Application win32 valide + pub indesirables
habib38
Messages postés
44
Date d'inscription
Statut
Membre
Dernière intervention
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
Depuis quelques jours je ne peux plus lancer plusieurs applications ou logiciel. Une boite de dialogue me parle d'application win32 valide. C'est depuis que j'ai voulu faire un peu de ménages en supprimant des logiciels dont je ne me servais plus. J'ai peut être supprimer quelque chose qui ne fallait pas dans panneaux de config/ajout/supp de programmes. De plus depuis ce moment là j'ai plein de pop up qui se lancent.
Merci de votre aide.
Depuis quelques jours je ne peux plus lancer plusieurs applications ou logiciel. Une boite de dialogue me parle d'application win32 valide. C'est depuis que j'ai voulu faire un peu de ménages en supprimant des logiciels dont je ne me servais plus. J'ai peut être supprimer quelque chose qui ne fallait pas dans panneaux de config/ajout/supp de programmes. De plus depuis ce moment là j'ai plein de pop up qui se lancent.
Merci de votre aide.
A voir également:
- Application win32 valide + pub indesirables
- Ethernet n'a pas de configuration ip valide - Guide
- Supprimer pub youtube - Accueil - Streaming
- Desinstaller application windows - Guide
- Nommez une application d'appel vidéo ou de visioconférence - Guide
- Stop pub gratuit - Télécharger - Divers Utilitaires
48 réponses
voici le rapoort:
--------- FindyKill V2.O55 par Chiquitine29 ---------
[ Suppression effectuée à 18:26:53 | 06/09/2008 ]
[ INSTALL LOCATION : C:\Documents and Settings\x\Bureau\FindyKill\Tools\FindyKill.bat ]
[ USER : x | PC : X-SF5ZD1SFP4WB8 ]
[ BOOT MODE : Normal ]
----------- /!\..... Suppression ...../!\ -----------
---------- /!\..... Second passage ...../!\ ----------
--------- FindyKill V2.O55 par Chiquitine29 ---------
[ Suppression effectuée à 18:26:53 | 06/09/2008 ]
[ INSTALL LOCATION : C:\Documents and Settings\x\Bureau\FindyKill\Tools\FindyKill.bat ]
[ USER : x | PC : X-SF5ZD1SFP4WB8 ]
[ BOOT MODE : Normal ]
----------- /!\..... Suppression ...../!\ -----------
---------- /!\..... Second passage ...../!\ ----------
Telecharge Kb2 sur ce lien : (merci a moe pour la réalisation !)
http://sd-1.archive-host.com/membres/up/1366464061/KB2.exe
Telecharge la nouvelle version d´eliblaga ici : (en bas de cette page)
http://www.zonavirus.com/datos/descargas/95/elibagla.asp (clique sur le bouton "Descargar Elibagla") sur ton bureau.
Etape 1 :
Si tu as connecté une cle usb depuis que tu as été infecté branche la sans l´ouvrir...
Etape 2 :
Sur ton bureau double clic sur KB.exe.
Tu verras apparaître sur le bureau, un raccourci nommé "KillB".
Fait glisser le fichier Elibagla.exe sur ce raccourci, exactement comme si tu voulais le déposer dans un dossier.
Elibagla va se lancer automatiquement.
Clic sur "Ok" aux premières boîtes de dialogue qui peuvent apparaître avant le menu principal de l'outil :
<ital>Por favor, envienos una muestra del fichero
C:\Muestras\HLDRRR.EXE.Muestra EliBagle v11.18
a "virus@satinfo.es". Gracias
et/ou
Eliminando Gusano BAGLE<ital>
Une fois fait, le menu principal d'Elibagla apparaîtra :
- Laisse la case "Eliminar ficheros automaticamente" coché
- Clic sur "Explorar" pour lancer le scan.
/!\ Pendant toute la durée du scan, n'utilise pas ton pc, n'ouvre aucun programmes et laisse l'outil travailler.
/!\ Ne redemarre pas le pc après le scan.
Le scan terminé, copie/colle sur le forum le rapport situé dans C:\KB\KB.txt et celui d'Elibagla situé dans C:\Infosat.txt
http://sd-1.archive-host.com/membres/up/1366464061/KB2.exe
Telecharge la nouvelle version d´eliblaga ici : (en bas de cette page)
http://www.zonavirus.com/datos/descargas/95/elibagla.asp (clique sur le bouton "Descargar Elibagla") sur ton bureau.
Etape 1 :
Si tu as connecté une cle usb depuis que tu as été infecté branche la sans l´ouvrir...
Etape 2 :
Sur ton bureau double clic sur KB.exe.
Tu verras apparaître sur le bureau, un raccourci nommé "KillB".
Fait glisser le fichier Elibagla.exe sur ce raccourci, exactement comme si tu voulais le déposer dans un dossier.
Elibagla va se lancer automatiquement.
Clic sur "Ok" aux premières boîtes de dialogue qui peuvent apparaître avant le menu principal de l'outil :
<ital>Por favor, envienos una muestra del fichero
C:\Muestras\HLDRRR.EXE.Muestra EliBagle v11.18
a "virus@satinfo.es". Gracias
et/ou
Eliminando Gusano BAGLE<ital>
Une fois fait, le menu principal d'Elibagla apparaîtra :
- Laisse la case "Eliminar ficheros automaticamente" coché
- Clic sur "Explorar" pour lancer le scan.
/!\ Pendant toute la durée du scan, n'utilise pas ton pc, n'ouvre aucun programmes et laisse l'outil travailler.
/!\ Ne redemarre pas le pc après le scan.
Le scan terminé, copie/colle sur le forum le rapport situé dans C:\KB\KB.txt et celui d'Elibagla situé dans C:\Infosat.txt
Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Avant de telecharger clic sur enregistrer renome le en killbagle et enregistre le sur le bureau
-> Double clique sur killbagle.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Avant d'utiliser ComboFix :
-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
Une fois fait, sur ton bureau double-clic sur killbagle.exe.
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
Avant de telecharger clic sur enregistrer renome le en killbagle et enregistre le sur le bureau
-> Double clique sur killbagle.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Avant d'utiliser ComboFix :
-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
Une fois fait, sur ton bureau double-clic sur killbagle.exe.
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
j'ai fait le scan. l'ordi redémarre plusieurs fois. Par contre aucun rapport n'est délivré même à la racine du disque. C'est normal?
Telecharge malwarebytes
-> http://www.malwarebytes.org/mbam/program/mbam-setup.exe
Tu l´instale; le programme va se mettre automatiquement a jour.
Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".
Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".
Puis click sur "rechercher".
Laisse le scanner le pc...
Si des elements on ete trouvés > click sur supprimer la selection.
si il t´es demandé de redemarrer > click sur "yes".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.
PS : les rapport sont aussi rangé dans l onglet rapport/log
-> http://www.malwarebytes.org/mbam/program/mbam-setup.exe
Tu l´instale; le programme va se mettre automatiquement a jour.
Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".
Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".
Puis click sur "rechercher".
Laisse le scanner le pc...
Si des elements on ete trouvés > click sur supprimer la selection.
si il t´es demandé de redemarrer > click sur "yes".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.
PS : les rapport sont aussi rangé dans l onglet rapport/log
Malwarebytes' Anti-Malware 1.26
Version de la base de données: 1125
Windows 5.1.2600 Service Pack 2
2008-09-08 00:05:01
mbam-log-2008-09-08 (00-05-01).txt
Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|)
Eléments examinés: 155870
Temps écoulé: 4 hour(s), 31 minute(s), 4 second(s)
Processus mémoire infecté(s): 6
Module(s) mémoire infecté(s): 5
Clé(s) du Registre infectée(s): 42
Valeur(s) du Registre infectée(s): 9
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 13
Fichier(s) infecté(s): 198
Processus mémoire infecté(s):
C:\WINDOWS\faceback.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Program Files\Sakora\Sakora.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Documents and Settings\x\Mes documents\?ystem\spoolsv.exe (Adware.ClickSpring) -> Unloaded process successfully.
C:\Program Files\GetPack\GetPack20.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Program Files\VnrBlock\VnrBlock20.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\system32\mbvyy0h7.exe (Trojan.Downloader) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\konjlfra.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\nnnnKecy.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\geBsstrP.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Program Files\Mozilla Firefox\components\srff.dll (Adware.SurfAccuracy) -> Delete on reboot.
C:\WINDOWS\system32\gtqazn.dll (Trojan.Vundo) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{17a05b11-279b-4fff-845f-f57eb02a9b16} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{17a05b11-279b-4fff-845f-f57eb02a9b16} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6620a5ec-1ca9-4f62-ae4b-7eb603ea5672} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6620a5ec-1ca9-4f62-ae4b-7eb603ea5672} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{db036a52-3a88-466b-bd39-05a6d9d9b18a} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebsstrp (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{db036a52-3a88-466b-bd39-05a6d9d9b18a} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3c73e7e4-d26c-4c4a-a001-5defde524c3e} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3c73e7e4-d26c-4c4a-a001-5defde524c3e} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho.1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{63334394-3da3-4b29-a041-03535909d361} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{ff46f4ab-a85f-487e-b399-3f191ac0fe23} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{7e66936c-fea0-4984-ad26-7b6661ac5b2e} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bannerstyle (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\testCPV6.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Error Safe Free (Rogue.Errorsafe) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\GetPack (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Webtools (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo (Adware.PurityScan) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa (Rootkit.Bagle) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa (Rootkit.Bagle) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa (Rootkit.Bagle) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d132cf2-d1d0-8df3-14a4-2962790d0f78} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6d132cf2-d1d0-8df3-14a4-2962790d0f78} (Adware.BHO) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cc60a7b0 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{db036a52-3a88-466b-bd39-05a6d9d9b18a} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runner1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sakora (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\getpack20 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vnrblock20 (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmcf53942c (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{d92ec2db-7319-ee49-1e23-c82631e52d50} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Security Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\nnnnkecy -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\nnnnkecy -> Delete on reboot.
Dossier(s) infecté(s):
C:\Program Files\Outerinfo (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\InetGet2 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Temporary (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down (Trojan.Downloader) -> Files: 10335 -> Quarantined and deleted successfully.
C:\Program Files\Webtools (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\VnrBlock (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Sakora (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\GetPack (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\iCheck (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Application Data\m (Trojan.Agent) -> Delete on reboot.
Fichier(s) infecté(s):
C:\WINDOWS\system32\nnnnKecy.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\yceKnnnn.ini (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\yceKnnnn.ini2 (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\gtqazn.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\geBsstrP.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\dssxqadt.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdaqxssd.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eeyseycn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ncyesyee.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jbkxrjvv.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vvjrxkbj.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\konjlfra.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\arfljnok.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\poxexaos.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\soaxexop.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tvttmclb.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\blcmttvt.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\celufm.dll (Trojan.BHO.H) -> Delete on reboot.
C:\WINDOWS\faceback.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Sakora\Sakora.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Mes documents\?ystem\spoolsv.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Program Files\GetPack\GetPack20.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\VnrBlock\VnrBlock20.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mbvyy0h7.exe (Trojan.Downloader) -> Delete on reboot.
C:\Program Files\Mozilla Firefox\components\srff.dll (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\Program Files\Mjcore\Mjcore.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Program Files\Webtools\webtools.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\x\LOCALS~1\Temp\AAWTMP\C31148198\AE730\b155.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Local Settings\Temp\__9D2.tmp (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Local Settings\Temporary Internet Files\Content.IE5\486VWCPK\upd105320[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Local Settings\Temporary Internet Files\Content.IE5\WCPN9YWX\nd82m0[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Mes documents\mes téléchargements\Codec(2).exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Mes documents\mes téléchargements\Codec.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\iCheck\iCheck.exe (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\iCheck\Uninstall.exe (Malware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\Fichiers communs\Yazzle1560OinAdmin.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Program Files\Fichiers communs\Yazzle1560OinUninstaller.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components\FF.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\WINDOWS\b128.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\b148.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\b157.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\meane.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu1188.exe.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\skbpugkb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cmigjr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\itbxxyid.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\adsfyedn.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ammjlern.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\apnbjcjc.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mdjqhh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbalvyvf.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\odokfl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fcxywoyo.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pisnzv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qfrfrded.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tkgisy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tudqaobc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ujnlnr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ukxxhu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ulgtrw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eovlubdr.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fvugue.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gbgrjytd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gjisuimx.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uqsyceke.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ckcdkihovag.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dkgftfle.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xwalgddk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yvefxmix.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\podamixf.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hbvviltb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hfcwewri.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hooachdk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vpwpfcjs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\miidejtn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jjxgufrm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jlrgnjvp.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\inhkxy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pclchs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\omsicavt.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bdtlhugl.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eanvgx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\flrxmolf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2144594243.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2144805887.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\103008.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2609784792.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\45544018.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\293802.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\29296195.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\117169440.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\437769499.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\265251.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\58227236.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\72760754.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\72766582.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\87392153.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\29783706.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2729133426.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2729355716.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1845122856.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1845149564.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\44222098.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\628032472.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2309589654.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\29145719.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\291659293.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1680141806.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1995114502.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1650179813.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1650204518.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1450445.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\146273149.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2204557005.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\14756608.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\14766142.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2520069067.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2055181174.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\14781975.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1935344237.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2084748339.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2384665818.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2384680198.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2549970563.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2549990192.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2550206342.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\175327227.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2234596079.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2234617550.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\68522179.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\30885220.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1755050088.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\91040098.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1665151941.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1830177045.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1815198647.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1815218626.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1965336454.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1965567025.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2114898783.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\286171.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\30670571.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\349895212.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\539928986.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\57864364.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\58915776.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\58937487.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\58945238.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\60101271.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\72376712.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\82548.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\87310335.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\93284.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\100875.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\134233.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\142785.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\14718454.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\14719165.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1710242678.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1724965038.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1724989373.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1725212234.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1740023501.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1740055307.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1740267802.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1784978843.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1784998401.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1785201954.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1800237074.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\07272008_124929\Documents and Settings\x\Application Data\SpeedRunner\SpeedRunner.exe (Adware.SpeedRunner) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\07272008_124929\Documents and Settings\x\Application Data\SpeedRunner\SRUninstall.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\07272008_124929\WINDOWS\b156.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\07272008_124929\WINDOWS\system32\jkkLDTmM.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\chrome.manifest (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\install.rdf (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\VnrBlock\xtarga.gz (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\GetPack\dictame.gz (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\GetPack\trgtame.gz (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Application Data\m\data.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Application Data\m\list.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Application Data\m\srvlist.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aQLvs2F5.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mbvyy0h7.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pbvcrmlo.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mdelk.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wintems.exe (Trojan.Spammer) -> Delete on reboot.
C:\Documents and Settings\x\Application Data\m\flec006.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BMcf53942c.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BMcf53942c.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nulkksdikyg.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\WINDOWS\b160.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\hldrrr.exe (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\srosa.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
Version de la base de données: 1125
Windows 5.1.2600 Service Pack 2
2008-09-08 00:05:01
mbam-log-2008-09-08 (00-05-01).txt
Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|)
Eléments examinés: 155870
Temps écoulé: 4 hour(s), 31 minute(s), 4 second(s)
Processus mémoire infecté(s): 6
Module(s) mémoire infecté(s): 5
Clé(s) du Registre infectée(s): 42
Valeur(s) du Registre infectée(s): 9
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 13
Fichier(s) infecté(s): 198
Processus mémoire infecté(s):
C:\WINDOWS\faceback.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Program Files\Sakora\Sakora.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Documents and Settings\x\Mes documents\?ystem\spoolsv.exe (Adware.ClickSpring) -> Unloaded process successfully.
C:\Program Files\GetPack\GetPack20.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Program Files\VnrBlock\VnrBlock20.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\system32\mbvyy0h7.exe (Trojan.Downloader) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\konjlfra.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\nnnnKecy.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\geBsstrP.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Program Files\Mozilla Firefox\components\srff.dll (Adware.SurfAccuracy) -> Delete on reboot.
C:\WINDOWS\system32\gtqazn.dll (Trojan.Vundo) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{17a05b11-279b-4fff-845f-f57eb02a9b16} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{17a05b11-279b-4fff-845f-f57eb02a9b16} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6620a5ec-1ca9-4f62-ae4b-7eb603ea5672} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6620a5ec-1ca9-4f62-ae4b-7eb603ea5672} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{db036a52-3a88-466b-bd39-05a6d9d9b18a} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebsstrp (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{db036a52-3a88-466b-bd39-05a6d9d9b18a} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3c73e7e4-d26c-4c4a-a001-5defde524c3e} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3c73e7e4-d26c-4c4a-a001-5defde524c3e} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho.1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{63334394-3da3-4b29-a041-03535909d361} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{ff46f4ab-a85f-487e-b399-3f191ac0fe23} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{7e66936c-fea0-4984-ad26-7b6661ac5b2e} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bannerstyle (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\testCPV6.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Error Safe Free (Rogue.Errorsafe) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\GetPack (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Webtools (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo (Adware.PurityScan) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa (Rootkit.Bagle) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa (Rootkit.Bagle) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa (Rootkit.Bagle) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d132cf2-d1d0-8df3-14a4-2962790d0f78} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6d132cf2-d1d0-8df3-14a4-2962790d0f78} (Adware.BHO) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cc60a7b0 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{db036a52-3a88-466b-bd39-05a6d9d9b18a} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runner1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sakora (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\getpack20 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vnrblock20 (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmcf53942c (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{d92ec2db-7319-ee49-1e23-c82631e52d50} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Security Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\nnnnkecy -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\nnnnkecy -> Delete on reboot.
Dossier(s) infecté(s):
C:\Program Files\Outerinfo (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\InetGet2 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Temporary (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down (Trojan.Downloader) -> Files: 10335 -> Quarantined and deleted successfully.
C:\Program Files\Webtools (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\VnrBlock (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Sakora (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\GetPack (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\iCheck (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Application Data\m (Trojan.Agent) -> Delete on reboot.
Fichier(s) infecté(s):
C:\WINDOWS\system32\nnnnKecy.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\yceKnnnn.ini (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\yceKnnnn.ini2 (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\gtqazn.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\geBsstrP.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\dssxqadt.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdaqxssd.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eeyseycn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ncyesyee.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jbkxrjvv.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vvjrxkbj.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\konjlfra.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\arfljnok.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\poxexaos.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\soaxexop.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tvttmclb.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\blcmttvt.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\celufm.dll (Trojan.BHO.H) -> Delete on reboot.
C:\WINDOWS\faceback.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Sakora\Sakora.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Mes documents\?ystem\spoolsv.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Program Files\GetPack\GetPack20.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\VnrBlock\VnrBlock20.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mbvyy0h7.exe (Trojan.Downloader) -> Delete on reboot.
C:\Program Files\Mozilla Firefox\components\srff.dll (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\Program Files\Mjcore\Mjcore.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Program Files\Webtools\webtools.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\x\LOCALS~1\Temp\AAWTMP\C31148198\AE730\b155.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Local Settings\Temp\__9D2.tmp (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Local Settings\Temporary Internet Files\Content.IE5\486VWCPK\upd105320[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Local Settings\Temporary Internet Files\Content.IE5\WCPN9YWX\nd82m0[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Mes documents\mes téléchargements\Codec(2).exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Mes documents\mes téléchargements\Codec.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\iCheck\iCheck.exe (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\iCheck\Uninstall.exe (Malware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\Fichiers communs\Yazzle1560OinAdmin.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Program Files\Fichiers communs\Yazzle1560OinUninstaller.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components\FF.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\WINDOWS\b128.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\b148.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\b157.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\meane.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu1188.exe.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\skbpugkb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cmigjr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\itbxxyid.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\adsfyedn.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ammjlern.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\apnbjcjc.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mdjqhh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbalvyvf.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\odokfl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fcxywoyo.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pisnzv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qfrfrded.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tkgisy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tudqaobc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ujnlnr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ukxxhu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ulgtrw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eovlubdr.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fvugue.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gbgrjytd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gjisuimx.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uqsyceke.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ckcdkihovag.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dkgftfle.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xwalgddk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yvefxmix.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\podamixf.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hbvviltb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hfcwewri.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hooachdk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vpwpfcjs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\miidejtn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jjxgufrm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jlrgnjvp.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\inhkxy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pclchs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\omsicavt.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bdtlhugl.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eanvgx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\flrxmolf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2144594243.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2144805887.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\103008.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2609784792.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\45544018.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\293802.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\29296195.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\117169440.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\437769499.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\265251.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\58227236.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\72760754.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\72766582.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\87392153.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\29783706.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2729133426.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2729355716.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1845122856.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1845149564.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\44222098.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\628032472.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2309589654.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\29145719.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\291659293.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1680141806.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1995114502.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1650179813.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1650204518.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1450445.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\146273149.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2204557005.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\14756608.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\14766142.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2520069067.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2055181174.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\14781975.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1935344237.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2084748339.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2384665818.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2384680198.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2549970563.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2549990192.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2550206342.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\175327227.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2234596079.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2234617550.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\68522179.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\30885220.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1755050088.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\91040098.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1665151941.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1830177045.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1815198647.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1815218626.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1965336454.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1965567025.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\2114898783.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\286171.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\30670571.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\349895212.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\539928986.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\57864364.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\58915776.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\58937487.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\58945238.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\60101271.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\72376712.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\82548.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\87310335.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\93284.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\100875.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\134233.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\142785.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\14718454.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\14719165.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1710242678.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1724965038.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1724989373.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1725212234.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1740023501.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1740055307.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1740267802.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1784978843.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1784998401.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1785201954.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\down\1800237074.exe (Worm.Bagle) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\07272008_124929\Documents and Settings\x\Application Data\SpeedRunner\SpeedRunner.exe (Adware.SpeedRunner) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\07272008_124929\Documents and Settings\x\Application Data\SpeedRunner\SRUninstall.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\07272008_124929\WINDOWS\b156.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\07272008_124929\WINDOWS\system32\jkkLDTmM.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\chrome.manifest (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\install.rdf (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\VnrBlock\xtarga.gz (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\GetPack\dictame.gz (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\GetPack\trgtame.gz (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Application Data\m\data.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Application Data\m\list.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\x\Application Data\m\srvlist.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aQLvs2F5.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mbvyy0h7.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pbvcrmlo.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mdelk.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wintems.exe (Trojan.Spammer) -> Delete on reboot.
C:\Documents and Settings\x\Application Data\m\flec006.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BMcf53942c.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BMcf53942c.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nulkksdikyg.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\WINDOWS\b160.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\hldrrr.exe (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\srosa.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
l'opération semble s'être bien déroulé puisque pour le moment je n'ai plus de pubs qui s'ouvrent. Quel anti-virus me conseille tu maintenant? Par contre je n'arrive toujours pas à ouvrir hijackthis le message "application win32 valide" s'affiche toujours.
Un grand merci pour ton aide.
Un grand merci pour ton aide.
le voilà:
ComboFix 08-09-05.09 - x 2008-09-08 18:33:31.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.269 [GMT 2:00]
Endroit: C:\Documents and Settings\x\Bureau\killbagle.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\NetworkService.AUTORITE NT\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\x\Application Data\inst.exe
C:\Documents and Settings\x\Application Data\m
C:\Documents and Settings\x\Cookies\x@date.ventivmedia[1].txt
C:\Documents and Settings\x\Cookies\x@mediatraffic[2].txt
C:\Documents and Settings\x\Cookies\x@metaffiliation[1].txt
C:\Documents and Settings\x\Cookies\x@reactivpub[3].txt
C:\Documents and Settings\x\Cookies\x@trafficmp[1].txt
C:\Documents and Settings\x\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Documents and Settings\x\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\x\Mes documents\YSTEM~1
C:\Documents and Settings\x\Mes documents\YSTEM~1\?ystem\
C:\Documents and Settings\x\Mes documents\YSTEM~1\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\aexmxz.dll
C:\WINDOWS\system32\ahvokfxk.dll
C:\WINDOWS\system32\annwsvgj.ini
C:\WINDOWS\system32\atmntmtk.ini
C:\WINDOWS\system32\bbdmxrvj.dll
C:\WINDOWS\system32\clfvuoyx.ini
C:\WINDOWS\system32\cmdahcyx.dll
C:\WINDOWS\system32\cnghrcso.dll
C:\WINDOWS\system32\cryqphkl.ini
C:\WINDOWS\system32\ctnfccmd.dll
C:\WINDOWS\system32\cvykuhgn.ini
C:\WINDOWS\system32\dbnfadmv.dll
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\eacindwf.dll
C:\WINDOWS\system32\elemhjrq.dll
C:\WINDOWS\system32\eogvasdp.dll
C:\WINDOWS\system32\eybnrmvw.ini
C:\WINDOWS\system32\fqqrwbxu.dll
C:\WINDOWS\system32\fumxvlyq.dll
C:\WINDOWS\system32\gwsigedq.dll
C:\WINDOWS\system32\harkxoku.dll
C:\WINDOWS\system32\hopddwxx.dll
C:\WINDOWS\system32\iakakhfs.dll
C:\WINDOWS\system32\ibfqkpfe.ini
C:\WINDOWS\system32\ipnhknru.dll
C:\WINDOWS\system32\ipulwcjm.ini
C:\WINDOWS\system32\itrsyett.dll
C:\WINDOWS\system32\iwohshti.dll
C:\WINDOWS\system32\iyeuwu.dll
C:\WINDOWS\system32\jhumelhj.dll
C:\WINDOWS\system32\jlryrgsg.dll
C:\WINDOWS\system32\jqiwxgwk.ini
C:\WINDOWS\system32\jrnjrmvs.dll
C:\WINDOWS\system32\kruakxxm.dll
C:\WINDOWS\system32\mlfwlgur.dll
C:\WINDOWS\system32\moydltww.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mskdchcu.dll
C:\WINDOWS\system32\muhmeitm.ini
C:\WINDOWS\system32\namagaob.dll
C:\WINDOWS\system32\nciqqkae.dll
C:\WINDOWS\system32\occfsyvh.ini
C:\WINDOWS\system32\pakzbf.dll
C:\WINDOWS\system32\pdnwvybl.dll
C:\WINDOWS\system32\pwmjlidy.dll
C:\WINDOWS\system32\qdcxyl.dll
C:\WINDOWS\system32\qisahvto.dll
C:\WINDOWS\system32\qpttlw.dll
C:\WINDOWS\system32\qrgjytfv.ini
C:\WINDOWS\system32\rcmmshsb.ini
C:\WINDOWS\system32\rgusqmec.ini
C:\WINDOWS\system32\rucsfium.dll
C:\WINDOWS\system32\rugxpg.dll
C:\WINDOWS\system32\sbpdexin.dll
C:\WINDOWS\system32\settcvxa.dll
C:\WINDOWS\system32\sfgecdyk.dll
C:\WINDOWS\system32\thbvxneo.ini
C:\WINDOWS\system32\txrkofns.dll
C:\WINDOWS\system32\tyncndbj.dll
C:\WINDOWS\system32\ubmxqhek.dll
C:\WINDOWS\system32\urteyjem.ini
C:\WINDOWS\system32\vaghysoh.ini
C:\WINDOWS\system32\vkcohrjd.dll
C:\WINDOWS\system32\vklovuyy.dll
C:\WINDOWS\system32\vmyxgfrm.dll
C:\WINDOWS\system32\vndsaitv.dll
C:\WINDOWS\system32\vriwcl.dll
C:\WINDOWS\system32\whkmemwx.dll
C:\WINDOWS\system32\xdhapfck.dll
C:\WINDOWS\system32\xnpecegc.dll
C:\WINDOWS\system32\ymgtslri.dll
C:\Documents and Settings\x\Application Data\YSTEM3~1\t?skmgr.exe . . . . Echec de suppression
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
-------\Service_srosa
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-08-08 to 2008-09-08 ))))))))))))))))))))))))))))))))))))
.
2008-09-08 18:56 . 2008-09-08 19:09 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-08 18:48 . 2008-09-08 18:48 <REP> d-------- C:\WINDOWS\LastGood
2008-09-08 00:06 . 2008-09-08 00:06 <REP> d--h----- C:\m
2008-09-06 20:18 . 2008-09-06 20:18 <REP> dr------- C:\Documents and Settings\LocalService.AUTORITE NT\Favoris
2008-09-06 17:02 . 2008-09-06 17:02 <REP> dr------- C:\Documents and Settings\NetworkService.AUTORITE NT\Favoris
2008-09-06 13:50 . 2008-09-06 15:06 <REP> d-------- C:\Program Files\Navilog1
2008-09-06 09:55 . 2008-09-06 09:55 29,824 --a------ C:\WINDOWS\system32\aQLvs2F5.exe
2008-08-26 21:43 . 2008-08-26 21:43 268 --ah----- C:\sqmdata12.sqm
2008-08-26 21:43 . 2008-08-26 21:43 244 --ah----- C:\sqmnoopt12.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-08 15:44 --------- d-----w C:\Documents and Settings\x\Application Data\OpenOffice.org2
2008-09-07 20:19 --------- d-----w C:\Program Files\eMule
2008-09-07 17:43 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-09-07 16:58 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-09-01 22:16 38,528 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-01 22:16 17,200 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-08-26 19:37 --------- d-----w C:\Program Files\HomePlayer1.5
2008-07-27 15:54 --------- d-----w C:\Documents and Settings\x\Application Data\Malwarebytes
2008-07-27 15:54 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-07-26 12:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2008-07-26 12:51 --------- d-----w C:\Program Files\CCleaner
2008-07-26 12:48 --------- d-----w C:\Program Files\Yahoo!
2008-07-25 18:20 --------- d-----w C:\Program Files\Trend Micro
2008-07-25 18:17 --------- d-----w C:\Program Files\Panicware
2008-07-24 16:28 --------- d-----w C:\Documents and Settings\x\Application Data\Image Zone Express
2008-07-21 14:51 --------- d-----w C:\Documents and Settings\x\Application Data\?ystem32
2008-07-20 13:39 --------- d-----w C:\Documents and Settings\x\Application Data\LimeWire
2008-07-20 13:26 --------- d-----w C:\Program Files\LimeWire
2008-07-20 09:47 --------- d-----w C:\Program Files\GigaTribe
2008-07-19 12:46 --------- d-----w C:\Program Files\DirectVobSub
2008-06-20 17:45 19,896 ----a-w C:\Documents and Settings\x\Application Data\GDIPFONTCACHEV1.DAT
2008-04-25 12:36 3,861,320 -c--a-w C:\Program Files\eMule0.48a-Installer2.exe
2007-09-29 10:19 47,360 ----a-w C:\Documents and Settings\x\Application Data\pcouffin.sys
2005-01-23 22:16 19,560 -c--a-w C:\Documents and Settings\Administrateur\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kmwmjdbc"="C:\Documents and Settings\x\Application Data\?ystem32\t?skmgr.exe" [?]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-19 405583]
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [2005-03-17 536576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 98304]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"Athan"="C:\Program Files\Athan\Athan.exe" [2007-09-06 1003520]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-15 155648]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-11-09 128920]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-20 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-19 405583]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=qdcxyl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"MSACM.CEGSM"= mobilev.acm
"vidc.mpng"= C:\Program Files\t@b\[u]0[/u].957\686\tabdec.dll
"vidc.mvjp"= C:\Program Files\t@b\[u]0[/u].957\686\tabdec.dll
"vidc.444p"= C:\Program Files\t@b\[u]0[/u].957\686\tabdec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Documents and Settings\\x\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:5\\eMule\\emule.exe"=
"C:\\Program Files\\HomePlayer1.5\\HomePlayer.exe"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
R3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 21344]
R3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5211.sys [2003-07-17 322560]
S3 PIXMCV;JVC Communication PIX-MCV Driver;C:\WINDOWS\system32\Drivers\pixmcvc.sys [2002-09-28 32000]
S3 PIXMCVA;JVC PIX-MCV Audio Capture;C:\WINDOWS\system32\Drivers\pixmcva.sys [2002-10-03 28057]
S3 PIXMCVV;JVC PIX-MCV Video Capture;C:\WINDOWS\system32\Drivers\pixmcvv.sys [2002-11-28 21081]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4942bc1-ba3e-11dc-8bed-0007cb0000ff}]
\Shell\AutoRun\command - I:\fooool.exe
\Shell\explore\Command - I:\fooool.exe
\Shell\open\Command - I:\fooool.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
.
- - - - ORPHANS REMOVED - - - -
BHO-{FB359D39-28A8-0207-FF3F-0CA2E09D19B3} - C:\WINDOWS\system32\hdk.dll
HKCU-Run-swg - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKCU-Run-Masp - C:\DOCUME~1\x\MESDOC~1\YSTEM~1\spoolsv.exe
HKLM-Run-avast! - C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
HKU-Default-Run-drvsyskit - C:\WINDOWS\system32\drivers\hldrrr.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\x\Application Data\Mozilla\Firefox\Profiles\h6cw9tgq.habib\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.lephoceen.fr/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-08 19:49:31
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.bin
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\WINDOWS\SoftwareDistribution\Download\b51583c5f22da0e6e536a968a9783fd0\update\update.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-09-08 20:13:32 - machine was rebooted [x]
ComboFix-quarantined-files.txt 2008-09-08 18:12:15
Pre-Run: 474,103,808 octets libres
Post-Run: 116,596,736 octets libres
244 --- E O F --- 2008-01-23 21:19:08
ComboFix 08-09-05.09 - x 2008-09-08 18:33:31.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.269 [GMT 2:00]
Endroit: C:\Documents and Settings\x\Bureau\killbagle.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\NetworkService.AUTORITE NT\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\x\Application Data\inst.exe
C:\Documents and Settings\x\Application Data\m
C:\Documents and Settings\x\Cookies\x@date.ventivmedia[1].txt
C:\Documents and Settings\x\Cookies\x@mediatraffic[2].txt
C:\Documents and Settings\x\Cookies\x@metaffiliation[1].txt
C:\Documents and Settings\x\Cookies\x@reactivpub[3].txt
C:\Documents and Settings\x\Cookies\x@trafficmp[1].txt
C:\Documents and Settings\x\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Documents and Settings\x\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\x\Mes documents\YSTEM~1
C:\Documents and Settings\x\Mes documents\YSTEM~1\?ystem\
C:\Documents and Settings\x\Mes documents\YSTEM~1\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\aexmxz.dll
C:\WINDOWS\system32\ahvokfxk.dll
C:\WINDOWS\system32\annwsvgj.ini
C:\WINDOWS\system32\atmntmtk.ini
C:\WINDOWS\system32\bbdmxrvj.dll
C:\WINDOWS\system32\clfvuoyx.ini
C:\WINDOWS\system32\cmdahcyx.dll
C:\WINDOWS\system32\cnghrcso.dll
C:\WINDOWS\system32\cryqphkl.ini
C:\WINDOWS\system32\ctnfccmd.dll
C:\WINDOWS\system32\cvykuhgn.ini
C:\WINDOWS\system32\dbnfadmv.dll
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\eacindwf.dll
C:\WINDOWS\system32\elemhjrq.dll
C:\WINDOWS\system32\eogvasdp.dll
C:\WINDOWS\system32\eybnrmvw.ini
C:\WINDOWS\system32\fqqrwbxu.dll
C:\WINDOWS\system32\fumxvlyq.dll
C:\WINDOWS\system32\gwsigedq.dll
C:\WINDOWS\system32\harkxoku.dll
C:\WINDOWS\system32\hopddwxx.dll
C:\WINDOWS\system32\iakakhfs.dll
C:\WINDOWS\system32\ibfqkpfe.ini
C:\WINDOWS\system32\ipnhknru.dll
C:\WINDOWS\system32\ipulwcjm.ini
C:\WINDOWS\system32\itrsyett.dll
C:\WINDOWS\system32\iwohshti.dll
C:\WINDOWS\system32\iyeuwu.dll
C:\WINDOWS\system32\jhumelhj.dll
C:\WINDOWS\system32\jlryrgsg.dll
C:\WINDOWS\system32\jqiwxgwk.ini
C:\WINDOWS\system32\jrnjrmvs.dll
C:\WINDOWS\system32\kruakxxm.dll
C:\WINDOWS\system32\mlfwlgur.dll
C:\WINDOWS\system32\moydltww.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mskdchcu.dll
C:\WINDOWS\system32\muhmeitm.ini
C:\WINDOWS\system32\namagaob.dll
C:\WINDOWS\system32\nciqqkae.dll
C:\WINDOWS\system32\occfsyvh.ini
C:\WINDOWS\system32\pakzbf.dll
C:\WINDOWS\system32\pdnwvybl.dll
C:\WINDOWS\system32\pwmjlidy.dll
C:\WINDOWS\system32\qdcxyl.dll
C:\WINDOWS\system32\qisahvto.dll
C:\WINDOWS\system32\qpttlw.dll
C:\WINDOWS\system32\qrgjytfv.ini
C:\WINDOWS\system32\rcmmshsb.ini
C:\WINDOWS\system32\rgusqmec.ini
C:\WINDOWS\system32\rucsfium.dll
C:\WINDOWS\system32\rugxpg.dll
C:\WINDOWS\system32\sbpdexin.dll
C:\WINDOWS\system32\settcvxa.dll
C:\WINDOWS\system32\sfgecdyk.dll
C:\WINDOWS\system32\thbvxneo.ini
C:\WINDOWS\system32\txrkofns.dll
C:\WINDOWS\system32\tyncndbj.dll
C:\WINDOWS\system32\ubmxqhek.dll
C:\WINDOWS\system32\urteyjem.ini
C:\WINDOWS\system32\vaghysoh.ini
C:\WINDOWS\system32\vkcohrjd.dll
C:\WINDOWS\system32\vklovuyy.dll
C:\WINDOWS\system32\vmyxgfrm.dll
C:\WINDOWS\system32\vndsaitv.dll
C:\WINDOWS\system32\vriwcl.dll
C:\WINDOWS\system32\whkmemwx.dll
C:\WINDOWS\system32\xdhapfck.dll
C:\WINDOWS\system32\xnpecegc.dll
C:\WINDOWS\system32\ymgtslri.dll
C:\Documents and Settings\x\Application Data\YSTEM3~1\t?skmgr.exe . . . . Echec de suppression
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
-------\Service_srosa
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-08-08 to 2008-09-08 ))))))))))))))))))))))))))))))))))))
.
2008-09-08 18:56 . 2008-09-08 19:09 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-08 18:48 . 2008-09-08 18:48 <REP> d-------- C:\WINDOWS\LastGood
2008-09-08 00:06 . 2008-09-08 00:06 <REP> d--h----- C:\m
2008-09-06 20:18 . 2008-09-06 20:18 <REP> dr------- C:\Documents and Settings\LocalService.AUTORITE NT\Favoris
2008-09-06 17:02 . 2008-09-06 17:02 <REP> dr------- C:\Documents and Settings\NetworkService.AUTORITE NT\Favoris
2008-09-06 13:50 . 2008-09-06 15:06 <REP> d-------- C:\Program Files\Navilog1
2008-09-06 09:55 . 2008-09-06 09:55 29,824 --a------ C:\WINDOWS\system32\aQLvs2F5.exe
2008-08-26 21:43 . 2008-08-26 21:43 268 --ah----- C:\sqmdata12.sqm
2008-08-26 21:43 . 2008-08-26 21:43 244 --ah----- C:\sqmnoopt12.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-08 15:44 --------- d-----w C:\Documents and Settings\x\Application Data\OpenOffice.org2
2008-09-07 20:19 --------- d-----w C:\Program Files\eMule
2008-09-07 17:43 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-09-07 16:58 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-09-01 22:16 38,528 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-01 22:16 17,200 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-08-26 19:37 --------- d-----w C:\Program Files\HomePlayer1.5
2008-07-27 15:54 --------- d-----w C:\Documents and Settings\x\Application Data\Malwarebytes
2008-07-27 15:54 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-07-26 12:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2008-07-26 12:51 --------- d-----w C:\Program Files\CCleaner
2008-07-26 12:48 --------- d-----w C:\Program Files\Yahoo!
2008-07-25 18:20 --------- d-----w C:\Program Files\Trend Micro
2008-07-25 18:17 --------- d-----w C:\Program Files\Panicware
2008-07-24 16:28 --------- d-----w C:\Documents and Settings\x\Application Data\Image Zone Express
2008-07-21 14:51 --------- d-----w C:\Documents and Settings\x\Application Data\?ystem32
2008-07-20 13:39 --------- d-----w C:\Documents and Settings\x\Application Data\LimeWire
2008-07-20 13:26 --------- d-----w C:\Program Files\LimeWire
2008-07-20 09:47 --------- d-----w C:\Program Files\GigaTribe
2008-07-19 12:46 --------- d-----w C:\Program Files\DirectVobSub
2008-06-20 17:45 19,896 ----a-w C:\Documents and Settings\x\Application Data\GDIPFONTCACHEV1.DAT
2008-04-25 12:36 3,861,320 -c--a-w C:\Program Files\eMule0.48a-Installer2.exe
2007-09-29 10:19 47,360 ----a-w C:\Documents and Settings\x\Application Data\pcouffin.sys
2005-01-23 22:16 19,560 -c--a-w C:\Documents and Settings\Administrateur\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kmwmjdbc"="C:\Documents and Settings\x\Application Data\?ystem32\t?skmgr.exe" [?]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-19 405583]
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [2005-03-17 536576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 98304]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"Athan"="C:\Program Files\Athan\Athan.exe" [2007-09-06 1003520]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-15 155648]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-11-09 128920]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-20 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-19 405583]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=qdcxyl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"MSACM.CEGSM"= mobilev.acm
"vidc.mpng"= C:\Program Files\t@b\[u]0[/u].957\686\tabdec.dll
"vidc.mvjp"= C:\Program Files\t@b\[u]0[/u].957\686\tabdec.dll
"vidc.444p"= C:\Program Files\t@b\[u]0[/u].957\686\tabdec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Documents and Settings\\x\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:5\\eMule\\emule.exe"=
"C:\\Program Files\\HomePlayer1.5\\HomePlayer.exe"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
R3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 21344]
R3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5211.sys [2003-07-17 322560]
S3 PIXMCV;JVC Communication PIX-MCV Driver;C:\WINDOWS\system32\Drivers\pixmcvc.sys [2002-09-28 32000]
S3 PIXMCVA;JVC PIX-MCV Audio Capture;C:\WINDOWS\system32\Drivers\pixmcva.sys [2002-10-03 28057]
S3 PIXMCVV;JVC PIX-MCV Video Capture;C:\WINDOWS\system32\Drivers\pixmcvv.sys [2002-11-28 21081]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4942bc1-ba3e-11dc-8bed-0007cb0000ff}]
\Shell\AutoRun\command - I:\fooool.exe
\Shell\explore\Command - I:\fooool.exe
\Shell\open\Command - I:\fooool.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
.
- - - - ORPHANS REMOVED - - - -
BHO-{FB359D39-28A8-0207-FF3F-0CA2E09D19B3} - C:\WINDOWS\system32\hdk.dll
HKCU-Run-swg - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKCU-Run-Masp - C:\DOCUME~1\x\MESDOC~1\YSTEM~1\spoolsv.exe
HKLM-Run-avast! - C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
HKU-Default-Run-drvsyskit - C:\WINDOWS\system32\drivers\hldrrr.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\x\Application Data\Mozilla\Firefox\Profiles\h6cw9tgq.habib\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.lephoceen.fr/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-08 19:49:31
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.bin
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\WINDOWS\SoftwareDistribution\Download\b51583c5f22da0e6e536a968a9783fd0\update\update.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-09-08 20:13:32 - machine was rebooted [x]
ComboFix-quarantined-files.txt 2008-09-08 18:12:15
Pre-Run: 474,103,808 octets libres
Post-Run: 116,596,736 octets libres
244 --- E O F --- 2008-01-23 21:19:08
Copie le texte ci-dessous :
File::
I:\fooool.exe
C:\Documents and Settings\x\Application Data\YSTEM3~1\t?skmgr.exe
C:\WINDOWS\system32\aQLvs2F5.exe
Folder::
C:\Documents and Settings\x\Application Data\YSTEM3~1
C:\WINDOWS\system32\CatRoot_bak
C:\m
C:\Program Files\Navilog1
C:\Documents and Settings\x\Application Data\?ystem32
C:\Program Files\t@b
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"=-
"vidc.DIV4"=-
"msacm.divxa32"=-
"MSACM.CEGSM"=-
"vidc.mpng"=-
"vidc.mvjp"=-
"vidc.444p"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4942bc1-ba3e-11dc-8bed-0007cb0000ff}]
DirLook::
C:\WINDOWS\SoftwareDistribution\Download
C:\WINDOWS\SoftwareDistribution\Download\b51583c5f22da0e6e536a968a9783fd0
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
File::
I:\fooool.exe
C:\Documents and Settings\x\Application Data\YSTEM3~1\t?skmgr.exe
C:\WINDOWS\system32\aQLvs2F5.exe
Folder::
C:\Documents and Settings\x\Application Data\YSTEM3~1
C:\WINDOWS\system32\CatRoot_bak
C:\m
C:\Program Files\Navilog1
C:\Documents and Settings\x\Application Data\?ystem32
C:\Program Files\t@b
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"=-
"vidc.DIV4"=-
"msacm.divxa32"=-
"MSACM.CEGSM"=-
"vidc.mpng"=-
"vidc.mvjp"=-
"vidc.444p"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4942bc1-ba3e-11dc-8bed-0007cb0000ff}]
DirLook::
C:\WINDOWS\SoftwareDistribution\Download
C:\WINDOWS\SoftwareDistribution\Download\b51583c5f22da0e6e536a968a9783fd0
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
voici le rapport combofix:
ComboFix 08-09-05.12 - x 2008-09-09 17:30:34.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.134 [GMT 2:00]
Endroit: C:\Documents and Settings\x\Bureau\killbagle.exe
Command switches used :: C:\Documents and Settings\x\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\x\Application Data\YSTEM3~1\t?skmgr.exe
C:\m
C:\m\flec006.exe
C:\Program Files\Navilog1
C:\Program Files\Navilog1\catchme.exe
C:\Program Files\Navilog1\Contents\Filess.bat
C:\Program Files\Navilog1\Contents\Folders.bat
C:\Program Files\Navilog1\Contents\Folderss.bat
C:\Program Files\Navilog1\Contents\Gnc2.bat
C:\Program Files\Navilog1\Contents\Gnc2su.bat
C:\Program Files\Navilog1\Contents\Gncs.bat
C:\Program Files\Navilog1\Contents\Gncssfil.bat
C:\Program Files\Navilog1\Contents\Heurs.bat
C:\Program Files\Navilog1\Contents\Heurss.bat
C:\Program Files\Navilog1\Contents\Orphus.bat
C:\Program Files\Navilog1\Contents\Wlist.bat
C:\Program Files\Navilog1\fsbl1.txt
C:\Program Files\Navilog1\fsblreg.txt
C:\Program Files\Navilog1\GetPaths.exe
C:\Program Files\Navilog1\gnc.exe
C:\Program Files\Navilog1\navilog1.bat
C:\Program Files\Navilog1\Navreb.bat
C:\Program Files\Navilog1\oem2ansi.exe
C:\Program Files\Navilog1\Process.exe
C:\Program Files\Navilog1\recherok.txt
C:\Program Files\Navilog1\reg.exe
C:\Program Files\Navilog1\regnavi.reg
C:\Program Files\Navilog1\traite.bat
C:\Program Files\Navilog1\traite2.bat
C:\Program Files\Navilog1\traite3.bat
C:\Program Files\Navilog1\unins000.dat
C:\Program Files\Navilog1\unins000.exe
C:\Program Files\t@b
C:\Program Files\t@b\[u]0[/u].957\686\banana.png
C:\Program Files\t@b\[u]0[/u].957\686\bzip2.txt
C:\Program Files\t@b\[u]0[/u].957\686\c\module.info
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\AlphaAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\AlphaTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\AlphaValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\beginning
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\end
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\left
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\leftswitch
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\right
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\rightswitch
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\tickpos
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\ticksleft
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\ticksright
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_events\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_export\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_openfile\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_picturedigs\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_tabout\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_video\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bananacrop\l
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bananacrop\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\BlueAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\BlueTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\BlueValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\agree
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\cancel
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\disagree
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\false
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\negative
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\no
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\off
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\ok
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\on
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\positive
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\true
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\yes
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\buddyview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\choice\choice
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\choice\next
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\choice\previous
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\choice\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\choice_audiodevice\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\classview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\classview_ZS4Effect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\digslides\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\editorview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\fadein
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\fadeout
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\normalize
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\normalize_is_off
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\normalize_is_on
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\dirname
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\export
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\filename
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\maxwidth
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\title
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\usesizelimit
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\folderview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\fontpig_maker\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\fontsize\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\fontview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\gadgetstate\gad_state_focus
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\gadgetstate\gad_state_hover
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\gadgetstate\gad_state_normal
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\gadgetstate\gad_state_pressed
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\GreenAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\GreenTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\GreenValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_compiler
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_dir_bin
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_dir_desktop
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_dir_drives
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_dir_font
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_dir_proginst
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_flavour
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_homedir
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_language
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\da
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\de-ch
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\de
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\en-ca
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\en
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\es
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\fr
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\it
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\uz
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\add2project
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\channels
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\dims
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\done
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errcantopen
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errepeat
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errintrnl
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errnofilnam
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errwhileloading
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errwhilesaving
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\expaud
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\expfnam
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\export
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\expvid
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\fps
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\height
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\maxheight
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\maxwidth
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\nuproj
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\open
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\project
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\reloadproj
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\save
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\savprojas
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\search
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\shiftdrag
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\track
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\trackhite
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\tracklen
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\trackpos
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\tracktimes
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_adjdown
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_adjup
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_change
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_keyadd
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_keydel
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_keynext
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_keyprev
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_next
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_prev
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_setdft
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_setmax
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_setmin
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_value
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\width
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmo_export\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmoptions\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\cancel
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\cancelled
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\done
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\enter
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\no
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\yes
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProject\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmtrackedit\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmtrackvars\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmtravars\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\always
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\close
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\continue
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\exit
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\finish
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\license
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\load
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\never
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\open
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\save
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\alpha
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\blue
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\green
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\opacity
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\red
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\RedAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\RedTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\RedValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\setup\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\beginning
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\device
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\dig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\duration
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\end
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\exit
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\filename
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\filesize
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\nextdig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\playpause
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\position
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\savwavsel
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\selectbeginning
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\selectend
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\status
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\stop
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\timeline
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\undig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showdocument\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showfolder\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showfont\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimage\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\clock
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\counter
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\dig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\exit
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\first
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\infoleft
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\inforight
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\last
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\next
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\nextdig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\previous
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\revert
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\save
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\toolbar
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\undig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showtext\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\SrcEffDest\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\checkversion
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\thisis
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\unknown
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\up2date
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\upgrade
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\TimesteinProps\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\TSTrackExport\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\vee_mixer\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VeeAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\veecur\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\a
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\d
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\e
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\i
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\m
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\o
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\p
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\s
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\timeline
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\z
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VeeTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VeeValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewbuddy\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewclass\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewfont\facebox
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewfont\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewgadget\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewobject\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewtrans\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viff_keyrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viff_keyyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viff_pixelfilter\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\WhyAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\WhyTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\WhyValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\YouAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\YouTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\YouValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_FullRotations\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_OutputOpacity\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_OutputPositionX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_OutputPositionY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_OutputSizeX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_OutputSizeY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_RotationAngle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceCropBottom\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceCropLeft\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceCropRight\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceCropTop\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceOpacity\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceVolume\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\ZS4AudioEffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\ZS4Effect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\ZS4VideoEffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\AlphaAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\AlphaBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\AlphaTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\AlphaValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\audiovisualization\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_audio\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_events\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_export\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_openfile\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_picturedigs\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_tabout\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_video\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\BlueAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\BlueBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\BlueTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\BlueValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\BlurrFilters\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\choice_tweener\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\circ2_angle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\circ2_bumps\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\classview_ZS4Effect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\compatt\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\dig\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\digentry\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\digslides\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EdgeFilters\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\editorview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjHalf\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjMax\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjMin\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjMPos\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjNeg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjNeutral\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\export_digaudio\fadein
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\export_digaudio\fadeout
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\export_digaudio\normalize_is_off
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\export_digaudio\normalize_is_on
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\export_digaudio\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\exportdig\export
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\exportdig\maxwidth
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\exportdig\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ffeffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ffsource\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\focal_distadd\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\focus0_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\focus0_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\focus1_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\focus1_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\folderview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\fontclass\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\fontitem\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\fontsize\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\fontview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\GreenAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\GreenBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\GreenTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\GreenValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_a2c\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_c2a\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_mul\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_negative\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_swap\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_xpand\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_B\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_B_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_B_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_B_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_G\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_G_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_G_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_G_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_R\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_R_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_R_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_R_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_S\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_S_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_S_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_S_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_U\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_U_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_U_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_U_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_V\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_V_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_V_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_V_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_Y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_Y_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_Y_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_Y_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\keeptilable\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\maketilable\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\MediaMixer\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmconv_stat_radius\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmconv2\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\add2project
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\expaud
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\expfnam
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\expvid
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\maxhalf
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\nuproj
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\reloadproj
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\savprojas
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\var_change
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\var_value
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\vqual
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\MMImport\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmo_export\selcodec
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmo_export\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmoptab\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmoptions\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\MMProgress\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\MMProject\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmt_position\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmt_space\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmtext\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmtrack\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmtrackedit\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmtrackvars\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmtravars\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmvpatt\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\momomaniac\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattrepe_bottom\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattrepe_left\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattrepe_right\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattrepe_top\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattslant_hori\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattslant_vert\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_hamp\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_hfreq\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_hpos\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_vamp\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_vars\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_vfreq\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_vpos\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\PixChanMulCentre\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\PixChanMulFactor\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RedAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RedBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RedTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RedValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_lb_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_lb_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_lt_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_lt_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_rb_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_rb_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_rt_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_rt_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_angle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_count\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_distance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_iterate_angle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_iterate_dist\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_iterate_size\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_startsize\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_from_alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_from_blue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_from_green\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_from_red\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_to_alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_to_blue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_to_green\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_to_red\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\rotile\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\sgtx_fontsize\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\showcanvas\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\SrcEffDest\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tabfreeframe\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tabout\thisis
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tabout\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tabout\unknown
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tiff_reverse\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\timestein\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\TimesteinProps\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\TSTrackExport\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tweener\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tweenolin\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tweenspline\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tweensquare\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tweenweird1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VECircCentreX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VECircCentreY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VECircRadius\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VeeAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VeeBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\veecur\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEEnlargeFactor\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEES\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VeeTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VeeValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEPoint0X\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEPoint0Y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEPoint1X\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEPoint1Y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VETangentRange\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_a2rgbgrad\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_adjhsl\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_adjrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_adjyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alpha2b\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alpha2g\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alpha2r\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alpha2rgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alphagrad\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alphamod\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alphashape\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_bt\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_cirgro\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_cirshr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_elli\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_ello\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_lr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_rl\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_simple\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_tb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_wipe\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_b2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_blura\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_blurr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_blurr_chroma\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_bmf_misc\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_bmfilter\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_box\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_boxi\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_brighten1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_calpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_calphi\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_calphl\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_calphm\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_coloradjusters\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_conmix\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_cont_pixelmode\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_cont_shapegrad\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_cont_shapesharp\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_container\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_convolution\matsiz
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_convolution\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_copaq\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_darken1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_desaturate\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_destblend\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_destbleni\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_circ1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_circ2\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_mouth1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_mouth2\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_mouth3\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_mouth4\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_place1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_quad1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_distort\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dither\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dither12bit\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dither8bit2222\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dither8bit332\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_edga\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_edge\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_effrms\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_even\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_fields\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_g2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_keydiff\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_keyers\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_keyrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_keysmoothe\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_keyyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_kezrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_kezyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_l2r\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_mmt_credits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_mmt_ticker\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_negrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_negyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_odd\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_oval\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_ovali\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pattrepe\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pattrms\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pattslant\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pattwave\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pf_adv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pf_dumb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pixelchan\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pixelfilter\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_points\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_polialph\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_polialpo\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_policonti\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_policonto\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_ma\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_mb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_mg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_mr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_my\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_na\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_nb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_ng\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_nh\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_nr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_ns\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_ny\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_xa\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_xb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_xg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_xr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_xy\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantize\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantize12bit\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantize8bit2222\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantize8bit332\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantrgba\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantyuva\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_r2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_remperspect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rep\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_reph\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_replin\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_reppfronts\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_reppoints\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_reprec\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_repscale\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_repv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rotblue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rotfwd\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rotgreen\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rotred\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rotyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_s2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_saturate\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_sg_text\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_sggr_line\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_sgtx_digitime\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_sgtx_string\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_circle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_circli\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_elli\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_ello\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_recti\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_recto\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_rlini\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_rlino\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_circle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_circli\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_elli\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_ello\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_recti\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_recto\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_rlini\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_rlino\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_signalgen\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_swapanb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_swapang\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_swapanr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_t2b\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_tintrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_u2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_v2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_y2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\WhyAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\WhyBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\WhyTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\WhyValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\wipe_angle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\wipe_position\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\wipe_smoothing\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\YouAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\YouBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\YouTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\YouValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_FullRotations\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_gradient_size\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_luma_adjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_luma_centre\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_luma_factor\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_MediaTimeOffset\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputOpacity\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputPositionX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputPositionY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputPositionZ\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputSizeX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputSizeY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputSizeZ\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_powadj_1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_powadj_2\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_rect_bottom\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_rect_left\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_rect_right\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_rect_top\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_RotationAngle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_satu_ratio\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCenterX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCenterY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCenterZ\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCropBottom\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCropLeft\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCropRight\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCropTop\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceOpacity\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceVolume\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_text_align\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_text_valign\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ZS4AudioEffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ZS4Effect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4FontName\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4TextFile\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4TextString\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ZS4TimeEffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ZS4VideoEffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\cmd.dll
C:\Program Files\t@b\[u]0[/u].957\686\desktop.dll
C:\Program Files\t@b\[u]0[/u].957\686\document_dig.dll
C:\Program Files\t@b\[u]0[/u].957\686\expat.txt
C:\Program Files\t@b\[u]0[/u].957\686\font\Caliban.ttf
C:\Program Files\t@b\[u]0[/u].957\686\freeframe.txt
C:\Program Files\t@b\[u]0[/u].957\686\freeframe\readme.txt
C:\Program Files\t@b\[u]0[/u].957\686\ftfont.dll
C:\Program Files\t@b\[u]0[/u].957\686\ftl.txt
C:\Program Files\t@b\[u]0[/u].957\686\gadclsview.dll
C:\Program Files\t@b\[u]0[/u].957\686\grafix.dll
C:\Program Files\t@b\[u]0[/u].957\686\gui_wingdi.dll
C:\Program Files\t@b\[u]0[/u].957\686\http.dll
C:\Program Files\t@b\[u]0[/u].957\686\jpeg62.dll
C:\Program Files\t@b\[u]0[/u].957\686\jpg.txt
C:\Program Files\t@b\[u]0[/u].957\686\kernel.dll
C:\Program Files\t@b\[u]0[/u].957\686\lesser.txt
C:\Program Files\t@b\[u]0[/u].957\686\lgpl.txt
C:\Program Files\t@b\[u]0[/u].957\686\libtiff.txt
C:\Program Files\t@b\[u]0[/u].957\686\libtiff3.dll
C:\Program Files\t@b\[u]0[/u].957\686\license-fi.txt
C:\Program Files\t@b\[u]0[/u].957\686\LICENSE.txt
C:\Program Files\t@b\[u]0[/u].957\686\mmconv2.dll
C:\Program Files\t@b\[u]0[/u].957\686\mmeditor.dll
C:\Program Files\t@b\[u]0[/u].957\686\mmtext.dll
C:\Program Files\t@b\[u]0[/u].957\686\mmvpatt.dll
C:\Program Files\t@b\[u]0/u
ComboFix 08-09-05.12 - x 2008-09-09 17:30:34.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.134 [GMT 2:00]
Endroit: C:\Documents and Settings\x\Bureau\killbagle.exe
Command switches used :: C:\Documents and Settings\x\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\x\Application Data\YSTEM3~1\t?skmgr.exe
C:\m
C:\m\flec006.exe
C:\Program Files\Navilog1
C:\Program Files\Navilog1\catchme.exe
C:\Program Files\Navilog1\Contents\Filess.bat
C:\Program Files\Navilog1\Contents\Folders.bat
C:\Program Files\Navilog1\Contents\Folderss.bat
C:\Program Files\Navilog1\Contents\Gnc2.bat
C:\Program Files\Navilog1\Contents\Gnc2su.bat
C:\Program Files\Navilog1\Contents\Gncs.bat
C:\Program Files\Navilog1\Contents\Gncssfil.bat
C:\Program Files\Navilog1\Contents\Heurs.bat
C:\Program Files\Navilog1\Contents\Heurss.bat
C:\Program Files\Navilog1\Contents\Orphus.bat
C:\Program Files\Navilog1\Contents\Wlist.bat
C:\Program Files\Navilog1\fsbl1.txt
C:\Program Files\Navilog1\fsblreg.txt
C:\Program Files\Navilog1\GetPaths.exe
C:\Program Files\Navilog1\gnc.exe
C:\Program Files\Navilog1\navilog1.bat
C:\Program Files\Navilog1\Navreb.bat
C:\Program Files\Navilog1\oem2ansi.exe
C:\Program Files\Navilog1\Process.exe
C:\Program Files\Navilog1\recherok.txt
C:\Program Files\Navilog1\reg.exe
C:\Program Files\Navilog1\regnavi.reg
C:\Program Files\Navilog1\traite.bat
C:\Program Files\Navilog1\traite2.bat
C:\Program Files\Navilog1\traite3.bat
C:\Program Files\Navilog1\unins000.dat
C:\Program Files\Navilog1\unins000.exe
C:\Program Files\t@b
C:\Program Files\t@b\[u]0[/u].957\686\banana.png
C:\Program Files\t@b\[u]0[/u].957\686\bzip2.txt
C:\Program Files\t@b\[u]0[/u].957\686\c\module.info
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\AlphaAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\AlphaTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\AlphaValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\beginning
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\end
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\left
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\leftswitch
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\right
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\rightswitch
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\tickpos
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\ticksleft
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\ticksright
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\audiovisualization\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_events\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_export\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_openfile\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_picturedigs\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_tabout\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\av_video\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bananacrop\l
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bananacrop\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\BlueAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\BlueTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\BlueValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\agree
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\cancel
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\disagree
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\false
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\negative
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\no
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\off
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\ok
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\on
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\positive
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\true
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\bool\yes
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\buddyview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\choice\choice
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\choice\next
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\choice\previous
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\choice\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\choice_audiodevice\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\classview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\classview_ZS4Effect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\digslides\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\editorview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\fadein
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\fadeout
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\normalize
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\normalize_is_off
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\normalize_is_on
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\export_digaudio\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\dirname
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\export
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\filename
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\maxwidth
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\title
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\exportdig\usesizelimit
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\folderview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\fontpig_maker\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\fontsize\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\fontview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\gadgetstate\gad_state_focus
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\gadgetstate\gad_state_hover
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\gadgetstate\gad_state_normal
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\gadgetstate\gad_state_pressed
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\GreenAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\GreenTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\GreenValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_compiler
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_dir_bin
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_dir_desktop
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_dir_drives
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_dir_font
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_dir_proginst
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_flavour
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_homedir
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\kernel_info\kernel_info_language
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\da
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\de-ch
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\de
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\en-ca
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\en
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\es
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\fr
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\it
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\language\uz
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\add2project
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\channels
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\dims
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\done
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errcantopen
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errepeat
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errintrnl
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errnofilnam
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errwhileloading
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\errwhilesaving
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\expaud
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\expfnam
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\export
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\expvid
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\fps
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\height
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\maxheight
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\maxwidth
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\nuproj
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\open
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\project
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\reloadproj
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\save
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\savprojas
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\search
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\shiftdrag
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\track
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\trackhite
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\tracklen
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\trackpos
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\tracktimes
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_adjdown
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_adjup
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_change
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_keyadd
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_keydel
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_keynext
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_keyprev
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_next
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_prev
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_setdft
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_setmax
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_setmin
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\var_value
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmeditor\width
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmo_export\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmoptions\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\cancel
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\cancelled
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\done
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\enter
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\no
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProgress\yes
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\MMProject\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmtrackedit\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmtrackvars\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\mmtravars\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\always
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\close
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\continue
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\exit
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\finish
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\license
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\load
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\never
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\open
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\save
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\object\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\alpha
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\blue
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\green
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\opacity
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\red
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\pixelchannel\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\RedAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\RedTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\RedValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\setup\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\beginning
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\device
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\dig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\duration
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\end
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\exit
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\filename
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\filesize
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\nextdig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\playpause
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\position
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\savwavsel
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\selectbeginning
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\selectend
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\status
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\stop
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\timeline
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showaudio\undig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showdocument\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showfolder\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showfont\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimage\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\clock
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\counter
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\dig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\exit
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\first
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\infoleft
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\inforight
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\last
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\next
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\nextdig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\previous
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\revert
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\save
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\toolbar
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showimages\undig
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\showtext\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\SrcEffDest\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\checkversion
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\thisis
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\unknown
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\up2date
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\tabout\upgrade
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\TimesteinProps\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\TSTrackExport\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\vee_mixer\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VeeAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\veecur\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\a
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\d
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\e
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\i
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\m
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\o
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\p
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\s
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\timeline
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VEES\z
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VeeTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\VeeValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewbuddy\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewclass\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewfont\facebox
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewfont\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewgadget\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewobject\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viewtrans\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viff_keyrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viff_keyyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\viff_pixelfilter\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\WhyAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\WhyTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\WhyValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\YouAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\YouTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\YouValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_FullRotations\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_OutputOpacity\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_OutputPositionX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_OutputPositionY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_OutputSizeX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_OutputSizeY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_RotationAngle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceCropBottom\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceCropLeft\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceCropRight\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceCropTop\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceOpacity\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\zs4_SourceVolume\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\ZS4AudioEffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\ZS4Effect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\de\ZS4VideoEffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\AlphaAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\AlphaBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\AlphaTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\AlphaValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\audiovisualization\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_audio\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_events\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_export\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_openfile\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_picturedigs\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_tabout\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\av_video\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\BlueAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\BlueBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\BlueTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\BlueValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\BlurrFilters\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\choice_tweener\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\circ2_angle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\circ2_bumps\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\classview_ZS4Effect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\compatt\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\dig\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\digentry\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\digslides\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EdgeFilters\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\editorview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjHalf\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjMax\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjMin\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjMPos\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjNeg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\EffAdjNeutral\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\export_digaudio\fadein
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\export_digaudio\fadeout
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\export_digaudio\normalize_is_off
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\export_digaudio\normalize_is_on
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\export_digaudio\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\exportdig\export
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\exportdig\maxwidth
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\exportdig\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ffeffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ffsource\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\focal_distadd\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\focus0_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\focus0_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\focus1_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\focus1_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\folderview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\fontclass\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\fontitem\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\fontsize\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\fontview\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\GreenAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\GreenBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\GreenTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\GreenValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_a2c\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_c2a\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_mul\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_negative\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_swap\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_pxch_xpand\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_B\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_B_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_B_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_B_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_G\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_G_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_G_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_G_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_R\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_R_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_R_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_R_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_S\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_S_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_S_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_S_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_U\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_U_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_U_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_U_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_V\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_V_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_V_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_V_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_Y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_Y_avg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_Y_max\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\i_viff_s2a_Y_min\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\keeptilable\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\maketilable\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\MediaMixer\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmconv_stat_radius\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmconv2\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\add2project
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\expaud
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\expfnam
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\expvid
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\maxhalf
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\nuproj
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\reloadproj
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\savprojas
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\var_change
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\var_value
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmeditor\vqual
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\MMImport\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmo_export\selcodec
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmo_export\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmoptab\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmoptions\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\MMProgress\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\MMProject\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmt_position\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmt_space\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmtext\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmtrack\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmtrackedit\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmtrackvars\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmtravars\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\mmvpatt\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\momomaniac\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattrepe_bottom\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattrepe_left\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattrepe_right\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattrepe_top\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattslant_hori\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattslant_vert\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_hamp\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_hfreq\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_hpos\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_vamp\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_vars\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_vfreq\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\pattwave_vpos\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\PixChanMulCentre\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\PixChanMulFactor\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RedAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RedBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RedTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RedValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_lb_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_lb_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_lt_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_lt_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_rb_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_rb_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_rt_x\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\remperspect_rt_y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_angle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_count\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_distance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_iterate_angle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_iterate_dist\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_iterate_size\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\replin_startsize\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_from_alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_from_blue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_from_green\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_from_red\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_to_alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_to_blue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_to_green\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\RGBA_to_red\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\rotile\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\sgtx_fontsize\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\showcanvas\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\SrcEffDest\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tabfreeframe\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tabout\thisis
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tabout\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tabout\unknown
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tiff_reverse\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\timestein\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\TimesteinProps\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\TSTrackExport\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tweener\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tweenolin\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tweenspline\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tweensquare\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\tweenweird1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VECircCentreX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VECircCentreY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VECircRadius\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VeeAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VeeBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\veecur\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEEnlargeFactor\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEES\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VeeTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VeeValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEPoint0X\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEPoint0Y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEPoint1X\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VEPoint1Y\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\VETangentRange\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_a2rgbgrad\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_adjhsl\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_adjrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_adjyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alpha2b\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alpha2g\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alpha2r\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alpha2rgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alphagrad\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alphamod\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_alphashape\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_bt\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_cirgro\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_cirshr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_elli\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_ello\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_lr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_rl\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_simple\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_tb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_am_wipe\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_b2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_blura\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_blurr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_blurr_chroma\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_bmf_misc\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_bmfilter\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_box\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_boxi\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_brighten1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_calpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_calphi\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_calphl\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_calphm\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_coloradjusters\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_conmix\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_cont_pixelmode\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_cont_shapegrad\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_cont_shapesharp\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_container\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_convolution\matsiz
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_convolution\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_copaq\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_darken1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_desaturate\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_destblend\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_destbleni\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_circ1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_circ2\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_mouth1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_mouth2\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_mouth3\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_mouth4\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_place1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dist_quad1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_distort\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dither\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dither12bit\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dither8bit2222\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_dither8bit332\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_edga\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_edge\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_effrms\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_even\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_fields\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_g2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_keydiff\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_keyers\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_keyrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_keysmoothe\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_keyyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_kezrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_kezyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_l2r\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_mmt_credits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_mmt_ticker\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_negrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_negyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_odd\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_oval\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_ovali\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pattrepe\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pattrms\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pattslant\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pattwave\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pf_adv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pf_dumb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pixelchan\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pixelfilter\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_points\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_polialph\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_polialpo\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_policonti\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_policonto\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_ma\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_mb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_mg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_mr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_my\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_na\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_nb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_ng\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_nh\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_nr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_ns\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_ny\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_xa\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_xb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_xg\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_xr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_pxch_xy\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantize\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantize12bit\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantize8bit2222\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantize8bit332\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantrgba\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_quantyuva\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_r2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_remperspect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rep\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_reph\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_replin\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_reppfronts\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_reppoints\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_reprec\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_repscale\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_repv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rotblue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rotfwd\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rotgreen\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rotred\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_rotyuv\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_s2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_saturate\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_sg_text\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_sggr_line\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_sgtx_digitime\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_sgtx_string\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_circle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_circli\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_elli\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_ello\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_recti\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_recto\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_rlini\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shalpha_rlino\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_circle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_circli\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_elli\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_ello\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_recti\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_recto\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_rlini\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_shape_rlino\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_signalgen\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_swapanb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_swapang\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_swapanr\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_t2b\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_tintrgb\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_u2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_v2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\viff_y2alpha\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\WhyAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\WhyBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\WhyTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\WhyValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\wipe_angle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\wipe_position\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\wipe_smoothing\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\YouAdjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\YouBits\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\YouTolerance\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\YouValue\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_FullRotations\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_gradient_size\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_luma_adjust\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_luma_centre\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_luma_factor\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_MediaTimeOffset\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputOpacity\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputPositionX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputPositionY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputPositionZ\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputSizeX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputSizeY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_OutputSizeZ\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_powadj_1\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_powadj_2\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_rect_bottom\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_rect_left\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_rect_right\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_rect_top\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_RotationAngle\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_satu_ratio\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCenterX\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCenterY\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCenterZ\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCropBottom\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCropLeft\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCropRight\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceCropTop\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceOpacity\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_SourceVolume\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_text_align\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4_text_valign\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ZS4AudioEffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ZS4Effect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4FontName\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4TextFile\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\zs4TextString\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ZS4TimeEffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\c\t\en\ZS4VideoEffect\translation
C:\Program Files\t@b\[u]0[/u].957\686\cmd.dll
C:\Program Files\t@b\[u]0[/u].957\686\desktop.dll
C:\Program Files\t@b\[u]0[/u].957\686\document_dig.dll
C:\Program Files\t@b\[u]0[/u].957\686\expat.txt
C:\Program Files\t@b\[u]0[/u].957\686\font\Caliban.ttf
C:\Program Files\t@b\[u]0[/u].957\686\freeframe.txt
C:\Program Files\t@b\[u]0[/u].957\686\freeframe\readme.txt
C:\Program Files\t@b\[u]0[/u].957\686\ftfont.dll
C:\Program Files\t@b\[u]0[/u].957\686\ftl.txt
C:\Program Files\t@b\[u]0[/u].957\686\gadclsview.dll
C:\Program Files\t@b\[u]0[/u].957\686\grafix.dll
C:\Program Files\t@b\[u]0[/u].957\686\gui_wingdi.dll
C:\Program Files\t@b\[u]0[/u].957\686\http.dll
C:\Program Files\t@b\[u]0[/u].957\686\jpeg62.dll
C:\Program Files\t@b\[u]0[/u].957\686\jpg.txt
C:\Program Files\t@b\[u]0[/u].957\686\kernel.dll
C:\Program Files\t@b\[u]0[/u].957\686\lesser.txt
C:\Program Files\t@b\[u]0[/u].957\686\lgpl.txt
C:\Program Files\t@b\[u]0[/u].957\686\libtiff.txt
C:\Program Files\t@b\[u]0[/u].957\686\libtiff3.dll
C:\Program Files\t@b\[u]0[/u].957\686\license-fi.txt
C:\Program Files\t@b\[u]0[/u].957\686\LICENSE.txt
C:\Program Files\t@b\[u]0[/u].957\686\mmconv2.dll
C:\Program Files\t@b\[u]0[/u].957\686\mmeditor.dll
C:\Program Files\t@b\[u]0[/u].957\686\mmtext.dll
C:\Program Files\t@b\[u]0[/u].957\686\mmvpatt.dll
C:\Program Files\t@b\[u]0/u
par contre je ne peux toujours pas ouvrir HIJACKTHIS le messaege suivant apparaît: "...... n'est pas une application WIN32 valide". Est ce normal?
oui c est normal ..
Supprime fIndykill , ensuite :
Télécharge ToolsCleaner sur ton bureau.
-->
ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
http://pc-system.fr/
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
Supprime fIndykill , ensuite :
Télécharge ToolsCleaner sur ton bureau.
-->
ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
http://pc-system.fr/
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
voici le rapport:
[ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]
-->- Recherche:
\Combofix.txt: trouvé !
\fixnavi.txt: trouvé !
\avenger: trouvé !
\Qoobox: trouvé !
\_OtMoveIt: trouvé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis: trouvé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Navilog1: trouvé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
\Documents and Settings\x\Bureau\fixnavi.txt: trouvé !
\Documents and Settings\x\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe: trouvé !
\Documents and Settings\x\Bureau\Raccourcis Bureau non utilisés\hijackthis.log: trouvé !
\Documents and Settings\x\Mes documents\mes téléchargements\Dss.exe: trouvé !
\Documents and Settings\x\Mes documents\mes téléchargements\Navilog1.exe: trouvé !
\Documents and Settings\x\Mes documents\mes téléchargements\ComboFix.exe: trouvé !
\Documents and Settings\x\Mes documents\mes téléchargements\HJTInstall.exe: trouvé !
\Program Files\Trend Micro\HijackThis: trouvé !
\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
\QooBox\Quarantine\C\Program Files\Navilog1: trouvé !
---------------------------------
-->- Suppression:
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
\Documents and Settings\x\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe: supprimé !
\Documents and Settings\x\Mes documents\mes téléchargements\Dss.exe: supprimé !
\Documents and Settings\x\Mes documents\mes téléchargements\Navilog1.exe: supprimé !
\Documents and Settings\x\Mes documents\mes téléchargements\ComboFix.exe: supprimé !
\Documents and Settings\x\Mes documents\mes téléchargements\HJTInstall.exe: supprimé !
\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
\Combofix.txt: supprimé !
\fixnavi.txt: supprimé !
\Documents and Settings\x\Bureau\fixnavi.txt: supprimé !
\Documents and Settings\x\Bureau\Raccourcis Bureau non utilisés\hijackthis.log: supprimé !
\avenger: supprimé !
\Qoobox: supprimé !
\_OtMoveIt: supprimé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis: supprimé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Navilog1: supprimé !
\Program Files\Trend Micro\HijackThis: supprimé !
[ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]
-->- Recherche:
\Combofix.txt: trouvé !
\fixnavi.txt: trouvé !
\avenger: trouvé !
\Qoobox: trouvé !
\_OtMoveIt: trouvé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis: trouvé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Navilog1: trouvé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
\Documents and Settings\x\Bureau\fixnavi.txt: trouvé !
\Documents and Settings\x\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe: trouvé !
\Documents and Settings\x\Bureau\Raccourcis Bureau non utilisés\hijackthis.log: trouvé !
\Documents and Settings\x\Mes documents\mes téléchargements\Dss.exe: trouvé !
\Documents and Settings\x\Mes documents\mes téléchargements\Navilog1.exe: trouvé !
\Documents and Settings\x\Mes documents\mes téléchargements\ComboFix.exe: trouvé !
\Documents and Settings\x\Mes documents\mes téléchargements\HJTInstall.exe: trouvé !
\Program Files\Trend Micro\HijackThis: trouvé !
\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
\QooBox\Quarantine\C\Program Files\Navilog1: trouvé !
---------------------------------
-->- Suppression:
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
\Documents and Settings\x\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe: supprimé !
\Documents and Settings\x\Mes documents\mes téléchargements\Dss.exe: supprimé !
\Documents and Settings\x\Mes documents\mes téléchargements\Navilog1.exe: supprimé !
\Documents and Settings\x\Mes documents\mes téléchargements\ComboFix.exe: supprimé !
\Documents and Settings\x\Mes documents\mes téléchargements\HJTInstall.exe: supprimé !
\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
\Combofix.txt: supprimé !
\fixnavi.txt: supprimé !
\Documents and Settings\x\Bureau\fixnavi.txt: supprimé !
\Documents and Settings\x\Bureau\Raccourcis Bureau non utilisés\hijackthis.log: supprimé !
\avenger: supprimé !
\Qoobox: supprimé !
\_OtMoveIt: supprimé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis: supprimé !
\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Navilog1: supprimé !
\Program Files\Trend Micro\HijackThis: supprimé !
supprime findykill donc et retelecharge le :
Telecharge FindyKill :
Fais un clic droit sur le lien et choisi enregistrer la cible sous .... le bureau
----> http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.rar
--> Dezippe le (extraire) sur ton bureau
--> Entre dans le dossier FindyKill
--> Double clic sur findyKill.bat
choisi l option 1 (Recherche)
Post le rapport FindyKill.txt
Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
Telecharge FindyKill :
Fais un clic droit sur le lien et choisi enregistrer la cible sous .... le bureau
----> http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.rar
--> Dezippe le (extraire) sur ton bureau
--> Entre dans le dossier FindyKill
--> Double clic sur findyKill.bat
choisi l option 1 (Recherche)
Post le rapport FindyKill.txt
Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
dans le dossier tu as 2 dossier fixreg et tools et un fichier findykill ou findykill.cmd
double clic dessus et fais l option 1
double clic dessus et fais l option 1
ça y est voici le rapport:
----------------- FindyKill V3.075 -----------------
Recherche effectuée à 18:41:47 le 11/09/2008
Emplacement : C:\Documents and Settings\x\Bureau\FindyKill\FindyKill.bat
Outils Mis a jours le 11/09/08
----------------- *** Recherche *** ------------------
»»»» Presence des fichiers dans C:
»»»» Presence des fichiers dans C:\WINDOWS
»»»» Presence des fichiers dans C:\WINDOWS\Prefetch
C:\WINDOWS\Prefetch\FLEC006.EXE-????????.pf - Present !
»»»» Presence des fichiers dans C:\WINDOWS\system32
»»»» Presence des fichiers dans C:\WINDOWS\system32\drivers
»»»» Presence des fichiers dans C:\Documents and Settings\x\Application Data
»»»» Registre :
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HP Component Manager REG_SZ "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
OrderReminder REG_SZ C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
BluetoothAuthenticationAgent REG_SZ rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
Athan REG_SZ C:\Program Files\Athan\Athan.exe
QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
DAEMON Tools REG_SZ "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
HP Software Update REG_SZ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
AVG8_TRAY REG_SZ C:\PROGRA~1\AVG\AVG8\avgtray.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
H/PC Connection Agent REG_SZ "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
Kmwmjdbc REG_SZ "C:\Documents and Settings\x\Application Data\?ystem32\t?skmgr.exe"
PopUpStopperFreeEdition REG_SZ "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
»»»» Presence d infections dans Support amovible :
----------- ! Recherche realisée avec success ! -----------
----------------- FindyKill V3.075 -----------------
Recherche effectuée à 18:41:47 le 11/09/2008
Emplacement : C:\Documents and Settings\x\Bureau\FindyKill\FindyKill.bat
Outils Mis a jours le 11/09/08
----------------- *** Recherche *** ------------------
»»»» Presence des fichiers dans C:
»»»» Presence des fichiers dans C:\WINDOWS
»»»» Presence des fichiers dans C:\WINDOWS\Prefetch
C:\WINDOWS\Prefetch\FLEC006.EXE-????????.pf - Present !
»»»» Presence des fichiers dans C:\WINDOWS\system32
»»»» Presence des fichiers dans C:\WINDOWS\system32\drivers
»»»» Presence des fichiers dans C:\Documents and Settings\x\Application Data
»»»» Registre :
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HP Component Manager REG_SZ "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
OrderReminder REG_SZ C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
BluetoothAuthenticationAgent REG_SZ rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
Athan REG_SZ C:\Program Files\Athan\Athan.exe
QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
DAEMON Tools REG_SZ "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
HP Software Update REG_SZ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
AVG8_TRAY REG_SZ C:\PROGRA~1\AVG\AVG8\avgtray.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
H/PC Connection Agent REG_SZ "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
Kmwmjdbc REG_SZ "C:\Documents and Settings\x\Application Data\?ystem32\t?skmgr.exe"
PopUpStopperFreeEdition REG_SZ "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
»»»» Presence d infections dans Support amovible :
----------- ! Recherche realisée avec success ! -----------