Bonjour,
J'ai fais plusieurs contrôles de mon ordi, que ce soit avec spy bot ou adware, je n'arrive pas à me débarrasser de fxstaller ainsi que de différents chevaux de Troie qui réapparaissent.
J'ai suivis les conseilles de D11D, dans un premier temps j'ai fais un contrôle avec ToolBarSD et ensuite SDFIX.
Je vous transmets le rapport si quelqu'un peut y jeter un coup d'oeil, d'avance merci et surtout me dire quelle est la marche suivre pour la suite.
A+
Philippe
-----------\\ ToolBar S&D 1.2.6 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.20GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : philippe TIJERAS ( Administrator )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:92 Go (Free:12 Go)
D:\ (Local Disk) - NTFS - Total:91 Go (Free:87 Go)
E:\ (Local Disk) - FAT32 - Total:2 Go (Free:0 Go)
F:\ (CD or DVD)
G:\ (CD or DVD)
I:\ (USB)
J:\ (USB) - FAT - Total:949 Mo (Free:0 Go)
K:\ (USB)
L:\ (USB)
M:\ (USB)
"C:\ToolBar SD" ( MAJ : 04-12-2008|20:40 )
Option : [1] ( 15/12/2008|11:42 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\WINDOWS\iun6002.exe
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="
https://www.google.com/?gws_rd=ssl "
"Start Page"="
https://www.google.fr/?gws_rd=ssl "
"Search Bar"="
https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC "
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome "
"Default_Search_URL"="
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch "
"Start Page"="http://www.carrefour.fr"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
[b]==> EGDACCESS <==/b
C:\WINDOWS\system32\LkRqYJlm.ini
C:\WINDOWS\system32\LkRqYJlm.ini2
C:\WINDOWS\system32\UDLorBeg.ini
C:\WINDOWS\system32\UDLorBeg.ini2
C:\WINDOWS\system32\mlJYqRkL.dll
C:\WINDOWS\system32\geBroLDU.dll
[b]==> VUNDO <==/b
1 - "C:\ToolBar SD\TB_1.txt" - 15/12/2008|11:43 - Option : [1]
-----------\\ Fin du rapport a 11:43:46,06
[b]SDFix: Version 1.240 /b
Run by philippe TIJERAS on 15/12/2008 at 13:27
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services /b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files /b:
Trojan Files Found:
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP10.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP12.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP15.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP18.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP1E.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP33.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP35.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP3C.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP3F.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP40.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP46.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP47.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP48.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP56.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP58.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP59.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP5B.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP5D.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP5E.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP5F.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP60.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP61.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP62.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP63.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP64.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP65.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP66.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP7.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP70.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP78.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP8.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMP9.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMPA.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMPB.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMPC.tmp - Deleted
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\TMPD.tmp - Deleted
C:\WINDOWS\fxstaller.exe - Deleted
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-15 18:32:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\\Messenger\\msmsgs.exe"="%ProgramFiles%\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%WinDir%\\system32\\fxsclnt.exe"="%WinDir%\\system32\\fxsclnt.exe:*:enabled:Microsoft Fax Console"
"C:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"="C:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe:*:Disabled:BF1942"
"C:\\Program Files\\NovaLogic\\Joint Operations Typhoon Rising\\UPDATE.EXE"="C:\\Program Files\\NovaLogic\\Joint Operations Typhoon Rising\\UPDATE.EXE:*:Enabled:UPDATE"
"C:\\Program Files\\JVTorrent\\btdownloadgui.exe"="C:\\Program Files\\JVTorrent\\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Assistance … distance - Windows Messenger et voix"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe"="C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe:*:Enabled:HP Software Update Client"
"C:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\patchget.dat"="C:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\patchget.dat:*:Enabled:patchgrabber"
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"="C:\\Program Files\\BitTornado\\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\\Soldat\\Soldat.exe"="C:\\Soldat\\Soldat.exe:*:Disabled:Soldat"
"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"="C:\\Program Files\\GameSpy Arcade\\Aphex.exe:*:Enabled:GameSpy Arcade"
"D:\\dfbhdlc.exe"="D:\\dfbhdlc.exe:*:Enabled:dfbhdlc"
"D:\\UPDATE.EXE"="D:\\UPDATE.EXE:*:Enabled:UPDATE"
"C:\\Program Files\\Livecom\\Application\\eConfv4\\ftplayer.exe"="C:\\Program Files\\Livecom\\Application\\eConfv4\\ftplayer.exe:*:Disabled:eConf player"
"C:\\Program Files\\AOL 9.0\\WAOL.exe"="C:\\Program Files\\AOL 9.0\\WAOL.exe:*:Disabled:AOL 9.0"
"C:\\Program Files\\AOL 9.0\\AOL.exe"="C:\\Program Files\\AOL 9.0\\AOL.exe:*:Disabled:AOL 9.0"
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDIAL.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDIAL.exe:*:Disabled:AOL 9.0 (Connectivity Service Dialer)"
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLACSD.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLACSD.exe:*:Disabled:AOL 9.0 (Connectivity Service)"
"D:\\Program Files\\iMesh\\iMesh5\\iMesh.exe"="D:\\Program Files\\iMesh\\iMesh5\\iMesh.exe:*:Disabled:iMesh 5"
"C:\\Program Files\\iMesh\\iMesh5\\iMesh.exe"="C:\\Program Files\\iMesh\\iMesh5\\iMesh.exe:*:Disabled:iMesh 5"
"C:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\game.dat"="C:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\game.dat:*:Disabled:La Bataille pour la Terre du Milieu(tm)"
"C:\\Program Files\\TribalWeb.net\\tribalweb.exe"="C:\\Program Files\\TribalWeb.net\\tribalweb.exe:*:Enabled:TribalWeb.net : R‚seau priv‚ sur Internet"
"C:\\Program Files\\LucasArts\\Star Wars JK II Jedi Outcast\\GameData\\jk2mp.exe"="C:\\Program Files\\LucasArts\\Star Wars JK II Jedi Outcast\\GameData\\jk2mp.exe:*:Enabled:jk2mp"
"C:\\Program Files\\Electronic Arts\\La Bataille pour la Terre du Milieu II\\patchget.dat"="C:\\Program Files\\Electronic Arts\\La Bataille pour la Terre du Milieu II\\patchget.dat:*:Enabled:patchgrabber"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Ex‚cuter une DLL en tant qu'application"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\\pc\\igi2.exe"="D:\\pc\\igi2.exe:*:Disabled:IGI2:Covert Strike"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\Steam\\SteamApps\\philippe357\\half-life deathmatch source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\philippe357\\half-life deathmatch source\\hl2.exe:*:Enabled:hl2"
"C:\\WINDOWS\\system32\\rtcshare.exe"="C:\\WINDOWS\\system32\\rtcshare.exe:*:Enabled:Partage de l'application RTC"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Disabled:eMule"
"C:\\Program Files\\Codemasters\\IGI 2\\pc\\igi2.exe"="C:\\Program Files\\Codemasters\\IGI 2\\pc\\igi2.exe:*:Disabled:IGI2:Covert Strike"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Disabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Disabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"="C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:Disabled:IncrediMail"
"C:\\Program Files\\NovaLogic\\Joint Operations Typhoon Rising\\Jointops.exe"="C:\\Program Files\\NovaLogic\\Joint Operations Typhoon Rising\\Jointops.exe:*:Disabled:Jointops"
"C:\\Program Files\\Electronic Arts\\La Bataille pour la Terre du Milieu II\\game.dat"="C:\\Program Files\\Electronic Arts\\La Bataille pour la Terre du Milieu II\\game.dat:*:Disabled:La Bataille pour la Terre du Milieu T II"
"C:\\Program Files\\Quake III Arena\\quake3.exe"="C:\\Program Files\\Quake III Arena\\quake3.exe:*:Disabled:quake3"
"C:\\games\\RedFaction\\rf.exe"="C:\\games\\RedFaction\\rf.exe:*:Disabled:Red Faction"
"C:\\games\\RedFaction\\RedFaction.exe"="C:\\games\\RedFaction\\RedFaction.exe:*:Disabled:Red Faction Launcher"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\\Messenger\\msmsgs.exe"="%ProgramFiles%\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%ProgramFiles%\\AOL 9.0\\AOL.exe"="%ProgramFiles%\\AOL 9.0\\AOL.exe:*:enabled:AOL 9.0"
"%ProgramFiles%\\AOL 9.0\\WAOL.exe"="%ProgramFiles%\\AOL 9.0\\WAOL.exe:*:enabled:AOL 9.0"
"%CommonProgramFiles%\\AOL\\ACS\\AOLACSD.exe"="%CommonProgramFiles%\\AOL\\ACS\\AOLACSD.exe:*:enabled:AOL 9.0 (Connectivity Service)"
"%CommonProgramFiles%\\AOL\\ACS\\AOLDIAL.exe"="%CommonProgramFiles%\\AOL\\ACS\\AOLDIAL.exe:*:enabled:AOL 9.0 (Connectivity Service Dialer)"
"%WinDir%\\system32\\fxsclnt.exe"="%WinDir%\\system32\\fxsclnt.exe:*:enabled:Microsoft Fax Console"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files /b:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes /b:
Mon 14 Apr 2008 1,695,232 A.SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll"
Thu 14 Aug 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Wed 30 Jul 2008 4,891,984 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Wed 22 Oct 2008 962,896 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\Tools.dll"
Wed 27 Oct 2004 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 16 Sep 2005 2,687 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv10.bak"
Mon 4 Dec 2006 1,544 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv11.bak"
Thu 28 Dec 2006 1,163 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv12.bak"
Sat 30 Sep 2006 2,687 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv13.bak"
Thu 24 May 2007 1,544 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv14.bak"
Sat 9 Jun 2007 782 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv15.bak"
Sun 12 Nov 2006 1,544 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv16.bak"
Sun 3 Feb 2008 1,544 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv17.bak"
Mon 4 Dec 2006 1,925 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv18.bak"
Sun 12 Nov 2006 1,163 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv19.bak"
Thu 19 Jun 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 18 Apr 2005 60,201,096 A..H. --- "C:\Documents and Settings\nathalie TIJERAS\Local Settings\Temp\dn24.tmp"
Wed 13 Apr 2005 4,686,852 A..H. --- "C:\Documents and Settings\nathalie TIJERAS\Local Settings\Temp\dn241.tmp"
Tue 12 Apr 2005 62,956,971 A..H. --- "C:\Documents and Settings\nathalie TIJERAS\Local Settings\Temp\dn246.tmp"
Tue 19 Apr 2005 6,196,054 A..H. --- "C:\Documents and Settings\nathalie TIJERAS\Local Settings\Temp\dn25.tmp"
Sat 4 Jun 2005 60,201,096 A..H. --- "C:\Documents and Settings\nathalie TIJERAS\Local Settings\Temp\dn26.tmp"
Thu 21 Apr 2005 60,201,096 A..H. --- "C:\Documents and Settings\nathalie TIJERAS\Local Settings\Temp\dn2D9.tmp"
Sun 1 Oct 2006 174 A..H. --- "C:\Documents and Settings\nathalie TIJERAS\Local Settings\Temp\Free Download Manager\tic5.tmp"
Sun 1 Oct 2006 53 A..H. --- "C:\Documents and Settings\nathalie TIJERAS\Local Settings\Temp\Free Download Manager\tic7.tmp"
Sun 1 Oct 2006 151 A..H. --- "C:\Documents and Settings\nathalie TIJERAS\Local Settings\Temp\Free Download Manager\ticA.tmp"
Wed 1 Nov 2006 0 ...H. --- "C:\Documents and Settings\philippe TIJERAS\Application Data\Microsoft\Word\~WRL0005.tmp"
Wed 27 Oct 2004 4,348 ...H. --- "C:\Documents and Settings\philippe TIJERAS\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Wed 27 Oct 2004 20 A..H. --- "C:\Documents and Settings\philippe TIJERAS\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Wed 27 Oct 2004 312 A.SH. --- "C:\Documents and Settings\philippe TIJERAS\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Thu 13 Oct 2005 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\7e808a3c27f845e09ebb11aa4251afd5\BIT8.tmp"
Mon 15 Dec 2008 5,940 A.SH. --- "C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE2.tmp"
[b]Finished!/b
Afficher la suite