9 réponses
neor
- Messages postés
- 1084
- Date d'inscription
- samedi 22 novembre 2008
- Statut
- Membre
- Dernière intervention
- 28 janvier 2010
Télécharge HijackThis ici :
-> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe
Tutoriel d´instalation : (Merci a Balltrap34 pour cette réalisation)
-> http://pageperso.aol.fr/balltrap34/Hijenr.gif
Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)
-> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
Renomer Hijackthis, pour contrer une éventuelle infection de Vundo.
ex:Renomme le fichier HijackThis.exe en CCM.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste
Ensuite avec Explorer créer un dossier c:\hijackthis
Décompresser Hijackthis dans ce dossier.
C'est important pour les sauvegardes.
Lance Hitjack this
Do a system scan and save a log file
Post le rapport généré ici stp...
-> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe
Tutoriel d´instalation : (Merci a Balltrap34 pour cette réalisation)
-> http://pageperso.aol.fr/balltrap34/Hijenr.gif
Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)
-> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
Renomer Hijackthis, pour contrer une éventuelle infection de Vundo.
ex:Renomme le fichier HijackThis.exe en CCM.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste
Ensuite avec Explorer créer un dossier c:\hijackthis
Décompresser Hijackthis dans ce dossier.
C'est important pour les sauvegardes.
Lance Hitjack this
Do a system scan and save a log file
Post le rapport généré ici stp...
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
Bonjourrr;
poste un rapport hijackthis (outil de diagnostic)
Télécharge http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
--) Enregistre HJTInstall.exe sur ton bureau
--) Double-clique sur HJTInstall.exe pour lancer le programme
--) Par défaut, il s'installera içi C:\Programme Files\Trend Micro\HijackThis
--) Accepte la license en cliquant sur le bouton "I Accept"
--) Choisis l'option "Do a system scan and save a log file"
--) Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
--) Clique sur "Édition -> Sélectionner tout", puis sur "Édition -> Copier" pour copier tout le contenu du rapport
--) Colle le rapport que tu viens de copier sur ce forum
--) Ne fixe encore AUCUNE ligne,
poste un rapport hijackthis (outil de diagnostic)
Télécharge http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
--) Enregistre HJTInstall.exe sur ton bureau
--) Double-clique sur HJTInstall.exe pour lancer le programme
--) Par défaut, il s'installera içi C:\Programme Files\Trend Micro\HijackThis
--) Accepte la license en cliquant sur le bouton "I Accept"
--) Choisis l'option "Do a system scan and save a log file"
--) Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
--) Clique sur "Édition -> Sélectionner tout", puis sur "Édition -> Copier" pour copier tout le contenu du rapport
--) Colle le rapport que tu viens de copier sur ce forum
--) Ne fixe encore AUCUNE ligne,
marc57
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:21:42, on 24/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnp2std.exe
C:\WINDOWS\vsnp2std.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Utilisateur\Local Settings\Temporary Internet Files\Content.IE5\2OD1Y0QB\HiJackThis[1].exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Reset.lnk = C:\WINDOWS\repair\reset.bat
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3985B1C-5A25-46EB-A287-E279A588BC71}: NameServer = 80.10.246.1 81.253.149.2
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Scan saved at 10:21:42, on 24/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnp2std.exe
C:\WINDOWS\vsnp2std.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Utilisateur\Local Settings\Temporary Internet Files\Content.IE5\2OD1Y0QB\HiJackThis[1].exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Reset.lnk = C:\WINDOWS\repair\reset.bat
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3985B1C-5A25-46EB-A287-E279A588BC71}: NameServer = 80.10.246.1 81.253.149.2
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
marc571
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
-----------\\ ToolBar S&D 1.2.5 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Utilisateur ( Administrator )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:78 Go (Free:35 Go)
D:\ (Local Disk) - NTFS - Total:36 Go (Free:14 Go)
F:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 20-11-2008|20:25 )
Option : [1] ( 24/11/2008|11:21 )
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.orange.fr/portail"
"Search Page"="https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC"
"Search Bar"="https://www.orange.fr/portail"
"SearchMigratedDefaultURL"="https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\UTILIS~1\.housecall6.6\Quarantine\Windows XP SP2 Pro & Home Activation Crack.zip.bac_a03588
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Jasc Paintshop Pro v7.04 (with Animation Shop v3.04) - CRACK.zip
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial.zip
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\AUTORUN.INF
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Nero 6 Ultra Edition
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Nero 6_Keygen.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\NERO.ICO
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\NeroBurnRights
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\NeroMIX
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\NeroVision Express 2
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Serial No.txt
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\setup.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\MenuTemplates
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Setup.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\MenuTemplates\nve-mtmpl.bin
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\alienplanet16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\alienplanet4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\artichoke1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\artichoke1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\artichoke2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\artichoke2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\barbecue16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\barbecue4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\birthday16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\birthday4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\camping16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\camping4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\cinema16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\cinema4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\cool_baptism16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\cool_baptism4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\desert16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\desert4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\diffuse_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\diffus_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\easter_egg16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\easter_egg4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\fire1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\fire1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\fire2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\fire2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\first_school16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\first_school4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower10_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower10_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower11_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower11_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower12_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower12_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower13_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower13_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower5_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower5_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower6_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower6_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower7_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower7_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower8_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower8_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower9_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower9_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\graffiti_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\graffiti_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\greencove16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\greencove4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\greenland16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\greenland4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground5_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground5_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground6_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground6_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground7_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground7_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground8_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground8_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\halloween16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\halloween4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\Icon[013]
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\island16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\island4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\karaoke16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\karaoke4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\knobs_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\knobs_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves10_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves10_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves11_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves11_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves5_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves5_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves6_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves6_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves7_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves7_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves8_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves8_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves9_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves9_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light10_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light10_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light11_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light11_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light12_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light12_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light13_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light13_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light14_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light14_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light15_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light15_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light16_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light16_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r5_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r5_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r6_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r6_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r7_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r8_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r8_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r9_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r9_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_re_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_re_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\Llight_r7_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_f0_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_f0_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_f2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_f2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_p2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_p2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_pl_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_pl_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\mosaic_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\mosaic_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\music16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\music4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\oranges_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\oranges_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\paper_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\paper_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_ef_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_ef_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\pyramids16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\pyramids4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\santa_claus16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\santa_claus4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sardines_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sardines_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\summer16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\summer4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sunrise_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sunrise_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sylvester16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sylvester4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\tomato1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\tomato1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\tomato2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\tomato2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\vegetables2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\vegetables2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\vegetables_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\vegetables_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\weave1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\weave1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\wildsky16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\wildsky4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\winterfun16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\winterfun4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\inCDPard.vxd
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\incdrm.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\incdrm.VXD
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\incdudfr.vxd
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\nt4
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\setup.cfg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\Setup.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\Version.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\nt4\incdrm.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Common Files
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\nt4
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Redist
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Setup
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\setup.cfg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Setup.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\w2k
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\w9x
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Common Files\Lib
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Common Files\Lib\apreg.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Common Files\Lib\DriveLocker.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\dma.bin
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\Error.log
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\gaa.bin
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\InCD 4 - FAQ.html
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\incd1252.txt
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\InCDL.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\incdshx.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\InCD_eng.chm
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\InCD_eng.pdf
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\lgc.bin
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\product.ini
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\nt4\incdfs.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\nt4\incdpass.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Redist\mfc42.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Redist\msvcrt.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Setup\EULA_eng.txt
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\InCD.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\incdapi.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\incdrec.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\incdsrv.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\incdunt.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\SrvError.Log
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\w2k\incdfs.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\w2k\incdpass.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\w9x\bsudf.vxd
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Inc
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Utilisateur ( Administrator )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:78 Go (Free:35 Go)
D:\ (Local Disk) - NTFS - Total:36 Go (Free:14 Go)
F:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 20-11-2008|20:25 )
Option : [1] ( 24/11/2008|11:21 )
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.orange.fr/portail"
"Search Page"="https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC"
"Search Bar"="https://www.orange.fr/portail"
"SearchMigratedDefaultURL"="https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\UTILIS~1\.housecall6.6\Quarantine\Windows XP SP2 Pro & Home Activation Crack.zip.bac_a03588
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Jasc Paintshop Pro v7.04 (with Animation Shop v3.04) - CRACK.zip
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial.zip
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\AUTORUN.INF
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Nero 6 Ultra Edition
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Nero 6_Keygen.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\NERO.ICO
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\NeroBurnRights
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\NeroMIX
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\NeroVision Express 2
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Serial No.txt
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\setup.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\MenuTemplates
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Setup.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\MenuTemplates\nve-mtmpl.bin
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\alienplanet16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\alienplanet4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\artichoke1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\artichoke1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\artichoke2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\artichoke2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\barbecue16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\barbecue4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\bark4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\birthday16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\birthday4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\camping16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\camping4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\cinema16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\cinema4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\cool_baptism16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\cool_baptism4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\crystal_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\desert16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\desert4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\diffuse_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\diffus_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\easter_egg16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\easter_egg4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\fire1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\fire1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\fire2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\fire2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\first_school16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\first_school4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower10_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower10_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower11_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower11_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower12_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower12_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower13_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower13_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower5_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower5_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower6_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower6_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower7_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower7_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower8_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower8_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower9_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower9_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\flower_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\glass4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\graffiti_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\graffiti_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\greencove16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\greencove4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\greenland16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\greenland4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground5_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground5_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground6_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground6_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground7_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground7_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground8_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\ground8_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\halloween16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\halloween4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\Icon[013]
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\island16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\island4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\karaoke16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\karaoke4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\knobs_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\knobs_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves10_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves10_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves11_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves11_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves5_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves5_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves6_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves6_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves7_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves7_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves8_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves8_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves9_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\leaves9_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light10_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light10_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light11_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light11_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light12_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light12_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light13_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light13_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light14_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light14_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light15_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light15_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light16_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light16_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r5_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r5_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r6_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r6_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r7_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r8_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r8_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r9_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_r9_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_re_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\light_re_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\Llight_r7_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_f0_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_f0_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_f2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_f2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_p2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_p2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_pl_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\metal_pl_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\mosaic_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\mosaic_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\music16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\music4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\oranges_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\oranges_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\paper_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\paper_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_e4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_ef_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\prism_ef_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\pyramids16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\pyramids4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\santa_claus16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\santa_claus4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sardines_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sardines_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sky3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\summer16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\summer4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sunrise_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sunrise_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sylvester16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\sylvester4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\textile_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\tomato1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\tomato1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\tomato2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\tomato2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\trees4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\vegetables2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\vegetables2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\vegetables_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\vegetables_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water2_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water2_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water3_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water3_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water4_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\water4_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\weave1_16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\weave1_4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\wildsky16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\wildsky4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\winterfun16_9.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\Content\Pictures\winterfun4_3.jpg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\inCDPard.vxd
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\incdrm.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\incdrm.VXD
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\incdudfr.vxd
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\nt4
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\setup.cfg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\Setup.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\Version.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\EasyWrite Reader\nt4\incdrm.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Common Files
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\nt4
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Redist
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Setup
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\setup.cfg
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Setup.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\w2k
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\w9x
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Common Files\Lib
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Common Files\Lib\apreg.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Common Files\Lib\DriveLocker.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\dma.bin
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\Error.log
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\gaa.bin
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\InCD 4 - FAQ.html
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\incd1252.txt
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\InCDL.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\incdshx.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\InCD_eng.chm
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\InCD_eng.pdf
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\lgc.bin
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\InCD\product.ini
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\nt4\incdfs.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\nt4\incdpass.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Redist\mfc42.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Redist\msvcrt.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\Setup\EULA_eng.txt
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\InCD.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\incdapi.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\incdrec.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\incdsrv.exe
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\incdunt.dll
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\sharedNT\SrvError.Log
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\w2k\incdfs.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\w2k\incdpass.sys
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Incl Keygen & Serial\Nero.Burning.Rom.6.0.Ultra.Edition.incl.keygen.&.serial\InCD 4\w9x\bsudf.vxd
C:\DOCUME~1\UTILIS~1\Mes documents\LimeWire\Saved\Nero Burning Rom 7 Ultra Edition Inc
neor
- Messages postés
- 1084
- Date d'inscription
- samedi 22 novembre 2008
- Statut
- Membre
- Dernière intervention
- 28 janvier 2010
désinstall gamesbar
"bonjour pour enlever gamesbar , il faut faire panneau de configuration,ajout/suppression puis tu va sur gamesbar 1. etc, tu cliques supprimer, là tu vas avoir une fenetre jeux.orange qui va s'ouvrir et un message va s'afficher te disant de refaire ce que je viens de te dire de faire, tu fermasla fenetre tu retournes sur panneau de configuration et tu refait supprimer et tu attends , le fenetre ne sera pas en surbrillance elle se remettra en surbrillance lorsque le message que la désinstallation a bien été effectué et la tu pourras fermé ta fenetre et gamesbar sera désinstallé, tu retournes dans panneau de....et tu refait ajout/.....pour verifier qu'il est bien parti. voilà, je viens de le faire et cela a marché."
ne va pas résoudre ton problème mais ça fait le ménage
"bonjour pour enlever gamesbar , il faut faire panneau de configuration,ajout/suppression puis tu va sur gamesbar 1. etc, tu cliques supprimer, là tu vas avoir une fenetre jeux.orange qui va s'ouvrir et un message va s'afficher te disant de refaire ce que je viens de te dire de faire, tu fermasla fenetre tu retournes sur panneau de configuration et tu refait supprimer et tu attends , le fenetre ne sera pas en surbrillance elle se remettra en surbrillance lorsque le message que la désinstallation a bien été effectué et la tu pourras fermé ta fenetre et gamesbar sera désinstallé, tu retournes dans panneau de....et tu refait ajout/.....pour verifier qu'il est bien parti. voilà, je viens de le faire et cela a marché."
ne va pas résoudre ton problème mais ça fait le ménage
marc571
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
- Messages postés
- 1084
- Date d'inscription
- samedi 22 novembre 2008
- Statut
- Membre
- Dernière intervention
- 28 janvier 2010
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:42, on 24/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnp2std.exe
C:\WINDOWS\vsnp2std.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Utilisateur\Bureau\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Reset.lnk = C:\WINDOWS\repair\reset.bat
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3985B1C-5A25-46EB-A287-E279A588BC71}: NameServer = 80.10.246.1 81.253.149.2
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Scan saved at 11:15:42, on 24/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnp2std.exe
C:\WINDOWS\vsnp2std.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Utilisateur\Bureau\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Reset.lnk = C:\WINDOWS\repair\reset.bat
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3985B1C-5A25-46EB-A287-E279A588BC71}: NameServer = 80.10.246.1 81.253.149.2
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
neor
- Messages postés
- 1084
- Date d'inscription
- samedi 22 novembre 2008
- Statut
- Membre
- Dernière intervention
- 28 janvier 2010
Nod32
Poste un rapport Nod32 https://www.eset.com/
- coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :
- C:\Program Files\EsetOnlineScanner\log.txt
Poste un rapport Nod32 https://www.eset.com/
- coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :
- C:\Program Files\EsetOnlineScanner\log.txt
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
salut
toolscleaner tu le supprime on faisant un clic droit et supprimer
comme antivirus içi un tuto comparatif des meilleure antivirus et pour antivir il y'a des tuto pour bien le configurer qui sont en français
http://www.infos-du-net.com/actualite/dossiers/102-17-comparatif-antivirus-2008.html
-----------------------------------
tu va télécharger Ccleaner https://www.ccleaner.com/ccleaner/download
ouvre "Ccleaner" vas dans l'onglet "Option" puis "Avancé" puis décoches "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures."
. Puis vas dans l'onglet "Nettoyeur" fais "Analyse" puis "Lancer le nettoyage".
Puis vas dans l'onglet "Registre" puis fait "Chercher des erreurs" puis "Réparer les erreurs sélectionnée"
. Tu refais tous ca 4-5 fois (le nettoyage et le registre).
Puis reste dans "Ccleaner" puis va dans "Option" puis "Propriété" puis coches "Nettoyer automatiquement l'ordinateur au démarrage".
içi mode d'emploi pour ccleaner
https://www.malekal.com/tutoriel-ccleaner/
toolscleaner tu le supprime on faisant un clic droit et supprimer
comme antivirus içi un tuto comparatif des meilleure antivirus et pour antivir il y'a des tuto pour bien le configurer qui sont en français
http://www.infos-du-net.com/actualite/dossiers/102-17-comparatif-antivirus-2008.html
-----------------------------------
tu va télécharger Ccleaner https://www.ccleaner.com/ccleaner/download
ouvre "Ccleaner" vas dans l'onglet "Option" puis "Avancé" puis décoches "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures."
. Puis vas dans l'onglet "Nettoyeur" fais "Analyse" puis "Lancer le nettoyage".
Puis vas dans l'onglet "Registre" puis fait "Chercher des erreurs" puis "Réparer les erreurs sélectionnée"
. Tu refais tous ca 4-5 fois (le nettoyage et le registre).
Puis reste dans "Ccleaner" puis va dans "Option" puis "Propriété" puis coches "Nettoyer automatiquement l'ordinateur au démarrage".
içi mode d'emploi pour ccleaner
https://www.malekal.com/tutoriel-ccleaner/
marc571
>
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
ccleaner je l avait deja et j ai deja supprimer des choses avant que tu me le dises peut etre qu il va me manquer certaines parties pas grave je ferais avec du moment que je n ai plus le virus
voila c fait
voila c fait
marc571
>
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
bonsoir , donc cet ap j ai essayé un scan avec kasperski online resultat il me trouve encore un virus et des objets infectés suite j ai pas été jusqu au bout , ensuite j ai supprimé avast et je me suis telecharger antivir tant bien que mal meme avec le tutorel pas tout a fait idem bref apparemment ca a fonctionné , j ai fait un scan en mode sans echec resultat aucune detection que dois je faire ensuite ? en attendant salutation distinguée
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
re
si antivir ne trouve rien c'est bon signe
tu peut refaire un scan en ligne sur trendmicro pour voir s'il te détecte encore leTrojan vm killer b
https://www.trendmicro.com/en_us/forHome/products/housecall.html
si antivir ne trouve rien c'est bon signe
tu peut refaire un scan en ligne sur trendmicro pour voir s'il te détecte encore leTrojan vm killer b
https://www.trendmicro.com/en_us/forHome/products/housecall.html
marc571
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
c fait resultat il est tjr la sous le meme nom , apparemment il rester des coockies que j ai supprimé
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
Re
Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
-> Double clique combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Avant d'utiliser ComboFix :
-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
-Attention Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes. risque de figer l'ordi
- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
!\ Ne touche à rien tant que le scan n'est pas terminé. /!\ : risque de figer l'ordi (plantage complet)
::Si combofix demande a faire mise a jour tu refuse
::Si combofix detecte quelque chose et de demande a redemarer tu accepte
Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
-> Double clique combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Avant d'utiliser ComboFix :
-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
-Attention Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes. risque de figer l'ordi
- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
!\ Ne touche à rien tant que le scan n'est pas terminé. /!\ : risque de figer l'ordi (plantage complet)
::Si combofix demande a faire mise a jour tu refuse
::Si combofix detecte quelque chose et de demande a redemarer tu accepte
marc571
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
voila le resultat bonne soirée a la prochaine
ComboFix 08-11-27.03 - Utilisateur 2008-11-27 21:41:53.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.207 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Mes documents\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\spps.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-27 au 2008-11-27 ))))))))))))))))))))))))))))))))))))
.
2008-11-26 21:26 . 2008-11-26 21:29 <REP> d-------- c:\program files\Windows Live
2008-11-26 21:26 . 2008-11-26 21:28 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-26 21:25 . 2008-11-26 21:25 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\program files\Avira
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-25 17:15 . 2008-11-25 20:47 <REP> d-------- c:\windows\ERUNT
2008-11-25 17:15 . 2008-11-25 17:21 <REP> d-------- C:\Backups
2008-11-24 22:18 . 2008-11-24 22:18 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-24 22:17 . 2007-08-21 07:36 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-24 22:17 . 2007-08-20 16:56 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-24 22:17 . 2008-11-24 22:17 <REP> d-------- c:\documents and settings\Administrateur
2008-11-24 20:54 . 2008-11-24 20:54 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-11-24 21:03 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-24 20:53 . 2008-11-24 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 20:53 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-24 18:21 . 2008-11-24 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-24 18:10 . 2008-11-26 18:32 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 22:02 . 2008-11-23 22:02 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-23 19:53 . 2008-11-27 17:59 <REP> d-------- c:\documents and settings\Utilisateur\.housecall6.6
2008-11-22 16:56 . 2008-11-22 16:56 124,688 --a------ c:\windows\system32\Mswinsck.ocx
2008-11-22 16:56 . 2008-11-22 16:57 355 --a------ c:\windows\ps
2008-11-21 10:32 . 2008-11-21 10:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-21 10:26 . 2008-11-21 10:26 <REP> d-------- c:\program files\Yahoo!
2008-11-21 10:26 . 2008-11-21 10:27 <REP> d-------- c:\program files\CCleaner
2008-11-18 08:36 . 2008-11-18 08:36 <REP> d-------- c:\program files\Fichiers communs\snp2std
2008-11-18 08:36 . 2006-06-07 10:34 10,305,280 --a------ c:\windows\system32\drivers\snp2sxp.sys
2008-11-18 08:36 . 2006-05-15 15:52 675,840 --a------ c:\windows\vsnp2std.exe
2008-11-18 08:36 . 2005-01-26 15:45 349,472 --a------ c:\windows\WindowsXP-KB822603-x86.exe
2008-11-18 08:36 . 2006-06-19 13:37 262,144 --a------ c:\windows\tsnp2std.exe
2008-11-18 08:36 . 2006-04-07 10:33 147,456 --a------ c:\windows\rsnp2std.dll
2008-11-18 08:36 . 2006-05-04 11:14 61,440 --a------ c:\windows\vsnp2std.dll
2008-11-18 08:36 . 2005-11-23 13:55 53,248 --a------ c:\windows\system32\csnp2std.dll
2008-11-18 08:36 . 2006-04-27 20:43 24,832 --a------ c:\windows\system32\drivers\sncamd.sys
2008-11-18 08:36 . 2006-06-01 11:26 20,480 --------- c:\windows\FixCamera.exe
2008-11-18 08:36 . 2004-12-09 17:23 15,497 --a------ c:\windows\snp2std.ini
2008-11-18 08:36 . 2004-12-09 17:23 13,022 --a------ c:\windows\snp2std.src
2008-11-18 01:00 . 2008-11-18 01:00 19,560 --a------ c:\documents and settings\Utilisateur\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-27 20:43 62,453,792 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-27 20:40 --------- d-----w c:\program files\Wanadoo
2008-11-27 18:10 733,112 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-26 17:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 17:13 --------- d-----w c:\program files\Lavasoft
2008-11-18 07:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-14 16:09 --------- d-----w c:\program files\DivX
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"WooCnxMon"="c:\progra~1\Wanadoo\CnxMon.exe" [2004-10-13 24576]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-10-13 24576]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-17 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-13 974898]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"FixCamera"="c:\windows\FixCamera.exe" [2006-06-01 20480]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-06-19 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-09 962661]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-07 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Reset.lnk - c:\windows\repair\reset.bat [2001-05-21 238]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Utilisateur\\Mes documents\\engelh\\eMulev0[1].48a.-MorphXTv10.5-bin\\emule\\eMule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-11-27 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-autoclk - autoclk.exe
HKLM-Run-adiras - adiras.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.wanadoo.fr
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-27 21:43:25
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-11-27 21:44:11
ComboFix-quarantined-files.txt 2008-11-27 20:44:09
Avant-CF: 51 463 032 832 octets libres
Après-CF: 51,445,600,256 octets libres
183 --- E O F --- 2008-10-10 00:36:16
ComboFix 08-11-27.03 - Utilisateur 2008-11-27 21:41:53.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.207 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Mes documents\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\spps.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-27 au 2008-11-27 ))))))))))))))))))))))))))))))))))))
.
2008-11-26 21:26 . 2008-11-26 21:29 <REP> d-------- c:\program files\Windows Live
2008-11-26 21:26 . 2008-11-26 21:28 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-26 21:25 . 2008-11-26 21:25 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\program files\Avira
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-25 17:15 . 2008-11-25 20:47 <REP> d-------- c:\windows\ERUNT
2008-11-25 17:15 . 2008-11-25 17:21 <REP> d-------- C:\Backups
2008-11-24 22:18 . 2008-11-24 22:18 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-24 22:17 . 2007-08-21 07:36 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-24 22:17 . 2007-08-20 16:56 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-24 22:17 . 2008-11-24 22:17 <REP> d-------- c:\documents and settings\Administrateur
2008-11-24 20:54 . 2008-11-24 20:54 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-11-24 21:03 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-24 20:53 . 2008-11-24 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 20:53 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-24 18:21 . 2008-11-24 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-24 18:10 . 2008-11-26 18:32 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 22:02 . 2008-11-23 22:02 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-23 19:53 . 2008-11-27 17:59 <REP> d-------- c:\documents and settings\Utilisateur\.housecall6.6
2008-11-22 16:56 . 2008-11-22 16:56 124,688 --a------ c:\windows\system32\Mswinsck.ocx
2008-11-22 16:56 . 2008-11-22 16:57 355 --a------ c:\windows\ps
2008-11-21 10:32 . 2008-11-21 10:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-21 10:26 . 2008-11-21 10:26 <REP> d-------- c:\program files\Yahoo!
2008-11-21 10:26 . 2008-11-21 10:27 <REP> d-------- c:\program files\CCleaner
2008-11-18 08:36 . 2008-11-18 08:36 <REP> d-------- c:\program files\Fichiers communs\snp2std
2008-11-18 08:36 . 2006-06-07 10:34 10,305,280 --a------ c:\windows\system32\drivers\snp2sxp.sys
2008-11-18 08:36 . 2006-05-15 15:52 675,840 --a------ c:\windows\vsnp2std.exe
2008-11-18 08:36 . 2005-01-26 15:45 349,472 --a------ c:\windows\WindowsXP-KB822603-x86.exe
2008-11-18 08:36 . 2006-06-19 13:37 262,144 --a------ c:\windows\tsnp2std.exe
2008-11-18 08:36 . 2006-04-07 10:33 147,456 --a------ c:\windows\rsnp2std.dll
2008-11-18 08:36 . 2006-05-04 11:14 61,440 --a------ c:\windows\vsnp2std.dll
2008-11-18 08:36 . 2005-11-23 13:55 53,248 --a------ c:\windows\system32\csnp2std.dll
2008-11-18 08:36 . 2006-04-27 20:43 24,832 --a------ c:\windows\system32\drivers\sncamd.sys
2008-11-18 08:36 . 2006-06-01 11:26 20,480 --------- c:\windows\FixCamera.exe
2008-11-18 08:36 . 2004-12-09 17:23 15,497 --a------ c:\windows\snp2std.ini
2008-11-18 08:36 . 2004-12-09 17:23 13,022 --a------ c:\windows\snp2std.src
2008-11-18 01:00 . 2008-11-18 01:00 19,560 --a------ c:\documents and settings\Utilisateur\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-27 20:43 62,453,792 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-27 20:40 --------- d-----w c:\program files\Wanadoo
2008-11-27 18:10 733,112 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-26 17:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 17:13 --------- d-----w c:\program files\Lavasoft
2008-11-18 07:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-14 16:09 --------- d-----w c:\program files\DivX
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"WooCnxMon"="c:\progra~1\Wanadoo\CnxMon.exe" [2004-10-13 24576]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-10-13 24576]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-17 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-13 974898]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"FixCamera"="c:\windows\FixCamera.exe" [2006-06-01 20480]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-06-19 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-09 962661]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-07 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Reset.lnk - c:\windows\repair\reset.bat [2001-05-21 238]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Utilisateur\\Mes documents\\engelh\\eMulev0[1].48a.-MorphXTv10.5-bin\\emule\\eMule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-11-27 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-autoclk - autoclk.exe
HKLM-Run-adiras - adiras.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.wanadoo.fr
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-27 21:43:25
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-11-27 21:44:11
ComboFix-quarantined-files.txt 2008-11-27 20:44:09
Avant-CF: 51 463 032 832 octets libres
Après-CF: 51,445,600,256 octets libres
183 --- E O F --- 2008-10-10 00:36:16
marc571
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
je fais comment pour desactivé en temps reel sur antivir et malwarebytes ainsi que ccleaner
marc571
>
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
le probleme c que avec house call je c pas comment aller chercher le rapport si ce n est qu il me donne le nom de trj vm killer b sans information supplementaire qu il n existe pas d information supplementaire ni de nom du fichier sinon je te l aurai deja donné et des failles de securité type mso8-061,067 068 c tout ce que je peux te donner tu me dis que c peut etre ma cam ou le pilote , bref c possible car j ai du mal a l installé par en ce moment je peux supprimer le programme si tu veux ce n est pas grave
merci et bonne journée a bientot
merci et bonne journée a bientot
marc571
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
mon cher ami si je peux me permettre ca y est j ai reussi a trouvé , donc tu avais raison apparemment programme infecté c est le c:/windows/fix camera .exe pour l instant j attends que tu me dis la suite si il faut je deconnecte la cam et je supprime le programme ou scan avec antivir sur ce prog enfin j attends ta reponse merci encore et encore de prendre autant de temps pour moi a bientot
marc571
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
je ne sais pas si j ai bien fait ou pas mais toujours pas de reponse je verrai d ici la fin de la soirée a bientot
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
salut;desactive ton teatimer de spybot avant de faire la manipulation
on va se supprimer se fichier
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:files
c:\windows\FixCamera.exe
:commands
[emptytemp]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
on va se supprimer se fichier
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:files
c:\windows\FixCamera.exe
:commands
[emptytemp]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
marc571
>
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder c:\windows\FixCamera.exe not found.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\ZLT02ae3.TMP scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ZLT02ae6.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 12022008_134531
Files moved on Reboot...
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\ZLT02ae3.TMP not found!
File C:\WINDOWS\temp\ZLT02ae6.TMP not found!
voila le rapport avec un peu de mal mai je crois que ca n a pas marché normalement
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder c:\windows\FixCamera.exe not found.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\ZLT02ae3.TMP scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ZLT02ae6.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 12022008_134531
Files moved on Reboot...
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\ZLT02ae3.TMP not found!
File C:\WINDOWS\temp\ZLT02ae6.TMP not found!
voila le rapport avec un peu de mal mai je crois que ca n a pas marché normalement
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
non sa na pas marcher
Désactive toute tes protection (antivirus;antispywre)
/!\ Manip crée spécialement pour cet utilisateur , ne pas reproduire chez soi ... /!\
Ouvre le Bloc-Notes (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Copie ce texte ( en gras )d'une traite ( CTRL+C pour copier ) puis colle-le ( CTRL+V dans le bloc-note )
Killall::
File::
c:\windows\FixCamera.exe
Sauvegarde ce fichier sur ton bureau sous le nom de CFScript.txt.
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
Désactive toute tes protection (antivirus;antispywre)
/!\ Manip crée spécialement pour cet utilisateur , ne pas reproduire chez soi ... /!\
Ouvre le Bloc-Notes (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Copie ce texte ( en gras )d'une traite ( CTRL+C pour copier ) puis colle-le ( CTRL+V dans le bloc-note )
Killall::
File::
c:\windows\FixCamera.exe
Sauvegarde ce fichier sur ton bureau sous le nom de CFScript.txt.
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
marc571
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
apparemment ca a fonctionné je crois d apres ce que j ai lu mai bon je c pas si tu as les 2 fichiers sinon je recommence hij bref tu me dis a plus et une fois de plus merci
marc571
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:16:33, on 02/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Reset.lnk = C:\WINDOWS\repair\reset.bat
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - https://www.eset.com/
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Scan saved at 18:16:33, on 02/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Reset.lnk = C:\WINDOWS\repair\reset.bat
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - https://www.eset.com/
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
marc571
- Messages postés
- 50
- Date d'inscription
- lundi 24 novembre 2008
- Statut
- Membre
- Dernière intervention
- 6 février 2010
ComboFix 08-11-27.03 - Utilisateur 2008-12-02 17:39:14.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.206 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Mes documents\ComboFix.exe
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
.
2008-12-02 12:57 . 2008-12-02 12:57 <REP> d-------- C:\_OTMoveIt
2008-11-28 14:39 . 2008-11-28 14:39 <REP> d-------- c:\program files\VirusTotalUploader
2008-11-28 10:22 . 2008-11-28 11:30 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\HouseCall 6.6
2008-11-26 21:26 . 2008-11-26 21:29 <REP> d-------- c:\program files\Windows Live
2008-11-26 21:26 . 2008-11-26 21:28 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-26 21:25 . 2008-11-26 21:25 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\program files\Avira
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-25 17:15 . 2008-11-25 20:47 <REP> d-------- c:\windows\ERUNT
2008-11-25 17:15 . 2008-11-25 17:21 <REP> d-------- C:\Backups
2008-11-24 22:18 . 2008-11-24 22:18 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-24 22:17 . 2007-08-21 07:36 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-24 22:17 . 2007-08-20 16:56 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-24 22:17 . 2008-11-24 22:17 <REP> d-------- c:\documents and settings\Administrateur
2008-11-24 20:54 . 2008-11-24 20:54 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-11-24 21:03 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-24 20:53 . 2008-11-24 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 20:53 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-24 18:21 . 2008-11-24 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-24 18:10 . 2008-11-26 18:32 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 22:02 . 2008-11-23 22:02 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-23 19:53 . 2008-12-02 12:45 <REP> d-------- c:\documents and settings\Utilisateur\.housecall6.6
2008-11-22 16:56 . 2008-11-22 16:56 124,688 --a------ c:\windows\system32\Mswinsck.ocx
2008-11-22 16:56 . 2008-11-22 16:57 355 --a------ c:\windows\ps
2008-11-21 10:32 . 2008-11-21 10:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-21 10:26 . 2008-11-21 10:26 <REP> d-------- c:\program files\Yahoo!
2008-11-21 10:26 . 2008-11-21 10:27 <REP> d-------- c:\program files\CCleaner
2008-11-18 08:36 . 2008-11-18 08:36 <REP> d-------- c:\program files\Fichiers communs\snp2std
2008-11-18 08:36 . 2006-06-07 10:34 10,305,280 --a------ c:\windows\system32\drivers\snp2sxp.sys
2008-11-18 08:36 . 2006-05-15 15:52 675,840 --a------ c:\windows\vsnp2std.exe
2008-11-18 08:36 . 2005-01-26 15:45 349,472 --a------ c:\windows\WindowsXP-KB822603-x86.exe
2008-11-18 08:36 . 2006-06-19 13:37 262,144 --a------ c:\windows\tsnp2std.exe
2008-11-18 08:36 . 2006-04-07 10:33 147,456 --a------ c:\windows\rsnp2std.dll
2008-11-18 08:36 . 2006-05-04 11:14 61,440 --a------ c:\windows\vsnp2std.dll
2008-11-18 08:36 . 2005-11-23 13:55 53,248 --a------ c:\windows\system32\csnp2std.dll
2008-11-18 08:36 . 2006-04-27 20:43 24,832 --a------ c:\windows\system32\drivers\sncamd.sys
2008-11-18 08:36 . 2004-12-09 17:23 15,497 --a------ c:\windows\snp2std.ini
2008-11-18 08:36 . 2004-12-09 17:23 13,022 --a------ c:\windows\snp2std.src
2008-11-18 01:00 . 2008-11-18 01:00 19,560 --a------ c:\documents and settings\Utilisateur\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 16:41 63,766,560 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-02 16:37 --------- d-----w c:\program files\Wanadoo
2008-12-02 14:31 748,616 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-28 08:10 1,746,519 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-11-26 17:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 17:13 --------- d-----w c:\program files\Lavasoft
2008-11-18 07:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-14 16:09 --------- d-----w c:\program files\DivX
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((( snapshot@2008-11-27_21.43.43,73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 11:28:42 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-02 16:11:25 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"WooCnxMon"="c:\progra~1\Wanadoo\CnxMon.exe" [2004-10-13 24576]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-10-13 24576]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-17 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-13 974898]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-06-19 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-09 962661]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-07 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Reset.lnk - c:\windows\repair\reset.bat [2001-05-21 238]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Utilisateur\\Mes documents\\engelh\\eMulev0[1].48a.-MorphXTv10.5-bin\\emule\\eMule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
.
Contenu du dossier 'Tâches planifiées'
2008-12-02 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-FixCamera - c:\windows\FixCamera.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.wanadoo.fr
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 17:40:47
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-12-02 17:41:41
ComboFix-quarantined-files.txt 2008-12-02 16:41:39
ComboFix2.txt 2008-11-27 20:44:13
Avant-CF: 51 248 078 848 octets libres
Après-CF: 51,225,804,800 octets libres
183 --- E O F --- 2008-10-10 00:36:16
ComboFix 08-11-27.03 - Utilisateur 2008-12-02 17:39:14.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.206 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Mes documents\ComboFix.exe
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
.
2008-12-02 12:57 . 2008-12-02 12:57 <REP> d-------- C:\_OTMoveIt
2008-11-28 14:39 . 2008-11-28 14:39 <REP> d-------- c:\program files\VirusTotalUploader
2008-11-28 10:22 . 2008-11-28 11:30 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\HouseCall 6.6
2008-11-26 21:26 . 2008-11-26 21:29 <REP> d-------- c:\program files\Windows Live
2008-11-26 21:26 . 2008-11-26 21:28 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-26 21:25 . 2008-11-26 21:25 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\program files\Avira
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-25 17:15 . 2008-11-25 20:47 <REP> d-------- c:\windows\ERUNT
2008-11-25 17:15 . 2008-11-25 17:21 <REP> d-------- C:\Backups
2008-11-24 22:18 . 2008-11-24 22:18 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-24 22:17 . 2007-08-21 07:36 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-24 22:17 . 2007-08-20 16:56 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-24 22:17 . 2008-11-24 22:17 <REP> d-------- c:\documents and settings\Administrateur
2008-11-24 20:54 . 2008-11-24 20:54 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-11-24 21:03 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-24 20:53 . 2008-11-24 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 20:53 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-24 18:21 . 2008-11-24 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-24 18:10 . 2008-11-26 18:32 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 22:02 . 2008-11-23 22:02 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-23 19:53 . 2008-12-02 12:45 <REP> d-------- c:\documents and settings\Utilisateur\.housecall6.6
2008-11-22 16:56 . 2008-11-22 16:56 124,688 --a------ c:\windows\system32\Mswinsck.ocx
2008-11-22 16:56 . 2008-11-22 16:57 355 --a------ c:\windows\ps
2008-11-21 10:32 . 2008-11-21 10:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-21 10:26 . 2008-11-21 10:26 <REP> d-------- c:\program files\Yahoo!
2008-11-21 10:26 . 2008-11-21 10:27 <REP> d-------- c:\program files\CCleaner
2008-11-18 08:36 . 2008-11-18 08:36 <REP> d-------- c:\program files\Fichiers communs\snp2std
2008-11-18 08:36 . 2006-06-07 10:34 10,305,280 --a------ c:\windows\system32\drivers\snp2sxp.sys
2008-11-18 08:36 . 2006-05-15 15:52 675,840 --a------ c:\windows\vsnp2std.exe
2008-11-18 08:36 . 2005-01-26 15:45 349,472 --a------ c:\windows\WindowsXP-KB822603-x86.exe
2008-11-18 08:36 . 2006-06-19 13:37 262,144 --a------ c:\windows\tsnp2std.exe
2008-11-18 08:36 . 2006-04-07 10:33 147,456 --a------ c:\windows\rsnp2std.dll
2008-11-18 08:36 . 2006-05-04 11:14 61,440 --a------ c:\windows\vsnp2std.dll
2008-11-18 08:36 . 2005-11-23 13:55 53,248 --a------ c:\windows\system32\csnp2std.dll
2008-11-18 08:36 . 2006-04-27 20:43 24,832 --a------ c:\windows\system32\drivers\sncamd.sys
2008-11-18 08:36 . 2004-12-09 17:23 15,497 --a------ c:\windows\snp2std.ini
2008-11-18 08:36 . 2004-12-09 17:23 13,022 --a------ c:\windows\snp2std.src
2008-11-18 01:00 . 2008-11-18 01:00 19,560 --a------ c:\documents and settings\Utilisateur\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 16:41 63,766,560 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-02 16:37 --------- d-----w c:\program files\Wanadoo
2008-12-02 14:31 748,616 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-28 08:10 1,746,519 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-11-26 17:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 17:13 --------- d-----w c:\program files\Lavasoft
2008-11-18 07:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-14 16:09 --------- d-----w c:\program files\DivX
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((( snapshot@2008-11-27_21.43.43,73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 11:28:42 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-02 16:11:25 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"WooCnxMon"="c:\progra~1\Wanadoo\CnxMon.exe" [2004-10-13 24576]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-10-13 24576]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-17 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-13 974898]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-06-19 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-09 962661]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-07 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Reset.lnk - c:\windows\repair\reset.bat [2001-05-21 238]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Utilisateur\\Mes documents\\engelh\\eMulev0[1].48a.-MorphXTv10.5-bin\\emule\\eMule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
.
Contenu du dossier 'Tâches planifiées'
2008-12-02 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-FixCamera - c:\windows\FixCamera.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.wanadoo.fr
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 17:40:47
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-12-02 17:41:41
ComboFix-quarantined-files.txt 2008-12-02 16:41:39
ComboFix2.txt 2008-11-27 20:44:13
Avant-CF: 51 248 078 848 octets libres
Après-CF: 51,225,804,800 octets libres
183 --- E O F --- 2008-10-10 00:36:16
ComboFix 08-11-27.03 - Utilisateur 2008-12-02 17:39:14.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.206 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Mes documents\ComboFix.exe
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
.
2008-12-02 12:57 . 2008-12-02 12:57 <REP> d-------- C:\_OTMoveIt
2008-11-28 14:39 . 2008-11-28 14:39 <REP> d-------- c:\program files\VirusTotalUploader
2008-11-28 10:22 . 2008-11-28 11:30 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\HouseCall 6.6
2008-11-26 21:26 . 2008-11-26 21:29 <REP> d-------- c:\program files\Windows Live
2008-11-26 21:26 . 2008-11-26 21:28 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-26 21:25 . 2008-11-26 21:25 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\program files\Avira
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-25 17:15 . 2008-11-25 20:47 <REP> d-------- c:\windows\ERUNT
2008-11-25 17:15 . 2008-11-25 17:21 <REP> d-------- C:\Backups
2008-11-24 22:18 . 2008-11-24 22:18 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-24 22:17 . 2007-08-21 07:36 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-24 22:17 . 2007-08-20 16:56 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-24 22:17 . 2008-11-24 22:17 <REP> d-------- c:\documents and settings\Administrateur
2008-11-24 20:54 . 2008-11-24 20:54 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-11-24 21:03 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-24 20:53 . 2008-11-24 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 20:53 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-24 18:21 . 2008-11-24 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-24 18:10 . 2008-11-26 18:32 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 22:02 . 2008-11-23 22:02 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-23 19:53 . 2008-12-02 12:45 <REP> d-------- c:\documents and settings\Utilisateur\.housecall6.6
2008-11-22 16:56 . 2008-11-22 16:56 124,688 --a------ c:\windows\system32\Mswinsck.ocx
2008-11-22 16:56 . 2008-11-22 16:57 355 --a------ c:\windows\ps
2008-11-21 10:32 . 2008-11-21 10:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-21 10:26 . 2008-11-21 10:26 <REP> d-------- c:\program files\Yahoo!
2008-11-21 10:26 . 2008-11-21 10:27 <REP> d-------- c:\program files\CCleaner
2008-11-18 08:36 . 2008-11-18 08:36 <REP> d-------- c:\program files\Fichiers communs\snp2std
2008-11-18 08:36 . 2006-06-07 10:34 10,305,280 --a------ c:\windows\system32\drivers\snp2sxp.sys
2008-11-18 08:36 . 2006-05-15 15:52 675,840 --a------ c:\windows\vsnp2std.exe
2008-11-18 08:36 . 2005-01-26 15:45 349,472 --a------ c:\windows\WindowsXP-KB822603-x86.exe
2008-11-18 08:36 . 2006-06-19 13:37 262,144 --a------ c:\windows\tsnp2std.exe
2008-11-18 08:36 . 2006-04-07 10:33 147,456 --a------ c:\windows\rsnp2std.dll
2008-11-18 08:36 . 2006-05-04 11:14 61,440 --a------ c:\windows\vsnp2std.dll
2008-11-18 08:36 . 2005-11-23 13:55 53,248 --a------ c:\windows\system32\csnp2std.dll
2008-11-18 08:36 . 2006-04-27 20:43 24,832 --a------ c:\windows\system32\drivers\sncamd.sys
2008-11-18 08:36 . 2004-12-09 17:23 15,497 --a------ c:\windows\snp2std.ini
2008-11-18 08:36 . 2004-12-09 17:23 13,022 --a------ c:\windows\snp2std.src
2008-11-18 01:00 . 2008-11-18 01:00 19,560 --a------ c:\documents and settings\Utilisateur\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 16:41 63,766,560 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-02 16:37 --------- d-----w c:\program files\Wanadoo
2008-12-02 14:31 748,616 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-28 08:10 1,746,519 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-11-26 17:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 17:13 --------- d-----w c:\program files\Lavasoft
2008-11-18 07:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-14 16:09 --------- d-----w c:\program files\DivX
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((( snapshot@2008-11-27_21.43.43,73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 11:28:42 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-02 16:11:25 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"WooCnxMon"="c:\progra~1\Wanadoo\CnxMon.exe" [2004-10-13 24576]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-10-13 24576]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-17 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-13 974898]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-06-19 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-09 962661]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-07 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Reset.lnk - c:\windows\repair\reset.bat [2001-05-21 238]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Utilisateur\\Mes documents\\engelh\\eMulev0[1].48a.-MorphXTv10.5-bin\\emule\\eMule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
.
Contenu du dossier 'Tâches planifiées'
2008-12-02 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-FixCamera - c:\windows\FixCamera.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.wanadoo.fr
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 17:40:47
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-12-02 17:41:41
ComboFix-quarantined-files.txt 2008-12-02 16:41:39
ComboFix2.txt 2008-11-27 20:44:13
Avant-CF: 51 248 078 848 octets libres
Après-CF: 51,225,804,800 octets libres
183 --- E O F --- 2008-10-10 00:36:16
ComboFix 08-11-27.03 - Utilisateur 2008-12-02 17:39:14.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.206 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Mes documents\ComboFix.exe
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
.
2008-12-02 12:57 . 2008-12-02 12:57 <REP> d-------- C:\_OTMoveIt
2008-11-28 14:39 . 2008-11-28 14:39 <REP> d-------- c:\program files\VirusTotalUploader
2008-11-28 10:22 . 2008-11-28 11:30 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\HouseCall 6.6
2008-11-26 21:26 . 2008-11-26 21:29 <REP> d-------- c:\program files\Windows Live
2008-11-26 21:26 . 2008-11-26 21:28 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-26 21:25 . 2008-11-26 21:25 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\program files\Avira
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-25 17:15 . 2008-11-25 20:47 <REP> d-------- c:\windows\ERUNT
2008-11-25 17:15 . 2008-11-25 17:21 <REP> d-------- C:\Backups
2008-11-24 22:18 . 2008-11-24 22:18 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-24 22:17 . 2007-08-21 07:36 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-24 22:17 . 2007-08-20 16:56 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-24 22:17 . 2008-11-24 22:17 <REP> d-------- c:\documents and settings\Administrateur
2008-11-24 20:54 . 2008-11-24 20:54 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-11-24 21:03 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-24 20:53 . 2008-11-24 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 20:53 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-24 18:21 . 2008-11-24 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-24 18:10 . 2008-11-26 18:32 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 22:02 . 2008-11-23 22:02 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-23 19:53 . 2008-12-02 12:45 <REP> d-------- c:\documents and settings\Utilisateur\.housecall6.6
2008-11-22 16:56 . 2008-11-22 16:56 124,688 --a------ c:\windows\system32\Mswinsck.ocx
2008-11-22 16:56 . 2008-11-22 16:57 355 --a------ c:\windows\ps
2008-11-21 10:32 . 2008-11-21 10:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-21 10:26 . 2008-11-21 10:26 <REP> d-------- c:\program files\Yahoo!
2008-11-21 10:26 . 2008-11-21 10:27 <REP> d-------- c:\program files\CCleaner
2008-11-18 08:36 . 2008-11-18 08:36 <REP> d-------- c:\program files\Fichiers communs\snp2std
2008-11-18 08:36 . 2006-06-07 10:34 10,305,280 --a------ c:\windows\system32\drivers\snp2sxp.sys
2008-11-18 08:36 . 2006-05-15 15:52 675,840 --a------ c:\windows\vsnp2std.exe
2008-11-18 08:36 . 2005-01-26 15:45 349,472 --a------ c:\windows\WindowsXP-KB822603-x86.exe
2008-11-18 08:36 . 2006-06-19 13:37 262,144 --a------ c:\windows\tsnp2std.exe
2008-11-18 08:36 . 2006-04-07 10:33 147,456 --a------ c:\windows\rsnp2std.dll
2008-11-18 08:36 . 2006-05-04 11:14 61,440 --a------ c:\windows\vsnp2std.dll
2008-11-18 08:36 . 2005-11-23 13:55 53,248 --a------ c:\windows\system32\csnp2std.dll
2008-11-18 08:36 . 2006-04-27 20:43 24,832 --a------ c:\windows\system32\drivers\sncamd.sys
2008-11-18 08:36 . 2004-12-09 17:23 15,497 --a------ c:\windows\snp2std.ini
2008-11-18 08:36 . 2004-12-09 17:23 13,022 --a------ c:\windows\snp2std.src
2008-11-18 01:00 . 2008-11-18 01:00 19,560 --a------ c:\documents and settings\Utilisateur\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 16:41 63,766,560 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-02 16:37 --------- d-----w c:\program files\Wanadoo
2008-12-02 14:31 748,616 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-28 08:10 1,746,519 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-11-26 17:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 17:13 --------- d-----w c:\program files\Lavasoft
2008-11-18 07:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-14 16:09 --------- d-----w c:\program files\DivX
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((( snapshot@2008-11-27_21.43.43,73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 11:28:42 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-02 16:11:25 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"WooCnxMon"="c:\progra~1\Wanadoo\CnxMon.exe" [2004-10-13 24576]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-10-13 24576]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-17 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-13 974898]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-06-19 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-09 962661]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-07 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Reset.lnk - c:\windows\repair\reset.bat [2001-05-21 238]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Utilisateur\\Mes documents\\engelh\\eMulev0[1].48a.-MorphXTv10.5-bin\\emule\\eMule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
.
Contenu du dossier 'Tâches planifiées'
2008-12-02 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-FixCamera - c:\windows\FixCamera.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.wanadoo.fr
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 17:40:47
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-12-02 17:41:41
ComboFix-quarantined-files.txt 2008-12-02 16:41:39
ComboFix2.txt 2008-11-27 20:44:13
Avant-CF: 51 248 078 848 octets libres
Après-CF: 51,225,804,800 octets libres
183 --- E O F --- 2008-10-10 00:36:16
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.206 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Mes documents\ComboFix.exe
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
.
2008-12-02 12:57 . 2008-12-02 12:57 <REP> d-------- C:\_OTMoveIt
2008-11-28 14:39 . 2008-11-28 14:39 <REP> d-------- c:\program files\VirusTotalUploader
2008-11-28 10:22 . 2008-11-28 11:30 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\HouseCall 6.6
2008-11-26 21:26 . 2008-11-26 21:29 <REP> d-------- c:\program files\Windows Live
2008-11-26 21:26 . 2008-11-26 21:28 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-26 21:25 . 2008-11-26 21:25 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\program files\Avira
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-25 17:15 . 2008-11-25 20:47 <REP> d-------- c:\windows\ERUNT
2008-11-25 17:15 . 2008-11-25 17:21 <REP> d-------- C:\Backups
2008-11-24 22:18 . 2008-11-24 22:18 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-24 22:17 . 2007-08-21 07:36 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-24 22:17 . 2007-08-20 16:56 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-24 22:17 . 2008-11-24 22:17 <REP> d-------- c:\documents and settings\Administrateur
2008-11-24 20:54 . 2008-11-24 20:54 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-11-24 21:03 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-24 20:53 . 2008-11-24 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 20:53 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-24 18:21 . 2008-11-24 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-24 18:10 . 2008-11-26 18:32 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 22:02 . 2008-11-23 22:02 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-23 19:53 . 2008-12-02 12:45 <REP> d-------- c:\documents and settings\Utilisateur\.housecall6.6
2008-11-22 16:56 . 2008-11-22 16:56 124,688 --a------ c:\windows\system32\Mswinsck.ocx
2008-11-22 16:56 . 2008-11-22 16:57 355 --a------ c:\windows\ps
2008-11-21 10:32 . 2008-11-21 10:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-21 10:26 . 2008-11-21 10:26 <REP> d-------- c:\program files\Yahoo!
2008-11-21 10:26 . 2008-11-21 10:27 <REP> d-------- c:\program files\CCleaner
2008-11-18 08:36 . 2008-11-18 08:36 <REP> d-------- c:\program files\Fichiers communs\snp2std
2008-11-18 08:36 . 2006-06-07 10:34 10,305,280 --a------ c:\windows\system32\drivers\snp2sxp.sys
2008-11-18 08:36 . 2006-05-15 15:52 675,840 --a------ c:\windows\vsnp2std.exe
2008-11-18 08:36 . 2005-01-26 15:45 349,472 --a------ c:\windows\WindowsXP-KB822603-x86.exe
2008-11-18 08:36 . 2006-06-19 13:37 262,144 --a------ c:\windows\tsnp2std.exe
2008-11-18 08:36 . 2006-04-07 10:33 147,456 --a------ c:\windows\rsnp2std.dll
2008-11-18 08:36 . 2006-05-04 11:14 61,440 --a------ c:\windows\vsnp2std.dll
2008-11-18 08:36 . 2005-11-23 13:55 53,248 --a------ c:\windows\system32\csnp2std.dll
2008-11-18 08:36 . 2006-04-27 20:43 24,832 --a------ c:\windows\system32\drivers\sncamd.sys
2008-11-18 08:36 . 2004-12-09 17:23 15,497 --a------ c:\windows\snp2std.ini
2008-11-18 08:36 . 2004-12-09 17:23 13,022 --a------ c:\windows\snp2std.src
2008-11-18 01:00 . 2008-11-18 01:00 19,560 --a------ c:\documents and settings\Utilisateur\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 16:41 63,766,560 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-02 16:37 --------- d-----w c:\program files\Wanadoo
2008-12-02 14:31 748,616 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-28 08:10 1,746,519 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-11-26 17:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 17:13 --------- d-----w c:\program files\Lavasoft
2008-11-18 07:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-14 16:09 --------- d-----w c:\program files\DivX
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((( snapshot@2008-11-27_21.43.43,73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 11:28:42 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-02 16:11:25 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"WooCnxMon"="c:\progra~1\Wanadoo\CnxMon.exe" [2004-10-13 24576]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-10-13 24576]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-17 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-13 974898]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-06-19 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-09 962661]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-07 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Reset.lnk - c:\windows\repair\reset.bat [2001-05-21 238]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Utilisateur\\Mes documents\\engelh\\eMulev0[1].48a.-MorphXTv10.5-bin\\emule\\eMule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
.
Contenu du dossier 'Tâches planifiées'
2008-12-02 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-FixCamera - c:\windows\FixCamera.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.wanadoo.fr
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 17:40:47
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-12-02 17:41:41
ComboFix-quarantined-files.txt 2008-12-02 16:41:39
ComboFix2.txt 2008-11-27 20:44:13
Avant-CF: 51 248 078 848 octets libres
Après-CF: 51,225,804,800 octets libres
183 --- E O F --- 2008-10-10 00:36:16
ComboFix 08-11-27.03 - Utilisateur 2008-12-02 17:39:14.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.206 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Mes documents\ComboFix.exe
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
.
2008-12-02 12:57 . 2008-12-02 12:57 <REP> d-------- C:\_OTMoveIt
2008-11-28 14:39 . 2008-11-28 14:39 <REP> d-------- c:\program files\VirusTotalUploader
2008-11-28 10:22 . 2008-11-28 11:30 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\HouseCall 6.6
2008-11-26 21:26 . 2008-11-26 21:29 <REP> d-------- c:\program files\Windows Live
2008-11-26 21:26 . 2008-11-26 21:28 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-26 21:25 . 2008-11-26 21:25 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\program files\Avira
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-25 17:15 . 2008-11-25 20:47 <REP> d-------- c:\windows\ERUNT
2008-11-25 17:15 . 2008-11-25 17:21 <REP> d-------- C:\Backups
2008-11-24 22:18 . 2008-11-24 22:18 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-24 22:17 . 2007-08-21 07:36 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-24 22:17 . 2007-08-20 16:56 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-24 22:17 . 2008-11-24 22:17 <REP> d-------- c:\documents and settings\Administrateur
2008-11-24 20:54 . 2008-11-24 20:54 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-11-24 21:03 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-24 20:53 . 2008-11-24 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 20:53 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-24 18:21 . 2008-11-24 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-24 18:10 . 2008-11-26 18:32 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 22:02 . 2008-11-23 22:02 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-23 19:53 . 2008-12-02 12:45 <REP> d-------- c:\documents and settings\Utilisateur\.housecall6.6
2008-11-22 16:56 . 2008-11-22 16:56 124,688 --a------ c:\windows\system32\Mswinsck.ocx
2008-11-22 16:56 . 2008-11-22 16:57 355 --a------ c:\windows\ps
2008-11-21 10:32 . 2008-11-21 10:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-21 10:26 . 2008-11-21 10:26 <REP> d-------- c:\program files\Yahoo!
2008-11-21 10:26 . 2008-11-21 10:27 <REP> d-------- c:\program files\CCleaner
2008-11-18 08:36 . 2008-11-18 08:36 <REP> d-------- c:\program files\Fichiers communs\snp2std
2008-11-18 08:36 . 2006-06-07 10:34 10,305,280 --a------ c:\windows\system32\drivers\snp2sxp.sys
2008-11-18 08:36 . 2006-05-15 15:52 675,840 --a------ c:\windows\vsnp2std.exe
2008-11-18 08:36 . 2005-01-26 15:45 349,472 --a------ c:\windows\WindowsXP-KB822603-x86.exe
2008-11-18 08:36 . 2006-06-19 13:37 262,144 --a------ c:\windows\tsnp2std.exe
2008-11-18 08:36 . 2006-04-07 10:33 147,456 --a------ c:\windows\rsnp2std.dll
2008-11-18 08:36 . 2006-05-04 11:14 61,440 --a------ c:\windows\vsnp2std.dll
2008-11-18 08:36 . 2005-11-23 13:55 53,248 --a------ c:\windows\system32\csnp2std.dll
2008-11-18 08:36 . 2006-04-27 20:43 24,832 --a------ c:\windows\system32\drivers\sncamd.sys
2008-11-18 08:36 . 2004-12-09 17:23 15,497 --a------ c:\windows\snp2std.ini
2008-11-18 08:36 . 2004-12-09 17:23 13,022 --a------ c:\windows\snp2std.src
2008-11-18 01:00 . 2008-11-18 01:00 19,560 --a------ c:\documents and settings\Utilisateur\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 16:41 63,766,560 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-02 16:37 --------- d-----w c:\program files\Wanadoo
2008-12-02 14:31 748,616 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-28 08:10 1,746,519 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-11-26 17:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 17:13 --------- d-----w c:\program files\Lavasoft
2008-11-18 07:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-14 16:09 --------- d-----w c:\program files\DivX
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((( snapshot@2008-11-27_21.43.43,73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 11:28:42 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-02 16:11:25 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"WooCnxMon"="c:\progra~1\Wanadoo\CnxMon.exe" [2004-10-13 24576]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-10-13 24576]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-17 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-13 974898]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-06-19 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-09 962661]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-07 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Reset.lnk - c:\windows\repair\reset.bat [2001-05-21 238]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Utilisateur\\Mes documents\\engelh\\eMulev0[1].48a.-MorphXTv10.5-bin\\emule\\eMule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
.
Contenu du dossier 'Tâches planifiées'
2008-12-02 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-FixCamera - c:\windows\FixCamera.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.wanadoo.fr
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 17:40:47
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-12-02 17:41:41
ComboFix-quarantined-files.txt 2008-12-02 16:41:39
ComboFix2.txt 2008-11-27 20:44:13
Avant-CF: 51 248 078 848 octets libres
Après-CF: 51,225,804,800 octets libres
183 --- E O F --- 2008-10-10 00:36:16
ComboFix 08-11-27.03 - Utilisateur 2008-12-02 17:39:14.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.206 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Mes documents\ComboFix.exe
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
.
2008-12-02 12:57 . 2008-12-02 12:57 <REP> d-------- C:\_OTMoveIt
2008-11-28 14:39 . 2008-11-28 14:39 <REP> d-------- c:\program files\VirusTotalUploader
2008-11-28 10:22 . 2008-11-28 11:30 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\HouseCall 6.6
2008-11-26 21:26 . 2008-11-26 21:29 <REP> d-------- c:\program files\Windows Live
2008-11-26 21:26 . 2008-11-26 21:28 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-26 21:25 . 2008-11-26 21:25 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\program files\Avira
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-25 17:15 . 2008-11-25 20:47 <REP> d-------- c:\windows\ERUNT
2008-11-25 17:15 . 2008-11-25 17:21 <REP> d-------- C:\Backups
2008-11-24 22:18 . 2008-11-24 22:18 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-24 22:17 . 2007-08-21 07:36 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-24 22:17 . 2007-08-20 16:56 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-24 22:17 . 2008-11-24 22:17 <REP> d-------- c:\documents and settings\Administrateur
2008-11-24 20:54 . 2008-11-24 20:54 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-11-24 21:03 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-24 20:53 . 2008-11-24 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 20:53 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-24 18:21 . 2008-11-24 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-24 18:10 . 2008-11-26 18:32 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 22:02 . 2008-11-23 22:02 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-23 19:53 . 2008-12-02 12:45 <REP> d-------- c:\documents and settings\Utilisateur\.housecall6.6
2008-11-22 16:56 . 2008-11-22 16:56 124,688 --a------ c:\windows\system32\Mswinsck.ocx
2008-11-22 16:56 . 2008-11-22 16:57 355 --a------ c:\windows\ps
2008-11-21 10:32 . 2008-11-21 10:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-21 10:26 . 2008-11-21 10:26 <REP> d-------- c:\program files\Yahoo!
2008-11-21 10:26 . 2008-11-21 10:27 <REP> d-------- c:\program files\CCleaner
2008-11-18 08:36 . 2008-11-18 08:36 <REP> d-------- c:\program files\Fichiers communs\snp2std
2008-11-18 08:36 . 2006-06-07 10:34 10,305,280 --a------ c:\windows\system32\drivers\snp2sxp.sys
2008-11-18 08:36 . 2006-05-15 15:52 675,840 --a------ c:\windows\vsnp2std.exe
2008-11-18 08:36 . 2005-01-26 15:45 349,472 --a------ c:\windows\WindowsXP-KB822603-x86.exe
2008-11-18 08:36 . 2006-06-19 13:37 262,144 --a------ c:\windows\tsnp2std.exe
2008-11-18 08:36 . 2006-04-07 10:33 147,456 --a------ c:\windows\rsnp2std.dll
2008-11-18 08:36 . 2006-05-04 11:14 61,440 --a------ c:\windows\vsnp2std.dll
2008-11-18 08:36 . 2005-11-23 13:55 53,248 --a------ c:\windows\system32\csnp2std.dll
2008-11-18 08:36 . 2006-04-27 20:43 24,832 --a------ c:\windows\system32\drivers\sncamd.sys
2008-11-18 08:36 . 2004-12-09 17:23 15,497 --a------ c:\windows\snp2std.ini
2008-11-18 08:36 . 2004-12-09 17:23 13,022 --a------ c:\windows\snp2std.src
2008-11-18 01:00 . 2008-11-18 01:00 19,560 --a------ c:\documents and settings\Utilisateur\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 16:41 63,766,560 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-02 16:37 --------- d-----w c:\program files\Wanadoo
2008-12-02 14:31 748,616 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-28 08:10 1,746,519 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-11-26 17:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 17:13 --------- d-----w c:\program files\Lavasoft
2008-11-18 07:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-14 16:09 --------- d-----w c:\program files\DivX
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((( snapshot@2008-11-27_21.43.43,73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 11:28:42 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-02 16:11:25 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"WooCnxMon"="c:\progra~1\Wanadoo\CnxMon.exe" [2004-10-13 24576]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-10-13 24576]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-17 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-13 974898]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-06-19 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-09 962661]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-07 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Reset.lnk - c:\windows\repair\reset.bat [2001-05-21 238]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Utilisateur\\Mes documents\\engelh\\eMulev0[1].48a.-MorphXTv10.5-bin\\emule\\eMule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
.
Contenu du dossier 'Tâches planifiées'
2008-12-02 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-FixCamera - c:\windows\FixCamera.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.wanadoo.fr
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 17:40:47
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-12-02 17:41:41
ComboFix-quarantined-files.txt 2008-12-02 16:41:39
ComboFix2.txt 2008-11-27 20:44:13
Avant-CF: 51 248 078 848 octets libres
Après-CF: 51,225,804,800 octets libres
183 --- E O F --- 2008-10-10 00:36:16
ComboFix 08-11-27.03 - Utilisateur 2008-12-02 17:39:14.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.206 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Mes documents\ComboFix.exe
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
.
2008-12-02 12:57 . 2008-12-02 12:57 <REP> d-------- C:\_OTMoveIt
2008-11-28 14:39 . 2008-11-28 14:39 <REP> d-------- c:\program files\VirusTotalUploader
2008-11-28 10:22 . 2008-11-28 11:30 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\HouseCall 6.6
2008-11-26 21:26 . 2008-11-26 21:29 <REP> d-------- c:\program files\Windows Live
2008-11-26 21:26 . 2008-11-26 21:28 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-26 21:25 . 2008-11-26 21:25 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\program files\Avira
2008-11-26 18:40 . 2008-11-26 18:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-25 17:15 . 2008-11-25 20:47 <REP> d-------- c:\windows\ERUNT
2008-11-25 17:15 . 2008-11-25 17:21 <REP> d-------- C:\Backups
2008-11-24 22:18 . 2008-11-24 22:18 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-24 22:17 . 2007-08-21 07:36 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-24 22:17 . 2007-08-20 16:56 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-11-24 22:17 . 2007-08-20 16:56 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-24 22:17 . 2008-11-24 22:17 <REP> d-------- c:\documents and settings\Administrateur
2008-11-24 20:54 . 2008-11-24 20:54 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-11-24 21:03 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-24 20:53 . 2008-11-24 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 20:53 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 20:53 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-24 18:21 . 2008-11-24 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-24 18:10 . 2008-11-26 18:32 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 22:02 . 2008-11-23 22:02 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-23 19:53 . 2008-12-02 12:45 <REP> d-------- c:\documents and settings\Utilisateur\.housecall6.6
2008-11-22 16:56 . 2008-11-22 16:56 124,688 --a------ c:\windows\system32\Mswinsck.ocx
2008-11-22 16:56 . 2008-11-22 16:57 355 --a------ c:\windows\ps
2008-11-21 10:32 . 2008-11-21 10:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-21 10:26 . 2008-11-21 10:26 <REP> d-------- c:\program files\Yahoo!
2008-11-21 10:26 . 2008-11-21 10:27 <REP> d-------- c:\program files\CCleaner
2008-11-18 08:36 . 2008-11-18 08:36 <REP> d-------- c:\program files\Fichiers communs\snp2std
2008-11-18 08:36 . 2006-06-07 10:34 10,305,280 --a------ c:\windows\system32\drivers\snp2sxp.sys
2008-11-18 08:36 . 2006-05-15 15:52 675,840 --a------ c:\windows\vsnp2std.exe
2008-11-18 08:36 . 2005-01-26 15:45 349,472 --a------ c:\windows\WindowsXP-KB822603-x86.exe
2008-11-18 08:36 . 2006-06-19 13:37 262,144 --a------ c:\windows\tsnp2std.exe
2008-11-18 08:36 . 2006-04-07 10:33 147,456 --a------ c:\windows\rsnp2std.dll
2008-11-18 08:36 . 2006-05-04 11:14 61,440 --a------ c:\windows\vsnp2std.dll
2008-11-18 08:36 . 2005-11-23 13:55 53,248 --a------ c:\windows\system32\csnp2std.dll
2008-11-18 08:36 . 2006-04-27 20:43 24,832 --a------ c:\windows\system32\drivers\sncamd.sys
2008-11-18 08:36 . 2004-12-09 17:23 15,497 --a------ c:\windows\snp2std.ini
2008-11-18 08:36 . 2004-12-09 17:23 13,022 --a------ c:\windows\snp2std.src
2008-11-18 01:00 . 2008-11-18 01:00 19,560 --a------ c:\documents and settings\Utilisateur\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 16:41 63,766,560 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-02 16:37 --------- d-----w c:\program files\Wanadoo
2008-12-02 14:31 748,616 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-28 08:10 1,746,519 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-11-26 17:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 17:13 --------- d-----w c:\program files\Lavasoft
2008-11-18 07:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-14 16:09 --------- d-----w c:\program files\DivX
2008-09-16 00:14 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((( snapshot@2008-11-27_21.43.43,73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 11:28:42 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-02 16:11:25 114,968 ----a-w c:\windows\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"WooCnxMon"="c:\progra~1\Wanadoo\CnxMon.exe" [2004-10-13 24576]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-10-13 24576]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-17 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-13 974898]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-06-19 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-09 962661]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-07 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Reset.lnk - c:\windows\repair\reset.bat [2001-05-21 238]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Utilisateur\\Mes documents\\engelh\\eMulev0[1].48a.-MorphXTv10.5-bin\\emule\\eMule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
.
Contenu du dossier 'Tâches planifiées'
2008-12-02 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-FixCamera - c:\windows\FixCamera.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.wanadoo.fr
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b51ba0388b634d1ba1594ec9826202b5
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b51ba0388b634d1ba1594ec9826202b5
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 17:40:47
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-12-02 17:41:41
ComboFix-quarantined-files.txt 2008-12-02 16:41:39
ComboFix2.txt 2008-11-27 20:44:13
Avant-CF: 51 248 078 848 octets libres
Après-CF: 51,225,804,800 octets libres
183 --- E O F --- 2008-10-10 00:36:16
marc571
>
benurrr
- Messages postés
- 9638
- Date d'inscription
- samedi 24 mai 2008
- Statut
- Contributeur sécurité
- Dernière intervention
- 11 janvier 2012
salut apparemment c bon j ai fais un scan avec trend micro house call et il ma donné coockies et faille de securite mais plus de troj donc c bon merci beaucoup sans toi je n aurai pas pu le faire