b5a458.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0810.JPG.43b5a480.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0813.JPG.43b5a718.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0815.JPG.43b5a772.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0816.JPG.43b5a7b2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0818.JPG.43b5a804.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0819.JPG.43b650fe.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0821.JPG.43b6e95e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0822.JPG.43b6e97c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0823.JPG.43b6ea22.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0826.JPG.43b6ed24.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0829.JPG.43b70994.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0832.JPG.43b70eb0.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0833.JPG.43b70ec6.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0834.JPG.43b70fb8.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0836.JPG.43b71112.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0838.JPG.43b71176.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0841.JPG.43b71a2a.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0843.JPG.43ad5ede.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0849.JPG.43beda40.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0850.JPG.43bedabe.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0858.JPG.43bee30e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0860.JPG.43bee904.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0861.JPG.43bee938.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0862.JPG.43bee962.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0867.JPG.43beef70.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0868.JPG.43beefca.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0869.JPG.43bef184.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0871.JPG.43bef206.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0872.JPG.43bef220.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0907.JPG.4437efc0.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0908.JPG.4437efda.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0912.JPG.4437ff90.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0913.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0914.JPG.44381090.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0915.JPG.443810a6.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0916.JPG.445b8372.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0916.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0917.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0918.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0920.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0921.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0922.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0923.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0925.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0926.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0927.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0928.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0930.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0931.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0932.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0933.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0934.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0935.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0937.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0938.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0939.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0942.JPG.445b920d.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0943.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0944.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0945.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0946.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0947.JPG.44384a08.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0948.JPG.44384a0a.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0954.JPG.444b50a6.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0955.JPG.444b50cc.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0956.JPG.444b50ee.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0957.JPG.444b512a.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0958.JPG.444b5142.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0959.JPG.445bcf73.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0960.JPG.444b574e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0961.JPG.444b81b6.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\DSCN0962.JPG.444b81d0.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\FSCN0919.JPG.445b9182.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG0.JPG.3eea4728.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG1.jpg.3eea4710.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG10.jpg.3eea4554.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG11.jpg.3eea4554.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG12.jpg.3eea4554.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG13.jpg.3eea4734.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG2.JPG.3eea473c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG3.JPG.3eea4746.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG4.JPG.3eea4750.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG5.jpg.3eea475c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG6.jpg.3eea4558.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG7.jpg.3eea476a.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG8.JPG.3eea4778.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\IMG9.JPG.3eea4780.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0651.JPG.43a75db8.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0652.JPG.43a75e78.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0653.JPG.43a75eba.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0654.JPG.43a75eec.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0655.JPG.43a75f70.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0780.JPG.43b268a8.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0811.JPG.43b5a49c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0830.JPG.43b70a12.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0835.JPG.43b70fd2.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0837.JPG.43b71138.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0863.JPG.43bee9aa.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0873.JPG.43bef23e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\RSCN0904.JPG.43d36b6e.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\Sample_Picture01.jpg.41b2b144.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\Sample_Picture02.jpg.41b2b144.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\Sample_Picture03.jpg.41b2b144.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\Sample_Picture04.jpg.41b2b142.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\Sample_Picture05.jpg.41b2b14c.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\Sample_Picture06.jpg.41b2b144.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\Sample_Picture07.jpg.41b2b144.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\Sample_Picture08.jpg.41b2b144.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\Sample_Picture09.jpg.41b2b144.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\dscrp\Sample_Picture10.jpg.41b2b144.mpd L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\scratch\ERRSTAT.HTM L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\ccSubSDK\submissions.idx L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.DAT L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\volatile.DAT L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\{72AA2410-A046-4FBE-9906-8EA27A7634C7}.DAT L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\{C6AF4535-2114-4E68-BFAF-BAD6D181EFDA}.DAT L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\{EB3E7330-C70A-4DD1-B81C-8F9531188332}.DAT L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\{EE0332E7-C36D-46BA-B46F-CB2B6D7F5FAC}.DAT L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-06-04_Log.ALUSchedulerSvc.LiveUpdate L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0A11149A.exe L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0BD2294E.exe L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\23211D3F.tmp L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\29DE0930.tmp Infecté : Trojan.Java.ClassLoader.ao ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FB1776B.exe L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\556B431B.tmp Infecté : Trojan.Java.ClassLoader.ao ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\68AA70DB.dll Infecté : Trojan.Win32.P2E.co ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\index.qbs L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{E1FCFC70-3C45-411C-A7A7-FDE2F9213B8D}.ldb L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{E1FCFC70-3C45-411C-A7A7-FDE2F9213B8D}.sds L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\04CC5074.TMP L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\7381FBB2.TMP L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Documents\Config\desktop2.idf L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Documents\Fonts\SwUniNew.tff L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Documents\TV enregistrée\TempRec\TempSBE\MSDVRMM_1085754711_16252928_58192 L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Documents\TV enregistrée\TempRec\TempSBE\MSDVRMM_1085754711_2752512_86547 L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Documents\TV enregistrée\TempRec\TempSBE\SBE1.tmp L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Documents\TV enregistrée\TempRec\TempSBE\SBE2.tmp L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Documents\TV enregistrée\TempRec\{300DD95C-3838-4BC9-9B17-CBB65F38D4AA}.TmpSBE L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Documents\TV enregistrée\TempRec\{8012B4DE-1A8E-403D-AB34-D5FEE6CEEA3A}.TmpSBE L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\DRM\drmstore.hds L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Application Data\Symantec\NPMDataStore\CIMStore.xml L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Cookies\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\ApplicationHistory\cli.exe.c88dbd71.ini.inuse L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Local Settings\Temp\hpodvd09.log L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Local Settings\Temp\Perflib_Perfdata_13d8.dat L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Local Settings\Temp\Perflib_Perfdata_d88.dat L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Local Settings\Temp\_hphtra07.log L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\Mes documents\Downloads\Adobe Photshop CS3 Extended Keygen - NEWLY Added 20May2008\Adobe Photoshop CS3 Extended Keygen.exe/data0000.cab/UNINST~1.EXE Infecté : Trojan.Win32.Monder.gen ignoré

C:\Documents and Settings\HP_Administrateur\Mes documents\Downloads\Adobe Photshop CS3 Extended Keygen - NEWLY Added 20May2008\Adobe Photoshop CS3 Extended Keygen.exe/data0000.cab Infecté : Trojan.Win32.Monder.gen ignoré

C:\Documents and Settings\HP_Administrateur\Mes documents\Downloads\Adobe Photshop CS3 Extended Keygen - NEWLY Added 20May2008\Adobe Photoshop CS3 Extended Keygen.exe Rsrc-Package: infecté - 2 ignoré

C:\Documents and Settings\HP_Administrateur\ntuser.dat L'objet est verrouillé ignoré

C:\Documents and Settings\HP_Administrateur\ntuser.dat.LOG L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré

C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré

C:\Program Files\Adobe\Adobe Bridge\install.adb L'objet est verrouillé ignoré

C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcrst.dll L'objet est verrouillé ignoré

C:\Program Files\Fichiers communs\Symantec Shared\eengine\EPERSIST.DAT L'objet est verrouillé ignoré

C:\Program Files\Fichiers communs\Symantec Shared\NFWEVT.LOG L'objet est verrouillé ignoré

C:\Program Files\Fichiers communs\Symantec Shared\SNDALRT.log L'objet est verrouillé ignoré

C:\Program Files\Fichiers communs\Symantec Shared\SNDCON.log L'objet est verrouillé ignoré

C:\Program Files\Fichiers communs\Symantec Shared\SNDDBG.log L'objet est verrouillé ignoré

C:\Program Files\Fichiers communs\Symantec Shared\SNDFW.log L'objet est verrouillé ignoré

C:\Program Files\Fichiers communs\Symantec Shared\SNDIDS.log L'objet est verrouillé ignoré

C:\Program Files\Fichiers communs\Symantec Shared\SNDSYS.log L'objet est verrouillé ignoré

C:\Program Files\Google\Google Updater\swg-2.0.301.7164\SearchWithGoogleUpdate_fr.exe L'objet est verrouillé ignoré

C:\Program Files\InstallShield Installation Information\{8AF3E926-ED59-11D4-A44B-0000E86D2305}\setup.ilg L'objet est verrouillé ignoré

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log L'objet est verrouillé ignoré

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log L'objet est verrouillé ignoré

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log L'objet est verrouillé ignoré

C:\Program Files\winLAME\COPYING L'objet est verrouillé ignoré

C:\Program Files\winLAME\libfaac.dll L'objet est verrouillé ignoré

C:\Program Files\winLAME\libfaad2.dll L'objet est verrouillé ignoré

C:\Program Files\winLAME\libmad.dll L'objet est verrouillé ignoré

C:\Program Files\winLAME\libmmd.dll L'objet est verrouillé ignoré

C:\Program Files\winLAME\libsndfile.dll L'objet est verrouillé ignoré

C:\Program Files\winLAME\libvorbis.dll L'objet est verrouillé ignoré

C:\Program Files\winLAME\nLAME.dll L'objet est verrouillé ignoré

C:\Program Files\winLAME\presets.xml L'objet est verrouillé ignoré

C:\Program Files\winLAME\readme.txt L'objet est verrouillé ignoré

C:\Program Files\winLAME\UnInstall_WinLAME.exe L'objet est verrouillé ignoré

C:\Program Files\winLAME\winLAME.chm L'objet est verrouillé ignoré

C:\Program Files\winLAME\winLAME.exe L'objet est verrouillé ignoré

C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré

C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP49\A0024416.exe Infecté : Trojan-Downloader.Win32.VB.dyo ignoré

C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP50\A0028771.exe/is152259.exe Infecté : Trojan.Win32.Monder.gen ignoré

C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP50\A0028771.exe RAR: infecté - 1 ignoré

C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP50\A0028775.exe Infecté : Backdoor.Win32.Rbot.gen ignoré

C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039343.dll Infecté : Trojan.Win32.Monder.gen ignoré

C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039346.dll Infecté : Trojan.Win32.Monder.gen ignoré

C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP64\A0039350.dll Infecté : Trojan.Win32.Monder.gen ignoré

C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP66\change.log L'objet est verrouillé ignoré

C:\upload_moi_NOM-FB9B15D2723.tar.gz/upload_moi.tar/qoobox/Quarantine/C/WINDOWS/system32/fwoembfd.dll.vir Infecté : Trojan.Win32.Monder.gen ignoré

C:\upload_moi_NOM-FB9B15D2723.tar.gz/upload_moi.tar/qoobox/Quarantine/C/WINDOWS/system32/gwvwjrbl.dll.vir Infecté : Trojan.Win32.Monder.gen ignoré

C:\upload_moi_NOM-FB9B15D2723.tar.gz/upload_moi.tar/qoobox/Quarantine/C/WINDOWS/system32/mueogucf.dll.vir Infecté : Trojan.Win32.Monder.gen ignoré

C:\upload_moi_NOM-FB9B15D2723.tar.gz/upload_moi.tar/qoobox/Quarantine/C/WINDOWS/system32/ycmpffyv.dll.vir Infecté : Trojan.Win32.Monder.gen ignoré

C:\upload_moi_NOM-FB9B15D2723.tar.gz/upload_moi.tar Infecté : Trojan.Win32.Monder.gen ignoré

C:\upload_moi_NOM-FB9B15D2723.tar.gz GZIP: infecté - 5 ignoré

C:\USERDATA\.fonts.cache-1 L'objet est verrouillé ignoré

C:\USERDATA\.GalleryRemote\GalleryRemoteApplet.properties L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\colorrc L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\documents L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\gimprc L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\gradients\Aneurism-copy.ggr L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\gtkrc L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\menurc L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\parasiterc L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\pluginrc L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\sessionrc L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\templaterc L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\themerc L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-airbrush-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-airbrush-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-blend-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-blend-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-brightness-contrast-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-brightness-contrast-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-bucket-fill-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-bucket-fill-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-by-color-select-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-by-color-select-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-clone-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-clone-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-color-balance-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-color-balance-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-color-picker-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-color-picker-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-colorize-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-colorize-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-convolve-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-convolve-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-crop-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-crop-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-curves-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-curves-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-dodgeburn-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-dodgeburn-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-ellipse-select-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-ellipse-select-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-eraser-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-eraser-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-flip-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-flip-tool.presets L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-free-select-tool L'objet est verrouillé ignoré

C:\USERDATA\.gimp-2.0\tool-options\gimp-free-select-tool.presets L'objet est verrouillé ignoré

C:\USERDAT
0
g!rly Messages postés 18462 Statut Contributeur 406
 
ok covani,

ce sont des fichiers contenus dans la quarantaine de norton et kaspersky detecte egalement les outils que nous avons utilisés; la restauration system est aussi touché...

procede comme ceci :

vide la quarantaine de norton

puis

fais ceci :

Désactive ta restauration système:
pour cela :
Click droit sur poste de travail, dans l´arborescence sur propriétés;
dans la nouvelle fenettre click sur l´onglet restauration système;
coche la case désactiver la restauration systèm et applique.
puis redemarre le pc et click droit sur poste de travail, dans l´arborescence sur propriétés;
dans la nouvelle fenettre click sur l´onglet restauration systèm
décoche la case désactiver la restauration systèm et applique.

puis

post un nouveau hijack this stp

@+
0
cocovani
 
meme si c est long merci encor de ta rapidité a repondre je me sens moins seul lol
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:34:52, on 04/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\HP_Administrateur\Mes documents\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: (no name) - {8E03E4D5-0F28-4427-A975-A6F21E627323} - C:\WINDOWS\system32\nnnmlLDw.dll (file missing)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {F9CF21E9-812E-4341-ACFE-D9CB2A611AA9} - C:\WINDOWS\system32\byXOfEWp.dll (file missing)
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Barre d'état système d'ATI CATALYST.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.3.5.cab
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
0
g!rly Messages postés 18462 Statut Contributeur 406
 
ok ;-)

a l´aide de hijack this coche et fix :

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {8E03E4D5-0F28-4427-A975-A6F21E627323} - C:\WINDOWS\system32\nnnmlLDw.dll (file missing)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {F9CF21E9-812E-4341-ACFE-D9CB2A611AA9} - C:\WINDOWS\system32\byXOfEWp.dll (file missing)
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.3.5.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/...
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

puis

ta version de acrobat reader n´est pas a jour, tu veux la version 8.1 derniere en date alors desinstale ta version par le panneau de configuration / ajoue et suppression de programme

et instale la derniere :

https://get2.adobe.com/reader/otherversions/

ou oublie completement acrobat reader et instales foxit plus léger a la place:

https://www.clubic.com/telecharger-fiche13808-foxit-reader.html

et

regarde ce tutorial pour mettre ta console java a jour :

https://www.malekal.com/maintenir-java-adobe-reader-et-le-player-flash-a-jour/

et encore :

pour plus de securité :

instal

spywareblaster :

http://www.brightfort.com/spywareblaster.html

c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

tuto : https://www.malekal.com/tutorial-spywareblaster/

et pourquoi ne pas surfer avec firefox? = plus sur, tout en gardant ie 7.0 pour les mises a jour windows car impossible a effectuer sous firefox

http://www.mozilla-europe.org/fr/

plugins :ad block plus, no script ect...

https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org

pour supprimer les fix/outils utilisés :

Télécharge ToolsCleaner sur ton bureau.
--> http://www.commentcamarche.net/telecharger/telechargement 34055291 toolsclean(...)
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

dis moi quoi

@+
0
cocovani
 
dis moi quoi. toi aussi tu as vu bienvenue chez les chtis ,LOL
merci pour les petits conseil en plus
je m'occuperais de firefox demain a tete reposée, depuis le temps que j'en entends parler
donc je pense que le post est resolu
le rapport
-->- Recherche:

C:\HijackThis.exe: trouvé !
C:\Combofix: trouvé !
C:\Vundofix backups: trouvé !
C:\Qoobox: trouvé !
C:\Documents and Settings\HP_Administrateur\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\HP_Administrateur\Bureau\ComboFix.exe: trouvé !
C:\Documents and Settings\HP_Administrateur\Bureau\vundoFix.exe: trouvé !
C:\Documents and Settings\HP_Administrateur\Bureau\girly\Clean.zip: trouvé !
C:\Documents and Settings\HP_Administrateur\Mes documents\ComboFix.exe: trouvé !
C:\Documents and Settings\HP_Administrateur\Mes documents\vundoFix.exe: trouvé !
C:\Documents and Settings\HP_Administrateur\Mes documents\HijackThis.exe: trouvé !
C:\Documents and Settings\HP_Administrateur\Recent\HijackThis.lnk: trouvé !

---------------------------------
-->- Suppression:

C:\HijackThis.exe: supprimé !
C:\Documents and Settings\HP_Administrateur\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\HP_Administrateur\Bureau\ComboFix.exe: supprimé !
C:\Documents and Settings\HP_Administrateur\Bureau\vundoFix.exe: supprimé !
C:\Documents and Settings\HP_Administrateur\Bureau\girly\Clean.zip: supprimé !
C:\Documents and Settings\HP_Administrateur\Mes documents\ComboFix.exe: supprimé !
C:\Documents and Settings\HP_Administrateur\Mes documents\vundoFix.exe: supprimé !
C:\Documents and Settings\HP_Administrateur\Mes documents\HijackThis.exe: ERREUR DE SUPPRESSION !!
C:\Documents and Settings\HP_Administrateur\Recent\HijackThis.lnk: supprimé !
C:\Combofix: supprimé !
C:\Vundofix backups: supprimé !
C:\Qoobox: supprimé !
repasserai demain
et encor merci
@+ ( enfin,j'espere pas,cela voudra dire que j'ai encor un probleme)
0
g!rly Messages postés 18462 Statut Contributeur 406
 
ok covani ;-)
bye`
g!rly`
0