Tom's Guide > Forum > Sécurité - Virus > [résolu] Pages internet qui s'ouvrent toutes seules !
[résolu] Pages internet qui s'ouvrent toutes seules ! - Sécurité - Virus
TomsGuide.com : 800 000 inscrits répondent à toutes vos questions high-tech et informatique. Pour obtenir de l'aide, inscrivez-vous gratuitement !
Mot :    Pseudo :           
 

Bonjour a tous,
depuis environ 4 jours j'ai des pages internet (porno) qui s'ouvrent toutes seules et mon pc se bloque de plus en plus souvent.
Voici le rapport de hijackthis :


Logfile of HijackThis v1.99.1
Scan saved at 16:27:05, on 17/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Logfile of HijackThis v1.99.1
Scan saved at 16:40:57, on 17/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Fichiers communs\DriveCleaner 2006 Free\SDRmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\TEMP\win76.tmp.exe
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\HijackThis\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2810AAE0-EDAA-41F6-86F3-FF420FF9052F} - C:\WINDOWS\system32\urqqqpo.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\nhytwhcv.dll
O2 - BHO: (no name) - {F1CFED7F-EED0-4D42-9313-56A78DC475B2} - C:\WINDOWS\system32\vturq.dll
O2 - BHO: (no name) - {FE4FDF23-7EBC-45F9-B1E3-71B334CF01F9} - C:\WINDOWS\system32\vturq.dll
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [WinLiveUpdate] C:\Program Files\Fichiers communs\Microsoft Shared\DAO\svchost.exe
O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [AutoSys] C:\WINDOWS\system32\autosys.exe
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\hdglridv.dll",setvm
O4 - HKLM\..\Run: [SDR6V_Check] "C:\Program Files\Fichiers communs\DriveCleaner 2006 Free\SDRmon.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [UDial] C:\WINDOWS\system32/udial.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzShadow\YzShadow.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {42E1F024-ECC3-456F-B98A-4CE5ACDBF25C} (ActiveFormX Contrôle) - https://ssl-tb.sitadelle.com/selfca [...] Config.ocx
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/bina [...] b32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: urqqqpo - C:\WINDOWS\SYSTEM32\urqqqpo.dll
O20 - Winlogon Notify: vturq - C:\WINDOWS\system32\vturq.dll
O20 - Winlogon Notify: winepi32 - C:\WINDOWS\SYSTEM32\winepi32.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe



Voila je vous en prie aidez moi ! :cry: :cry: :cry:


Message édité par enjoii89 le 24-01-2007 à 14:11:48
Liens sponsorisés
Inscrivez-vous ou connectez-vous pour masquer ceci.

Je crois que j'ai le meme virus que dans ce topic :
http://www.infos-du-net.com/forum/ [...] ool-resolu

Répondre à enjoii89

bonjour, ;)
~Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
http://www.atribune.org/ccount/click.php?id=4
Double-clique VundoFix.exe afin de le lancer
Clique sur le bouton Scan for Vundo.
~Lorsque le scan est complété, clique sur le bouton Remove Vundo
Une invite te demandera si tu veux supprimer les fichiers, clique YES
Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK.
~Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse
Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo

Répondre à Sham_Rock

Merci beaucoup d'avoir répondu sham-rock !
Alors :
Le rapport de vundofix :


VundoFix V6.3.2

Checking Java version...

Java version is 1.5.0.9

Scan started at 16:59:50 17/01/2007

Listing files found while scanning....

C:\Program Files\VSAdd-in\VSAdd-in.dll
C:\WINDOWS\system32\hdglridv.dll
C:\WINDOWS\system32\nfmucbjc.exe
C:\WINDOWS\system32\nhytwhcv.dll
C:\WINDOWS\system32\qrutv.bak1
C:\WINDOWS\system32\qrutv.bak2
C:\WINDOWS\system32\qrutv.ini
C:\WINDOWS\system32\qrutv.ini2
C:\WINDOWS\system32\rmsyaxnr.dll
C:\WINDOWS\system32\urqqqpo.dll
C:\WINDOWS\system32\vdirlgdh.ini
C:\WINDOWS\system32\vdirlgdh.ini2
C:\WINDOWS\system32\vturq.dll
C:\WINDOWS\system32\xtgxrmpl.exe

Beginning removal...

Attempting to delete C:\Program Files\VSAdd-in\VSAdd-in.dll
C:\Program Files\VSAdd-in\VSAdd-in.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hdglridv.dll
C:\WINDOWS\system32\hdglridv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nfmucbjc.exe
C:\WINDOWS\system32\nfmucbjc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\nhytwhcv.dll
C:\WINDOWS\system32\nhytwhcv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qrutv.bak1
C:\WINDOWS\system32\qrutv.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\qrutv.bak2
C:\WINDOWS\system32\qrutv.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\qrutv.ini
C:\WINDOWS\system32\qrutv.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\qrutv.ini2
C:\WINDOWS\system32\qrutv.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\rmsyaxnr.dll
C:\WINDOWS\system32\rmsyaxnr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\urqqqpo.dll
C:\WINDOWS\system32\urqqqpo.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\vdirlgdh.ini
C:\WINDOWS\system32\vdirlgdh.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\vdirlgdh.ini2
C:\WINDOWS\system32\vdirlgdh.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\vturq.dll
C:\WINDOWS\system32\vturq.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xtgxrmpl.exe
C:\WINDOWS\system32\xtgxrmpl.exe Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\urqqqpo.dll
C:\WINDOWS\system32\urqqqpo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vturq.dll
C:\WINDOWS\system32\vturq.dll Has been deleted!

Performing Repairs to the registry.
Done!


Le rapport de hijackthis :

Logfile of HijackThis v1.99.1
Scan saved at 17:14:08, on 17/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Fichiers communs\DriveCleaner 2006 Free\SDRmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\HijackThis\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2810AAE0-EDAA-41F6-86F3-FF420FF9052F} - C:\WINDOWS\system32\urqqqpo.dll (file missing)
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\nhytwhcv.dll (file missing)
O2 - BHO: (no name) - {F1CFED7F-EED0-4D42-9313-56A78DC475B2} - C:\WINDOWS\system32\vturq.dll (file missing)
O2 - BHO: (no name) - {FE4FDF23-7EBC-45F9-B1E3-71B334CF01F9} - C:\WINDOWS\system32\vturq.dll (file missing)
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [WinLiveUpdate] C:\Program Files\Fichiers communs\Microsoft Shared\DAO\svchost.exe
O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [AutoSys] C:\WINDOWS\system32\autosys.exe
O4 - HKLM\..\Run: [SDR6V_Check] "C:\Program Files\Fichiers communs\DriveCleaner 2006 Free\SDRmon.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzShadow\YzShadow.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {42E1F024-ECC3-456F-B98A-4CE5ACDBF25C} (ActiveFormX Contrôle) - https://ssl-tb.sitadelle.com/selfca [...] Config.ocx
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/bina [...] b32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: winepi32 - C:\WINDOWS\SYSTEM32\winepi32.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe


voila ! :)

Répondre à enjoii89

on continue (il y a du boulot)
supprime vundofix

1
~Télécharge Smitfraudfix

http://siri.urz.free.fr/Fix/SmitfraudFix.zip

~Dezippe la totalité de l'archive smitfraudfix.zip
Recherche:
~Double clique sur smitfraudfix.cmd
~Sélectionne 1 et presse Entrée dans le menu pour créer un rapport des fichiers responsables de l'infection. Le rapport se trouve à la racine du disque système C:\rapport.txt
~Poste ce rapport.
process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

2

Cette procédure doit être imprimée pour que tu puisses l’avoir sous les yeux quand tu seras en mode sans échec.

~Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

http://downloads.andymanchesta.com/R...ools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :

~Redémarre ton ordinateur
Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
Choisis ton compte.

~Déroule la liste des instructions ci-dessous :
Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur RunThis.bat pour lancer le script.
Appuie sur Y pour commencer le processus de nettoyage.
Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
Appuie sur une touche pour redémarrer le PC.
Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.

~Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis et le rapport smitfraud.


Répondre à Sham_Rock

Probleme : le lien vers SDfix est mort

Répondre à enjoii89

attends, je vais chercher ;)

Répondre à Sham_Rock

ok pas de soucis (je peux reviser mon anglais en attendant)
merci encore de m'aider ;)

Répondre à enjoii89

RE
j'ai fait ce que tu m'as dit,
mais lorsque j'ai redémarré l'ordi apres avoir fait le truc avec SDfix avast m'annoncait plein de virus et a chaque fois que je cliquait sur quarantaine avast ma matait un message d'erreur comme quoi une appli utilisait deja le programme
mais j'ai redémarré et plus rien
just des pages qui s'ouvrent toujours ..
voici les raports :

SMITFRAUDFIX :

SmitFraudFix v2.132

Rapport fait à 17:58:03,14, 17/01/2007
Executé à partir de C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\QUENTI~1.CL-\Favoris


»»»»»»»»»»»»»»»»»»»»»»»» Bureau


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues


»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

pe386 détecté, utilisez un scanner de Rootkit

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


»»»»»»»»»»»»»»»»»»»»»»»» Fin




SDFix :


SDFix: Version 1.59

17/01/2007 - 18:05:08,79

Microsoft Windows XP [version 5.1.2600]

Running From: C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\SDFix

Safe Mode:

Checking Services:

Name:


Path:



Restoring Windows Registry Entries
Restoring Default Hosts File

Rebooting

Normal Mode:

Checking Files:


Files will be copied to Backups folder then removed:

C:\WINDOWS\system32\unsvchosts.lzma - Deleted
C:\WINDOWS\Temp\win1.tmp - Deleted
C:\WINDOWS\Temp\win10.tmp - Deleted
C:\WINDOWS\Temp\win100.tmp - Deleted
C:\WINDOWS\Temp\win101.tmp - Deleted
C:\WINDOWS\Temp\win102.tmp - Deleted
C:\WINDOWS\Temp\win103.tmp - Deleted
C:\WINDOWS\Temp\win104.tmp - Deleted
C:\WINDOWS\Temp\win105.tmp - Deleted
C:\WINDOWS\Temp\win106.tmp - Deleted
C:\WINDOWS\Temp\win107.tmp - Deleted
C:\WINDOWS\Temp\win108.tmp - Deleted
C:\WINDOWS\Temp\win109.tmp - Deleted
C:\WINDOWS\Temp\win10A.tmp - Deleted
C:\WINDOWS\Temp\win10B.tmp - Deleted
C:\WINDOWS\Temp\win10C.tmp - Deleted
C:\WINDOWS\Temp\win10D.tmp - Deleted
C:\WINDOWS\Temp\win10E.tmp - Deleted
C:\WINDOWS\Temp\win10F.tmp - Deleted
C:\WINDOWS\Temp\win11.tmp - Deleted
C:\WINDOWS\Temp\win110.tmp - Deleted
C:\WINDOWS\Temp\win111.tmp - Deleted
C:\WINDOWS\Temp\win112.tmp - Deleted
C:\WINDOWS\Temp\win113.tmp - Deleted
C:\WINDOWS\Temp\win114.tmp - Deleted
C:\WINDOWS\Temp\win115.tmp - Deleted
C:\WINDOWS\Temp\win116.tmp - Deleted
C:\WINDOWS\Temp\win117.tmp - Deleted
C:\WINDOWS\Temp\win118.tmp - Deleted
C:\WINDOWS\Temp\win119.tmp - Deleted
C:\WINDOWS\Temp\win11A.tmp - Deleted
C:\WINDOWS\Temp\win11B.tmp - Deleted
C:\WINDOWS\Temp\win11C.tmp - Deleted
C:\WINDOWS\Temp\win11D.tmp - Deleted
C:\WINDOWS\Temp\win11E.tmp - Deleted
C:\WINDOWS\Temp\win11F.tmp - Deleted
C:\WINDOWS\Temp\win12.tmp - Deleted
C:\WINDOWS\Temp\win120.tmp - Deleted
C:\WINDOWS\Temp\win121.tmp - Deleted
C:\WINDOWS\Temp\win122.tmp - Deleted
C:\WINDOWS\Temp\win123.tmp - Deleted
C:\WINDOWS\Temp\win124.tmp - Deleted
C:\WINDOWS\Temp\win125.tmp - Deleted
C:\WINDOWS\Temp\win126.tmp - Deleted
C:\WINDOWS\Temp\win127.tmp - Deleted
C:\WINDOWS\Temp\win128.tmp - Deleted
C:\WINDOWS\Temp\win129.tmp - Deleted
C:\WINDOWS\Temp\win12A.tmp - Deleted
C:\WINDOWS\Temp\win12B.tmp - Deleted
C:\WINDOWS\Temp\win12C.tmp - Deleted
C:\WINDOWS\Temp\win12D.tmp - Deleted
C:\WINDOWS\Temp\win12E.tmp - Deleted
C:\WINDOWS\Temp\win12F.tmp - Deleted
C:\WINDOWS\Temp\win13.tmp - Deleted
C:\WINDOWS\Temp\win130.tmp - Deleted
C:\WINDOWS\Temp\win131.tmp - Deleted
C:\WINDOWS\Temp\win132.tmp - Deleted
C:\WINDOWS\Temp\win133.tmp - Deleted
C:\WINDOWS\Temp\win134.tmp - Deleted
C:\WINDOWS\Temp\win135.tmp - Deleted
C:\WINDOWS\Temp\win136.tmp - Deleted
C:\WINDOWS\Temp\win137.tmp - Deleted
C:\WINDOWS\Temp\win138.tmp - Deleted
C:\WINDOWS\Temp\win139.tmp - Deleted
C:\WINDOWS\Temp\win13A.tmp - Deleted
C:\WINDOWS\Temp\win13B.tmp - Deleted
C:\WINDOWS\Temp\win13C.tmp - Deleted
C:\WINDOWS\Temp\win13D.tmp - Deleted
C:\WINDOWS\Temp\win13E.tmp - Deleted
C:\WINDOWS\Temp\win13F.tmp - Deleted
C:\WINDOWS\Temp\win14.tmp - Deleted
C:\WINDOWS\Temp\win140.tmp - Deleted
C:\WINDOWS\Temp\win141.tmp - Deleted
C:\WINDOWS\Temp\win142.tmp - Deleted
C:\WINDOWS\Temp\win143.tmp - Deleted
C:\WINDOWS\Temp\win144.tmp - Deleted
C:\WINDOWS\Temp\win145.tmp - Deleted
C:\WINDOWS\Temp\win146.tmp - Deleted
C:\WINDOWS\Temp\win147.tmp - Deleted
C:\WINDOWS\Temp\win148.tmp - Deleted
C:\WINDOWS\Temp\win149.tmp - Deleted
C:\WINDOWS\Temp\win14A.tmp - Deleted
C:\WINDOWS\Temp\win14B.tmp - Deleted
C:\WINDOWS\Temp\win14C.tmp - Deleted
C:\WINDOWS\Temp\win14D.tmp - Deleted
C:\WINDOWS\Temp\win14E.tmp - Deleted
C:\WINDOWS\Temp\win14F.tmp - Deleted
C:\WINDOWS\Temp\win15.tmp - Deleted
C:\WINDOWS\Temp\win150.tmp - Deleted
C:\WINDOWS\Temp\win151.tmp - Deleted
C:\WINDOWS\Temp\win152.tmp - Deleted
C:\WINDOWS\Temp\win153.tmp - Deleted
C:\WINDOWS\Temp\win154.tmp - Deleted
C:\WINDOWS\Temp\win155.tmp - Deleted
C:\WINDOWS\Temp\win156.tmp - Deleted
C:\WINDOWS\Temp\win157.tmp - Deleted
C:\WINDOWS\Temp\win158.tmp - Deleted
C:\WINDOWS\Temp\win159.tmp - Deleted
C:\WINDOWS\Temp\win15A.tmp - Deleted
C:\WINDOWS\Temp\win15B.tmp - Deleted
C:\WINDOWS\Temp\win15C.tmp - Deleted
C:\WINDOWS\Temp\win15D.tmp - Deleted
C:\WINDOWS\Temp\win15E.tmp - Deleted
C:\WINDOWS\Temp\win15F.tmp - Deleted
C:\WINDOWS\Temp\win16.tmp - Deleted
C:\WINDOWS\Temp\win160.tmp - Deleted
C:\WINDOWS\Temp\win161.tmp - Deleted
C:\WINDOWS\Temp\win162.tmp - Deleted
C:\WINDOWS\Temp\win163.tmp - Deleted
C:\WINDOWS\Temp\win164.tmp - Deleted
C:\WINDOWS\Temp\win165.tmp - Deleted
C:\WINDOWS\Temp\win166.tmp - Deleted
C:\WINDOWS\Temp\win167.tmp - Deleted
C:\WINDOWS\Temp\win168.tmp - Deleted
C:\WINDOWS\Temp\win169.tmp - Deleted
C:\WINDOWS\Temp\win16A.tmp - Deleted
C:\WINDOWS\Temp\win16B.tmp - Deleted
C:\WINDOWS\Temp\win16C.tmp - Deleted
C:\WINDOWS\Temp\win16D.tmp - Deleted
C:\WINDOWS\Temp\win16E.tmp - Deleted
C:\WINDOWS\Temp\win16F.tmp - Deleted
C:\WINDOWS\Temp\win17.tmp - Deleted
C:\WINDOWS\Temp\win170.tmp - Deleted
C:\WINDOWS\Temp\win171.tmp - Deleted
C:\WINDOWS\Temp\win172.tmp - Deleted
C:\WINDOWS\Temp\win173.tmp - Deleted
C:\WINDOWS\Temp\win174.tmp - Deleted
C:\WINDOWS\Temp\win175.tmp - Deleted
C:\WINDOWS\Temp\win176.tmp - Deleted
C:\WINDOWS\Temp\win177.tmp - Deleted
C:\WINDOWS\Temp\win178.tmp - Deleted
C:\WINDOWS\Temp\win179.tmp - Deleted
C:\WINDOWS\Temp\win17A.tmp - Deleted
C:\WINDOWS\Temp\win17B.tmp - Deleted
C:\WINDOWS\Temp\win17C.tmp - Deleted
C:\WINDOWS\Temp\win17D.tmp - Deleted
C:\WINDOWS\Temp\win17E.tmp - Deleted
C:\WINDOWS\Temp\win17F.tmp - Deleted
C:\WINDOWS\Temp\win18.tmp - Deleted
C:\WINDOWS\Temp\win180.tmp - Deleted
C:\WINDOWS\Temp\win181.tmp - Deleted
C:\WINDOWS\Temp\win182.tmp - Deleted
C:\WINDOWS\Temp\win183.tmp - Deleted
C:\WINDOWS\Temp\win184.tmp - Deleted
C:\WINDOWS\Temp\win185.tmp - Deleted
C:\WINDOWS\Temp\win186.tmp - Deleted
C:\WINDOWS\Temp\win187.tmp - Deleted
C:\WINDOWS\Temp\win188.tmp - Deleted
C:\WINDOWS\Temp\win189.tmp - Deleted
C:\WINDOWS\Temp\win18A.tmp - Deleted
C:\WINDOWS\Temp\win18B.tmp - Deleted
C:\WINDOWS\Temp\win18C.tmp - Deleted
C:\WINDOWS\Temp\win18D.tmp - Deleted
C:\WINDOWS\Temp\win18E.tmp - Deleted
C:\WINDOWS\Temp\win18F.tmp - Deleted
C:\WINDOWS\Temp\win19.tmp - Deleted
C:\WINDOWS\Temp\win190.tmp - Deleted
C:\WINDOWS\Temp\win191.tmp - Deleted
C:\WINDOWS\Temp\win192.tmp - Deleted
C:\WINDOWS\Temp\win193.tmp - Deleted
C:\WINDOWS\Temp\win194.tmp - Deleted
C:\WINDOWS\Temp\win195.tmp - Deleted
C:\WINDOWS\Temp\win196.tmp - Deleted
C:\WINDOWS\Temp\win197.tmp - Deleted
C:\WINDOWS\Temp\win198.tmp - Deleted
C:\WINDOWS\Temp\win199.tmp - Deleted
C:\WINDOWS\Temp\win19A.tmp - Deleted
C:\WINDOWS\Temp\win19B.tmp - Deleted
C:\WINDOWS\Temp\win19C.tmp - Deleted
C:\WINDOWS\Temp\win19D.tmp - Deleted
C:\WINDOWS\Temp\win19E.tmp - Deleted
C:\WINDOWS\Temp\win19F.tmp - Deleted
C:\WINDOWS\Temp\win1A.tmp - Deleted
C:\WINDOWS\Temp\win1A0.tmp - Deleted
C:\WINDOWS\Temp\win1A1.tmp - Deleted
C:\WINDOWS\Temp\win1A2.tmp - Deleted
C:\WINDOWS\Temp\win1A3.tmp - Deleted
C:\WINDOWS\Temp\win1A4.tmp - Deleted
C:\WINDOWS\Temp\win1A5.tmp - Deleted
C:\WINDOWS\Temp\win1A6.tmp - Deleted
C:\WINDOWS\Temp\win1A7.tmp - Deleted
C:\WINDOWS\Temp\win1A8.tmp - Deleted
C:\WINDOWS\Temp\win1A9.tmp - Deleted
C:\WINDOWS\Temp\win1AA.tmp - Deleted
C:\WINDOWS\Temp\win1AB.tmp - Deleted
C:\WINDOWS\Temp\win1AC.tmp - Deleted
C:\WINDOWS\Temp\win1AD.tmp - Deleted
C:\WINDOWS\Temp\win1AE.tmp - Deleted
C:\WINDOWS\Temp\win1AF.tmp - Deleted
C:\WINDOWS\Temp\win1B.tmp - Deleted
C:\WINDOWS\Temp\win1B0.tmp - Deleted
C:\WINDOWS\Temp\win1B1.tmp - Deleted
C:\WINDOWS\Temp\win1B2.tmp - Deleted
C:\WINDOWS\Temp\win1B3.tmp - Deleted
C:\WINDOWS\Temp\win1B4.tmp - Deleted
C:\WINDOWS\Temp\win1B5.tmp - Deleted
C:\WINDOWS\Temp\win1B6.tmp - Deleted
C:\WINDOWS\Temp\win1B7.tmp - Deleted
C:\WINDOWS\Temp\win1B8.tmp - Deleted
C:\WINDOWS\Temp\win1B9.tmp - Deleted
C:\WINDOWS\Temp\win1BA.tmp - Deleted
C:\WINDOWS\Temp\win1BB.tmp - Deleted
C:\WINDOWS\Temp\win1BC.tmp - Deleted
C:\WINDOWS\Temp\win1BD.tmp - Deleted
C:\WINDOWS\Temp\win1BE.tmp - Deleted
C:\WINDOWS\Temp\win1BF.tmp - Deleted
C:\WINDOWS\Temp\win1C.tmp - Deleted
C:\WINDOWS\Temp\win1C0.tmp - Deleted
C:\WINDOWS\Temp\win1C1.tmp - Deleted
C:\WINDOWS\Temp\win1C2.tmp - Deleted
C:\WINDOWS\Temp\win1C3.tmp - Deleted
C:\WINDOWS\Temp\win1C4.tmp - Deleted
C:\WINDOWS\Temp\win1C5.tmp - Deleted
C:\WINDOWS\Temp\win1C6.tmp - Deleted
C:\WINDOWS\Temp\win1C7.tmp - Deleted
C:\WINDOWS\Temp\win1C8.tmp - Deleted
C:\WINDOWS\Temp\win1C9.tmp - Deleted
C:\WINDOWS\Temp\win1CA.tmp - Deleted
C:\WINDOWS\Temp\win1CB.tmp - Deleted
C:\WINDOWS\Temp\win1CC.tmp - Deleted
C:\WINDOWS\Temp\win1CD.tmp - Deleted
C:\WINDOWS\Temp\win1CE.tmp - Deleted
C:\WINDOWS\Temp\win1CF.tmp - Deleted
C:\WINDOWS\Temp\win1D.tmp - Deleted
C:\WINDOWS\Temp\win1D0.tmp - Deleted
C:\WINDOWS\Temp\win1D1.tmp - Deleted
C:\WINDOWS\Temp\win1D2.tmp - Deleted
C:\WINDOWS\Temp\win1D3.tmp - Deleted
C:\WINDOWS\Temp\win1D4.tmp - Deleted
C:\WINDOWS\Temp\win1D5.tmp - Deleted
C:\WINDOWS\Temp\win1D6.tmp - Deleted
C:\WINDOWS\Temp\win1D7.tmp - Deleted
C:\WINDOWS\Temp\win1D8.tmp - Deleted
C:\WINDOWS\Temp\win1D9.tmp - Deleted
C:\WINDOWS\Temp\win1DA.tmp - Deleted
C:\WINDOWS\Temp\win1DB.tmp - Deleted
C:\WINDOWS\Temp\win1DC.tmp - Deleted
C:\WINDOWS\Temp\win1DD.tmp - Deleted
C:\WINDOWS\Temp\win1DE.tmp - Deleted
C:\WINDOWS\Temp\win1DF.tmp - Deleted
C:\WINDOWS\Temp\win1E.tmp - Deleted
C:\WINDOWS\Temp\win1E0.tmp - Deleted
C:\WINDOWS\Temp\win1E1.tmp - Deleted
C:\WINDOWS\Temp\win1E2.tmp - Deleted
C:\WINDOWS\Temp\win1E3.tmp - Deleted
C:\WINDOWS\Temp\win1E4.tmp - Deleted
C:\WINDOWS\Temp\win1E5.tmp - Deleted
C:\WINDOWS\Temp\win1E6.tmp - Deleted
C:\WINDOWS\Temp\win1E7.tmp - Deleted
C:\WINDOWS\Temp\win1E8.tmp - Deleted
C:\WINDOWS\Temp\win1E9.tmp - Deleted
C:\WINDOWS\Temp\win1EA.tmp - Deleted
C:\WINDOWS\Temp\win1EB.tmp - Deleted
C:\WINDOWS\Temp\win1EC.tmp - Deleted
C:\WINDOWS\Temp\win1ED.tmp - Deleted
C:\WINDOWS\Temp\win1EE.tmp - Deleted
C:\WINDOWS\Temp\win1EF.tmp - Deleted
C:\WINDOWS\Temp\win1F.tmp - Deleted
C:\WINDOWS\Temp\win1F0.tmp - Deleted
C:\WINDOWS\Temp\win1F1.tmp - Deleted
C:\WINDOWS\Temp\win1F2.tmp - Deleted
C:\WINDOWS\Temp\win1F3.tmp - Deleted
C:\WINDOWS\Temp\win1F4.tmp - Deleted
C:\WINDOWS\Temp\win1F5.tmp - Deleted
C:\WINDOWS\Temp\win1F6.tmp - Deleted
C:\WINDOWS\Temp\win1F7.tmp - Deleted
C:\WINDOWS\Temp\win1F8.tmp - Deleted
C:\WINDOWS\Temp\win1F9.tmp - Deleted
C:\WINDOWS\Temp\win1FA.tmp - Deleted
C:\WINDOWS\Temp\win1FB.tmp - Deleted
C:\WINDOWS\Temp\win1FC.tmp - Deleted
C:\WINDOWS\Temp\win1FD.tmp - Deleted
C:\WINDOWS\Temp\win1FE.tmp - Deleted
C:\WINDOWS\Temp\win1FF.tmp - Deleted
C:\WINDOWS\Temp\win2.tmp - Deleted
C:\WINDOWS\Temp\win20.tmp - Deleted
C:\WINDOWS\Temp\win200.tmp - Deleted
C:\WINDOWS\Temp\win201.tmp - Deleted
C:\WINDOWS\Temp\win202.tmp - Deleted
C:\WINDOWS\Temp\win203.tmp - Deleted
C:\WINDOWS\Temp\win204.tmp - Deleted
C:\WINDOWS\Temp\win205.tmp - Deleted
C:\WINDOWS\Temp\win206.tmp - Deleted
C:\WINDOWS\Temp\win207.tmp - Deleted
C:\WINDOWS\Temp\win208.tmp - Deleted
C:\WINDOWS\Temp\win209.tmp - Deleted
C:\WINDOWS\Temp\win20A.tmp - Deleted
C:\WINDOWS\Temp\win20B.tmp - Deleted
C:\WINDOWS\Temp\win20C.tmp - Deleted
C:\WINDOWS\Temp\win20D.tmp - Deleted
C:\WINDOWS\Temp\win20E.tmp - Deleted
C:\WINDOWS\Temp\win20F.tmp - Deleted
C:\WINDOWS\Temp\win21.tmp - Deleted
C:\WINDOWS\Temp\win210.tmp - Deleted
C:\WINDOWS\Temp\win211.tmp - Deleted
C:\WINDOWS\Temp\win212.tmp - Deleted
C:\WINDOWS\Temp\win213.tmp - Deleted
C:\WINDOWS\Temp\win214.tmp - Deleted
C:\WINDOWS\Temp\win215.tmp - Deleted
C:\WINDOWS\Temp\win216.tmp - Deleted
C:\WINDOWS\Temp\win217.tmp - Deleted
C:\WINDOWS\Temp\win218.tmp - Deleted
C:\WINDOWS\Temp\win219.tmp - Deleted
C:\WINDOWS\Temp\win21A.tmp - Deleted
C:\WINDOWS\Temp\win21B.tmp - Deleted
C:\WINDOWS\Temp\win21C.tmp - Deleted
C:\WINDOWS\Temp\win21D.tmp - Deleted
C:\WINDOWS\Temp\win21E.tmp - Deleted
C:\WINDOWS\Temp\win21F.tmp - Deleted
C:\WINDOWS\Temp\win22.tmp - Deleted
C:\WINDOWS\Temp\win220.tmp - Deleted
C:\WINDOWS\Temp\win221.tmp - Deleted
C:\WINDOWS\Temp\win222.tmp - Deleted
C:\WINDOWS\Temp\win223.tmp - Deleted
C:\WINDOWS\Temp\win224.tmp - Deleted
C:\WINDOWS\Temp\win225.tmp - Deleted
C:\WINDOWS\Temp\win226.tmp - Deleted
C:\WINDOWS\Temp\win227.tmp - Deleted
C:\WINDOWS\Temp\win228.tmp - Deleted
C:\WINDOWS\Temp\win229.tmp - Deleted
C:\WINDOWS\Temp\win22A.tmp - Deleted
C:\WINDOWS\Temp\win22B.tmp - Deleted
C:\WINDOWS\Temp\win22C.tmp - Deleted
C:\WINDOWS\Temp\win22D.tmp - Deleted
C:\WINDOWS\Temp\win22E.tmp - Deleted
C:\WINDOWS\Temp\win22F.tmp - Deleted
C:\WINDOWS\Temp\win23.tmp - Deleted
C:\WINDOWS\Temp\win230.tmp - Deleted
C:\WINDOWS\Temp\win231.tmp - Deleted
C:\WINDOWS\Temp\win232.tmp - Deleted
C:\WINDOWS\Temp\win233.tmp - Deleted
C:\WINDOWS\Temp\win234.tmp - Deleted
C:\WINDOWS\Temp\win235.tmp - Deleted
C:\WINDOWS\Temp\win236.tmp - Deleted
C:\WINDOWS\Temp\win237.tmp - Deleted
C:\WINDOWS\Temp\win238.tmp - Deleted
C:\WINDOWS\Temp\win239.tmp - Deleted
C:\WINDOWS\Temp\win23A.tmp - Deleted
C:\WINDOWS\Temp\win23B.tmp - Deleted
C:\WINDOWS\Temp\win23C.tmp - Deleted
C:\WINDOWS\Temp\win23D.tmp - Deleted
C:\WINDOWS\Temp\win23E.tmp - Deleted
C:\WINDOWS\Temp\win23F.tmp - Deleted
C:\WINDOWS\Temp\win24.tmp - Deleted
C:\WINDOWS\Temp\win240.tmp - Deleted
C:\WINDOWS\Temp\win241.tmp - Deleted
C:\WINDOWS\Temp\win242.tmp - Deleted
C:\WINDOWS\Temp\win243.tmp - Deleted
C:\WINDOWS\Temp\win244.tmp - Deleted
C:\WINDOWS\Temp\win245.tmp - Deleted
C:\WINDOWS\Temp\win246.tmp - Deleted
C:\WINDOWS\Temp\win247.tmp - Deleted
C:\WINDOWS\Temp\win248.tmp - Deleted
C:\WINDOWS\Temp\win249.tmp - Deleted
C:\WINDOWS\Temp\win24A.tmp - Deleted
C:\WINDOWS\Temp\win24B.tmp - Deleted
C:\WINDOWS\Temp\win24C.tmp - Deleted
C:\WINDOWS\Temp\win24D.tmp - Deleted
C:\WINDOWS\Temp\win24E.tmp - Deleted
C:\WINDOWS\Temp\win24F.tmp - Deleted
C:\WINDOWS\Temp\win25.tmp - Deleted
C:\WINDOWS\Temp\win250.tmp - Deleted
C:\WINDOWS\Temp\win251.tmp - Deleted
C:\WINDOWS\Temp\win252.tmp - Deleted
C:\WINDOWS\Temp\win253.tmp - Deleted
C:\WINDOWS\Temp\win254.tmp - Deleted
C:\WINDOWS\Temp\win255.tmp - Deleted
C:\WINDOWS\Temp\win256.tmp - Deleted
C:\WINDOWS\Temp\win257.tmp - Deleted
C:\WINDOWS\Temp\win258.tmp - Deleted
C:\WINDOWS\Temp\win259.tmp - Deleted
C:\WINDOWS\Temp\win25A.tmp - Deleted
C:\WINDOWS\Temp\win25B.tmp - Deleted
C:\WINDOWS\Temp\win25C.tmp - Deleted
C:\WINDOWS\Temp\win25D.tmp - Deleted
C:\WINDOWS\Temp\win25E.tmp - Deleted
C:\WINDOWS\Temp\win25F.tmp - Deleted
C:\WINDOWS\Temp\win26.tmp - Deleted
C:\WINDOWS\Temp\win260.tmp - Deleted
C:\WINDOWS\Temp\win261.tmp - Deleted
C:\WINDOWS\Temp\win262.tmp - Deleted
C:\WINDOWS\Temp\win263.tmp - Deleted
C:\WINDOWS\Temp\win264.tmp - Deleted
C:\WINDOWS\Temp\win265.tmp - Deleted
C:\WINDOWS\Temp\win266.tmp - Deleted
C:\WINDOWS\Temp\win267.tmp - Deleted
C:\WINDOWS\Temp\win268.tmp - Deleted
C:\WINDOWS\Temp\win269.tmp - Deleted
C:\WINDOWS\Temp\win26A.tmp - Deleted
C:\WINDOWS\Temp\win26B.tmp - Deleted
C:\WINDOWS\Temp\win26C.tmp - Deleted
C:\WINDOWS\Temp\win26D.tmp - Deleted
C:\WINDOWS\Temp\win26E.tmp - Deleted
C:\WINDOWS\Temp\win26F.tmp - Deleted
C:\WINDOWS\Temp\win27.tmp - Deleted
C:\WINDOWS\Temp\win270.tmp - Deleted
C:\WINDOWS\Temp\win271.tmp - Deleted
C:\WINDOWS\Temp\win272.tmp - Deleted
C:\WINDOWS\Temp\win273.tmp - Deleted
C:\WINDOWS\Temp\win274.tmp - Deleted
C:\WINDOWS\Temp\win275.tmp - Deleted
C:\WINDOWS\Temp\win276.tmp - Deleted
C:\WINDOWS\Temp\win277.tmp - Deleted
C:\WINDOWS\Temp\win278.tmp - Deleted
C:\WINDOWS\Temp\win279.tmp - Deleted
C:\WINDOWS\Temp\win27A.tmp - Deleted
C:\WINDOWS\Temp\win27B.tmp - Deleted
C:\WINDOWS\Temp\win27C.tmp - Deleted
C:\WINDOWS\Temp\win27D.tmp - Deleted
C:\WINDOWS\Temp\win27E.tmp - Deleted
C:\WINDOWS\Temp\win27F.tmp - Deleted
C:\WINDOWS\Temp\win28.tmp - Deleted
C:\WINDOWS\Temp\win280.tmp - Deleted
C:\WINDOWS\Temp\win281.tmp - Deleted
C:\WINDOWS\Temp\win282.tmp - Deleted
C:\WINDOWS\Temp\win283.tmp - Deleted
C:\WINDOWS\Temp\win284.tmp - Deleted
C:\WINDOWS\Temp\win285.tmp - Deleted
C:\WINDOWS\Temp\win286.tmp - Deleted
C:\WINDOWS\Temp\win287.tmp - Deleted
C:\WINDOWS\Temp\win288.tmp - Deleted
C:\WINDOWS\Temp\win289.tmp - Deleted
C:\WINDOWS\Temp\win28A.tmp - Deleted
C:\WINDOWS\Temp\win28B.tmp - Deleted
C:\WINDOWS\Temp\win28C.tmp - Deleted
C:\WINDOWS\Temp\win28D.tmp - Deleted
C:\WINDOWS\Temp\win28E.tmp - Deleted
C:\WINDOWS\Temp\win28F.tmp - Deleted
C:\WINDOWS\Temp\win29.tmp - Deleted
C:\WINDOWS\Temp\win290.tmp - Deleted
C:\WINDOWS\Temp\win291.tmp - Deleted
C:\WINDOWS\Temp\win292.tmp - Deleted
C:\WINDOWS\Temp\win293.tmp - Deleted
C:\WINDOWS\Temp\win294.tmp - Deleted
C:\WINDOWS\Temp\win295.tmp - Deleted
C:\WINDOWS\Temp\win296.tmp - Deleted
C:\WINDOWS\Temp\win297.tmp - Deleted
C:\WINDOWS\Temp\win298.tmp - Deleted
C:\WINDOWS\Temp\win299.tmp - Deleted
C:\WINDOWS\Temp\win29A.tmp - Deleted
C:\WINDOWS\Temp\win29B.tmp - Deleted
C:\WINDOWS\Temp\win29C.tmp - Deleted
C:\WINDOWS\Temp\win29D.tmp - Deleted
C:\WINDOWS\Temp\win29E.tmp - Deleted
C:\WINDOWS\Temp\win29F.tmp - Deleted
C:\WINDOWS\Temp\win2A.tmp - Deleted
C:\WINDOWS\Temp\win2A0.tmp - Deleted
C:\WINDOWS\Temp\win2A1.tmp - Deleted
C:\WINDOWS\Temp\win2A2.tmp - Deleted
C:\WINDOWS\Temp\win2A3.tmp - Deleted
C:\WINDOWS\Temp\win2A4.tmp - Deleted
C:\WINDOWS\Temp\win2A5.tmp - Deleted
C:\WINDOWS\Temp\win2A6.tmp - Deleted
C:\WINDOWS\Temp\win2A7.tmp - Deleted
C:\WINDOWS\Temp\win2A8.tmp - Deleted
C:\WINDOWS\Temp\win2A9.tmp - Deleted
C:\WINDOWS\Temp\win2AA.tmp - Deleted
C:\WINDOWS\Temp\win2AB.tmp - Deleted
C:\WINDOWS\Temp\win2AC.tmp - Deleted
C:\WINDOWS\Temp\win2AD.tmp - Deleted
C:\WINDOWS\Temp\win2AE.tmp - Deleted
C:\WINDOWS\Temp\win2AF.tmp - Deleted
C:\WINDOWS\Temp\win2B.tmp - Deleted
C:\WINDOWS\Temp\win2B0.tmp - Deleted
C:\WINDOWS\Temp\win2B1.tmp - Deleted
C:\WINDOWS\Temp\win2B2.tmp - Deleted
C:\WINDOWS\Temp\win2B3.tmp - Deleted
C:\WINDOWS\Temp\win2B4.tmp - Deleted
C:\WINDOWS\Temp\win2B5.tmp - Deleted
C:\WINDOWS\Temp\win2B6.tmp - Deleted
C:\WINDOWS\Temp\win2B7.tmp - Deleted
C:\WINDOWS\Temp\win2B8.tmp - Deleted
C:\WINDOWS\Temp\win2B9.tmp - Deleted
C:\WINDOWS\Temp\win2BA.tmp - Deleted
C:\WINDOWS\Temp\win2BB.tmp - Deleted
C:\WINDOWS\Temp\win2BC.tmp - Deleted
C:\WINDOWS\Temp\win2BD.tmp - Deleted
C:\WINDOWS\Temp\win2BE.tmp - Deleted
C:\WINDOWS\Temp\win2BF.tmp - Deleted
C:\WINDOWS\Temp\win2C.tmp - Deleted
C:\WINDOWS\Temp\win2C0.tmp - Deleted
C:\WINDOWS\Temp\win2C1.tmp - Deleted
C:\WINDOWS\Temp\win2C2.tmp - Deleted
C:\WINDOWS\Temp\win2C3.tmp - Deleted
C:\WINDOWS\Temp\win2C4.tmp - Deleted
C:\WINDOWS\Temp\win2C5.tmp - Deleted
C:\WINDOWS\Temp\win2C6.tmp - Deleted
C:\WINDOWS\Temp\win2C7.tmp - Deleted
C:\WINDOWS\Temp\win2C8.tmp - Deleted
C:\WINDOWS\Temp\win2C9.tmp - Deleted
C:\WINDOWS\Temp\win2CA.tmp - Deleted
C:\WINDOWS\Temp\win2CB.tmp - Deleted
C:\WINDOWS\Temp\win2CC.tmp - Deleted
C:\WINDOWS\Temp\win2CD.tmp - Deleted
C:\WINDOWS\Temp\win2CE.tmp - Deleted
C:\WINDOWS\Temp\win2CF.tmp - Deleted
C:\WINDOWS\Temp\win2D.tmp - Deleted
C:\WINDOWS\Temp\win2D0.tmp - Deleted
C:\WINDOWS\Temp\win2D1.tmp - Deleted
C:\WINDOWS\Temp\win2D2.tmp - Deleted
C:\WINDOWS\Temp\win2D3.tmp - Deleted
C:\WINDOWS\Temp\win2D4.tmp - Deleted
C:\WINDOWS\Temp\win2D5.tmp - Deleted
C:\WINDOWS\Temp\win2D6.tmp - Deleted
C:\WINDOWS\Temp\win2D7.tmp - Deleted
C:\WINDOWS\Temp\win2D8.tmp - Deleted
C:\WINDOWS\Temp\win2D9.tmp - Deleted
C:\WINDOWS\Temp\win2DA.tmp - Deleted
C:\WINDOWS\Temp\win2DB.tmp - Deleted
C:\WINDOWS\Temp\win2DC.tmp - Deleted
C:\WINDOWS\Temp\win2DD.tmp - Deleted
C:\WINDOWS\Temp\win2DE.tmp - Deleted
C:\WINDOWS\Temp\win2DF.tmp - Deleted
C:\WINDOWS\Temp\win2E.tmp - Deleted
C:\WINDOWS\Temp\win2E0.tmp - Deleted
C:\WINDOWS\Temp\win2E1.tmp - Deleted
C:\WINDOWS\Temp\win2E2.tmp - Deleted
C:\WINDOWS\Temp\win2E3.tmp - Deleted
C:\WINDOWS\Temp\win2E4.tmp - Deleted
C:\WINDOWS\Temp\win2E5.tmp - Deleted
C:\WINDOWS\Temp\win2E6.tmp - Deleted
C:\WINDOWS\Temp\win2E7.tmp - Deleted
C:\WINDOWS\Temp\win2E8.tmp - Deleted
C:\WINDOWS\Temp\win2E9.tmp - Deleted
C:\WINDOWS\Temp\win2EA.tmp - Deleted
C:\WINDOWS\Temp\win2EB.tmp - Deleted
C:\WINDOWS\Temp\win2EC.tmp - Deleted
C:\WINDOWS\Temp\win2ED.tmp - Deleted
C:\WINDOWS\Temp\win2EE.tmp - Deleted
C:\WINDOWS\Temp\win2EF.tmp - Deleted
C:\WINDOWS\Temp\win2F.tmp - Deleted
C:\WINDOWS\Temp\win2F0.tmp - Deleted
C:\WINDOWS\Temp\win2F1.tmp - Deleted
C:\WINDOWS\Temp\win2F2.tmp - Deleted
C:\WINDOWS\Temp\win2F3.tmp - Deleted
C:\WINDOWS\Temp\win2F4.tmp - Deleted
C:\WINDOWS\Temp\win2F5.tmp - Deleted
C:\WINDOWS\Temp\win2F6.tmp - Deleted
C:\WINDOWS\Temp\win2F7.tmp - Deleted
C:\WINDOWS\Temp\win2F8.tmp - Deleted
C:\WINDOWS\Temp\win2F9.tmp - Deleted
C:\WINDOWS\Temp\win2FA.tmp - Deleted
C:\WINDOWS\Temp\win2FB.tmp - Deleted
C:\WINDOWS\Temp\win2FC.tmp - Deleted
C:\WINDOWS\Temp\win2FD.tmp - Deleted
C:\WINDOWS\Temp\win2FE.tmp - Deleted
C:\WINDOWS\Temp\win2FF.tmp - Deleted
C:\WINDOWS\Temp\win3.tmp - Deleted
C:\WINDOWS\Temp\win30.tmp - Deleted
C:\WINDOWS\Temp\win300.tmp - Deleted
C:\WINDOWS\Temp\win301.tmp - Deleted
C:\WINDOWS\Temp\win302.tmp - Deleted
C:\WINDOWS\Temp\win303.tmp - Deleted
C:\WINDOWS\Temp\win304.tmp - Deleted
C:\WINDOWS\Temp\win305.tmp - Deleted
C:\WINDOWS\Temp\win306.tmp - Deleted
C:\WINDOWS\Temp\win307.tmp - Deleted
C:\WINDOWS\Temp\win308.tmp - Deleted
C:\WINDOWS\Temp\win309.tmp - Deleted
C:\WINDOWS\Temp\win30A.tmp - Deleted
C:\WINDOWS\Temp\win30B.tmp - Deleted
C:\WINDOWS\Temp\win30C.tmp - Deleted
C:\WINDOWS\Temp\win30D.tmp - Deleted
C:\WINDOWS\Temp\win30E.tmp - Deleted
C:\WINDOWS\Temp\win30F.tmp - Deleted
C:\WINDOWS\Temp\win31.tmp - Deleted
C:\WINDOWS\Temp\win310.tmp - Deleted
C:\WINDOWS\Temp\win311.tmp - Deleted
C:\WINDOWS\Temp\win312.tmp - Deleted
C:\WINDOWS\Temp\win313.tmp - Deleted
C:\WINDOWS\Temp\win314.tmp - Deleted
C:\WINDOWS\Temp\win315.tmp - Deleted
C:\WINDOWS\Temp\win316.tmp - Deleted
C:\WINDOWS\Temp\win317.tmp - Deleted
C:\WINDOWS\Temp\win318.tmp - Deleted
C:\WINDOWS\Temp\win319.tmp - Deleted
C:\WINDOWS\Temp\win31A.tmp - Deleted
C:\WINDOWS\Temp\win31B.tmp - Deleted
C:\WINDOWS\Temp\win31C.tmp - Deleted
C:\WINDOWS\Temp\win31D.tmp - Deleted
C:\WINDOWS\Temp\win31E.tmp - Deleted
C:\WINDOWS\Temp\win31F.tmp - Deleted
C:\WINDOWS\Temp\win32.tmp - Deleted
C:\WINDOWS\Temp\win320.tmp - Deleted
C:\WINDOWS\Temp\win321.tmp - Deleted
C:\WINDOWS\Temp\win322.tmp - Deleted
C:\WINDOWS\Temp\win323.tmp - Deleted
C:\WINDOWS\Temp\win324.tmp - Deleted
C:\WINDOWS\Temp\win325.tmp - Deleted
C:\WINDOWS\Temp\win326.tmp - Deleted
C:\WINDOWS\Temp\win327.tmp - Deleted
C:\WINDOWS\Temp\win328.tmp - Deleted
C:\WINDOWS\Temp\win329.tmp - Deleted
C:\WINDOWS\Temp\win32A.tmp - Deleted
C:\WINDOWS\Temp\win32B.tmp - Deleted
C:\WINDOWS\Temp\win32C.tmp - Deleted
C:\WINDOWS\Temp\win32D.tmp - Deleted
C:\WINDOWS\Temp\win32E.tmp - Deleted
C:\WINDOWS\Temp\win32F.tmp - Deleted
C:\WINDOWS\Temp\win33.tmp - Deleted
C:\WINDOWS\Temp\win330.tmp - Deleted
C:\WINDOWS\Temp\win331.tmp - Deleted
C:\WINDOWS\Temp\win332.tmp - Deleted
C:\WINDOWS\Temp\win333.tmp - Deleted
C:\WINDOWS\Temp\win334.tmp - Deleted
C:\WINDOWS\Temp\win335.tmp - Deleted
C:\WINDOWS\Temp\win336.tmp - Deleted
C:\WINDOWS\Temp\win337.tmp - Deleted
C:\WINDOWS\Temp\win338.tmp - Deleted
C:\WINDOWS\Temp\win339.tmp - Deleted
C:\WINDOWS\Temp\win33A.tmp - Deleted
C:\WINDOWS\Temp\win33B.tmp - Deleted
C:\WINDOWS\Temp\win33C.tmp - Deleted
C:\WINDOWS\Temp\win33D.tmp - Deleted
C:\WINDOWS\Temp\win33E.tmp - Deleted
C:\WINDOWS\Temp\win33F.tmp - Deleted
C:\WINDOWS\Temp\win34.tmp - Deleted
C:\WINDOWS\Temp\win340.tmp - Deleted
C:\WINDOWS\Temp\win341.tmp - Deleted
C:\WINDOWS\Temp\win342.tmp - Deleted
C:\WINDOWS\Temp\win343.tmp - Deleted
C:\WINDOWS\Temp\win344.tmp - Deleted
C:\WINDOWS\Temp\win345.tmp - Deleted
C:\WINDOWS\Temp\win346.tmp - Deleted
C:\WINDOWS\Temp\win347.tmp - Deleted
C:\WINDOWS\Temp\win348.tmp - Deleted
C:\WINDOWS\Temp\win349.tmp - Deleted
C:\WINDOWS\Temp\win34A.tmp - Deleted
C:\WINDOWS\Temp\win34B.tmp - Deleted
C:\WINDOWS\Temp\win34C.tmp - Deleted
C:\WINDOWS\Temp\win34D.tmp - Deleted
C:\WINDOWS\Temp\win34E.tmp - Deleted
C:\WINDOWS\Temp\win34F.tmp - Deleted
C:\WINDOWS\Temp\win35.tmp - Deleted
C:\WINDOWS\Temp\win350.tmp - Deleted
C:\WINDOWS\Temp\win351.tmp - Deleted
C:\WINDOWS\Temp\win352.tmp - Deleted
C:\WINDOWS\Temp\win353.tmp - Deleted
C:\WINDOWS\Temp\win354.tmp - Deleted
C:\WINDOWS\Temp\win355.tmp - Deleted
C:\WINDOWS\Temp\win356.tmp - Deleted
C:\WINDOWS\Temp\win357.tmp - Deleted
C:\WINDOWS\Temp\win358.tmp - Deleted
C:\WINDOWS\Temp\win359.tmp - Deleted
C:\WINDOWS\Temp\win35A.tmp - Deleted
C:\WINDOWS\Temp\win35B.tmp - Deleted
C:\WINDOWS\Temp\win35C.tmp - Deleted
C:\WINDOWS\Temp\win35D.tmp - Deleted
C:\WINDOWS\Temp\win35E.tmp - Deleted
C:\WINDOWS\Temp\win35F.tmp - Deleted
C:\WINDOWS\Temp\win36.tmp - Deleted
C:\WINDOWS\Temp\win360.tmp - Deleted
C:\WINDOWS\Temp\win361.tmp - Deleted
C:\WINDOWS\Temp\win362.tmp - Deleted
C:\WINDOWS\Temp\win363.tmp - Deleted
C:\WINDOWS\Temp\win364.tmp - Deleted
C:\WINDOWS\Temp\win365.tmp - Deleted
C:\WINDOWS\Temp\win366.tmp - Deleted
C:\WINDOWS\Temp\win367.tmp - Deleted
C:\WINDOWS\Temp\win368.tmp - Deleted
C:\WINDOWS\Temp\win369.tmp - Deleted
C:\WINDOWS\Temp\win36A.tmp - Deleted
C:\WINDOWS\Temp\win36B.tmp - Deleted
C:\WINDOWS\Temp\win36C.tmp - Deleted
C:\WINDOWS\Temp\win36D.tmp - Deleted
C:\WINDOWS\Temp\win36E.tmp - Deleted
C:\WINDOWS\Temp\win36F.tmp - Deleted
C:\WINDOWS\Temp\win37.tmp - Deleted
C:\WINDOWS\Temp\win370.tmp - Deleted
C:\WINDOWS\Temp\win371.tmp - Deleted
C:\WINDOWS\Temp\win372.tmp - Deleted
C:\WINDOWS\Temp\win373.tmp - Deleted
C:\WINDOWS\Temp\win374.tmp - Deleted
C:\WINDOWS\Temp\win375.tmp - Deleted
C:\WINDOWS\Temp\win376.tmp - Deleted
C:\WINDOWS\Temp\win377.tmp - Deleted
C:\WINDOWS\Temp\win378.tmp - Deleted
C:\WINDOWS\Temp\win379.tmp - Deleted
C:\WINDOWS\Temp\win37A.tmp - Deleted
C:\WINDOWS\Temp\win37B.tmp - Deleted
C:\WINDOWS\Temp\win37C.tmp - Deleted
C:\WINDOWS\Temp\win37D.tmp - Deleted
C:\WINDOWS\Temp\win37E.tmp - Deleted
C:\WINDOWS\Temp\win37F.tmp - Deleted
C:\WINDOWS\Temp\win38.tmp - Deleted
C:\WINDOWS\Temp\win380.tmp - Deleted
C:\WINDOWS\Temp\win381.tmp - Deleted
C:\WINDOWS\Temp\win382.tmp - Deleted
C:\WINDOWS\Temp\win383.tmp - Deleted
C:\WINDOWS\Temp\win384.tmp - Deleted
C:\WINDOWS\Temp\win385.tmp - Deleted
C:\WINDOWS\Temp\win386.tmp - Deleted
C:\WINDOWS\Temp\win387.tmp - Deleted
C:\WINDOWS\Temp\win388.tmp - Deleted
C:\WINDOWS\Temp\win389.tmp - Deleted
C:\WINDOWS\Temp\win38A.tmp - Deleted
C:\WINDOWS\Temp\win38B.tmp - Deleted
C:\WINDOWS\Temp\win38C.tmp - Deleted
C:\WINDOWS\Temp\win38D.tmp - Deleted
C:\WINDOWS\Temp\win38E.tmp - Deleted
C:\WINDOWS\Temp\win38F.tmp - Deleted
C:\WINDOWS\Temp\win39.tmp - Deleted
C:\WINDOWS\Temp\win390.tmp - Deleted
C:\WINDOWS\Temp\win391.tmp - Deleted
C:\WINDOWS\Temp\win392.tmp - Deleted
C:\WINDOWS\Temp\win393.tmp - Deleted
C:\WINDOWS\Temp\win394.tmp - Deleted
C:\WINDOWS\Temp\win395.tmp - Deleted
C:\WINDOWS\Temp\win396.tmp - Deleted
C:\WINDOWS\Temp\win397.tmp - Deleted
C:\WINDOWS\Temp\win398.tmp - Deleted
C:\WINDOWS\Temp\win399.tmp - Deleted
C:\WINDOWS\Temp\win39A.tmp - Deleted
C:\WINDOWS\Temp\win39B.tmp - Deleted
C:\WINDOWS\Temp\win39C.tmp - Deleted
C:\WINDOWS\Temp\win39D.tmp - Deleted
C:\WINDOWS\Temp\win39E.tmp - Deleted
C:\WINDOWS\Temp\win39F.tmp - Deleted
C:\WINDOWS\Temp\win3A.tmp - Deleted
C:\WINDOWS\Temp\win3A0.tmp - Deleted
C:\WINDOWS\Temp\win3A1.tmp - Deleted
C:\WINDOWS\Temp\win3A2.tmp - Deleted
C:\WINDOWS\Temp\win3A3.tmp - Deleted
C:\WINDOWS\Temp\win3A4.tmp - Deleted
C:\WINDOWS\Temp\win3A5.tmp - Deleted
C:\WINDOWS\Temp\win3A6.tmp - Deleted
C:\WINDOWS\Temp\win3A7.tmp - Deleted
C:\WINDOWS\Temp\win3A8.tmp - Deleted
C:\WINDOWS\Temp\win3A9.tmp - Deleted
C:\WINDOWS\Temp\win3AA.tmp - Deleted
C:\WINDOWS\Temp\win3AB.tmp - Deleted
C:\WINDOWS\Temp\win3AC.tmp - Deleted
C:\WINDOWS\Temp\win3AD.tmp - Deleted
C:\WINDOWS\Temp\win3AE.tmp - Deleted
C:\WINDOWS\Temp\win3AF.tmp - Deleted
C:\WINDOWS\Temp\win3B.tmp - Deleted
C:\WINDOWS\Temp\win3B0.tmp - Deleted
C:\WINDOWS\Temp\win3B1.tmp - Deleted
C:\WINDOWS\Temp\win3B2.tmp - Deleted
C:\WINDOWS\Temp\win3B3.tmp - Deleted
C:\WINDOWS\Temp\win3B4.tmp - Deleted
C:\WINDOWS\Temp\win3B5.tmp - Deleted
C:\WINDOWS\Temp\win3B6.tmp - Deleted
C:\WINDOWS\Temp\win3B7.tmp - Deleted
C:\WINDOWS\Temp\win3B8.tmp - Deleted
C:\WINDOWS\Temp\win3B9.tmp - Deleted
C:\WINDOWS\Temp\win3BA.tmp - Deleted
C:\WINDOWS\Temp\win3BB.tmp - Deleted
C:\WINDOWS\Temp\win3BC.tmp - Deleted
C:\WINDOWS\Temp\win3BD.tmp - Deleted
C:\WINDOWS\Temp\win3BE.tmp - Deleted
C:\WINDOWS\Temp\win3BF.tmp - Deleted
C:\WINDOWS\Temp\win3C.tmp - Deleted
C:\WINDOWS\Temp\win3C0.tmp - Deleted
C:\WINDOWS\Temp\win3C1.tmp - Deleted
C:\WINDOWS\Temp\win3C2.tmp - Deleted
C:\WINDOWS\Temp\win3C3.tmp - Deleted
C:\WINDOWS\Temp\win3C4.tmp - Deleted
C:\WINDOWS\Temp\win3C5.tmp - Deleted
C:\WINDOWS\Temp\win3C6.tmp - Deleted
C:\WINDOWS\Temp\win3C7.tmp - Deleted
C:\WINDOWS\Temp\win3C8.tmp - Deleted
C:\WINDOWS\Temp\win3C9.tmp - Deleted
C:\WINDOWS\Temp\win3CA.tmp - Deleted
C:\WINDOWS\Temp\win3CB.tmp - Deleted
C:\WINDOWS\Temp\win3CC.tmp - Deleted
C:\WINDOWS\Temp\win3CD.tmp - Deleted
C:\WINDOWS\Temp\win3CE.tmp - Deleted
C:\WINDOWS\Temp\win3CF.tmp - Deleted
C:\WINDOWS\Temp\win3D.tmp - Deleted
C:\WINDOWS\Temp\win3D0.tmp - Deleted
C:\WINDOWS\Temp\win3D1.tmp - Deleted
C:\WINDOWS\Temp\win3D2.tmp - Deleted
C:\WINDOWS\Temp\win3D3.tmp - Deleted
C:\WINDOWS\Temp\win3D4.tmp - Deleted
C:\WINDOWS\Temp\win3D5.tmp - Deleted
C:\WINDOWS\Temp\win3D6.tmp - Deleted
C:\WINDOWS\Temp\win3D7.tmp - Deleted
C:\WINDOWS\Temp\win3D8.tmp - Deleted
C:\WINDOWS\Temp\win3D9.tmp - Deleted
C:\WINDOWS\Temp\win3DA.tmp - Deleted
C:\WINDOWS\Temp\win3DB.tmp - Deleted
C:\WINDOWS\Temp\win3DC.tmp - Deleted
C:\WINDOWS\Temp\win3DD.tmp - Deleted
C:\WINDOWS\Temp\win3DE.tmp - Deleted
C:\WINDOWS\Temp\win3DF.tmp - Deleted
C:\WINDOWS\Temp\win3E.tmp - Deleted
C:\WINDOWS\Temp\win3E0.tmp - Deleted
C:\WINDOWS\Temp\win3E1.tmp - Deleted
C:\WINDOWS\Temp\win3E2.tmp - Deleted
C:\WINDOWS\Temp\win3E3.tmp - Deleted
C:\WINDOWS\Temp\win3E4.tmp - Deleted
C:\WINDOWS\Temp\win3E5.tmp - Deleted
C:\WINDOWS\Temp\win3E6.tmp - Deleted
C:\WINDOWS\Temp\win3E7.tmp - Deleted
C:\WINDOWS\Temp\win3E8.tmp - Deleted
C:\WINDOWS\Temp\win3E9.tmp - Deleted
C:\WINDOWS\Temp\win3EA.tmp - Deleted
C:\WINDOWS\Temp\win3EB.tmp - Deleted
C:\WINDOWS\Temp\win3EC.tmp - Deleted
C:\WINDOWS\Temp\win3ED.tmp - Deleted
C:\WINDOWS\Temp\win3EE.tmp - Deleted
C:\WINDOWS\Temp\win3EF.tmp - Deleted
C:\WINDOWS\Temp\win3F.tmp - Deleted
C:\WINDOWS\Temp\win3F0.tmp - Deleted
C:\WINDOWS\Temp\win3F1.tmp - Deleted
C:\WINDOWS\Temp\win3F2.tmp - Deleted
C:\WINDOWS\Temp\win3F3.tmp - Deleted
C:\WINDOWS\Temp\win3F4.tmp - Deleted
C:\WINDOWS\Temp\win3F5.tmp - Deleted
C:\WINDOWS\Temp\win3F6.tmp - Deleted
C:\WINDOWS\Temp\win3F7.tmp - Deleted
C:\WINDOWS\Temp\win3F8.tmp - Deleted
C:\WINDOWS\Temp\win3F9.tmp - Deleted
C:\WINDOWS\Temp\win3FA.tmp - Deleted
C:\WINDOWS\Temp\win3FB.tmp - Deleted
C:\WINDOWS\Temp\win3FC.tmp - Deleted
C:\WINDOWS\Temp\win3FD.tmp - Deleted
C:\WINDOWS\Temp\win3FE.tmp - Deleted
C:\WINDOWS\Temp\win3FF.tmp - Deleted
C:\WINDOWS\Temp\win4.tmp - Deleted
C:\WINDOWS\Temp\win40.tmp - Deleted
C:\WINDOWS\Temp\win400.tmp - Deleted
C:\WINDOWS\Temp\win401.tmp - Deleted
C:\WINDOWS\Temp\win402.tmp - Deleted
C:\WINDOWS\Temp\win403.tmp - Deleted
C:\WINDOWS\Temp\win404.tmp - Deleted
C:\WINDOWS\Temp\win405.tmp - Deleted
C:\WINDOWS\Temp\win406.tmp - Deleted
C:\WINDOWS\Temp\win407.tmp - Deleted
C:\WINDOWS\Temp\win408.tmp - Deleted
C:\WINDOWS\Temp\win409.tmp - Deleted
C:\WINDOWS\Temp\win40A.tmp - Deleted
C:\WINDOWS\Temp\win40B.tmp - Deleted
C:\WINDOWS\Temp\win40C.tmp - Deleted
C:\WINDOWS\Temp\win40D.tmp - Deleted
C:\WINDOWS\Temp\win40E.tmp - Deleted
C:\WINDOWS\Temp\win40F.tmp - Deleted
C:\WINDOWS\Temp\win41.tmp - Deleted
C:\WINDOWS\Temp\win410.tmp - Deleted
C:\WINDOWS\Temp\win411.tmp - Deleted
C:\WINDOWS\Temp\win412.tmp - Deleted
C:\WINDOWS\Temp\win413.tmp - Deleted
C:\WINDOWS\Temp\win414.tmp - Deleted
C:\WINDOWS\Temp\win415.tmp - Deleted
C:\WINDOWS\Temp\win416.tmp - Deleted
C:\WINDOWS\Temp\win417.tmp - Deleted
C:\WINDOWS\Temp\win418.tmp - Deleted
C:\WINDOWS\Temp\win419.tmp - Deleted
C:\WINDOWS\Temp\win41A.tmp - Deleted
C:\WINDOWS\Temp\win41B.tmp - Deleted
C:\WINDOWS\Temp\win41C.tmp - Deleted
C:\WINDOWS\Temp\win41D.tmp - Deleted
C:\WINDOWS\Temp\win41E.tmp - Deleted
C:\WINDOWS\Temp\win41F.tmp - Deleted
C:\WINDOWS\Temp\win42.tmp - Deleted
C:\WINDOWS\Temp\win420.tmp - Deleted
C:\WINDOWS\Temp\win421.tmp - Deleted
C:\WINDOWS\Temp\win422.tmp - Deleted
C:\WINDOWS\Temp\win423.tmp - Deleted
C:\WINDOWS\Temp\win424.tmp - Deleted
C:\WINDOWS\Temp\win425.tmp - Deleted
C:\WINDOWS\Temp\win426.tmp - Deleted
C:\WINDOWS\Temp\win427.tmp - Deleted
C:\WINDOWS\Temp\win428.tmp - Deleted
C:\WINDOWS\Temp\win429.tmp - Deleted
C:\WINDOWS\Temp\win42A.tmp - Deleted
C:\WINDOWS\Temp\win42B.tmp - Deleted
C:\WINDOWS\Temp\win42C.tmp - Deleted
C:\WINDOWS\Temp\win42D.tmp - Deleted
C:\WINDOWS\Temp\win42E.tmp - Deleted
C:\WINDOWS\Temp\win42F.tmp - Deleted
C:\WINDOWS\Temp\win43.tmp - Deleted
C:\WINDOWS\Temp\win430.tmp - Deleted
C:\WINDOWS\Temp\win431.tmp - Deleted
C:\WINDOWS\Temp\win432.tmp - Deleted
C:\WINDOWS\Temp\win433.tmp - Deleted
C:\WINDOWS\Temp\win434.tmp - Deleted
C:\WINDOWS\Temp\win435.tmp - Deleted
C:\WINDOWS\Temp\win436.tmp - Deleted
C:\WINDOWS\Temp\win437.tmp - Deleted
C:\WINDOWS\Temp\win438.tmp - Deleted
C:\WINDOWS\Temp\win439.tmp - Deleted
C:\WINDOWS\Temp\win43A.tmp - Deleted
C:\WINDOWS\Temp\win43B.tmp - Deleted
C:\WINDOWS\Temp\win43C.tmp - Deleted
C:\WINDOWS\Temp\win43D.tmp - Deleted
C:\WINDOWS\Temp\win43E.tmp - Deleted
C:\WINDOWS\Temp\win43F.tmp - Deleted
C:\WINDOWS\Temp\win44.tmp - Deleted
C:\WINDOWS\Temp\win440.tmp - Deleted
C:\WINDOWS\Temp\win441.tmp - Deleted
C:\WINDOWS\Temp\win442.tmp - Deleted
C:\WINDOWS\Temp\win443.tmp - Deleted
C:\WINDOWS\Temp\win444.tmp - Deleted
C:\WINDOWS\Temp\win445.tmp - Deleted
C:\WINDOWS\Temp\win446.tmp - Deleted
C:\WINDOWS\Temp\win447.tmp - Deleted
C:\WINDOWS\Temp\win448.tmp - Deleted
C:\WINDOWS\Temp\win449.tmp - Deleted
C:\WINDOWS\Temp\win44A.tmp - Deleted
C:\WINDOWS\Temp\win44B.tmp - Deleted
C:\WINDOWS\Temp\win44C.tmp - Deleted
C:\WINDOWS\Temp\win44D.tmp - Deleted
C:\WINDOWS\Temp\win44E.tmp - Deleted
C:\WINDOWS\Temp\win44F.tmp - Deleted
C:\WINDOWS\Temp\win45.tmp - Deleted
C:\WINDOWS\Temp\win450.tmp - Deleted
C:\WINDOWS\Temp\win451.tmp - Deleted
C:\WINDOWS\Temp\win452.tmp - Deleted
C:\WINDOWS\Temp\win453.tmp - Deleted
C:\WINDOWS\Temp\win454.tmp - Deleted
C:\WINDOWS\Temp\win455.tmp - Deleted
C:\WINDOWS\Temp\win456.tmp - Deleted
C:\WINDOWS\Temp\win457.tmp - Deleted
C:\WINDOWS\Temp\win458.tmp - Deleted
C:\WINDOWS\Temp\win459.tmp - Deleted
C:\WINDOWS\Temp\win45A.tmp - Deleted
C:\WINDOWS\Temp\win45B.tmp - Deleted
C:\WINDOWS\Temp\win45C.tmp - Deleted
C:\WINDOWS\Temp\win45D.tmp - Deleted
C:\WINDOWS\Temp\win45E.tmp - Deleted
C:\WINDOWS\Temp\win45F.tmp - Deleted
C:\WINDOWS\Temp\win46.tmp - Deleted
C:\WINDOWS\Temp\win460.tmp - Deleted
C:\WINDOWS\Temp\win461.tmp - Deleted
C:\WINDOWS\Temp\win462.tmp - Deleted
C:\WINDOWS\Temp\win463.tmp - Deleted
C:\WINDOWS\Temp\win464.tmp - Deleted
C:\WINDOWS\Temp\win465.tmp - Deleted
C:\WINDOWS\Temp\win466.tmp - Deleted
C:\WINDOWS\Temp\win467.tmp - Deleted
C:\WINDOWS\Temp\win468.tmp - Deleted
C:\WINDOWS\Temp\win469.tmp - Deleted
C:\WINDOWS\Temp\win46A.tmp - Deleted
C:\WINDOWS\Temp\win46B.tmp - Deleted
C:\WINDOWS\Temp\win46C.tmp - Deleted
C:\WINDOWS\Temp\win46D.tmp - Deleted
C:\WINDOWS\Temp\win46E.tmp - Deleted
C:\WINDOWS\Temp\win46F.tmp - Deleted
C:\WINDOWS\Temp\win47.tmp - Deleted
C:\WINDOWS\Temp\win470.tmp - Deleted
C:\WINDOWS\Temp\win471.tmp - Deleted
C:\WINDOWS\Temp\win472.tmp - Deleted
C:\WINDOWS\Temp\win473.tmp - Deleted
C:\WINDOWS\Temp\win474.tmp - Deleted
C:\WINDOWS\Temp\win475.tmp - Deleted
C:\WINDOWS\Temp\win476.tmp - Deleted
C:\WINDOWS\Temp\win477.tmp - Deleted
C:\WINDOWS\Temp\win478.tmp - Deleted
C:\WINDOWS\Temp\win479.tmp - Deleted
C:\WINDOWS\Temp\win47A.tmp - Deleted
C:\WINDOWS\Temp\win47B.tmp - Deleted
C:\WINDOWS\Temp\win47C.tmp - Deleted
C:\WINDOWS\Temp\win47D.tmp - Deleted
C:\WINDOWS\Temp\win47E.tmp - Deleted
C:\WINDOWS\Temp\win47F.tmp - Deleted
C:\WINDOWS\Temp\win48.tmp - Deleted
C:\WINDOWS\Temp\win480.tmp - Deleted
C:\WINDOWS\Temp\win481.tmp - Deleted
C:\WINDOWS\Temp\win482.tmp - Deleted
C:\WINDOWS\Temp\win483.tmp - Deleted
C:\WINDOWS\Temp\win484.tmp - Deleted
C:\WINDOWS\Temp\win485.tmp - Deleted
C:\WINDOWS\Temp\win486.tmp - Deleted
C:\WINDOWS\Temp\win487.tmp - Deleted
C:\WINDOWS\Temp\win488.tmp - Deleted
C:\WINDOWS\Temp\win489.tmp - Deleted
C:\WINDOWS\Temp\win48A.tmp - Deleted
C:\WINDOWS\Temp\win48B.tmp - Deleted
C:\WINDOWS\Temp\win48C.tmp - Deleted
C:\WINDOWS\Temp\win48D.tmp - Deleted
C:\WINDOWS\Temp\win48E.tmp - Deleted
C:\WINDOWS\Temp\win48F.tmp - Deleted
C:\WINDOWS\Temp\win49.tmp - Deleted
C:\WINDOWS\Temp\win490.tmp - Deleted
C:\WINDOWS\Temp\win491.tmp - Deleted
C:\WINDOWS\Temp\win492.tmp - Deleted
C:\WINDOWS\Temp\win493.tmp - Deleted
C:\WINDOWS\Temp\win494.tmp - Deleted
C:\WINDOWS\Temp\win495.tmp - Deleted
C:\WINDOWS\Temp\win496.tmp - Deleted
C:\WINDOWS\Temp\win497.tmp - Deleted
C:\WINDOWS\Temp\win498.tmp - Deleted
C:\WINDOWS\Temp\win499.tmp - Deleted
C:\WINDOWS\Temp\win49A.tmp - Deleted
C:\WINDOWS\Temp\win49B.tmp - Deleted
C:\WINDOWS\Temp\win49C.tmp - Deleted
C:\WINDOWS\Temp\win49D.tmp - Deleted
C:\WINDOWS\Temp\win49E.tmp - Deleted
C:\WINDOWS\Temp\win49F.tmp - Deleted
C:\WINDOWS\Temp\win4A.tmp - Deleted
C:\WINDOWS\Temp\win4A0.tmp - Deleted
C:\WINDOWS\Temp\win4A1.tmp - Deleted
C:\WINDOWS\Temp\win4A2.tmp - Deleted
C:\WINDOWS\Temp\win4A3.tmp - Deleted
C:\WINDOWS\Temp\win4A4.tmp - Deleted
C:\WINDOWS\Temp\win4A5.tmp - Deleted
C:\WINDOWS\Temp\win4A6.tmp - Deleted
C:\WINDOWS\Temp\win4A7.tmp - Deleted
C:\WINDOWS\Temp\win4A8.tmp - Deleted
C:\WINDOWS\Temp\win4A9.tmp - Deleted
C:\WINDOWS\Temp\win4AA.tmp - Deleted
C:\WINDOWS\Temp\win4AB.tmp - Deleted
C:\WINDOWS\Temp\win4AC.tmp - Deleted
C:\WINDOWS\Temp\win4AD.tmp - Deleted
C:\WINDOWS\Temp\win4AE.tmp - Deleted
C:\WINDOWS\Temp\win4AF.tmp - Deleted
C:\WINDOWS\Temp\win4B.tmp - Deleted
C:\WINDOWS\Temp\win4B0.tmp - Deleted
C:\WINDOWS\Temp\win4B1.tmp - Deleted
C:\WINDOWS\Temp\win4B2.tmp - Deleted
C:\WINDOWS\Temp\win4B3.tmp - Deleted
C:\WINDOWS\Temp\win4B4.tmp - Deleted
C:\WINDOWS\Temp\win4B5.tmp - Deleted
C:\WINDOWS\Temp\win4B6.tmp - Deleted
C:\WINDOWS\Temp\win4B7.tmp - Deleted
C:\WINDOWS\Temp\win4B8.tmp - Deleted
C:\WINDOWS\Temp\win4B9.tmp - Deleted
C:\WINDOWS\Temp\win4BA.tmp - Deleted
C:\WINDOWS\Temp\win4BB.tmp - Deleted
C:\WINDOWS\Temp\win4BC.tmp - Deleted
C:\WINDOWS\Temp\win4BD.tmp - Deleted
C:\WINDOWS\Temp\win4BE.tmp - Deleted
C:\WINDOWS\Temp\win4BF.tmp - Deleted
C:\WINDOWS\Temp\win4C.tmp - Deleted
C:\WINDOWS\Temp\win4C0.tmp - Deleted
C:\WINDOWS\Temp\win4C1.tmp - Deleted
C:\WINDOWS\Temp\win4C2.tmp - Deleted
C:\WINDOWS\Temp\win4C3.tmp - Deleted
C:\WINDOWS\Temp\win4C4.tmp - Deleted
C:\WINDOWS\Temp\win4C5.tmp - Deleted
C:\WINDOWS\Temp\win4C6.tmp - Deleted
C:\WINDOWS\Temp\win4C7.tmp - Deleted
C:\WINDOWS\Temp\win4C8.tmp - Deleted
C:\WINDOWS\Temp\win4C9.tmp - Deleted
C:\WINDOWS\Temp\win4CA.tmp - Deleted
C:\WINDOWS\Temp\win4CB.tmp - Deleted
C:\WINDOWS\Temp\win4CC.tmp - Deleted
C:\WINDOWS\Temp\win4CD.tmp - Deleted
C:\WINDOWS\Temp\win4CE.tmp - Deleted
C:\WINDOWS\Temp\win4CF.tmp - Deleted
C:\WINDOWS\Temp\win4D.tmp - Deleted
C:\WINDOWS\Temp\win4D0.tmp - Deleted
C:\WINDOWS\Temp\win4D1.tmp - Deleted
C:\WINDOWS\Temp\win4D2.tmp - Deleted
C:\WINDOWS\Temp\win4D3.tmp - Deleted
C:\WINDOWS\Temp\win4D4.tmp - Deleted
C:\WINDOWS\Temp\win4D5.tmp - Deleted
C:\WINDOWS\Temp\win4D6.tmp - Deleted
C:\WINDOWS\Temp\win4D7.tmp - Deleted
C:\WINDOWS\Temp\win4D8.tmp - Deleted
C:\WINDOWS\Temp\win4D9.tmp - Deleted
C:\WINDOWS\Temp\win4DA.tmp - Deleted
C:\WINDOWS\Temp\win4DB.tmp - Deleted
C:\WINDOWS\Temp\win4DC.tmp - Deleted
C:\WINDOWS\Temp\win4DD.tmp - Deleted
C:\WINDOWS\Temp\win4DE.tmp - Deleted
C:\WINDOWS\Temp\win4DF.tmp - Deleted
C:\WINDOWS\Temp\win4E.tmp - Deleted
C:\WINDOWS\Temp\win4E0.tmp - Deleted
C:\WINDOWS\Temp\win4E1.tmp - Deleted
C:\WINDOWS\Temp\win4E2.tmp - Deleted
C:\WINDOWS\Temp\win4E3.tmp - Deleted
C:\WINDOWS\Temp\win4E4.tmp - Deleted
C:\WINDOWS\Temp\win4E5.tmp - Deleted
C:\WINDOWS\Temp\win4E6.tmp - Deleted
C:\WINDOWS\Temp\win4E7.tmp - Deleted
C:\WINDOWS\Temp\win4E8.tmp - Deleted
C:\WINDOWS\Temp\win4E9.tmp - Deleted
C:\WINDOWS\Temp\win4EA.tmp - Deleted
C:\WINDOWS\Temp\win4EB.tmp - Deleted
C:\WINDOWS\Temp\win4EC.tmp - Deleted
C:\WINDOWS\Temp\win4ED.tmp - Deleted
C:\WINDOWS\Temp\win4EE.tmp - Deleted
C:\WINDOWS\Temp\win4EF.tmp - Deleted
C:\WINDOWS\Temp\win4F.tmp - Deleted
C:\WINDOWS\Temp\win4F0.tmp - Deleted
C:\WINDOWS\Temp\win4F1.tmp - Deleted
C:\WINDOWS\Temp\win4F2.tmp - Deleted
C:\WINDOWS\Temp\win4F3.tmp - Deleted
C:\WINDOWS\Temp\win4F4.tmp - Deleted
C:\WINDOWS\Temp\win4F5.tmp - Deleted
C:\WINDOWS\Temp\win4F6.tmp - Deleted
C:\WINDOWS\Temp\win4F7.tmp - Deleted
C:\WINDOWS\Temp\win4F8.tmp - Deleted
C:\WINDOWS\Temp\win4F9.tmp - Deleted
C:\WINDOWS\Temp\win4FA.tmp - Deleted
C:\WINDOWS\Temp\win4FB.tmp - Deleted
C:\WINDOWS\Temp\win4FC.tmp - Deleted
C:\WINDOWS\Temp\win4FD.tmp - Deleted
C:\WINDOWS\Temp\win4FE.tmp - Deleted
C:\WINDOWS\Temp\win4FF.tmp - Deleted
C:\WINDOWS\Temp\win5.tmp - Deleted
C:\WINDOWS\Temp\win50.tmp - Deleted
C:\WINDOWS\Temp\win500.tmp - Deleted
C:\WINDOWS\Temp\win501.tmp - Deleted
C:\WINDOWS\Temp\win502.tmp - Deleted
C:\WINDOWS\Temp\win503.tmp - Deleted
C:\WINDOWS\Temp\win504.tmp - Deleted
C:\WINDOWS\Temp\win505.tmp - Deleted
C:\WINDOWS\Temp\win506.tmp - Deleted
C:\WINDOWS\Temp\win507.tmp - Deleted
C:\WINDOWS\Temp\win508.tmp - Deleted
C:\WINDOWS\Temp\win509.tmp - Deleted
C:\WINDOWS\Temp\win50A.tmp - Deleted
C:\WINDOWS\Temp\win50B.tmp - Deleted
C:\WINDOWS\Temp\win50C.tmp - Deleted
C:\WINDOWS\Temp\win50D.tmp - Deleted
C:\WINDOWS\Temp\win50E.tmp - Deleted
C:\WINDOWS\Temp\win50F.tmp - Deleted
C:\WINDOWS\Temp\win51.tmp - Deleted
C:\WINDOWS\Temp\win510.tmp - Deleted
C:\WINDOWS\Temp\win511.tmp - Deleted
C:\WINDOWS\Temp\win512.tmp - Deleted
C:\WINDOWS\Temp\win513.tmp - Deleted
C:\WINDOWS\Temp\win514.tmp - Deleted
C:\WINDOWS\Temp\win515.tmp - Deleted
C:\WINDOWS\Temp\win516.tmp - Deleted
C:\WINDOWS\Temp\win517.tmp - Deleted
C:\WINDOWS\Temp\win518.tmp - Deleted
C:\WINDOWS\Temp\win519.tmp - Deleted
C:\WINDOWS\Temp\win51A.tmp - Deleted
C:\WINDOWS\Temp\win51B.tmp - Deleted
C:\WINDOWS\Temp\win51C.tmp - Deleted
C:\WINDOWS\Temp\win51D.tmp - Deleted
C:\WINDOWS\Temp\win51E.tmp - Deleted
C:\WINDOWS\Temp\win51F.tmp - Deleted
C:\WINDOWS\Temp\win52.tmp - Deleted
C:\WINDOWS\Temp\win520.tmp - Deleted
C:\WINDOWS\Temp\win521.tmp - Deleted
C:\WINDOWS\Temp\win522.tmp - Deleted
C:\WINDOWS\Temp\win523.tmp - Deleted
C:\WINDOWS\Temp\win524.tmp - Deleted
C:\WINDOWS\Temp\win525.tmp - Deleted
C:\WINDOWS\Temp\win526.tmp - Deleted
C:\WINDOWS\Temp\win527.tmp - Deleted
C:\WINDOWS\Temp\win528.tmp - Deleted
C:\WINDOWS\Temp\win529.tmp - Deleted
C:\WINDOWS\Temp\win52A.tmp - Deleted
C:\WINDOWS\Temp\win52B.tmp - Deleted
C:\WINDOWS\Temp\win52C.tmp - Deleted
C:\WINDOWS\Temp\win52D.tmp - Deleted
C:\WINDOWS\Temp\win52E.tmp - Deleted
C:\WINDOWS\Temp\win52F.tmp - Deleted
C:\WINDOWS\Temp\win53.tmp - Deleted
C:\WINDOWS\Temp\win530.tmp - Deleted
C:\WINDOWS\Temp\win531.tmp - Deleted
C:\WINDOWS\Temp\win532.tmp - Deleted
C:\WINDOWS\Temp\win533.tmp - Deleted
C:\WINDOWS\Temp\win534.tmp - Deleted
C:\WINDOWS\Temp\win535.tmp - Deleted
C:\WINDOWS\Temp\win536.tmp - Deleted
C:\WINDOWS\Temp\win537.tmp - Deleted
C:\WINDOWS\Temp\win538.tmp - Deleted
C:\WINDOWS\Temp\win539.tmp - Deleted
C:\WINDOWS\Temp\win53A.tmp - Deleted
C:\WINDOWS\Temp\win53B.tmp - Deleted
C:\WINDOWS\Temp\win53C.tmp - Deleted
C:\WINDOWS\Temp\win53D.tmp - Deleted
C:\WINDOWS\Temp\win53E.tmp - Deleted
C:\WINDOWS\Temp\win53F.tmp - Deleted
C:\WINDOWS\Temp\win54.tmp - Deleted
C:\WINDOWS\Temp\win540.tmp - Deleted
C:\WINDOWS\Temp\win541.tmp - Deleted
C:\WINDOWS\Temp\win542.tmp - Deleted
C:\WINDOWS\Temp\win543.tmp - Deleted
C:\WINDOWS\Temp\win544.tmp - Deleted
C:\WINDOWS\Temp\win545.tmp - Deleted
C:\WINDOWS\Temp\win546.tmp - Deleted
C:\WINDOWS\Temp\win547.tmp - Deleted
C:\WINDOWS\Temp\win548.tmp - Deleted
C:\WINDOWS\Temp\win549.tmp - Deleted
C:\WINDOWS\Temp\win54A.tmp - Deleted
C:\WINDOWS\Temp\win54B.tmp - Deleted
C:\WINDOWS\Temp\win54C.tmp - Deleted
C:\WINDOWS\Temp\win54D.tmp - Deleted
C:\WINDOWS\Temp\win54E.tmp - Deleted
C:\WINDOWS\Temp\win54F.tmp - Deleted
C:\WINDOWS\Temp\win55.tmp - Deleted
C:\WINDOWS\Temp\win550.tmp - Deleted
C:\WINDOWS\Temp\win551.tmp - Deleted
C:\WINDOWS\Temp\win552.tmp - Deleted
C:\WINDOWS\Temp\win553.tmp - Deleted
C:\WINDOWS\Temp\win554.tmp - Deleted
C:\WINDOWS\Temp\win555.tmp - Deleted
C:\WINDOWS\Temp\win556.tmp - Deleted
C:\WINDOWS\Temp\win557.tmp - Deleted
C:\WINDOWS\Temp\win558.tmp - Deleted
C:\WINDOWS\Temp\win559.tmp - Deleted
C:\WINDOWS\Temp\win55A.tmp - Deleted
C:\WINDOWS\Temp\win55B.tmp - Deleted
C:\WINDOWS\Temp\win55C.tmp - Deleted
C:\WINDOWS\Temp\win55D.tmp - Deleted
C:\WINDOWS\Temp\win55E.tmp - Deleted
C:\WINDOWS\Temp\win55F.tmp - Deleted
C:\WINDOWS\Temp\win56.tmp - Deleted
C:\WINDOWS\Temp\win560.tmp - Deleted
C:\WINDOWS\Temp\win561.tmp - Deleted
C:\WINDOWS\Temp\win562.tmp - Deleted
C:\WINDOWS\Temp\win563.tmp - Deleted
C:\WINDOWS\Temp\win564.tmp - Deleted
C:\WINDOWS\Temp\win565.tmp - Deleted
C:\WINDOWS\Temp\win566.tmp - Deleted
C:\WINDOWS\Temp\win567.tmp - Deleted
C:\WINDOWS\Temp\win568.tmp - Deleted
C:\WINDOWS\Temp\win569.tmp - Deleted
C:\WINDOWS\Temp\win56A.tmp - Deleted
C:\WINDOWS\Temp\win56B.tmp - Deleted
C:\WINDOWS\Temp\win56C.tmp - Deleted
C:\WINDOWS\Temp\win56D.tmp - Deleted
C:\WINDOWS\Temp\win56E.tmp - Deleted
C:\WINDOWS\Temp\win56F.tmp - Deleted
C:\WINDOWS\Temp\win57.tmp - Deleted
C:\WINDOWS\Temp\win570.tmp - Deleted
C:\WINDOWS\Temp\win571.tmp - Deleted
C:\WINDOWS\Temp\win572.tmp - Deleted
C:\WINDOWS\Temp\win573.tmp - Deleted
C:\WINDOWS\Temp\win574.tmp - Deleted
C:\WINDOWS\Temp\win575.tmp - Deleted
C:\WINDOWS\Temp\win576.tmp - Deleted
C:\WINDOWS\Temp\win577.tmp - Deleted
C:\WINDOWS\Temp\win578.tmp - Deleted
C:\WINDOWS\Temp\win579.tmp - Deleted
C:\WINDOWS\Temp\win57A.tmp - Deleted
C:\WINDOWS\Temp\win57B.tmp - Deleted
C:\WINDOWS\Temp\win57C.tmp - Deleted
C:\WINDOWS\Temp\win57D.tmp - Deleted
C:\WINDOWS\Temp\win57E.tmp - Deleted
C:\WINDOWS\Temp\win57F.tmp - Deleted
C:\WINDOWS\Temp\win58.tmp - Deleted
C:\WINDOWS\Temp\win580.tmp - Deleted
C:\WINDOWS\Temp\win581.tmp - Deleted
C:\WINDOWS\Temp\win582.tmp - Deleted
C:\WINDOWS\Temp\win583.tmp - Deleted
C:\WINDOWS\Temp\win584.tmp - Deleted
C:\WINDOWS\Temp\win585.tmp - Deleted
C:\WINDOWS\Temp\win586.tmp - Deleted
C:\WINDOWS\Temp\win587.tmp - Deleted
C:\WINDOWS\Temp\win588.tmp - Deleted
C:\WINDOWS\Temp\win589.tmp - Deleted
C:\WINDOWS\Temp\win58A.tmp - Deleted
C:\WINDOWS\Temp\win58B.tmp - Deleted
C:\WINDOWS\Temp\win58C.tmp - Deleted
C:\WINDOWS\Temp\win58D.tmp - Deleted
C:\WINDOWS\Temp\win58E.tmp - Deleted
C:\WINDOWS\Temp\win58F.tmp - Deleted
C:\WINDOWS\Temp\win59.tmp - Deleted
C:\WINDOWS\Temp\win590.tmp - Deleted
C:\WINDOWS\Temp\win591.tmp - Deleted
C:\WINDOWS\Temp\win592.tmp - Deleted
C:\WINDOWS\Temp\win593.tmp - Deleted
C:\WINDOWS\Temp\win594.tmp - Deleted
C:\WINDOWS\Temp\win595.tmp - Deleted
C:\WINDOWS\Temp\win596.tmp - Deleted
C:\WINDOWS\Temp\win597.tmp - Deleted
C:\WINDOWS\Temp\win598.tmp - Deleted
C:\WINDOWS\Temp\win599.tmp - Deleted
C:\WINDOWS\Temp\win59A.tmp - Deleted
C:\WINDOWS\Temp\win59B.tmp - Deleted
C:\WINDOWS\Temp\win59C.tmp - Deleted
C:\WINDOWS\Temp\win59D.tmp - Deleted
C:\WINDOWS\Temp\win59E.tmp - Deleted
C:\WINDOWS\Temp\win59F.tmp - Deleted
C:\WINDOWS\Temp\win5A.tmp - Deleted
C:\WINDOWS\Temp\win5A0.tmp - Deleted
C:\WINDOWS\Temp\win5A1.tmp - Deleted
C:\WINDOWS\Temp\win5A2.tmp - Deleted
C:\WINDOWS\Temp\win5A3.tmp - Deleted
C:\WINDOWS\Temp\win5A4.tmp - Deleted
C:\WINDOWS\Temp\win5A5.tmp - Deleted
C:\WINDOWS\Temp\win5A6.tmp - Deleted
C:\WINDOWS\Temp\win5A7.tmp - Deleted
C:\WINDOWS\Temp\win5A8.tmp - Deleted
C:\WINDOWS\Temp\win5A9.tmp - Deleted
C:\WINDOWS\Temp\win5AA.tmp - Deleted
C:\WINDOWS\Temp\win5AB.tmp - Deleted
C:\WINDOWS\Temp\win5AC.tmp - Deleted
C:\WINDOWS\Temp\win5AD.tmp - Deleted
C:\WINDOWS\Temp\win5AE.tmp - Deleted
C:\WINDOWS\Temp\win5AF.tmp - Deleted
C:\WINDOWS\Temp\win5B.tmp - Deleted
C:\WINDOWS\Temp\win5B0.tmp - Deleted
C:\WINDOWS\Temp\win5B1.tmp - Deleted
C:\WINDOWS\Temp\win5B2.tmp - Deleted
C:\WINDOWS\Temp\win5B3.tmp - Deleted
C:\WINDOWS\Temp\win5B4.tmp - Deleted
C:\WINDOWS\Temp\win5B5.tmp - Deleted
C:\WINDOWS\Temp\win5B6.tmp - Deleted
C:\WINDOWS\Temp\win5B7.tmp - Deleted
C:\WINDOWS\Temp\win5B8.tmp - Deleted
C:\WINDOWS\Temp\win5B9.tmp - Deleted
C:\WINDOWS\Temp\win5BA.tmp - Deleted
C:\WINDOWS\Temp\win5BB.tmp - Deleted
C:\WINDOWS\Temp\win5BC.tmp - Deleted
C:\WINDOWS\Temp\win5BD.tmp - Deleted
C:\WINDOWS\Temp\win5BE.tmp - Deleted
C:\WINDOWS\Temp\win5BF.tmp - Deleted
C:\WINDOWS\Temp\win5C.tmp - Deleted
C:\WINDOWS\Temp\win5C0.tmp - Deleted
C:\WINDOWS\Temp\win5C1.tmp - Deleted
C:\WINDOWS\Temp\win5C2.tmp - Deleted
C:\WINDOWS\Temp\win5C3.tmp - Deleted
C:\WINDOWS\Temp\win5C4.tmp - Deleted
C:\WINDOWS\Temp\win5C5.tmp - Deleted
C:\WINDOWS\Temp\win5C6.tmp - Deleted
C:\WINDOWS\Temp\win5C7.tmp - Deleted
C:\WINDOWS\Temp\win5C8.tmp - Deleted
C:\WINDOWS\Temp\win5C9.tmp - Deleted
C:\WINDOWS\Temp\win5CA.tmp - Deleted
C:\WINDOWS\Temp\win5CB.tmp - Deleted
C:\WINDOWS\Temp\win5CC.tmp - Deleted
C:\WINDOWS\Temp\win5CD.tmp - Deleted
C:\WINDOWS\Temp\win5CE.tmp - Deleted
C:\WINDOWS\Temp\win5CF.tmp - Deleted
C:\WINDOWS\Temp\win5D.tmp - Deleted
C:\WINDOWS\Temp\win5D0.tmp - Deleted
C:\WINDOWS\Temp\win5D1.tmp - Deleted
C:\WINDOWS\Temp\win5D2.tmp - Deleted
C:\WINDOWS\Temp\win5D3.tmp - Deleted
C:\WINDOWS\Temp\win5D4.tmp - Deleted
C:\WINDOWS\Temp\win5D5.tmp - Deleted
C:\WINDOWS\Temp\win5D6.tmp - Deleted
C:\WINDOWS\Temp\win5D7.tmp - Deleted
C:\WINDOWS\Temp\win5D8.tmp - Deleted
C:\WINDOWS\Temp\win5D9.tmp - Deleted
C:\WINDOWS\Temp\win5DA.tmp - Deleted
C:\WINDOWS\Temp\win5DB.tmp - Deleted
C:\WINDOWS\Temp\win5DC.tmp - Deleted
C:\WINDOWS\Temp\win5DD.tmp - Deleted
C:\WINDOWS\Temp\win5DE.tmp - Deleted
C:\WINDOWS\Temp\win5DF.tmp - Deleted
C:\WINDOWS\Temp\win5E.tmp - Deleted
C:\WINDOWS\Temp\win5E0.tmp - Deleted
C:\WINDOWS\Temp\win5E1.tmp - Deleted
C:\WINDOWS\Temp\win5E2.tmp - Deleted
C:\WINDOWS\Temp\win5E3.tmp - Deleted
C:\WINDOWS\Temp\win5E4.tmp - Deleted
C:\WINDOWS\Temp\win5E5.tmp - Deleted
C:\WINDOWS\Temp\win5E6.tmp - Deleted
C:\WINDOWS\Temp\win5E7.tmp - Deleted
C:\WINDOWS\Temp\win5E8.tmp - Deleted
C:\WINDOWS\Temp\win5E9.tmp - Deleted
C:\WINDOWS\Temp\win5EA.tmp - Deleted
C:\WINDOWS\Temp\win5EB.tmp - Deleted
C:\WINDOWS\Temp\win5EC.tmp - Deleted
C:\WINDOWS\Temp\win5ED.tmp - Deleted
C:\WINDOWS\Temp\win5EE.tmp - Deleted
C:\WINDOWS\Temp\win5EF.tmp - Deleted
C:\WINDOWS\Temp\win5F.tmp - Deleted
C:\WINDOWS\Temp\win5F0.tmp - Deleted
C:\WINDOWS\Temp\win5F1.tmp - Deleted
C:\WINDOWS\Temp\win5F2.tmp - Deleted
C:\WINDOWS\Temp\win5F3.tmp - Deleted
C:\WINDOWS\Temp\win6.tmp - Deleted
C:\WINDOWS\Temp\win60.tmp - Deleted
C:\WINDOWS\Temp\win600.tmp - Deleted
C:\WINDOWS\Temp\win61.tmp - Deleted
C:\WINDOWS\Temp\win613.tmp - Deleted
C:\WINDOWS\Temp\win616.tmp - Deleted
C:\WINDOWS\Temp\win618.tmp - Deleted
C:\WINDOWS\Temp\win62.tmp - Deleted
C:\WINDOWS\Temp\win63.tmp - Deleted
C:\WINDOWS\Temp\win636.tmp - Deleted
C:\WINDOWS\Temp\win64.tmp - Deleted
C:\WINDOWS\Temp\win640.tmp - Deleted
C:\WINDOWS\Temp\win65.tmp - Deleted
C:\WINDOWS\Temp\win66.tmp - Deleted
C:\WINDOWS\Temp\win67.tmp - Deleted
C:\WINDOWS\Temp\win68.tmp - Deleted
C:\WINDOWS\Temp\win69.tmp - Deleted
C:\WINDOWS\Temp\win6A.tmp - Deleted
C:\WINDOWS\Temp\win6B.tmp - Deleted
C:\WINDOWS\Temp\win6C.tmp - Deleted
C:\WINDOWS\Temp\win6D.tmp - Deleted
C:\WINDOWS\Temp\win6E.tmp - Deleted
C:\WINDOWS\Temp\win6F.tmp - Deleted
C:\WINDOWS\Temp\win7.tmp - Deleted
C:\WINDOWS\Temp\win70.tmp - Deleted
C:\WINDOWS\Temp\win71.tmp - Deleted
C:\WINDOWS\Temp\win72.tmp - Deleted
C:\WINDOWS\Temp\win73.tmp - Deleted
C:\WINDOWS\Temp\win74.tmp - Deleted
C:\WINDOWS\Temp\win75.tmp - Deleted
C:\WINDOWS\Temp\win76.tmp - Deleted
C:\WINDOWS\Temp\win77.tmp - Deleted
C:\WINDOWS\Temp\win78.tmp - Deleted
C:\WINDOWS\Temp\win79.tmp - Deleted
C:\WINDOWS\Temp\win7A.tmp - Deleted
C:\WINDOWS\Temp\win7B.tmp - Deleted
C:\WINDOWS\Temp\win7C.tmp - Deleted
C:\WINDOWS\Temp\win7D.tmp - Deleted
C:\WINDOWS\Temp\win7E.tmp - Deleted
C:\WINDOWS\Temp\win7F.tmp - Deleted
C:\WINDOWS\Temp\win8.tmp - Deleted
C:\WINDOWS\Temp\win80.tmp - Deleted
C:\WINDOWS\Temp\win81.tmp - Deleted
C:\WINDOWS\Temp\win82.tmp - Deleted
C:\WINDOWS\Temp\win83.tmp - Deleted
C:\WINDOWS\Temp\win84.tmp - Deleted
C:\WINDOWS\Temp\win85.tmp - Deleted
C:\WINDOWS\Temp\win86.tmp - Deleted
C:\WINDOWS\Temp\win87.tmp - Deleted
C:\WINDOWS\Temp\win88.tmp - Deleted
C:\WINDOWS\Temp\win89.tmp - Deleted
C:\WINDOWS\Temp\win8A.tmp - Deleted
C:\WINDOWS\Temp\win8B.tmp - Deleted
C:\WINDOWS\Temp\win8C.tmp - Deleted
C:\WINDOWS\Temp\win8D.tmp - Deleted
C:\WINDOWS\Temp\win8E.tmp - Deleted
C:\WINDOWS\Temp\win8F.tmp - Deleted
C:\WINDOWS\Temp\win9.tmp - Deleted
C:\WINDOWS\Temp\win90.tmp - Deleted
C:\WINDOWS\Temp\win91.tmp - Deleted
C:\WINDOWS\Temp\win92.tmp - Deleted
C:\WINDOWS\Temp\win93.tmp - Deleted
C:\WINDOWS\Temp\win94.tmp - Deleted
C:\WINDOWS\Temp\win95.tmp - Deleted
C:\WINDOWS\Temp\win96.tmp - Deleted
C:\WINDOWS\Temp\win97.tmp - Deleted
C:\WINDOWS\Temp\win98.tmp - Deleted
C:\WINDOWS\Temp\win99.tmp - Deleted
C:\WINDOWS\Temp\win9A.tmp - Deleted
C:\WINDOWS\Temp\win9B.tmp - Deleted
C:\WINDOWS\Temp\win9C.tmp - Deleted
C:\WINDOWS\Temp\win9D.tmp - Deleted
C:\WINDOWS\Temp\win9E.tmp - Deleted
C:\WINDOWS\Temp\win9F.tmp - Deleted
C:\WINDOWS\Temp\winA.tmp - Deleted
C:\WINDOWS\Temp\winA0.tmp - Deleted
C:\WINDOWS\Temp\winA1.tmp - Deleted
C:\WINDOWS\Temp\winA2.tmp - Deleted
C:\WINDOWS\Temp\winA3.tmp - Deleted
C:\WINDOWS\Temp\winA4.tmp - Deleted
C:\WINDOWS\Temp\winA5.tmp - Deleted
C:\WINDOWS\Temp\winA6.tmp - Deleted
C:\WINDOWS\Temp\winA7.tmp - Deleted
C:\WINDOWS\Temp\winA8.tmp - Deleted
C:\WINDOWS\Temp\winA9.tmp - Deleted
C:\WINDOWS\Temp\winAA.tmp - Deleted
C:\WINDOWS\Temp\winAB.tmp - Deleted
C:\WINDOWS\Temp\winAC.tmp - Deleted
C:\WINDOWS\Temp\winAD.tmp - Deleted
C:\WINDOWS\Temp\winAE.tmp - Deleted
C:\WINDOWS\Temp\winAF.tmp - Deleted
C:\WINDOWS\Temp\winB.tmp - Deleted
C:\WINDOWS\Temp\winB0.tmp - Deleted
C:\WINDOWS\Temp\winB1.tmp - Deleted
C:\WINDOWS\Temp\winB2.tmp - Deleted
C:\WINDOWS\Temp\winB3.tmp - Deleted
C:\WINDOWS\Temp\winB4.tmp - Deleted
C:\WINDOWS\Temp\winB5.tmp - Deleted
C:\WINDOWS\Temp\winB6.tmp - Deleted
C:\WINDOWS\Temp\winB7.tmp - Deleted
C:\WINDOWS\Temp\winB8.tmp - Deleted
C:\WINDOWS\Temp\winB9.tmp - Deleted
C:\WINDOWS\Temp\winBA.tmp - Deleted
C:\WINDOWS\Temp\winBB.tmp - Deleted
C:\WINDOWS\Temp\winBC.tmp - Deleted
C:\WINDOWS\Temp\winBD.tmp - Deleted
C:\WINDOWS\Temp\winBE.tmp - Deleted
C:\WINDOWS\Temp\winBF.tmp - Deleted
C:\WINDOWS\Temp\winC.tmp - Deleted
C:\WINDOWS\Temp\winC0.tmp - Deleted
C:\WINDOWS\Temp\winC1.tmp - Deleted
C:\WINDOWS\Temp\winC2.tmp - Deleted
C:\WINDOWS\Temp\winC3.tmp - Deleted
C:\WINDOWS\Temp\winC4.tmp - Deleted
C:\WINDOWS\Temp\winC5.tmp - Deleted
C:\WINDOWS\Temp\winC6.tmp - Deleted
C:\WINDOWS\Temp\winC7.tmp - Deleted
C:\WINDOWS\Temp\winC8.tmp - Deleted
C:\WINDOWS\Temp\winC9.tmp - Deleted
C:\WINDOWS\Temp\winCA.tmp - Deleted
C:\WINDOWS\Temp\winCB.tmp - Deleted
C:\WINDOWS\Temp\winCC.tmp - Deleted
C:\WINDOWS\Temp\winCD.tmp - Deleted
C:\WINDOWS\Temp\winCE.tmp - Deleted
C:\WINDOWS\Temp\winCF.tmp - Deleted
C:\WINDOWS\Temp\winD.tmp - Deleted
C:\WINDOWS\Temp\winD0.tmp - Deleted
C:\WINDOWS\Temp\winD1.tmp - Deleted
C:\WINDOWS\Temp\winD2.tmp - Deleted
C:\WINDOWS\Temp\winD3.tmp - Deleted
C:\WINDOWS\Temp\winD4.tmp - Deleted
C:\WINDOWS\Temp\winD5.tmp - Deleted
C:\WINDOWS\Temp\winD6.tmp - Deleted
C:\WINDOWS\Temp\winD7.tmp - Deleted
C:\WINDOWS\Temp\winD8.tmp - Deleted
C:\WINDOWS\Temp\winD9.tmp - Deleted
C:\WINDOWS\Temp\winDA.tmp - Deleted
C:\WINDOWS\Temp\winDB.tmp - Deleted
C:\WINDOWS\Temp\winDC.tmp - Deleted
C:\WINDOWS\Temp\winDD.tmp - Deleted
C:\WINDOWS\Temp\winDE.tmp - Deleted
C:\WINDOWS\Temp\winDF.tmp - Deleted
C:\WINDOWS\Temp\winE.tmp - Deleted
C:\WINDOWS\Temp\winE0.tmp - Deleted
C:\WINDOWS\Temp\winE1.tmp - Deleted
C:\WINDOWS\Temp\winE2.tmp - Deleted
C:\WINDOWS\Temp\winE3.tmp - Deleted
C:\WINDOWS\Temp\winE4.tmp - Deleted
C:\WINDOWS\Temp\winE5.tmp - Deleted
C:\WINDOWS\Temp\winE6.tmp - Deleted
C:\WINDOWS\Temp\winE7.tmp - Deleted
C:\WINDOWS\Temp\winE8.tmp - Deleted
C:\WINDOWS\Temp\winE9.tmp - Deleted
C:\WINDOWS\Temp\winEA.tmp - Deleted
C:\WINDOWS\Temp\winEB.tmp - Deleted
C:\WINDOWS\Temp\winEC.tmp - Deleted
C:\WINDOWS\Temp\winED.tmp - Deleted
C:\WINDOWS\Temp\winEE.tmp - Deleted
C:\WINDOWS\Temp\winEF.tmp - Deleted
C:\WINDOWS\Temp\winF.tmp - Deleted
C:\WINDOWS\Temp\winF0.tmp - Deleted
C:\WINDOWS\Temp\winF1.tmp - Deleted
C:\WINDOWS\Temp\winF2.tmp - Deleted
C:\WINDOWS\Temp\winF3.tmp - Deleted
C:\WINDOWS\Temp\winF4.tmp - Deleted
C:\WINDOWS\Temp\winF5.tmp - Deleted
C:\WINDOWS\Temp\winF6.tmp - Deleted
C:\WINDOWS\Temp\winF7.tmp - Deleted
C:\WINDOWS\Temp\winF8.tmp - Deleted
C:\WINDOWS\Temp\winF9.tmp - Deleted
C:\WINDOWS\Temp\winFA.tmp - Deleted
C:\WINDOWS\Temp\winFB.tmp - Deleted
C:\WINDOWS\Temp\winFC.tmp - Deleted
C:\WINDOWS\Temp\winFD.tmp - Deleted
C:\WINDOWS\Temp\winFE.tmp - Deleted
C:\WINDOWS\Temp\winFF.tmp - Deleted



Alternate Stream Check:

C:\WINDOWS\system32
:lzx32.sys 70818
Total size: 70818 bytes.

Removing ADS...

system32: deleted 70818 bytes in 1 streams.

Checking for remaining Streams

C:\WINDOWS\system32
No streams found.
Final Check:

Remaining Services:
------------------

[COLOR=RED][B]Rootkit PE386 Found![/COLOR][/B]

Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\MSN Messenger\\MSNP13Downgrader.exe"="C:\\Program Files\\MSN Messenger\\MSNP13Downgrader.exe:*:Enabled:MSNP13Downgrader"
"C:\\Program Files\\Ubisoft\\Crytek\\Far Cry\\Bin32\\FarCry.exe"="C:\\Program Files\\Ubisoft\\Crytek\\Far Cry\\Bin32\\FarCry.exe:*:Enabled:Far Cry"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\WINDOWS\\system32\\svchost.exe"="C:\\WINDOWS\\system32\\svchost.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\41exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\41exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\57exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\57exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\4exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\4exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\22exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\22exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\81exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\81exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\88exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\88exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\95exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\95exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\69exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\69exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\8exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\8exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\7exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\7exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\0exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\0exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\70exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\70exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\8exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\8exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\51exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\51exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\1exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\1exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\80exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\80exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\63exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\63exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Te


Message édité par enjoii89 le 17-01-2007 à 19:26:40
Répondre à enjoii89

LA FIN DU COMPTE RENDU DE SDFix


"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\2exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\2exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\80exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\80exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\84exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\84exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\96exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\96exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\74exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\74exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\72exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\72exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\75exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\75exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\37exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\37exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\18exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\18exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\90exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\90exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\60exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\60exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\56exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\56exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\19exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\19exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\71exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\71exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\5exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\5exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\87exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\87exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\16exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\16exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\65exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\65exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\49exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\49exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\55exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\55exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\54exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\54exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\94exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\94exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\67exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\67exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\47exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\47exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\12exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\12exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\50exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\50exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\47exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\47exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\64exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\64exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\68exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\68exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\52exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\52exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\92exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\92exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\5exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\5exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\21exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\21exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\90exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\90exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\43exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\43exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\93exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\93exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\32exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\32exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\98exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\98exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\96exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\96exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\59exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\59exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\13exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\13exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\44exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\44exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\24exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\24exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\29exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\29exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\6exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\6exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\62exmodul32d.1.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\62exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exmodul32d.1.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exmodul32d.1.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\65exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\65exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\59exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\59exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\52exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\52exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\24exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\24exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\55exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\55exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\86exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\86exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\81exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\81exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\31exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\31exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\89exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\89exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\1exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\1exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\29exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\29exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\96exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\96exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\58exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\58exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\32exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\32exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\25exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\25exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\6exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\6exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\43exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\43exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\59exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\59exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\2exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\2exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\50exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\50exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\13exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\13exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\76exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\76exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\86exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\86exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\69exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\69exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\56exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\56exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\79exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\79exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\47exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\47exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\32exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\32exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\56exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\56exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\3exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\3exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\91exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\91exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\3exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\3exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\8exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\8exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\73exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\73exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\53exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\53exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\39exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\39exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\95exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\95exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\66exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\66exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\87exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\87exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\5exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\5exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\44exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\44exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\88exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\88exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\74exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\74exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\72exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\72exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\95exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\95exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\12exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\12exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\68exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\68exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\70exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\70exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\92exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\92exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\37exmodul32d.2.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\37exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exmodul32d.2.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exmodul32d.2.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\78exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\78exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\20exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\20exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\88exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\88exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\92exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\92exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\85exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\85exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\11exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\11exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\38exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\38exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\32exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\32exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\16exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\16exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\36exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\36exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\28exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\28exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\49exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\49exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\84exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\84exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\62exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\62exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\4exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\4exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\39exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\39exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\38exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\38exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\53exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\53exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\71exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\71exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\30exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\30exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\14exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\14exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\30exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\30exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\23exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\23exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\47exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\47exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\47exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\47exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\73exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\73exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\22exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\22exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\48exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\48exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\64exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\64exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\42exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\42exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\28exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\28exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\53exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\53exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\2exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\2exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\4exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\4exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\90exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\90exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\50exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\50exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\11exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\11exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\67exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\67exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\95exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\95exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\86exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\86exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\66exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\66exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\31exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\31exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\26exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\26exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\15exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\15exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\45exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\45exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\52exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\52exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\58exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\58exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\61exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\61exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\3exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\3exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\82exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\82exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\64exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\64exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\99exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\99exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\36exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\36exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\40exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\40exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\34exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\34exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\60exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\60exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\18exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\18exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\51exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\51exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\10exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\10exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\18exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\18exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\27exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\27exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\0exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\0exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\77exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\77exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\0exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\0exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\53exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\53exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\5exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\5exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\56exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\56exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\9exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\9exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\12exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\12exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\77exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\77exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\80exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\80exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\21exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\21exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\97exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\97exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\31exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\31exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\82exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\82exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\4exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\4exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\85exmodul32d.3.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\85exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\87exmodul32d.3.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\87exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\24exmodul32d.3.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\24exmodul32d.3.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\29exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\29exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\80exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\80exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\48exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\48exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\19exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\19exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\48exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\48exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\51exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\51exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\11exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\11exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\15exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\15exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\24exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\24exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\74exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\74exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\22exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\22exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\17exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\17exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\9exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\9exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\18exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\18exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\8exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\8exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\58exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\58exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\36exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\36exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\86exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\86exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\97exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\97exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\27exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\27exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\65exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\65exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\71exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\71exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\6exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\6exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\20exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\20exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\69exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\69exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\45exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\45exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\56exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\56exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\88exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\88exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\32exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\32exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\82exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\82exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\23exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\23exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\38exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\38exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\94exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\94exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\95exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\95exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\75exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\75exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\68exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\68exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\78exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\78exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\4exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\4exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\64exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\64exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\98exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\98exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\45exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\45exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\3exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\3exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\84exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\84exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\62exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\62exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\66exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\66exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\78exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\78exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\72exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\72exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\43exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\43exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\74exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\74exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\6exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\6exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\66exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\66exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\38exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\38exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\3exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\3exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\20exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\20exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\52exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\52exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\58exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\58exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\85exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\85exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\21exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\21exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\81exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\81exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\33exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\33exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\91exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\91exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\98exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\98exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\91exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\91exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\75exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\75exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\47exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\47exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\39exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\39exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\22exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\22exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\11exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\11exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\79exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\79exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\7exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\7exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\32exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\32exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\90exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\90exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\83exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\83exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\31exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\31exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\10exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\10exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\69exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\69exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\43exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\43exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\30exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\30exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\44exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\44exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\66exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\66exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\87exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\87exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\69exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\69exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\59exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\59exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\16exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\16exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\60exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\60exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\55exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\55exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\13exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\13exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\47exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\47exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\84exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\84exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\44exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\44exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\80exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\80exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\33exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\33exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\0exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\0exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\50exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\50exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\28exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\28exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\78exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\78exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\49exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\49exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\88exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\88exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\63exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\63exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\35exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\35exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\10exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\10exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\46exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\46exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\1exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\1exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\77exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\77exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\82exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\82exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\17exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\17exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\12exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\12exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\29exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\29exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\92exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\92exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\54exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\54exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\26exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\26exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\72exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\72exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\92exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\92exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\99exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\99exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\87exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\87exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\57exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\57exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\52exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\52exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\83exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\83exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\53exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\53exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\81exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\81exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\39exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\39exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\28exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\28exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\50exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\50exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\81exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\81exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\7exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\7exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\95exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\95exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\70exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\70exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\12exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\12exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\9exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\9exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\44exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\44exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\27exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\27exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\7exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\7exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\14exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\14exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\59exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\59exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\40exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\40exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\31exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\31exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\34exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\34exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\12exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\12exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\64exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\64exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\70exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\70exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\2exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\2exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\55exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\55exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\86exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\86exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\5exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\5exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\31exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\31exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\53exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\53exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\70exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\70exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\57exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\57exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\76exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\76exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\91exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\91exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\76exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\76exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\28exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\28exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\1exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\1exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\79exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\79exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\41exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\41exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\53exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\53exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\43exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\43exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\25exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\25exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\49exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\49exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\57exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\57exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\19exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\19exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\36exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\36exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\96exmodul32d.4.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\96exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\68exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\68exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\2exmodul32d.4.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\2exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\93exmodul32d.4.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\93exmodul32d.4.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\54exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\54exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\52exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\52exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\72exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\72exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\11exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\11exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\49exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\49exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\2exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\2exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\66exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\66exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\88exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\88exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\67exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\67exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\13exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\13exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\28exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\28exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\77exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\77exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\60exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\60exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\93exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\93exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\22exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\22exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\15exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\15exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\77exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\77exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\34exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\34exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\57exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\57exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\98exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\98exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\18exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\18exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\56exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\56exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\55exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\55exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\97exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\97exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\11exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\11exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\94exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\94exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\12exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\12exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\10exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\10exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\59exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\59exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\91exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\91exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\76exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\76exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\18exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\18exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\98exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\98exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\11exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\11exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\62exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\62exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\46exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\46exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\19exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\19exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\52exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\52exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\21exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\21exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\1exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\1exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\14exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\14exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\58exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\58exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\31exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\31exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\81exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\81exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\36exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\36exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\75exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\75exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\32exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\32exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\10exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\10exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\64exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\64exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\73exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\73exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\72exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\72exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\54exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\54exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\44exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\44exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\4exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\4exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\69exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\69exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\77exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\77exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\50exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\50exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\50exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\50exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\99exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\99exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\30exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\30exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\44exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\44exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\13exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\13exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:

Répondre à enjoii89

"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\59exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\59exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\43exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\43exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\4exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\4exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\38exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\38exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\40exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\40exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\43exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\43exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\39exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\39exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\70exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\70exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\30exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\30exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\50exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\50exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\41exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\41exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\41exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\41exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\29exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\29exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\80exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\80exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\71exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\71exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\7exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\7exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\76exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\76exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\1exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\1exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\89exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\89exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\46exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\46exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\51exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\51exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\85exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\85exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\0exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\0exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\26exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\26exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\1exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\1exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\26exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\26exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\62exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\62exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\52exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\52exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\27exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\27exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\86exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\86exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\0exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\0exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\6exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\6exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\75exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\75exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\92exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\92exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\87exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\87exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\5exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\5exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\48exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\48exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\65exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\65exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\9exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\9exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\55exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\55exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\74exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\74exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\80exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\80exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\12exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\12exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\56exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\56exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\36exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\36exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\83exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\83exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\9exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\9exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\6exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\6exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\68exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\68exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\63exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\63exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\99exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\99exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\65exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\65exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\39exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\39exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\73exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\73exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\66exmodul32d.5.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\66exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\40exmodul32d.5.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\40exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\5exmodul32d.5.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\5exmodul32d.5.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\33exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\33exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\6exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\6exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\70exmodul32d.6.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\70exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\3exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\3exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\78exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\78exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\63exmodul32d.6.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\63exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\55exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\55exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\82exmodul32d.6.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\82exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\96exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\96exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\88exmodul32d.6.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\88exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\64exmodul32d.6.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\64exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\86exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\86exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\71exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\71exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\91exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\91exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\77exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\77exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\85exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\85exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\67exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\67exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\73exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\73exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\6exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\6exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\19exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\19exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\63exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\63exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\38exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\38exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\61exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\61exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\78exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\78exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\64exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\64exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\51exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\51exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\65exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\65exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\69exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\69exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\87exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\87exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\81exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\81exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\65exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\65exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\59exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\59exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\1exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\1exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\85exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\85exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\51exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\51exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\30exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\30exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\82exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\82exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\28exmodul32d.6.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\28exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\68exmodul32d.6.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\68exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\97exmodul32d.6.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\97exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\39exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\39exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\94exmodul32d.6.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\94exmodul32d.6.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\56exmodul32d.7.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\56exmodul32d.7.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\79exmodul32d.7.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\79exmodul32d.7.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exmodul32d.7.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exmodul32d.7.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\92exmodul32d.7.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\92exmodul32d.7.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\40exmodul32d.8.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\40exmodul32d.8.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\11exmodul32d.8.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\11exmodul32d.8.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\35exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\35exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\1exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\1exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\83exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\83exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\40exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\40exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\34exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\34exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\75exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\75exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\41exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\41exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\57exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\57exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\27exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\27exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\60exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\60exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\24exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\24exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\91exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\91exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\15exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\15exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\73exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\73exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\4exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\4exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\1exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\1exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\39exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\39exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\82exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\82exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\22exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\22exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\45exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\45exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\63exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\63exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\4exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\4exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\2exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\2exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\19exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\19exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\20exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\20exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\48exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\48exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\85exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\85exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\20exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\20exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\45exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\45exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\97exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\97exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\67exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\67exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\46exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\46exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\29exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\29exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\62exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\62exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\5exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\5exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\7exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\7exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\31exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\31exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\19exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\19exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\56exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\56exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\70exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\70exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\59exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\59exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\96exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\96exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\41exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\41exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\37exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\37exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\34exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\34exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\49exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\49exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\72exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\72exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\47exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\47exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\81exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\81exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\40exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\40exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\30exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\30exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\76exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\76exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\46exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\46exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\55exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\55exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\48exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\48exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\70exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\70exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\75exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\75exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\21exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\21exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\23exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\23exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\69exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\69exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\32exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\32exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\73exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\73exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\24exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\24exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\13exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\13exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\49exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\49exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\0exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\0exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\93exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\93exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\90exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\90exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\92exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\92exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\95exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\95exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\78exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\78exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\97exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\97exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\88exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\88exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\31exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\31exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\17exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\17exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\92exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\92exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\36exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\36exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\82exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\82exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\93exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\93exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\55exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\55exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\99exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\99exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\28exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\28exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\44exmodul32d.a.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\44exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\54exmodul32d.a.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\54exmodul32d.a.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\72exmodul32d.b.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\72exmodul32d.b.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\67exmodul32d.b.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\67exmodul32d.b.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\91exmodul32d.b.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\91exmodul32d.b.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\96exmodul32d.b.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\96exmodul32d.b.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\68exmodul32d.b.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\68exmodul32d.b.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\11exmodul32d.b.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\11exmodul32d.b.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\11exmodul32d.c.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\11exmodul32d.c.exe:*:Enabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\99exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\99exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\99exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\99exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\96exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\96exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\96exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\96exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\92exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\92exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\90exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\90exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\88exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\88exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\88exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\88exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\87exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\87exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\87exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\87exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\86exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\86exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\86exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\86exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\85exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\85exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\84exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\84exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\83exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\83exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\82exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\82exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\82exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\82exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\81exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\81exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\80exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\80exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\77exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\77exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\76exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\76exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\76exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\76exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\72exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\72exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\72exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\72exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\71exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\71exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\71exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\71exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\69exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\69exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\68exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\68exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\67exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\67exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\67exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\67exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\66exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\66exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\65exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\65exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\65exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\65exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\63exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\63exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\63exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\63exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\62exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\62exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\62exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\62exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\61exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\61exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\60exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\60exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\5exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\5exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\59exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\59exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\59exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\59exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\57exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\57exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\55exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\55exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\54exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\54exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\54exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\54exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\52exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\52exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\50exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\50exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\4exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\4exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\49exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\49exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\47exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\47exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\47exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\47exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\46exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\46exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\44exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\44exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\44exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\44exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\43exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\43exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\43exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\43exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\42exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\42exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\40exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\40exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\3exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\3exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\3exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\3exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\39exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\39exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\37exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\37exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\36exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\36exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\35exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\35exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\35exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\35exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\34exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\34exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\33exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\33exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\32exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\32exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\32exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\32exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\31exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\31exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\31exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\31exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\30exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\30exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\30exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\30exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\2exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\2exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\29exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\29exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\28exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\28exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\25exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\25exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\25exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\25exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\23exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\23exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\22exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\22exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\21exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\21exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\21exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\21exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\20exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\20exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\20exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\20exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\1exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\1exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\1exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\1exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\17exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\17exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\17exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\17exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\15exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\15exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\15exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\15exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\14exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\14exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\14exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\14exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\13exmodul32d.c.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\13exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\client\\Local Settings\\Temp\\13exmodul32d.b.exe"="C:\\Documents and Settings\\client\\Local Settings\\Temp\\13exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\9exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\9exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\9exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\9exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\98exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\98exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\96exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\96exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\83exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\83exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\82exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\82exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\81exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\81exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\69exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\69exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\68exmodul32d.7.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\68exmodul32d.7.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\67exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\67exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\67exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\67exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\66exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\66exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\66exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\66exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\66exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\66exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\65exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\65exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\65exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\65exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\65exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\65exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\64exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\64exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\64exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\64exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\63exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\63exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\63exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\63exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\62exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\62exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\62exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\62exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\61exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\61exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\61exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\61exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\60exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\60exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\60exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\60exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\5exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\5exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\5exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\5exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\5exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\5exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\59exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\59exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\59exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\59exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\58exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\58exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\57exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\57exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\57exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\57exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\56exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\56exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\56exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\56exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\55exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\55exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\54exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\54exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\54exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\54exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\53exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\53exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\53exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\53exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\52exmodul32d.8.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\52exmodul32d.8.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\51exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\51exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\51exmodul32d.7.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\51exmodul32d.7.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\50exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\50exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\50exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\50exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\4exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\4exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\4exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\4exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\4exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\4exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\49exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\49exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\49exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\49exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\48exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\48exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\48exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\48exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\47exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\47exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\46exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\46exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\46exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\46exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\46exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\46exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\45exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\45exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\45exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\45exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\44exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\44exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\44exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\44exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\43exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\43exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\43exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\43exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\43exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\43exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\42exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\42exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\42exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\42exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\42exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\42exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\3exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\3exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\3exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\3exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\3exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\3exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\39exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\39exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\38exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\38exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\38exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\38exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\38exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\38exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\37exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\37exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\36exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\36exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\36exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\36exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\36exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\36exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\35exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\35exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\35exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\

Répondre à enjoii89

"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\35exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\35exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\34exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\34exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\34exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\34exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\34exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\34exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\33exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\33exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\33exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\33exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\33exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\33exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\32exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\32exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\32exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\32exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\31exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\31exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\31exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\31exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\30exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\30exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\30exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\30exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\2exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\2exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\2exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\2exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\2exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\2exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\29exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\29exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\29exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\29exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\28exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\28exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\28exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\28exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\27exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\27exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\26exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\26exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\26exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\26exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\25exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\25exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\25exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\25exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\25exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\25exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\24exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\24exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\23exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\23exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\23exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\23exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\22exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\22exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\22exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\22exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\22exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\22exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\21exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\21exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\20exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\20exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\20exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\20exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\1exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\1exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\18exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\18exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\17exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\17exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\16exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\16exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\15exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\15exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\15exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\15exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\15exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\15exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\14exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\14exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\13exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\13exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\13exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\13exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\11exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\11exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\11exmodul32d.1.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\11exmodul32d.1.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\10exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\10exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\10exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\10exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\10exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\10exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\10exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\10exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\0exmodul32d.c.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\0exmodul32d.c.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\0exmodul32d.b.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\0exmodul32d.b.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\0exmodul32d.a.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\0exmodul32d.a.exe:*:Disabled:Microsoft Update"
"C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\0exmodul32d.2.exe"="C:\\Documents and Settings\\QUENTIN\\Local Settings\\Temp\\0exmodul32d.2.exe:*:Disabled:Microsoft Update"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\10exinjs.n.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\10exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\41exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\41exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\4exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\4exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\71exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\71exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\1exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\1exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\89exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\89exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\45exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\45exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\15exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\15exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\2exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\2exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\93exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\93exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\25exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\25exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\43exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\43exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\56exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\56exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\98exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\98exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\9exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\9exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\74exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\74exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\0exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\0exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\7exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\7exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\92exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\92exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\67exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\67exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\23exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\23exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\12exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\12exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\28exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\28exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\85exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\85exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\84exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\84exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\64exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\64exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\20exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\20exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\70exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\70exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\55exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\55exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\73exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\73exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\61exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\61exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\77exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\77exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\21exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\21exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\62exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\62exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\97exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\97exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\86exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\86exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\72exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\72exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\57exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\57exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\51exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\51exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\94exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\94exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\10exinjs.n.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\10exinjs.n.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\36exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\36exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\85exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\85exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\71exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\71exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\45exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\45exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\91exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\91exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\58exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\58exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\81exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\81exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\94exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\94exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\98exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\98exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\86exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\86exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\63exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\63exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\65exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\65exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\26exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\26exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\72exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\72exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\79exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\79exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\19exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\19exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\22exinjs.o.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\22exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\69exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\69exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\27exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\62exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\62exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\31exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\31exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\77exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\77exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\82exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\82exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\25exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\25exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\52exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\52exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\43exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\43exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\47exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\47exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\89exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\89exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\45exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\45exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\13exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\13exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\99exinjs.o.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\99exinjs.o.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\34exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\34exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\71exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\71exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\14exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\14exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\41exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\41exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\99exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\99exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\42exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\42exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\13exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\13exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\97exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\97exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\73exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\73exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\0exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\0exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\31exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\31exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\95exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\95exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\1exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\1exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\85exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\85exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\72exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\72exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\74exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\74exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\78exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\78exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\5exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\5exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\87exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\87exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\40exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\40exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\30exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\30exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\94exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\94exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\39exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\39exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\25exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\25exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\49exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\49exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\90exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\90exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\80exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\80exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\68exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\68exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\48exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\32exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\32exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\10exinjs.p.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\10exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\23exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\23exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\35exinjs.p.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\35exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\38exinjs.p.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\38exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\22exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\22exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exinjs.p.exe"="C:\\DOCUME~1\\KIMI@\\LOCALS~1\\Temp\\42exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\34exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\34exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\41exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\41exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\12exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\12exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\70exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\70exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\15exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\15exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\20exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\20exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\19exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\19exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\36exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\36exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\11exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\11exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\50exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\50exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\98exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\98exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\54exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\54exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\69exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\69exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\36exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\36exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\62exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\62exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\54exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\54exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\23exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\87exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\87exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\11exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\11exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\96exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\96exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\51exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\51exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\7exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\7exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\28exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\28exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\64exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\64exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\73exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\73exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\24exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\24exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\86exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\86exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\74exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\74exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\71exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\71exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\65exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\65exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\93exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\93exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\13exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\13exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\46exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\46exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\37exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\37exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\12exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\12exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\58exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\58exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\72exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\72exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\60exinjs.p.exe"="C:\\DOCUME~1\\QUENTIN\\LOCALS~1\\Temp\\60exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\55exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\55exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\38exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\38exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\40exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\40exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:µTorrent"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\2exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\2exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\49exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\49exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\5exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\5exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\84exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\84exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\44exinjs.p.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\44exinjs.p.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\60exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\1exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\1exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\65exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\65exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\91exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\91exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\41exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\41exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\68exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\68exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\5exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\5exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\71exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\71exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\22exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\22exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTI~1.CL-\\LOCALS~1\\Temp\\67exinjs.q.exe"="C:\\DOCUME~1\\QUENTI~1.CL-\\LOCALS~1\\Temp\\67exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\62exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\62exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTI~1.CL-\\LOCALS~1\\Temp\\99exinjs.q.exe"="C:\\DOCUME~1\\QUENTI~1.CL-\\LOCALS~1\\Temp\\99exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTI~1.CL-\\LOCALS~1\\Temp\\71exinjs.q.exe"="C:\\DOCUME~1\\QUENTI~1.CL-\\LOCALS~1\\Temp\\71exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\53exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\53exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\10exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\10exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\QUENTI~1.CL-\\LOCALS~1\\Temp\\72exinjs.q.exe"="C:\\DOCUME~1\\QUENTI~1.CL-\\LOCALS~1\\Temp\\72exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\59exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\59exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\74exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\74exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\0exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\0exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\12exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\12exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\80exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\80exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\15exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\15exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\64exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\64exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\56exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\56exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\67exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\11exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\11exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\99exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\99exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\39exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\39exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\95exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\95exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\51exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\51exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\38exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\38exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\87exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\87exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\97exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\97exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\40exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\40exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\8exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\8exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\66exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\66exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\3exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\3exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\Documents and Settings\\QuEnTiN.CL-B83CD58EF849\\Bureau\\TrackMania Sunrise Demo\\TmSunriseExtremeDemo.exe"="C:\\Documents and Settings\\QuEnTiN.CL-B83CD58EF849\\Bureau\\TrackMania Sunrise Demo\\TmSunriseExtremeDemo.exe:*:Enabled:TmSunriseExtremeDemo"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\50exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\50exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\7exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\7exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\19exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\19exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\28exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\28exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\46exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\46exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\18exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\18exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exinjs.q.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exinjs.q.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\17exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\40exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\40exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\54exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\54exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\63exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\63exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\99exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\99exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\73exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\73exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\10exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\10exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\13exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\13exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\38exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\38exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\69exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\69exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\83exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\37exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\97exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\97exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\16exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\11exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\11exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\35exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\79exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\72exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\72exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\15exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\15exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\42exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\61exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\76exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\26exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\68exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\68exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\0exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\0exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\48exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\48exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\87exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\87exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\88exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\88exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\33exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exinjs.r.exe"="C:\\DOCUME~1\\client\\LOCALS~1\\Temp\\21exinjs.r.exe:*:Enabled:Microsoft Update"
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"="C:\\Program Files\\IncrediMail\\bin\\ImLc.exe:*:Enabled:IncrediMail"
"C:\\Documents and Settings\\QuEnTiN.CL-B83CD58EF849\\Bureau\\skull tag\\skulltag.exe"="C:\\Documents and Settings\\QuEnTiN.CL-B83CD58EF849\\Bureau\\skull tag\\skulltag.exe:*:Enabled:ZDoom"
"C:\\Documents and Settings\\QuEnTiN.CL-B83CD58EF849\\Bureau\\logiciels\\skull tag\\skulltag.exe"="C:\\Documents and Settings\\QuEnTiN.CL-B83CD58EF849\\Bureau\\logiciels\\skull tag\\skulltag.exe:*:Enabled:ZDoom"
"C:\\Program Files\\Ubisoft\\XIII Demo Online\\System\\XIII.exe"="C:\\Program Files\\Ubisoft\\XIII Demo Online\\System\\XIII.exe:*:Enabled:XIII"
"C:\\DOCUME~1\\QUENTI~1.CL-\\LOCALS~1\\Temp\\win80.tmp.exe"="C:\\DOCUME~1\\QUENTI~1.CL-\\LOCALS~1\\Temp\\win80.tmp.exe:*:Enabled:win80.tmp"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"


Remaining Files:
---------------

Backups Folder: - C:\DOCUME~1\QUENTI~1.CL-\Bureau\SDFix\backups\backups.zip

Checking For Files with Hidden Attributes :

C:\NTDETECT.COM
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\Ma musique\teckno.com 2007 cd-1+cd-2 BY OZE\teckno.com 2007 cd-1 teckno BY OZE NEW\desktop.ini
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\Ma musique\teckno.com 2007 cd-1+cd-2 BY OZE\teckno.com 2007 cd-2 BY OZE housse mix‚ NEW\desktop.ini
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\Ma musique\teckno.com 2007 cd-1+cd-2 BY OZE\teckno.com 2007 cd-2 BY OZE housse mix‚ NEW\Album inconnu (06-12-2006 16-54-25)\desktop.ini
C:\WINDOWS\system32\avisynth.dll
C:\WINDOWS\system32\AVSredirect.dll
C:\WINDOWS\system32\cygwin1.dll
C:\WINDOWS\system32\cygz.dll
C:\WINDOWS\system32\i420vfw.dll
C:\WINDOWS\system32\Smab.dll
C:\WINDOWS\system32\yv12vfw.dll
C:\Program Files\Fichiers communs\Adobe\ESD\DLMCleanup.exe
C:\Program Files\RamBoost XP\StopRam.exe
C:\WINDOWS\meta4.exe
C:\WINDOWS\MOTA113.exe
C:\WINDOWS\x2.64.exe
C:\WINDOWS\system32\cdplayer.exe.manifest
C:\WINDOWS\system32\logonui.exe.manifest
C:\WINDOWS\system32\x.264.exe
C:\hiberfil.sys
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\WINDOWS\system32\KGyGaAvL.sys
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\6e9c42a1e895ff016ed3a8bb3a107218\BITAD.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\eabe1622973d561afb591ab24f972644\download\BIT5FE.tmp

Finished

Répondre à enjoii89

ET HI JACKTHIS :
Logfile of HijackThis v1.99.1
Scan saved at 18:55:30, on 17/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Fichiers communs\DriveCleaner 2006 Free\SDRmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\udial.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\TEMP\winA.tmp.exe
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\HijackThis\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2810AAE0-EDAA-41F6-86F3-FF420FF9052F} - C:\WINDOWS\system32\urqqqpo.dll (file missing)
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
O2 - BHO: (no name) - {57A62825-840C-4FFE-8717-80A308558154} - C:\WINDOWS\system32\qomnlif.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\nhytwhcv.dll (file missing)
O2 - BHO: (no name) - {B01878F3-156E-47BC-832B-A2E133D7E458} - C:\WINDOWS\system32\jkkji.dll
O2 - BHO: (no name) - {F1CFED7F-EED0-4D42-9313-56A78DC475B2} - C:\WINDOWS\system32\vturq.dll (file missing)
O2 - BHO: (no name) - {FE4FDF23-7EBC-45F9-B1E3-71B334CF01F9} - C:\WINDOWS\system32\vturq.dll (file missing)
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [WinLiveUpdate] C:\Program Files\Fichiers communs\Microsoft Shared\DAO\svchost.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [SDR6V_Check] "C:\Program Files\Fichiers communs\DriveCleaner 2006 Free\SDRmon.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ncicmfyu.dll",setvm
O4 - HKLM\..\Run: [UDial] C:\WINDOWS\system32/udial.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzShadow\YzShadow.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {42E1F024-ECC3-456F-B98A-4CE5ACDBF25C} (ActiveFormX Contrôle) - https://ssl-tb.sitadelle.com/selfca [...] Config.ocx
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/bina [...] b32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: jkkji - C:\WINDOWS\system32\jkkji.dll
O20 - Winlogon Notify: qomnlif - C:\WINDOWS\SYSTEM32\qomnlif.dll
O20 - Winlogon Notify: winepi32 - C:\WINDOWS\SYSTEM32\winepi32.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe

Répondre à enjoii89

re, :)
garde sdfix pour le moment
on s'occupe du pe386
1

~Télécharge rusbfix (par ejvindh)

http://www.uploads.ejvindh.net/rustbfix.exe
Sauvegarde -le sur ton Bureau.
Double clique rustbfix.exe afin de lancer l'outil.

~Note :Si une infection Rustock.b est détectée, une invite t'indiquera qu'il est nécessaire de redémarrer ton PC. Ce redémarrage pourrait être plus long que d'habitude, et il est possible que deux redémarrages soient requis. Tout cela se fera automatiquement.
Suite au(x) redémarrage(s), deux rapports s'ouvriront : (%root%\avenger.txt & %root%\rustbfix\pelog.txt).

~Poste (Copie/Colle) le contenu de ces deux rapports, ainsi qu'un nouveau log smitfraud dans ta prochaine réponse.

2

~Télécharge. F-Secure Blacklight
https://europe.f-secure.com/exclude [...] blbeta.exe


- Lance F-Secure Blacklight (fichier blbeta.exe)
- Accepte la licence, et clique enfin sur "Scan" puis Next et Exit.
- Un rapport fsbl-bxxxx.log (xx sont des chiffres) va être créé dans le même dossier que blbeta.exe
- Ouvre fsbl-bxxxx.log , fais un copier/coller dans ton prochain message.

Attention ! .
Il ne faut pas choisir l'option "Rename". de suite : nous devons analyser le rapport, car des fichiers légitimes peuvent être présents, tel wbemtest.exe .
Tuto de F-Secure BlackLight : (merci à Malekal) .
http://www.malekal.com/tutorial_f- [...] Light.html




Répondre à Sham_Rock

VOICI CE QUE TU M'AS DEMANDE EN PREMIER

COMPTES RENDUS

AVENGER

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\seimmujc

*******************

Script file located at: \??\C:\WINDOWS\system32\uluubbds.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Driver PE386 unloaded successfully.
Program C:\Rustbfix\2run.bat successfully set up to run once on reboot.

Completed script processing.

*******************

Finished! Terminate.

PELOG

************************* Rustock.b-fix -- By ejvindh *************************
17/01/2007 20:27:03,15

******************* Pre-run Status of system *******************

Rootkit driver PE386 is found. Starting the unload-procedure....

Rustock.b-ADS attached to the System32-folder:
No streams found.

Looking for Rustock.b-files in the System32-folder:
system32\lzx32.sys FOUND!
attempting to delete lzx32.sys from system32-folder


******************* Post-run Status of system *******************

Rustock.b-driver on the system: NONE!

Rustock.b-ADS attached to the System32-folder:
No System32-ADS found.

Looking for Rustock.b-files in the System32-folder:
No Rustock.b-files found in system32


******************************* End of Logfile ********************************


Message édité par enjoii89 le 17-01-2007 à 20:36:00
Répondre à enjoii89

smitfraud

SmitFraudFix v2.132

Rapport fait à 20:33:59,79, 17/01/2007
Executé à partir de C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\QUENTI~1.CL-\Favoris


»»»»»»»»»»»»»»»»»»»»»»»» Bureau


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues


»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


»»»»»»»»»»»»»»»»»»»»»»»» Fin

Répondre à enjoii89

ok, c'est mieux mais pas fini...
continue ( avec blacklight)
puis:
~Redémarre l'ordinateur en mode sans échec (F8 au démarrage de l'ordinateur)
http://www.malekal.com/modesansechec.php

~Double clique sur smitfraudfix.cmd
~Sélectionne 2 et presse Entrée dans le menu pour supprimer les fichiers responsables de l'infection.
~Réponds Oui (o) à toutes les questions.
Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage.
~Poste le nouveau rapport ainsi qu'un nouveau rapport Hijackthis

Répondre à Sham_Rock

BLACKLIGHT

01/17/07 20:42:12 [Info]: BlackLight Engine 1.0.55 initialized
01/17/07 20:42:12 [Info]: OS: 5.1 build 2600 (Service Pack 2)
01/17/07 20:42:12 [Note]: 7019 4
01/17/07 20:42:12 [Note]: 7005 0
01/17/07 20:42:18 [Note]: 7006 0
01/17/07 20:42:18 [Note]: 7011 1784
01/17/07 20:42:18 [Note]: 7026 0
01/17/07 20:42:18 [Note]: 7026 0
01/17/07 20:42:27 [Note]: FSRAW library version 1.7.1021
01/17/07 20:48:06 [Note]: 4013 20696
01/17/07 20:48:06 [Note]: 4020 29 65536
01/17/07 20:48:06 [Note]: 4018 29 65536
01/17/07 20:49:38 [Note]: 2000 1012
01/17/07 20:49:38 [Note]: 2000 1012
01/17/07 21:17:17 [Note]: 7007 0

Répondre à enjoii89

Je fais ce que tu m'as demandé maintenan.

Répondre à enjoii89

SMITFRAUD

SmitFraudFix v2.132

Rapport fait à 21:24:49,76, 17/01/2007
Executé à partir de C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode sans echec

»»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés


»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

Nettoyage terminé.

»»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» Fin


HIJACKSTHIS

Logfile of HijackThis v1.99.1
Scan saved at 21:32:06, on 17/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Fichiers communs\DriveCleaner 2006 Free\SDRmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\udial.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\HijackThis\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2810AAE0-EDAA-41F6-86F3-FF420FF9052F} - C:\WINDOWS\system32\urqqqpo.dll (file missing)
O2 - BHO: (no name) - {38F4A92E-A670-4CB1-8A99-BBDFD14CE914} - C:\WINDOWS\system32\jkkji.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
O2 - BHO: (no name) - {57A62825-840C-4FFE-8717-80A308558154} - C:\WINDOWS\system32\qomnlif.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\nhytwhcv.dll (file missing)
O2 - BHO: (no name) - {F1CFED7F-EED0-4D42-9313-56A78DC475B2} - C:\WINDOWS\system32\vturq.dll (file missing)
O2 - BHO: (no name) - {FE4FDF23-7EBC-45F9-B1E3-71B334CF01F9} - C:\WINDOWS\system32\vturq.dll (file missing)
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [WinLiveUpdate] C:\Program Files\Fichiers communs\Microsoft Shared\DAO\svchost.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [SDR6V_Check] "C:\Program Files\Fichiers communs\DriveCleaner 2006 Free\SDRmon.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ncicmfyu.dll",setvm
O4 - HKLM\..\Run: [UDial] C:\WINDOWS\system32/udial.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzShadow\YzShadow.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {42E1F024-ECC3-456F-B98A-4CE5ACDBF25C} (ActiveFormX Contrôle) - https://ssl-tb.sitadelle.com/selfca [...] Config.ocx
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/bina [...] b32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: jkkji - C:\WINDOWS\system32\jkkji.dll
O20 - Winlogon Notify: qomnlif - C:\WINDOWS\SYSTEM32\qomnlif.dll
O20 - Winlogon Notify: winepi32 - C:\WINDOWS\SYSTEM32\winepi32.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe


Alors docteur ? ;)

Répondre à enjoii89

alors ça devient bon,
maintenant il faut que je rédige le fix à la main,
30 à 45mn ;)

Répondre à Sham_Rock

OK ok travail bien alr ;)
t'es trop simpas c gentil de m'aider :)

mais tu peux prendre ton temps pour "rédiger le fix" car je vais aller me coucher donc je retourne sur le pc demain vers 18-19h

voila bonne soirée !!

ps: poste moi d'autres consignes si il y en a et je les fait dès que je
rentre :jap:


Message édité par enjoii89 le 17-01-2007 à 21:46:04
Répondre à enjoii89

re,
à toi de jouer ;)

Imprime ou sauvegarde cette procédure sur ton bureau car une bonne partie de ton travail est à faire en mode sans échec. (tu n’auras alors pas accès au net pendant ce temps).Si tu ne comprends pas quelque-chose, dis-le moi.


Etape 1

~Télécharge AVG anti-spyware.
http://www.ewido.net/en/download/
~Mets le à jour. en cliquant sur le bouton mise à jour dans le menu du haut.

Etape 2

~Redémarre en mode sans échec
(f8 au démarrage de ton pc)
http://www.malekal.com/modesansechec.php
~Désinstalle si possible :
Les programmes:
-Boonty Games
-DriveCleaner 2006
-VSAdd-in

~Lance Hijackthis “Do a system scan only”.
Coche les lignes qui suivent si encore présentes et uniquement celles-là.

O2 - BHO: (no name) - {2810AAE0-EDAA-41F6-86F3-FF420FF9052F} - C:\WINDOWS\system32\urqqqpo.dll (file missing)

O2 - BHO: (no name) - {38F4A92E-A670-4CB1-8A99-BBDFD14CE914} - C:\WINDOWS\system32\jkkji.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
O2 - BHO: (no name) - {57A62825-840C-4FFE-8717-80A308558154} - C:\WINDOWS\system32\qomnlif.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\nhytwhcv.dll (file missing)
O2 - BHO: (no name) - {F1CFED7F-EED0-4D42-9313-56A78DC475B2} - C:\WINDOWS\system32\vturq.dll (file missing)
O2 - BHO: (no name) - {FE4FDF23-7EBC-45F9-B1E3-71B334CF01F9} - C:\WINDOWS\system32\vturq.dll (file missing)
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
O4 - HKLM\..\Run: [SDR6V_Check] "C:\Program Files\Fichiers communs\DriveCleaner 2006 Free\SDRmon.exe"
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ncicmfyu.dll",setvm
O4 - HKLM\..\Run: [UDial] C:\WINDOWS\system32/udial.exe
O16 - DPF: {42E1F024-ECC3-456F-B98A-4CE5ACDBF25C} (ActiveFormX Contrôle) - https://ssl-tb.sitadelle.com/selfca [...] Config.ocx
O20 - Winlogon Notify: jkkji - C:\WINDOWS\system32\jkkji.dll
O20 - Winlogon Notify: qomnlif - C:\WINDOWS\SYSTEM32\qomnlif.dll
O20 - Winlogon Notify: winepi32 - C:\WINDOWS\SYSTEM32\winepi32.dll


O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe

Clique sur Fix checked (en bas à gauche)

Tu cliques sur démarrer : executer/services.msc , type de démarrage désactivé puis tu arrêtes ces lignes de service :
Boonty Games - BOONTY, et "type de démarrage" sur arrêter.



Etape 3

Ensuite tu n'a plus qu'à supprimer les fichiers et les dossiers.

~Supprime
Les fichiers en gras qui suivent si encore présents, ils se trouvent sûrement dans les emplacements indiqués :

C:\WINDOWS\system32\jkkji.dll
C:\WINDOWS\system32\qomnlif.dll
C:\WINDOWS\system32\ncicmfyu.dll
C:\WINDOWS\system32/udial.exe
C:\WINDOWS\SYSTEM32\winepi32.dll


~Supprime les dossiers en gras :

C:\Program Files\Fichiers communs\BOONTY Shared
C:\Program Files\Fichiers communs\DriveCleaner 2006 Free


Note :

Citation :

Pour afficher les dossiers et fichiers cachés du système :
Panneau de configuration/Options des dossiers/onglet Affichage/cocher Afficher les fichiers et dossiers cachés, décocher Masquer les extensions de fichiers connus, décocher Masquer les fichiers protégés du Système.


Les fichiers et dossiers cachés du système apparaissent alors dans l'explorateur Windows en transparence.


Etape 4


Lance AVG :

~Dans l’onglet analyse, dans Paramètre, clique sur Actions recommandées : choisis Quarantaine.
~Clique sur Analyse puis Analyse complète du système pour commencer le scan.

~Une fois que le scan est terminé, clique sur Appliquer toutes les actions, pour supprimer tous les fichiers infectés trouvés par AVG Anti-Spyware.

~Une fois que la suppression des fichiers infectés a été faite, clique sur enregistrer le rapport et sauvegarde-le sur le bureau.
TutoAVG antispyware : (merci à Malekal) .
http://www.malekal.com/tutorial_AVG_AntiSpyware.html

Etape 5

~Redémarre normalement

cache à nouveau les fichiers pour te protéger.

Citation :


Panneau de configuration/Options des dossiers/onglet Affichage/décocher Afficher les fichiers et dossiers cachés, [/b]cocher Masquer les fichiers protégés du Système.


Tu garderas :Masquer les extensions de fichiers connus, décocher.

~Nous allons maintenant sécuriser ton ordinateur en installant un pare-feu. Je te propose ces logiciels :
Le pare-feu :zone alarm que tu peux télécharger ici http://www.zonelabs.com/store/cont [...] lid=nav_za
Tuto pour zone alarm http://www.malekal.com/tutorial_zonealarm.php
ou
Le pare-feu :Kerio que tu peux télécharger ici
http://www.sunbelt-software.com/ev [...] /kerio.exe

Tuto pour Kerio : http://www.malekal.com/kerio_firewall.php




poste-nous le rapport avg et un nouveau log Hijackthis

Bon courage :D

Répondre à Sham_Rock

Salut
j'ai fait ce que tu m'as demandé mais je n'ai pas pu supprimer ces fichiers
C:\WINDOWS\system32\jkkji.dll
C:\WINDOWS\system32\qomnlif.dll
C:\WINDOWS\system32\ncicmfyu.dll
C:\WINDOWS\system32/udial.exe
C:\WINDOWS\SYSTEM32\winepi32.dll

car l'acces était refusé.


Voici les rapports d'analyse de avg :


---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 20:40:07 18/01/2007

+ Résultat de l'analyse:



C:\WINDOWS\Temp\win4E.tmp.exe -> Adware.Universa : Nettoyé.
C:\WINDOWS\Temp\win5C7.tmp.exe -> Adware.Universa : Nettoyé.
C:\WINDOWS\Temp\win5E1.tmp.exe -> Adware.Universa : Nettoyé.
C:\WINDOWS\Temp\win90.tmp.exe -> Adware.Universa : Nettoyé.
C:\WINDOWS\Temp\winA.tmp.exe -> Adware.Universa : Nettoyé.
C:\WINDOWS\Temp\winAE.tmp.exe -> Adware.Universa : Nettoyé.
C:\System Volume Information\_restore{FD6630C4-736A-4E19-A8EC-C3F18C035346}\RP468\A0198013.exe -> Adware.WinFixer : Nettoyé.
C:\WINDOWS\Temp\idd18.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd19.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd3.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd31.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd480.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd4AE.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd574.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd595.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5B4.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5B5.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5BC.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5BE.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5C1.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5CF.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5D1.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5DB.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5E5.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5E8.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5EB.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd5EF.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd601.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd635.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd640.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd649.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd66F.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd69F.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd6D2.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\iddC8.tmp.exe -> Dialer.Agent.z : Nettoyé.
C:\WINDOWS\Temp\idd14.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd1A.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd2.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd42A.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd43B.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd448.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd454.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd5B6.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd5BF.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd5C2.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd5C6.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd5CA.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd5D2.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd5DF.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd5E6.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd5EA.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd5F0.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd6.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd602.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd615.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd637.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd697.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd7.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\idd7D.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\iddB5.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\iddE.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\iddE6.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\WINDOWS\Temp\iddF.tmp.exe -> Dialer.IDialer.m : Nettoyé.
C:\System Volume Information\_restore{FD6630C4-736A-4E19-A8EC-C3F18C035346}\RP462\A0189208.exe -> Downloader.Small.edb : Nettoyé.
C:\System Volume Information\_restore{FD6630C4-736A-4E19-A8EC-C3F18C035346}\RP462\A0191050.exe -> Hijacker.Costrat.ae : Nettoyé.
C:\RECYCLER\S-1-5-21-823518204-1801674531-682003330-1003\Dc5.exe -> Not-A-Virus.Downloader.Win32.WinFixer.m : Nettoyé.
C:\System Volume Information\_restore{FD6630C4-736A-4E19-A8EC-C3F18C035346}\RP462\A0189204.exe -> Proxy.Agent.lu : Nettoyé.
C:\WINDOWS\system32\winepi32.dll -> Proxy.Agent.lu : Nettoyé.
:mozilla.18:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.19:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.20:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.50:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.25:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.26:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.32:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.33:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.34:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.35:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.31:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Cookies\quentin@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Cookies\quentin@bfast[2].txt -> TrackingCookie.Bfast : Nettoyé.
:mozilla.15:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Cookies\quentin@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Nettoyé.
C:\Documents and Settings\client\Cookies\client@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.36:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.83:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.117:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.119:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Cookies\quentin@linksynergy[2].txt -> TrackingCookie.Linksynergy : Nettoyé.
:mozilla.37:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Cookies\quentin@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Cookies\quentin@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Nettoyé.
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Cookies\quentin@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.106:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.107:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.108:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.109:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.110:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.112:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.12:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.13:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.14:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.21:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.22:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.23:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.24:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.44:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.45:C:\Documents and Settings\client\Application Data\Mozilla\Firefox\Profiles\l244irhy.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\System Volume Information\_restore{FD6630C4-736A-4E19-A8EC-C3F18C035346}\RP463\A0191129.dll -> Trojan.Agent.acl : Nettoyé.
C:\System Volume Information\_restore{FD6630C4-736A-4E19-A8EC-C3F18C035346}\RP463\A0191209.dll -> Trojan.Agent.acl : Nettoyé.
C:\System Volume Information\_restore{FD6630C4-736A-4E19-A8EC-C3F18C035346}\RP463\A0192438.dll -> Trojan.Agent.acl : Nettoyé.
C:\System Volume Information\_restore{FD6630C4-736A-4E19-A8EC-C3F18C035346}\RP465\A0196662.dll -> Trojan.Agent.acl : Nettoyé.
C:\VundoFix Backups\VSAdd-in.dll.bad -> Trojan.Agent.acl : Nettoyé.
C:\System Volume Information\_restore{FD6630C4-736A-4E19-A8EC-C3F18C035346}\RP466\A0197757.sys -> Trojan.Rustock.nbh : Nettoyé.

Fin du rapport


HIJACKTHIS


Logfile of HijackThis v1.99.1
Scan saved at 20:52:03, on 18/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\udial.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\HijackThis\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {10B735B1-B92E-4EDB-A185-BD360D0FD1E7} - C:\WINDOWS\system32\jkkji.dll
O2 - BHO: (no name) - {57A62825-840C-4FFE-8717-80A308558154} - C:\WINDOWS\system32\qomnlif.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [WinLiveUpdate] C:\Program Files\Fichiers communs\Microsoft Shared\DAO\svchost.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [UDial] C:\WINDOWS\system32/udial.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzShadow\YzShadow.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/bina [...] b32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: jkkji - C:\WINDOWS\system32\jkkji.dll
O20 - Winlogon Notify: qomnlif - C:\WINDOWS\SYSTEM32\qomnlif.dll
O20 - Winlogon Notify: winepi32 - winepi32.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe


Voila ;)
J'ai malgrès tout encore des pages qui s'affichent. :(
En attendant de nouvelles instructions. ;)

Répondre à enjoii89

re,
tu as "oublié" d'installer le pare-feu. c'est indispensable si tu ne veux pas te faire réinfecter...

1. Télécharge ce fichier Combofix.exe
2. et sauvegarde le sur ton bureau et pas ailleurs !
3.
4. Clique sur le menu Démarrer puis Exécuter et copie/colle ceci :
5. "%userprofile%\Bureau\combofix.exe" /v jkkji qomnlif
6. puis clic sur OK.
7.
8. Suis les invites.
9.
10. Ne touche a rien et attends que combofix ait terminé, un rapport sera créé. Poste le rapport.

Répondre à Sham_Rock

Ok je ferais tout cela ce soir mais pour le pare feu je suis embeté il y en a un qui est en anglais et l'autre ne marche pas ...

Répondre à enjoii89

re, kerio, c'est l'anglais, par contre il est plus léger que zone alarm.
pour zone alarm tu peux essayer ici. On reste sur le site de l'éditeur pour le téléchargement.
http://www.zonelabs.com/store/cont [...] lid=nav_za

tu posteras aussi un rapport hijackthis après avoir utilisé combofix.stp

Répondre à Sham_Rock

Hey !
Voila j'ai installé ZoneAlarm et j'ai fait ce qu'il fallait faire avec combofix.

COMBOFIX

"QuEnTiN" - 07-01-19 19:34:19 Service Pack 2
ComboFix 07-01-18 - Running from: "C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau"
Command switches used :: /v jkkji qomnlif

(((((((((((((((((((((((((((((((((((((((((((((((( Vundo Log )))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\jkkji.dll
C:\WINDOWS\system32\qomnlif.dll
C:\WINDOWS\system32\ijkkj.bak1
C:\WINDOWS\system32\ijkkj.bak2
C:\WINDOWS\system32\ijkkj.ini
C:\WINDOWS\system32\ijkkj.ini2


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\QUENTI~1.CL-\Application Data\SearchToolbarCorp
C:\Program Files\VSAdd-in


((((((((((((((((((((((((((((((( Files Created from 2006-12-19 to 2007-01-19 ))))))))))))))))))))))))))))))))))


2007-01-19 19:39 88,340 --a------ C:\WINDOWS\system32\gfarwfsa.exe
2007-01-19 19:39 <REP> d-------- C:\WINDOWS\erdnt
2007-01-19 19:39 <REP> d-------- C:\Program Files\VSAdd-in
2007-01-19 19:39 <REP> d-------- C:\DOCUME~1\QUENTI~1.CL-\Application Data\SearchToolbarCorp
2007-01-19 19:06 42,920 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2007-01-19 19:04 <REP> d-------- C:\WINDOWS\system32\ZoneLabs
2007-01-19 19:03 <REP> d-------- C:\WINDOWS\Internet Logs
2007-01-19 18:31 76,412 --a------ C:\WINDOWS\system32\fioynxen.dll
2007-01-19 18:18 76,412 --a------ C:\WINDOWS\system32\rxegmigr.dll
2007-01-18 20:42 <REP> d-------- C:\Program Files\msn gaming zone
2007-01-18 19:53 37,376 --a------ C:\WINDOWS\system32\udial.exe
2007-01-18 18:38 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-18 18:38 <REP> d-------- C:\Program Files\Grisoft
2007-01-18 17:52 <REP> d-------- C:\Program Files\Samsung
2007-01-17 20:33 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-01-17 20:33 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-01-17 20:33 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-01-17 20:33 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-01-17 20:33 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-01-17 20:33 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-01-17 20:31 <REP> d-------- C:\avenger
2007-01-17 20:27 <REP> d-------- C:\Rustbfix
2007-01-17 18:18 76,412 --a------ C:\WINDOWS\system32\fankylhb.dll
2007-01-17 18:18 118,804 --a------ C:\WINDOWS\system32\ncicmfyu.dll
2007-01-17 17:58 3,446 --a------ C:\WINDOWS\system32\tmp.reg
2007-01-17 17:52 <REP> d-------- C:\SDFix
2007-01-17 16:59 <REP> d-------- C:\VundoFix Backups
2007-01-16 19:35 88,340 --a------ C:\WINDOWS\system32\isqchncj.exe
2007-01-16 17:26 94,424 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-01-16 17:26 90,112 --a------ C:\WINDOWS\system32\AVASTSS.scr
2007-01-16 17:26 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-01-16 17:26 689,280 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-01-16 17:26 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-01-16 17:26 31,560 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-01-16 17:26 23,352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-01-16 16:57 <REP> d-------- C:\Program Files\Internet Cleaner
2007-01-16 13:23 76,412 --a------ C:\WINDOWS\system32\umonuqsx.dll
2007-01-15 11:46 <REP> d-------- C:\DOCUME~1\client\Application Data\SearchToolbarCorp
2007-01-12 17:01 <REP> d-------- C:\Program Files\Eurobarre
2007-01-07 14:46 <REP> d-------- C:\Program Files\Rockstar Games
2007-01-05 15:23 <REP> d-------- C:\WINDOWS\PreviewSoft
2007-01-05 15:22 49,152 --a------ C:\WINDOWS\system32\INETWH32.dll
2007-01-05 15:22 1,056,768 --a------ C:\WINDOWS\system32\ROBOEX32.DLL
2007-01-05 15:22 <REP> d-------- C:\Program Files\Ulead Systems
2007-01-04 20:50 261,120 --a------ C:\WINDOWS\dbplugin.exe
2007-01-03 14:57 7,552 --a------ C:\WINDOWS\system32\drivers\enodpl.sys
2007-01-03 14:57 4,736 --a------ C:\WINDOWS\system32\drivers\tandpl.sys
2007-01-03 09:38 <REP> d-------- C:\Program Files\TrackMania Nations ESWC
2006-12-25 22:01 <REP> d-------- C:\Program Files\VirtualDJ
2006-12-24 12:56 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2006-12-23 17:12 <REP> d-------- C:\Program Files\Easy Gif Animator Extension
2006-12-23 17:10 <REP> d-------- C:\Multimedia Files
2006-12-23 11:07 <REP> d-------- C:\Program Files\Project64 v1.5


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-19 19:39 -------- d-------- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\searchtoolbarcorp
2007-01-19 19:32 -------- d-------- C:\Program Files\mozilla firefox
2007-01-19 17:23 -------- d-------- C:\Program Files\emule
2007-01-18 18:57 -------- d---s---- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\microsoft
2007-01-18 18:49 -------- d--h----- C:\Program Files\installshield installation information
2007-01-18 18:49 -------- d-------- C:\Program Files\ubisoft
2007-01-18 18:48 -------- d-------- C:\Program Files\windows nt
2007-01-17 16:18 -------- d-------- C:\Program Files\ramboost xp
2007-01-14 15:51 -------- d-------- C:\Program Files\quicktime
2006-12-12 20:25 -------- d-------- C:\Program Files\messenger plus! live
2006-12-11 17:44 -------- d-------- C:\Program Files\java
2006-12-11 17:43 -------- d-------- C:\Program Files\google
2006-12-10 20:22 -------- d-------- C:\Program Files\free audio pack
2006-12-10 19:38 -------- d-------- C:\Program Files\atomixmp3
2006-12-10 19:22 -------- d-------- C:\Program Files\incredimail
2006-12-10 19:15 51972 --a------ C:\WINDOWS\bricopackuninst.cmd
2006-12-10 19:15 3087 --a------ C:\WINDOWS\bricopackfoldersdelete.cmd
2006-12-10 19:15 219648 --a------ C:\WINDOWS\system32\uxtheme.dll
2006-12-07 17:35 -------- d-------- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\adobeum
2006-12-07 06:29 2374472 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-12-02 22:18 -------- d-------- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\utorrent
2006-12-02 21:01 -------- d-------- C:\Program Files\photofiltre
2006-12-02 18:55 -------- d-------- C:\Program Files\windows live safety center
2006-12-02 18:53 -------- d-------- C:\Program Files\msn messenger
2006-12-02 12:07 -------- d-------- C:\Program Files\sld codec pack
2006-11-29 18:02 -------- d-------- C:\Program Files\pspvideo9
2006-11-29 18:01 -------- d-------- C:\Program Files\avisynth 2.5
2006-11-29 17:43 -------- d-------- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\adobe
2006-11-27 19:18 -------- d-------- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\ahead
2006-11-26 21:26 -------- d-------- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\divx
2006-11-26 21:00 -------- d-------- C:\Program Files\divx
2006-11-24 21:18 -------- d-------- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\apple computer
2006-11-19 20:52 -------- d-------- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\macromedia
2006-11-19 20:47 -------- d-------- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\talkback
2006-11-19 20:45 -------- d-------- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\mozilla
2006-11-19 20:44 -------- d-------- C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Application Data\identities
2006-11-19 20:24 -------- d-------- C:\Program Files\utorrent
2006-11-19 15:41 -------- d-------- C:\Program Files\alwil software
2006-11-08 06:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-10-20 02:38 716800 --a------ C:\WINDOWS\system32\sxs.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMan"="SOUNDMAN.EXE"
"nForce Tray Options"="sstray.exe /r"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"ISUSPM Startup"="C:\\PROGRA~1\\FICHIE~1\\INSTAL~1\\UPDATE~1\\isuspm.exe -startup"
"ISUSScheduler"="\"C:\\Program Files\\Fichiers communs\\InstallShield\\UpdateService\\issch.exe\" -start"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Labtec\\Mouse\\2.1\\moffice.exe"
"WinLiveUpdate"="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\DAO\\svchost.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"SDR6V_Check"="\"C:\\Program Files\\Fichiers communs\\DriveCleaner 2006 Free\\SDRmon.exe\""
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"DllRunning"="rundll32.exe \"C:\\WINDOWS\\system32\\ncicmfyu.dll\",setvm"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{2810AAE0-EDAA-41F6-86F3-FF420FF9052F}"=""

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winepi32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G]
Shell\AutoRun\command G:\Install.exe


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 2100 series#1134835033.job

Completion time: 07-01-19 19:44:18


HIJACKTHIS

Logfile of HijackThis v1.99.1
Scan saved at 19:48:05, on 19/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\UberIcon\UberIcon Manager.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzShadow\YzShadow.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\HijackThis\scanner.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2810AAE0-EDAA-41F6-86F3-FF420FF9052F} - C:\WINDOWS\system32\urqqqpo.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\nhytwhcv.dll (file missing)
O2 - BHO: (no name) - {F1CFED7F-EED0-4D42-9313-56A78DC475B2} - C:\WINDOWS\system32\vturq.dll (file missing)
O2 - BHO: (no name) - {FE4FDF23-7EBC-45F9-B1E3-71B334CF01F9} - C:\WINDOWS\system32\vturq.dll (file missing)
O3 - Toolbar: (no name) - {74DD705D-6834-439C-A735-A6DBE2677452} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [WinLiveUpdate] C:\Program Files\Fichiers communs\Microsoft Shared\DAO\svchost.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [SDR6V_Check] "C:\Program Files\Fichiers communs\DriveCleaner 2006 Free\SDRmon.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ncicmfyu.dll",setvm
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzShadow\YzShadow.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {42E1F024-ECC3-456F-B98A-4CE5ACDBF25C} (ActiveFormX Contrôle) - https://ssl-tb.sitadelle.com/selfca [...] Config.ocx
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/bina [...] b32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: winepi32 - winepi32.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Répondre à enjoii89

re,
on continue :) :

1

~ Télécharge Killbox et installe-le sur ton bureau.
http://www.downloads.subratam.org/KillBox.zip
~Copie le texte ci-bas (sélectionne-le en entier avec ta souris, puis fais un clic-droit dessus et choisis "Copier" ) :

Citation :

C:\WINDOWS\system32\gfarwfsa.exe
C:\WINDOWS\system32\fioynxen.dll
C:\WINDOWS\system32\rxegmigr.dll
C:\WINDOWS\system32\fankylhb.dll
C:\WINDOWS\system32\ncicmfyu.dll
C:\WINDOWS\system32\isqchncj.exe
C:\WINDOWS\system32\umonuqsx.dll
C:\WINDOWS\system32\udial.exe




~Ouvre Killbox:
~Clique sur le menu "File" de KillBox (en haut à gauche) et choisis l'option « Paste from clipboard ».
~Sous "Full Path Of File To Delete" les fichiers viennent de s'inscrire: il faut t'en assurer en cliquant sur la petite flèche à droite!
~Coche les cases : "Delete on Reboot" & "Unregister Dll Before Deleting" .
~Une fois le bouton radio "Delete on Reboot" coché, la case "Single File" va clignoter: clique sur la case "All Files".
~Clique sur la croix blanche sur fond rouge , au message suivant qui va s'afficher:
Citation:

« File will be Removed on Reboot, Do you want to reboot now ? » : répondre YES Le PC va redémarrer et supprimer le fichier de la liste. Sinon redémarre manuellement.

~Une fois que tu auras redémarré, relance Killbox. Clique sur Menu "File" /"Logs" /"Actions History Log". Poste-nous ce rapport.

Tuto Killbox
http://perso.orange.fr/jesses/Docs [...] illBox.htm

2

supprime le dossier:
C:\Program Files\Eurobarre

3

Télécharge sur ton bureau : http://www.malekal.com/download/clean.zip
Une fois sur le bureau, tu fais un clic droit sur ton fichier clean.zip et dans le menu déroulant, tu clics sur extrait tout ou extraire ici.
Cela va créer un dossier clean.
Double-clic sur ce dossier clean, tu y trouveras dedans plusieurs fichiers.
Double-clic sur clean. Cela va ouvrir une fenêtre noire.
Un menu va apparaître, choisis l'option 1 en appuyant sur la touche 1 de ton clavier.
Clean va travailler.
Un rapport Va etre généré, colle le contenu entier ici.

Répondre à Sham_Rock

Voila pour Killbox par contre je n'ai pa pu cocher la case : "Unregister Dll Before Deleting" qui était grisée et impossible de la dégriser.

Killbox

Pocket Killbox version 2.0.0.648
Running on Windows XP as QuEnTiN(Administrator)
was started @ samedi, janvier 20, 2007, 6:42 AM

# 1 [Delete on Reboot]
Path = C:\WINDOWS\system32\gfarwfsa.exe


# 2 [Delete on Reboot]
Path = C:\WINDOWS\system32\fioynxen.dll


# 3 [Delete on Reboot]
Path = C:\WINDOWS\system32\rxegmigr.dll


# 4 [Delete on Reboot]
Path = C:\WINDOWS\system32\fankylhb.dll


# 5 [Delete on Reboot]
Path = C:\WINDOWS\system32\ncicmfyu.dll


# 6 [Delete on Reboot]
Path = C:\WINDOWS\system32\isqchncj.exe


# 7 [Delete on Reboot]
Path = C:\WINDOWS\system32\umonuqsx.dll


# 8 [Delete on Reboot]
Path = C:\WINDOWS\system32\udial.exe


I Rebooted @ 6:46:59 AM
Killbox Closed(Exit) @ 6:47:01 AM
__________________________________________________

Pocket Killbox version 2.0.0.648
Running on Windows XP as QuEnTiN(Administrator)
was started @ samedi, janvier 20, 2007, 6:50 AM

Killbox Closed(Exit) @ 6:50:30 AM
__________________________________________________

Pocket Killbox version 2.0.0.648
Running on Windows XP as QuEnTiN(Administrator)
was started @ samedi, janvier 20, 2007, 6:52 AM



J'ai supprimé eurobarre



CLEAN

Rapport clean par Malekal_morte - http://www.malekal.com
Option 1, executee le 20/01/2007 a 6:54:51,87

*** Recherche de fichiers sur C:

*** Recherche des fichiers dans C:\WINDOWS\

*** Recherche des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system32\bdod.bin FOUND

"C:\Program Files\VSAdd-in\" FOUND
*** Fin du rapport !


HIJACKTHIS

Logfile of HijackThis v1.99.1
Scan saved at 06:56:39, on 20/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\QuEnTiN.CL-B83CD58EF849\Bureau\HijackThis\scanner.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2810AAE0-EDAA-41F6-86F3-FF420FF9052F} - C:\WINDOWS\system32\urqqqpo.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\nhytwhcv.dll (file missing)
O2 - BHO: (no name) - {F1CFED7F-EED0-4D42-9313-56A78DC475B2} - C:\WINDOWS\system32\vturq.dll (file missing)
O2 - BHO: (no name) - {FE4FDF23-7EBC-45F9-B1E3-71B334CF01F9} - C:\WINDOWS\system32\vturq.dll (file missing)
O3 - Toolbar: (no name) - {74DD705D-6834-439C-A735-A6DBE2677452} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [WinLiveUpdate] C:\Program Files\Fichiers communs\Microsoft Shared\DAO\svchost.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [SDR6V_Check] "C:\Program Files\Fichiers communs\DriveCleaner 2006 Free\SDRmon.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ncicmfyu.dll",setvm
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\.