Tom's Guide > Forum > Sécurité - Virus > [RESOLU] aide svp ne sais plus quoi faire PC multiplement infecté !!!
[RESOLU] aide svp ne sais plus quoi faire PC multiplement infecté !!! - Sécurité - Virus
TomsGuide.com : 800 000 inscrits répondent à toutes vos questions high-tech et informatique. Pour obtenir de l'aide, inscrivez-vous gratuitement !
Mot :    Pseudo :           
 

Bonjour à tous,

Et bien voilà cela fait un petit temps déjà que mon ordi portable a des problèmes, cela empire de jours en jours. On dirait que je suis en train de me choper de plus en plus de crasses... Voici le résumé de mes problèmes :

- tout d'abord, mon dossier dans lequel je download mes fichiers torrent d'Azureus est ineffacable. Quand j'essaie de l'effacer l'explorer plante (avec la fenêtre classique explorer.exe a rencontré un problème et va fermer...). J'ai déjà essayer en désactivant explorer.exe et en l'effacant par ligne de commandes...impossible. J'ai essayé en mode sans échec...impossible. J'ai essayé en remplacant le dossier par un autre du même nom et en l'écrasant... impossible. Ce problème est très génant puisque ce dossier prend comme place la moitié de mon disque dur...

- Ensuite, je suis infecté par le cheval de Troie New Malware.j qui a infecté un fichier dans le répertoire C:\Windows. Mon antivirus McAffee qui m'a été fourni avec mon ordi par Dell n'est plus a jour (c'était juste une version d'évaluation de 90 jours donc je dois payer si je veux la mise a jour) et ne parvient pas à l'éradiquer. Suite à ca j'ai constamment une fenêtre de windows en bas à droite me disant que mon ordi est infecté.

- Je me suis fait avoir par cette saleté de logiciel Drive Cleaner (je n'ai pas donné mes numéros de carte banquaire j'ai juste downloadé le programme) qui maintenant lance tout le temps une fenêtre en me disant que j'ai 2135 infections ! Impossible de le désinstaller....

- Finalement, je ne sais pas si ce problème est dû à un virus ou si c'est la pile de la carte mère, mais la date de mon ordi change régulièrement pour se remettre systématiquement en 2003.

J'ai downloadé Spybot mais apparement mon ordi ne veut pas que je l'installe, le programme d'installation se coupe spontanément après quelques secondes quand je l'exécute....

Je ne sais pas exactement quels logiciels de désinfection utiliser, il y en a tellement, et je ne sais pas que faire car je n'ai pas vraiment le temps d'aller lire les forums pour l'instant, je suis en examens.

Voilà j'espère tout de même que mon pc est récupérable car pour le moment c'est vraiment la M. Si quelqu'un pouvait m'aider, je lui serait infiniment reconnaissant. Bonne journée


Message édité par blinkgreen le 29-05-2007 à 22:37:12
Liens sponsorisés
Inscrivez-vous ou connectez-vous pour masquer ceci.

Si cela peut aider voici le rapport de HiJackThis. C'est la première fois que j'utilise ce logiciel donc je ne sias pas si je l'utilise correctement ou si je dois suivre une certaine procédure avant de l'exécuter. Je l'ai juste dézipper sur mon bureau et j'ai cliqué sur do a system scan and save a logfile.



Logfile of HijackThis v1.99.1
Scan saved at 15:54:33, on 24/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\matlab6p5\bin\win32\matlab.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\clclean.0001
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Dell AIO 810\dlcgmon.exe
C:\windows\system32\drivers\uzcx.exe
C:\WINDOWS\smanager.7.exe
C:\WINDOWS\abc5019def.exe
C:\Program Files\DriveCleaner Free\UDC.exe
C:\Program Files\DriveCleaner Free\UDC6cw.exe
C:\Program Files\Fichiers communs\DriveCleaner Free\udcsdr.exe
C:\Program Files\Fichiers communs\DriveCleaner Free\udcwap.exe
C:\WINDOWS\system32\dlcgcoms.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Save\Save.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\abc5026def.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.782\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/ [...] l=fr&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/ [...] l=fr&s=gen
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NFSUserSIDGSSLink] C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe REG
O4 - HKLM\..\Run: [DLCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcgmon.exe] "C:\Program Files\Dell AIO 810\dlcgmon.exe"
O4 - HKLM\..\Run: [iut75] c:\windows\system32\drivers\uzcx.exe
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernels32.exe
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\abc5019def.exe
O4 - HKLM\..\Run: [DriveCleaner Free] "C:\Program Files\DriveCleaner Free\UDC.exe" /min
O4 - HKLM\..\Run: [UDC6cw] "C:\Program Files\DriveCleaner Free\UDC6cw.exe" -c
O4 - HKLM\..\Run: [SDR6V_Check] "C:\Program Files\Fichiers communs\DriveCleaner Free\udcsdr.exe"
O4 - HKLM\..\Run: [WA6PV_Check] "C:\Program Files\Fichiers communs\DriveCleaner Free\udcwap.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/229?176774bdf545422c9411324edd84addd
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/230?176774bdf545422c9411324edd84addd
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5630E9B7-C69B-4EBF-8E53-4F225802A5C1}: NameServer = 85.255.113.109
O17 - HKLM\System\CCS\Services\Tcpip\..\{906C8869-0287-4C6C-852A-C9F464A58480}: NameServer = 85.255.113.109
O17 - HKLM\System\CCS\Services\Tcpip\..\{D12AB822-C6BC-4368-97E6-4011E9F50980}: NameServer = 85.255.113.109
O17 - HKLM\System\CCS\Services\Tcpip\..\{D1EA1145-6107-4C9A-BE86-64A80B52CD1D}: NameServer = 85.255.113.109
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.109 85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.109 85.255.112.212
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: ANSYS FLEXlm license manager - Macrovision Corporation - C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlcg_device - - C:\WINDOWS\system32\dlcgcoms.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hummingbird Export (HCLExport) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


Merci d'avance

Répondre à blinkgreen

Bonjour


De nombreuses infections.


$$ Télécharge
SDFix sur ton bureau
http://downloads.andymanchesta.com [...] /SDFix.exe

clean.zip
http://www.malekal.com/download/clean.zip
Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.


$$ Télécharge Brute Force Uninstaller (de Merijn)
http://www.merijn.org/files/bfu.zip
Créé un nouveau dossier directement sur le C:\ et nomme-le BFU. Décompresse le fichier téléchargé dans ce nouveau dossier (C:\BFU)

FAIS UN CLIC-DROIT sur le lien suivant
http://www.alt-shift-return.org/In [...] ftware.bfu
et choisis "Enregistrer la cible sous..." afin de télécharger Winsoftware.bfu de Lazzzy
Sauvegarde dans le dossier créé (C:\BFU). **Note : si tu utlises Internet Explorer; lors de la sauvegarde, assure-toi que le champs "Type :" affiche "Tous les fichiers". Tu dois maintenant avoir deux fichiers dans le dossier C:\BFU : Winsoftware.bfu et BFU.exe (très important).


$$ Redémarre en mode sans échec.
Démarre l'ordinateur.
Une fois le chargement du BIOS terminé, il y a un écran noir. Appuye sur la touche F8 jusqu'à l'affichage du menu des options avancées de Windows.
En utilisant les touches du curseur, sélectionne Mode sans échec et appuye sur Entrée.


$$ Démarre le "Brute Force Uninstaller" en double-cliquant BFU.exe (du dossier C:\BFU)
Clique sur le petit dossier jaune, à la droite de la boîte Scriptline to execute, et double-clique sur :

Winsoftware.bfu

Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\Winsoftware.bfu
Clique sur Execute et laisse-le faire son travail.
Attendre que Complete script execution apparaîsse et clique sur OK.

Clique Exit pour fermer le programme BFU.


$$ Ouvre le dossier Clean qui se trouve sur ton bureau, et double-clic sur clean.cmd.
Choisis l'option 2
Enregistre le rapport une fois le scan terminé


$$ Double clique sur SDFix.exe et choisis Install
Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
Tape Y pour lancer le script.
Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire
Presse une touche pour redémarrer

Le PC va mettre du temps avant de démarrer, presse une touche lorsque "Finished" s'affiche

Ouvre le dossier SDFix et copie/colle ici le contenu du fichier "Report.txt" avec le rapport qui se trouve ici C:\rapport_clean.txt et un nouveau HijackThis.

------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_

Merci d'avoir répondu aussi vite !! Je viens de tenter les manoeuvres que tu viens de m'expliquer. Le problème, c'est que même en mode sans échec mon oridanteur est un échec !! J'ai des fenêtres tous le temps disant que explorer.exe doit fermer, et un peu après c'est drwnst32... J'ai donc ignorer ces fenêtres sans cliquer dessus et tenter de faire ce que tu m'as dit. Il n'y a pas eu de problème avec BFU, j'ai eu la fenêtre Complete script Execution a la fin. Par contre, cleanmgr a planté... J'ai quand même un rapport dans C:>rapport_clean.text Le voici :

Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec jeu. 24/05/2007 a 16:48:13,10

Microsoft Windows XP [version 5.1.2600]

*** Suppression des fichiers dans C:

*** Suppression des fichiers dans C:\WINDOWS\

*** Suppression des fichiers dans C:\WINDOWS\system32
tentative de suppression de C:\WINDOWS\services.dll
Impossible de supprimer C:\WINDOWS\services.dll
tentative de suppression de "C:\Documents and Settings\Guillaume\Application Data\DriveCleaner Free\"

*** Suppression des fichiers dans C:\Program Files

*** Suppression des clefs du registre effectuee..
*** Fin du rapport !



Après j'ai lancé SDfix mais il a planté, juste après qu'il dise this might take up to 10 minutes le bureau et l'explorer disparaissent et j'ai plus que l'écran noir avec au dessus et en dessous les lignes modes sans échec. Je n'ai donc pas su obtenir le rapport de SDFix. J'ai refait un HiJackThis juste après, voici le rapport :


Logfile of HijackThis v1.99.1
Scan saved at 17:09:30, on 24/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\clclean.0001
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\iTunes\iTunesHelper.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe
C:\Program Files\Dell AIO 810\dlcgmon.exe
C:\windows\system32\drivers\uzcx.exe
C:\WINDOWS\smanager.7.exe
C:\WINDOWS\abc5019def.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\matlab6p5\bin\win32\matlab.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\dlcgcoms.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.406\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/ [...] l=fr&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/ [...] l=fr&s=gen
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\WINDOWS\SNOWNOIT.EXE
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NFSUserSIDGSSLink] C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe REG
O4 - HKLM\..\Run: [DLCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcgmon.exe] "C:\Program Files\Dell AIO 810\dlcgmon.exe"
O4 - HKLM\..\Run: [iut75] c:\windows\system32\drivers\uzcx.exe
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\abc5019def.exe
O4 - HKLM\..\Run: [DriveCleaner Free] "C:\Program Files\DriveCleaner Free\UDC.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/229?176774bdf545422c9411324edd84addd
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/230?176774bdf545422c9411324edd84addd
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5630E9B7-C69B-4EBF-8E53-4F225802A5C1}: NameServer = 85.255.113.109,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\..\{906C8869-0287-4C6C-852A-C9F464A58480}: NameServer = 85.255.113.109,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\..\{D12AB822-C6BC-4368-97E6-4011E9F50980}: NameServer = 85.255.113.109,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\..\{D1EA1145-6107-4C9A-BE86-64A80B52CD1D}: NameServer = 85.255.113.109,85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.109 85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.109 85.255.112.212
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: ANSYS FLEXlm license manager - Macrovision Corporation - C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlcg_device - - C:\WINDOWS\system32\dlcgcoms.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hummingbird Export (HCLExport) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe




J'ai vraiment l'impression que mon ordi est à la mort la...


Répondre à blinkgreen

Re

Les infections déstabilisent le PC.


Télécharge FixWareout de l'un de ces deux liens :
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/fi [...] areout.exe

Sauvegarde-le sur ton Bureau


Relance un scan HijackThis et coche les lignes ci-dessous :

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{5630E9B7-C69B-4EBF-8E53-4F225802A5C1}: NameServer = 85.255.113.109,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\..\{906C8869-0287-4C6C-852A-C9F464A58480}: NameServer = 85.255.113.109,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\..\{D12AB822-C6BC-4368-97E6-4011E9F50980}: NameServer = 85.255.113.109,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\..\{D1EA1145-6107-4C9A-BE86-64A80B52CD1D}: NameServer = 85.255.113.109,85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.109 85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.109 85.255.112.212

Ferme toutes les fenêtres Windows, Internet explorer, Outlook,sauf le logiciel Hijackthis et clique sur « Fix checked »


Lance FixWareout
Clique Next, puis Install, et assure-toi que "Run fixit" soit coché, puis clique Finish.
Suis les directives à l'écran.
L'outil va te demander de redémarrer ton PC; fais-le s'il te plaît.
Le redémarrage risque de prendre un peu plus de temps; ceci est normal.

Lorsque redémarré, un fichier texte apparaîtra (report.txt); copie/colle ce rapport dans ta prochaine réponse, avec un nouveau rapport HijackThis! également.

------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_

Merci bcp de continuer à m'aider !! Voici le rapport de Fixwareout et après le nouveau HiJackThis



Fixwareout Last edited 5/15/2007
Post this report in the forums please
...
»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdztj.exe"

»»»»»

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
»»»»» Misc files.
C:\Documents and Settings\Guillaume\Application Data\Install.dat Deleted
....
»»»»» Checking for older varients.
....

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.


Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or http://virusscan.jotti.org/

»»»»» Other
C:\WINDOWS\Temp\kdztj.ren 63437 05/08/2004

»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_07\\bin\\jusched.exe"
"SigmatelSysTrayApp"="stsystra.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"Dell QuickSet"="C:\\Program Files\\Dell\\QuickSet\\quickset.exe"
"IntelZeroConfig"="\"C:\\Program Files\\Intel\\Wireless\\bin\\ZCfgSvc.exe\""
"IntelWireless"="\"C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe\" /tf Intel PROSet/Wireless"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy\\Surround Mixer\\CTSysVol.exe /r"
"MBMon"="Rundll32 CTMBHA.DLL,MBMon"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"VoiceCenter"="\"C:\\Program Files\\Creative\\VoiceCenter\\AndreaVC.exe\" /tray"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"DMXLauncher"="C:\\Program Files\\Dell\\Media Experience\\DMXLauncher.exe"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
@=""
"VSOCheckTask"="\"C:\\PROGRA~1\\McAfee.com\\VSO\\mcmnhdlr.exe\" /checktask"
"OASClnt"="C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe"
"MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe"
"MCUpdateExe"="C:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe"
"MSKDetectorExe"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MSKDetct.exe /startup"
"MSKAGENTEXE"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MskAgent.exe"
"VirusScan Online"="C:\\Program Files\\McAfee.com\\VSO\\mcvsshld.exe"
"MPFExe"="C:\\PROGRA~1\\McAfee.com\\PERSON~1\\MpfTray.exe"
"Corel Photo Downloader"="C:\\Program Files\\Corel\\Corel Photo Album 6\\MediaDetect.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"NFSUserSIDGSSLink"="C:\\Program Files\\Hummingbird\\Connectivity\\11.00\\NFS Maestro\\HumGSS.exe REG"
"DLCGCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\DLCGtime.dll,_RunDLLEntry@16"
"dlcgmon.exe"="\"C:\\Program Files\\Dell AIO 810\\dlcgmon.exe\""
"iut75"="c:\\windows\\system32\\drivers\\uzcx.exe"
"SManager"="smanager.7.exe"
"avp"="C:\\WINDOWS\\abc5019def.exe"
"DriveCleaner Free"="\"C:\\Program Files\\DriveCleaner Free\\UDC.exe\" /min"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"ModemOnHold"="C:\\Program Files\\NetWaiting\\netWaiting.exe"
"SetDefaultMIDI"="MIDIDef.exe"
"Creative Detector"="\"C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe\" /R"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"WhenUSave"="\"C:\\Program Files\\Save\\Save.exe\""
....
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»






Logfile of HijackThis v1.99.1
Scan saved at 18:39:51, on 24/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\clclean.0001
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Dell AIO 810\dlcgmon.exe
C:\windows\system32\drivers\uzcx.exe
C:\WINDOWS\smanager.7.exe
C:\WINDOWS\abc5019def.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\dlcgcoms.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.344\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/ [...] l=fr&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/ [...] l=fr&s=gen
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\WINDOWS\SNOWNOIT.EXE
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NFSUserSIDGSSLink] C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe REG
O4 - HKLM\..\Run: [DLCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcgmon.exe] "C:\Program Files\Dell AIO 810\dlcgmon.exe"
O4 - HKLM\..\Run: [iut75] c:\windows\system32\drivers\uzcx.exe
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\abc5019def.exe
O4 - HKLM\..\Run: [DriveCleaner Free] "C:\Program Files\DriveCleaner Free\UDC.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/229?176774bdf545422c9411324edd84addd
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/230?176774bdf545422c9411324edd84addd
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: ANSYS FLEXlm license manager - Macrovision Corporation - C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlcg_device - - C:\WINDOWS\system32\dlcgcoms.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hummingbird Export (HCLExport) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Répondre à blinkgreen

Au fait, je viens de réessayer de supprimer mon fichier de download d'Azureus, et ca a marché!!!! Déjà un problème en moins

Répondre à blinkgreen

On progresse.

Maintenant réessaye avec SDFix.

$$ Redémarre en mode sans échec. Attention, tu n'as pas accès à internet dans ce mode, note bien ce que tu as à faire.
Démarre l'ordinateur.
Une fois le chargement du BIOS terminé, il y a un écran noir. Appuye sur la touche F8 jusqu'à l'affichage du menu des options avancées de Windows.
En utilisant les touches du curseur, sélectionne Mode sans échec et appuye sur Entrée.


$$ Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
Tape Y pour lancer le script.
Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire
Presse une touche pour redémarrer

Le PC va mettre du temps avant de démarrer, presse une touche lorsque "Finished" s'affiche

Ouvre le dossier SDFix et copie/colle ici le contenu du fichier "Report.txt" avec un nouveau HijackThis.

------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_

Depuis, les dernières manoeuvres, plus de messages d'infection par New Malware.j et plus de message de cette merde de DriveCleaner, j'ai même réussi à désinstaller ce dernier. J'ai réessayer SDFix en mode sans échec et maintenant, ca marche ! Voici le rapport :




SDFix: Version 1.84

Run by Guillaume - jeu. 24/05/2007 - 22:37:50,37

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:






Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Missing Security Center Service
Restoring Missing SharedAccess Service

Rebooting...


Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\SYSTEM32\DRIVERS\DETECT.HTM - Deleted
C:\WINDOWS\SYSTEM32\DRIVERS\S_DETECT.HTM - Deleted
C:\WINDOWS\SYSTEM32\LOAD.EXE - Deleted
C:\WINDOWS\SYSTEM32\MSORCL32.EXE - Deleted
C:\WINDOWS\abc5019def.exe - Deleted
C:\WINDOWS\abc5026def.exe - Deleted
C:\WINDOWS\services.dll - Deleted
C:\WINDOWS\smanager.7.exe - Deleted
C:\WINDOWS\system32\drivers\uzcx.exe - Deleted



Removing Temp Files...

ADS Check:

Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.

Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.



Final Check:

Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Disabled:LimeWire"
"C:\\Program Files\\Hummingbird\\Connectivity\\11.00\\Exceed\\exceed.exe"="C:\\Program Files\\Hummingbird\\Connectivity\\11.00\\Exceed\\exceed.exe:*:Enabled:X Server for Windows 2000/XP/2003"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\Program Files\\Dassault Systemes\\B15\\intel_a\\code\\bin\\CNEXT.exe"="C:\\Program Files\\Dassault Systemes\\B15\\intel_a\\code\\bin\\CNEXT.exe:*:Enabled:CATIA"
"C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PreGui_ogl.exe"="C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PreGui_ogl.exe:*:Enabled:PreGui_ogl"
"C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PreEngine.exe"="C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PreEngine.exe:*:Enabled:PreEngine"
"C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PostGui_ogl.exe"="C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PostGui_ogl.exe:*:Enabled:PostGui_ogl"
"C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PostEngine.exe"="C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PostEngine.exe:*:Enabled:PostEngine"
"C:\\Program Files\\Java\\j2re1.4.2_07\\bin\\java.exe"="C:\\Program Files\\Java\\j2re1.4.2_07\\bin\\java.exe:*:Enabled:java"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"


Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip

Checking For Files with Hidden Attributes:

C:\WINDOWS\system32\68BEA66E75.sys
C:\WINDOWS\system32\756EA6BE68.sys
C:\WINDOWS\system32\KGyGaAvL.sys
C:\WINDOWS\LastGood(2).Tmp\INF\oem30(2).inf
C:\WINDOWS\LastGood(2).Tmp\INF\oem30(2).PNF

Finished






Et le voici le nouveau HiJackThis :



Logfile of HijackThis v1.99.1
Scan saved at 0:39:41, on 25/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\WINDOWS\Explorer.EXE
C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\clclean.0001
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe
C:\Program Files\Dell AIO 810\dlcgmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\dlcgcoms.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX01.937\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/ [...] l=fr&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/ [...] l=fr&s=gen
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NFSUserSIDGSSLink] C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe REG
O4 - HKLM\..\Run: [DLCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcgmon.exe] "C:\Program Files\Dell AIO 810\dlcgmon.exe"
O4 - HKLM\..\Run: [avp] C:\WINDOWS\abc5019def.exe
O4 - HKLM\..\Run: [DriveCleaner Free] "C:\Program Files\DriveCleaner Free\UDC.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/229?176774bdf545422c9411324edd84addd
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/230?176774bdf545422c9411324edd84addd
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: ANSYS FLEXlm license manager - Macrovision Corporation - C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlcg_device - - C:\WINDOWS\system32\dlcgcoms.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hummingbird Export (HCLExport) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe




Merci déjà mille fois de l'aide que vous m'avez apportée, sérieux mon ordi déconne beaucoup moins

Répondre à blinkgreen

Re


On finit de nettoyer Hijackthis.


Une partie de la procédure se déroulera sans avoir accès à internet, prière d'imprimer ces instructions, ou de les coller dans un fichier texte, pour lecture durant cette désinfection.
Les manipulations sont à faire sans interruption et dans l'ordre.
Si tu ne comprends pas quelque chose, demande des explications avant de commencer
.



1 Télécharge
CCleaner.

http://www.filehippo.com/download_ccleaner.html
Installe le dans un répertoire dédié.

AVG Anti-Spyware
http://www.ewido.net/en/download/
Tu l'installes.
Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente

clean.zip
http://www.malekal.com/download/clean.zip
Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.


2 Redémarre en mode sans echec. Attention, tu n'as pas accès à internet dans ce mode, note bien ce que tu as à faire.
Démarre l'ordinateur.
Une fois le chargement du BIOS terminé, il y a un écran noir. Appuye sur la touche F8 jusqu'à l'affichage du menu des options avancées de Windows.
En utilisant les touches du curseur, sélectionne Mode sans échec et appuye sur Entrée.


3 Relance un scan HijackThis et coche les lignes ci-dessous :

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/ [...] l=fr&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/ [...] l=fr&s=gen
O4 - HKLM\..\Run: [avp] C:\WINDOWS\abc5019def.exe
O4 - HKLM\..\Run: [DriveCleaner Free] "C:\Program Files\DriveCleaner Free\UDC.exe" /min
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

Ferme toutes les fenêtres Windows, Internet explorer, Outlook,sauf le logiciel Hijackthis et clique sur « Fix checked »


4 Désinstalle ces applications (si tu les trouves) dans Ajout-Suppression de programmes :

DriveCleaner Free
Save


5 Supprime les fichiers/dossiers incriminés (s'ils existent encore) :

C:\Program Files\DriveCleaner Free
C:\Program Files\Save


6 Lance le nettoyage avec CCleaner.


7 Lance AVG Anti-Spyware.
Clique sur le bouton Analyse (de la barre d'outils)
Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantine.
Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas.
Clique sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.


8 Ouvre le dossier Clean qui se trouve sur ton bureau, et double-clic sur clean.cmd.
Choisis l'option 2
Enregistre le rapport une fois le scan terminé


9 Redémarre normalement et poste un nouveau log HijackThis avec le rapport d'AVG Anti-Spyware et le rapport qui se trouve ici C:\[b]rapport_clean.txt[/b

------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_

Je suis désolé mais j'ai oublié de faire un truc. Ca a pris deux heures exactement de faire le scan avec AVG, alors a la fin j'en avais tellement marre que j'ai oublié de demander le rapport d'erreur. Mais j'ai tout de même scanner jusqu'au bout et fais toutes les actions. Dois-je recommencer? En attendant voici le rapport de clean et après le nouveau HiJackThis :


Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec ven. 25/05/2007 a 4:35:05,50

Microsoft Windows XP [version 5.1.2600]

*** Suppression des fichiers dans C:

*** Suppression des fichiers dans C:\WINDOWS\

*** Suppression des fichiers dans C:\WINDOWS\system32

*** Suppression des fichiers dans C:\Program Files

*** Suppression des clefs du registre effectuee..
*** Fin du rapport !



Logfile of HijackThis v1.99.1
Scan saved at 4:50:00, on 25/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\clclean.0001
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell AIO 810\dlcgmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
C:\Program Files\Messenger\msmsgs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dlcgcoms.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.796\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://english.ircfast.com/index.php?rvs=hompag
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DLCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcgmon.exe] "C:\Program Files\Dell AIO 810\dlcgmon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/229?176774bdf545422c9411324edd84addd
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/230?176774bdf545422c9411324edd84addd
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: ANSYS FLEXlm license manager - Macrovision Corporation - C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlcg_device - - C:\WINDOWS\system32\dlcgcoms.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe



J'ai l'impression que mon système est tout propre : pas un problème maintenant !

Répondre à blinkgreen

Bonjour


Tant pis pour le rapport.
Hijackthis est propre.

Comme McAffee est obsolète, il faut le remplacer.

Télécharge en un gratuit, par exemple AVAST Home Edition FREE
http://www.avast.com/eng/down_home.html
avec souscription obligatoire
http://www.avast.com/i_kat_207.php?lang=ENG
et son tutorial
http://www.pcentraide.com/index.php?showtopic=120

Tu le télécharges, tu sauvegarde les pages pour l'installation.

Tu te mets hors connection internet.

Tu désinstalle et supprime McAffee.
Tu installes Avast.

Tu te reconnecte et tu fais les mises à jour.

Ensuite, fais une analyse antivirus en ligne sur Kaspersky
http://webscanner.kaspersky.fr/
Clique sur Démarrer Online Scanner.
Sélectionne le poste de travail comme analyse.
Colle son rapport ici.

------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_

J'ai viré McAfee, installé Avast et ses mises à jour. Mais en ce qui concerne le scan Kaspersky il ne marche pas car il y a chaque fois un problème avec le téléchargement du contrôle ActiveX. Pourtant la sécurité de IExplorer est mise sur moyen comme il le dise...

D'autre part, est-ce normal que cela fait déjà trois fois que Avast me dit qu'il a trouvé un Malware alors que la seule page qui est ouverte sur mon ordi est celle de votre site? Voici ce que Avast me dit :

Malware was found !

File Name : http://gameglobin.info/g.php?wmid=bg001[UPX]
Malware name : Win32:Dialer-BN [Trj]
Malware type : Dialer
VPS version : 00743-5, 25/05/2007


Répondre à blinkgreen

En fait, ce n'est pas que sur votre site. Il semble que j'ai cette alerte toute les quelques minutes peu importe sur quel site je suis...

Répondre à blinkgreen

Avant le scan en ligne, on fait une autre recherche.

Télécharge DiagHelp.zip (de Malekal_Morte) sur ton bureau
http://www.malekal.com/download/DiagHelp.zip
- Fais un clic droit sur le fichier et extraire tout
- Un nouveau dossier chercher va être créé DiagHelp
- Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
- Une fenêtre va s'ouvrir, choisis l'option 1
- L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande
- A la fin de l'analyse, il te sera peut-être redemandé de redémarrer l'ordinateur... Une fois l'ordinateur redémarré le rapport va apparaître sur le bloc-note.. Ce dernier se trouve sur C:\resultat.txt
- Copie/colle le contenu du bloc-note qui s'ouvre, pour cela :
-- Dans le bloc-note, cliquez sur le menu Edition / Selectionner tout
-- A nouveau menu Edition / copier
-- Dans un nouveau message ici, faire un clic droit / coller


Message édité par chercheur_ le 26-05-2007 à 00:43:18
------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_

Voici le rapport de DiagHelp :


DiagHelp version v1.08.1 - http://www.malekal.com
excute le sam. 26/05/2007 à 10:04:40,32


Liste des fichiers modifies/crees dans les 24 dernieres heures...
\dlcg.log
\dlcgscan.log
\Documents and Settings\Administrateur\ntuser.dat.LOG
\Documents and Settings\All Users\Bureau
\Documents and Settings\All Users\Menu Démarrer\Programmes
\Documents and Settings\All Users\Menu Démarrer\Programmes\Accessoires\Outils système\Défragmenteur de disque.lnk
\Documents and Settings\All Users\Menu Démarrer\Programmes\avast! Antivirus
\Documents and Settings\All Users\Menu Démarrer\Programmes\avast! Antivirus\avast! Antivirus.lnk
\Documents and Settings\All Users\Menu Démarrer\Programmes\avast! Antivirus\avast! Web Site.url
\Documents and Settings\All Users\Menu Démarrer\Programmes\avast! Antivirus\Help.lnk
\Documents and Settings\Gaëtane\ntuser.dat.LOG
\Documents and Settings\Guillaume
\Documents and Settings\Guillaume\Bureau
\Documents and Settings\Guillaume\Bureau\DiagHelp
\Documents and Settings\Guillaume\Bureau\DiagHelp\DiagHelp
\Documents and Settings\Guillaume\Bureau\DiagHelp.zip
\Documents and Settings\Guillaume\Download
\Documents and Settings\Guillaume\Download\avastkey.txt
\Documents and Settings\Guillaume\Download\Greenday Discography
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\1000 Hours.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\16.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\409 In Your Coffeemaker.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\At The Library.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\Disappearing Boy.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\Dont Leave Me.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\Dry Ice.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\Going to Pasalacqua.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\Green Day.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\I Want to Be Alone.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\I Was There.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\Knowledge.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\Only Of You.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\Paper Lanterns.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\Rest.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\Road to Acceptance.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\The Judges Daughter.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\The One I Want.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\1039 Smoothed Out Slappy Hours\Why Do You Want Him.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\American Idiot.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Are We The Waiting.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Boulevard Of Broken Dreams.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Extraordinary Girl.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Give Me Novacaine.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Holiday.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Homecoming- The Death Of St. Jimmy.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Jesus Of Suburbia.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Letterbomb.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\American Idiot.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\Are We The Waiting.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\Boulevard Of Broken Dreams.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\Extraordinary Girl.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\Give Me Novacaine.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\Holiday.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\Homecoming- The Death of St. Jimmy.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\Jesus Of Suburbia.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\Letterbomb.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\Shes A Rebel.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\St. Jimmy.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\Wake Me Up When September Ends.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Metadata\Whatsername.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Shes A Rebel.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\St. Jimmy.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Wake Me Up When September Ends.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\American Idiot\Whatsername.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Bowling Bowling Bowling Parking Parking
\Documents and Settings\Guillaume\Download\Greenday Discography\Bowling Bowling Bowling Parking Parking\Armatage Shanks (Live).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Bowling Bowling Bowling Parking Parking\Basket Case (Live).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Bowling Bowling Bowling Parking Parking\Brain Stew (Live).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Bowling Bowling Bowling Parking Parking\Jaded (Live).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Bowling Bowling Bowling Parking Parking\Knowledge (Live).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Bowling Bowling Bowling Parking Parking\She (Live).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Bowling Bowling Bowling Parking Parking\Walking Contradiction (Live).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\All By Myself (Hidden Track).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\Basket Case.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\Burnout.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\Chump.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\Coming Clean.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\Emenius Sleepus.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\Having A Blast.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\In The End.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\Longview.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\Pulling Teeth.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\Sassafras Roots.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\She.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\Welcome To Paradise.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Dookie\When I Come Around.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth\2000 Light Years Away (Foot In Mouth Version).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth\Burnout (Foot In Mouth Version).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth\Chump (Foot In Mouth Version).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth\F.O.D.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth\Geek Stink Breath (Foot In Mouth Version).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth\Going To Pasalaqua (Foot In Mouth Version).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth\Longview.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth\One Of My Lies (Foot In Mouth Version).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth\Stuck With Me (Foot In Mouth Version).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth\Welcome To Paradise (Foot In Mouth Version).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Foot In Mouth\When I Come Around (Foot In Mouth Version).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\86.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Armatage Shanks.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Babs Uvula Who.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Brain Stew.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Brat.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Geek Stink Breath.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Jaded.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\No Pride.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Panic Song.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Stuart And The Ave.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Stuck With Me.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Tight Wad Hill.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Walkin Contradiction.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Insomniac\Westbound Sign.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\2000 Light Years Away.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\80.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\Android.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\Best Thing In Town.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\Christie Road.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\Dominated Love Slave.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\My Generation.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\No One Knows.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\One For The Razorbacks.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\One Of My Lies.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\Private Ale.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\Strangeland.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\Sweet Children.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\Welcome To Paradise (Kerplunk Version).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\Who Wrote Holden Caulfield.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Kerplunk\Words I Might Have Ate.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\All The Time.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Haushinka.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Hitchin' A Ride.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Jinx.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\King For A Day.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Last Ride In.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\All The Time.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Haushinka.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Hitchin' A Ride.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Jinx.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\King For A Day.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Last Ride In.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Nice Guys Finish Last.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Platypus (I Hate You).mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Prosthetic Head.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Redundant.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Scattered.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Suffocate.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Take Back.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\The Grouch.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Time of Your life.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Uptight.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Walking Alone.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Metadata\Worry Rock.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Nice Guys Finish Last.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Platypus (I Hate You).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Prosthetic Head.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Redundant.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Scattered.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Suffocate.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Take Back.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\The Grouch.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Time of Your life.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Uptight.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Walking Alone.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Nimrod\Worry Rock.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\Desensitized.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\Do Da Da.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\Dont Wanna Fall In Love.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\Espionage.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\Ha Ha Youre Dead.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\I Want To Be On TV.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\On The Wagon Again.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\Outsider.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\Rotting.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\Scumbag.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\Sick Of Me.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\Suffocate.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\Tired Of Waiting.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Shenanigans\You Lied.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Torrent downloaded from Demonoid.com.txt
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\86 (Live).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Blood, Sex And Booze.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Brat (Live).mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Castaway.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Church On Sunday.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Deadbeat Holiday.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Fashion Victim.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Hold On.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Jackass.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Macys Day Parade.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\86 (Live).mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Blood, Sex And Booze.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Brat (Live).mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Castaway.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Church On Sunday.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Deadbeat Holiday.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Fashion Victim.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Hold On.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Jackass.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Macys Day Parade.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Minority.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Misery.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Waiting.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Metadata\Warning.mp3.xml
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Minority.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Misery.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Waiting.mp3
\Documents and Settings\Guillaume\Download\Greenday Discography\Warning\Warning.mp3
\Documents and Settings\Guillaume\Download\Half Baked DVDRip KVCD by PJ(TUS Release)
\Documents and Settings\Guillaume\Download\Half Baked DVDRip KVCD by PJ(TUS Release)\Half Baked DVDRip KVCD by PJ(TUS Release).bin
\Documents and Settings\Guillaume\Download\Half Baked DVDRip KVCD by PJ(TUS Release)\Half Baked DVDRip KVCD by PJ(TUS Release).cue
\Documents and Settings\Guillaume\Download\Half Baked DVDRip KVCD by PJ(TUS Release)\Half Baked DVDRip KVCD by PJ(TUS Release).nfo
\Documents and Settings\Guillaume\Download\Half Baked DVDRip KVCD by PJ(TUS Release)\Need Help! Read Me!!.htm
\Documents and Settings\Guillaume\Download\Half Baked DVDRip KVCD by PJ(TUS Release)\Torrent downloaded from Demonoid.com.txt
\Documents and Settings\Guillaume\Download\Half-Baked
\Documents and Settings\Guillaume\Download\Half-Baked\Half-Baked.divx
\Documents and Settings\Guillaume\Download\Half-Baked\hangovervideo.nfo
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\01_ANYWHERE_BUT_HERE.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\02_WEAK.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\03_WANT_AD.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\04_REALIZE.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\05_THINK_TWICE.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\06_UNOPPOSED.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\07_THE_ASPECT.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\08_EARS_TO_HEAR.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\09_BAD_HAIR_DAY.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\10_TO_MUCH_THINKING.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\11_PXPX.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\12_TIME_BRINGS_CHANGE.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\13_JARS_OF_CLAY.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\14_HIGH_STANDARDS.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\15_ANOTHER_SONG_ABOUT_TV.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\16_TWISTED_WORDS.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\17_WALKING_BYE.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\18_NO_ROOM.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\19_JAY_JAY_S_SONG.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\20_ONE_WAY_WINDOW.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1995 - Pokinatcha\21_DEAD_END.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\01___MXPX___SUGARCOATED_POI.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\02___MXPX___DO___DON_T.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\03___MXPX___TEENAGE_POLITIC.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\04___MXPX___PUNK_RAWK_SHOW.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\05___MXPX___THE_OPPOSITE_OF.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\06___MXPX___FALSE_FICTION.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\07___MXPX___FALLING_DOWN.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\08___MXPX___MONEYTREE.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\09___MXPX___RAINYDAY.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\10___MXPX___LIKE_SAND_THRU_.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\11___MXPX___DEMOCRACY.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\12___MXPX___SOMETHING_MORE.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\13___MXPX___DIFFERENT_THING.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\14___MXPX___MISUNDERSTANDIN.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\15___MXPX___STUDY_HUMANS.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\16___MXPX___INQUIRING_MINDS.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\17___MXPX___I_M_THE_BAD_GUY.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\18___MXPX___AMERICANISM.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1996 - Teenage Politics\19___MXPX___DOLORES__MY_GIR.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\01 MxPx - Middlename.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\02 MxPx - My Mom Stil Cleans My Rooml.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\03 MxPx - Do You Feet Hurt.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\04 MxPx - Sometimes you have to ask Yourself.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\05 MxPx - The wonder Years.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\06 MxPx - Move to Bremerton.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\07 MxPx - New York To Nowhere.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\08 MxPx - Andrea.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\09 MxPx - Your problem my emergency.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\10 MxPx - Chick Magnet.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\11 MxPx - Today is in my way.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\12 MxPx - Sorry so Sorry.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\13 MxPx - Doing Time.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\14 MxPx - Correct me if I'm Wrong.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\15 MxPx - Cristalena.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\16 MxPx - Destroyed By you.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1997 - Life In General\17 MxPx - Southbound.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\01 Under Lock And Key.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\02 Tomorrow's Another Day.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\03 Final Slow Dance.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\04 I'm OK You're OK.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\05 Cold And All Alone.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\06 Party, My House, Be There.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\07 The Downfall Of Western Civilizat.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\08 Invitation to Understanding.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\09 Fist Vs. Tact.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\10 What's Mine Is Yours.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\11 Self Serving With A Purpose.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\12 For Always.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\13 Set The Record Straight.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\14 Get With It.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\15 Inches From Life.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1998 - Slowly Going The Way Of The Buffalo\16 The Theme Fiasco.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\01___MXPX___TOMORROW_S_ANOT.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\02___MXPX___SOMETIMES_YOU_H.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\03___MXPX___UNDER_LOCK_AND_.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\04___MXPX___CHICK_MAGNET__L.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\05___MXPX___GSF__LIVE_.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\06___MXPX___COLD_AND_ALL_AL.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\07___MXPX___PARTY__MY_HOUSE.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\08___MXPX___THE_DOWNFALL_OF.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\09___MXPX___TIME_BRINGS_CHA.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\10___MXPX___FIST_VS_TACT__L.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\11___MXPX___SMALL_TOWN_MIND.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\12___MXPX___WALKING_BYE__LI.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\13___MXPX___KKK_TOOK_MY_BAB.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\14___MXPX___ANDREA__LIVE_.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\15___MXPX___WANTAD__LIVE_.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\16___MXPX___LIFETIME_ENLIGH.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\17___MXPX___FORGIVE_AND_FOR.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\18___MXPX___INVITATION_TO_U.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\19___MXPX___DOLORES__LIVE_.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\20___MXPX___MIDDLENAME__LIV.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\21___MXPX___I_M_OK__YOU_RE_.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\22___MXPX___THE_THEME_FIASC.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - At The Show\23___MXPX___PUNK_RAWK_SHOW_.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\01_-Never_Learn.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\02_-Begin_To_Start.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\03_-Swing_Set_Girl.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\04_-Sick_Boy.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\05_-Oh_Donna.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\06_-Small_Town_Minds.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\07_-First_Class_Mail.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\08_-Can't_See_Not_Saying.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\09_-GSF.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\10_-Thoughts_And_Ideas.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\11_-Easier_Said_Than_Done.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\12_-Rock_And_Roll_Girl.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\13_-Important_Enough_To_Mention.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\14_-Elvis_Is_Dead.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\15_-Lifetime_Enlightenment.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\16_-Let_It_Happen.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\17_-Hot_And_Cold.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\18_-So_Kill_Me.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\19_-Suggestion_Box.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\20_-Creation.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\21_-Want_Ad_(Alternative_Mix).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\22_-Honest_Answers.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\23_-Late_Last_Night.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\24_-Biased_Bigotry.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\25_-Circumstance.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\26_-Do_Your_Feet_Hurt_(Critter_Mix).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\27_-Move_To_Bremerton_(Extended_Mix).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\28_-Chick_Magnet_(Demo_Version).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\29_-Sorry_So_Sorry_(Demo_Version).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\30_-Christalena_(Demo_Version).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\31_-South_Bound_(Demo_Version).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\1999 - Let it Happen\32_-Life_In_General_(Demo_Version).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\01 My Life Story.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\02 Buildings Tumble.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\03 Responsability.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\04 Two Whole Years.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\05 Prove It To The World.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\06 Educated Guess.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\07 Is The Answer In The Question.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\08 The Next Big Thing.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\09 Foolish.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\10 One Step Closer To Life.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\11 Unsaid.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\12 Here With Me.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\13 Without You.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\14 It's Undeniable.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2000 - The Ever Passing Moment\15 Misplaced Memories.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\01 Punk Rawk Show.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\02 My Mistake.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\03 Running Away.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\04 Chick Magnet.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\05 Want Ad.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\06 Tomorrows Another Day.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\07 Doing Time.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\08 The Broken Bones.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\10 Teenage Politics.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\11 Pxpx.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\12 Gsf.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\13 Do Your Feet Hurt.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\14 Let It Happen.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\15 Lonesome Town.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\16 Dolores.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\17 Rock And Roll Girl.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\18 Move To Bremerton.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\19 Middlename (Live).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2002 - Ten Years And Running\Folder.jpg
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\01 Before.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\02 Play It Loud - Halo Friendlies.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\03 Well Adjusted.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\04 It's Alright.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\05 Brokenhearted.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\06 First Day Of The Rest Of Our Live.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\07 Everything Sucks (When You're Gon.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\08 Quit Your Life.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\09 More Everything.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\10 Kings Of Hollywood.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\11 The Capitol.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\12 On The Outs.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\13 Don't Walk Away.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\14 You Make Me, Me.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\15 You're Not Alone.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\16 After.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2003 - Before Everything And After\Folder.jpg
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\01-mxpx-the_darkest_places.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\02-mxpx-young_and_depressed.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\03-mxpx-heard_that_sound.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\04-mxpx-cold_streets.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\05-mxpx-the_story.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\06-mxpx-wrecking_hotel_rooms.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\07-mxpx-late_again.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\08-mxpx-kicking_and_screaming.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\09-mxpx-grey_skies_turn_blue.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\10-mxpx-emotional_anarchist.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\11-mxpx-call_in_sick.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\12-mxpx-get_me_out.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\13-mxpx-waiting_for_the_world_to_end.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\14-mxpx-this_weekend.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2005 - Panic\Folder.jpg
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\01-mxpx-you_walk_i_run.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\02-mxpx-every_light.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\03-mxpx-1_and_3.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\04-mxpx-dont_forget_me_(when_youre_gone).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\05-mxpx-breathe_deep.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\06-mxpx-make_up_your_mind.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\07-mxpx-running_out_of_time.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\08-mxpx-slow_ride.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\09-mxpx-where_did_you_go.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\10-mxpx-sweet_sweet_thing_(acoustic).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\11-mxpx-last_train_(acoustic).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\2006 - Lets Rock\12-mxpx-you_walk_i_run_(acoustic).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Renaissance EP
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Renaissance EP\01 MXPX - Lonesome Town.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Renaissance EP\02 MXPX - Letting Go.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Renaissance EP\03 MXPX - Party II (Time to Go).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Renaissance EP\04 MXPX - Time Will Tell.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Renaissance EP\05 MXPX - The Opposite.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Renaissance EP\06 MXPX - Don't Look Back.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Renaissance EP\07 MXPX - Talk of the Town.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Renaissance EP\08 MXPX - The Struggle.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Renaissance EP\09 MXPX - Yuri Wakes Up Screaming.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - b-movie (acoustic) EP
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - b-movie (acoustic) EP\01 - Skies.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - b-movie (acoustic) EP\02 - Silver Screen.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - b-movie (acoustic) EP\03 - Invitation.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - b-movie (acoustic) EP\04 - Where Will We Go.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - b-movie (acoustic) EP\05 - Quit Your Life.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - 17 (i saw her standing there).MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - barbie girl.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - blue moon.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - brown eyed girl.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - Christmas Day (A Little Goes A Long Way).mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - Christmas Night Of Zombies.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - Coming Home for Christmas.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - Good Friends Are Hard To Find.MP3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - leaving on a jet plane.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - my boyfriends back.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - No Action.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - popeye the sailor man.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - Scooby Doo Where Are You.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - Covers, Christmas and others\mxpx - sick boy.mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - On the Cover EP
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - On the Cover EP\Folder.jpg
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - On the Cover EP\[mxpx] - [on the cover ep] - [01] - [summer of 69].mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - On the Cover EP\[mxpx] - [on the cover ep] - [02] - [oh, boy!].mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - On the Cover EP\[mxpx] - [on the cover ep] - [03] - [drum machine joy].mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - On the Cover EP\[mxpx] - [on the cover ep] - [04] - [you found me].mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - On the Cover EP\[mxpx] - [on the cover ep] - [05] - [take on me].mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - On the Cover EP\[mxpx] - [on the cover ep] - [06] - [marie, marie].mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - On the Cover EP\[mxpx] - [on the cover ep] - [07] - [you put this love in my heart].mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\MxPx - On the Cover EP\[mxpx] - [on the cover ep] - [08] - [no brain].mp3
\Documents and Settings\Guillaume\Download\MXPX - Discography 1995 - 2006 - 11 Albums, 3 EPs, rarietes\Torrent downloaded from Demonoid.com.txt
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\AlbumArtSmall.jpg
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\AlbumArt_{32290070-44E1-44A8-94D9-3DEFBF63B44F}_Large.jpg
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\AlbumArt_{32290070-44E1-44A8-94D9-3DEFBF63B44F}_Small.jpg
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\desktop.ini
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\Folder.jpg
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 01 - My Paper Heart.mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 02 - Your Star.mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 03 - Swing, Swing.mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 04 - Time Stands Still.mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 05 - One More Sad Song.mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 06 - Why Worry.mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 07 - Don't Leave Me.mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 08 - Too Far Gone.mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 09 - Drive Away.mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 10 - Happy Endings.mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 11 - The Last Song.mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - 12 - The Cigarette Song (Acoustic Bonus Track).mp3
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\The All-American Rejects - The All-American Rejects.m3u
\Documents and Settings\Guillaume\Download\The All-American Rejects - (2002) - The All-American Rejects (192kps)\Thumbs.db
\Documents and Settings\G

Répondre à blinkgreen

Voici la suite car j'ai l'impression que la fenetre du message n'est pas assez grande pour tout contenir (désolé pour les download mais comme j'ai tout effacé, j'ai relancé pas mal de téléchargements hier) :



\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\00-yellowcard-lights_and_sounds-2006.m3u
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\00-yellowcard-lights_and_sounds-2006.nfo
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\00-yellowcard-lights_and_sounds-2006.sfv
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\01-yellowcard-three_flights_up.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\02-yellowcard-lights_and_sounds.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\03-yellowcard-down_on_my_head.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\04-yellowcard-sure_thing_falling.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\05-yellowcard-city_of_devils.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\06-yellowcard-rough_landing_holly.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\07-yellowcard-two_weeks_from_twenty.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\08-yellowcard-waiting_game.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\09-yellowcard-martin_sheen_or_jfk.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\10-yellowcard-space_travel.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\11-yellowcard-grey.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\12-yellowcard-words_hands_hearts.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\13-yellowcard-how_i_go.mp3
\Documents and Settings\Guillaume\Download\Yellowcard-Lights_And_Sounds-2006-RNS\14-yellowcard-holly_wood_died.mp3
\Documents and Settings\Guillaume\Local Settings\desktop.ini
\Documents and Settings\Guillaume\Local Settings\Temp
\Documents and Settings\Guillaume\Local Settings\Temp\21b0_appcompat.txt
\Documents and Settings\Guillaume\Local Settings\Temp\AZ_35962.bin
\Documents and Settings\Guillaume\Local Settings\Temp\AZ_35964.mp3
\Documents and Settings\Guillaume\Local Settings\Temp\AZ_4751.bin
\Documents and Settings\Guillaume\Local Settings\Temp\AZ_4753.mp3
\Documents and Settings\Guillaume\Local Settings\Temp\AZ_50223.mp3
\Documents and Settings\Guillaume\Local Settings\Temp\AZ_5309.mp3
\Documents and Settings\Guillaume\Local Settings\Temp\AZ_5311.divx
\Documents and Settings\Guillaume\Local Settings\Temp\AZ_5313.bin
\Documents and Settings\Guillaume\Local Settings\Temp\AZ_5315.MP3
\Documents and Settings\Guillaume\Local Settings\Temp\AZ_58654.mp3
\Documents and Settings\Guillaume\Local Settings\Temp\AZ_9279.mp3
\Documents and Settings\Guillaume\Local Settings\Temp\clclean.0001
\Documents and Settings\Guillaume\Local Settings\Temp\clclean.0001.dir.0000
\Documents and Settings\Guillaume\Local Settings\Temp\clclean.0001.dir.0000\ActivationGui.dll
\Documents and Settings\Guillaume\Local Settings\Temp\clclean.0001.dir.0000\ApiExShell.dll
\Documents and Settings\Guillaume\Local Settings\Temp\clclean.0001.dir.0000\Ky5s96SF.csa
\Documents and Settings\Guillaume\Local Settings\Temp\clclean.0001.dir.0000\PfdRun.pfd
\Documents and Settings\Guillaume\Local Settings\Temp\clclean.0001.dir.0000\~de1785.tmp
\Documents and Settings\Guillaume\Local Settings\Temp\clclean.0001.dir.0000\~df394b.tmp
\Documents and Settings\Guillaume\Local Settings\Temp\clclean.0001.dir.0000\~efe2.tmp
\Documents and Settings\Guillaume\Local Settings\Temp\CTJBNS
\Documents and Settings\Guillaume\Local Settings\Temp\CTJBNS\Copy
\Documents and Settings\Guillaume\Local Settings\Temp\CTJBNS\Excute
\Documents and Settings\Guillaume\Local Settings\Temp\e4j4C6.tmp_dir12653
\Documents and Settings\Guillaume\Local Settings\Temp\e4j4C6.tmp_dir12653\exe4jlib.jar
\Documents and Settings\Guillaume\Local Settings\Temp\e4jA5.tmp_dir31997
\Documents and Settings\Guillaume\Local Settings\Temp\e4jA5.tmp_dir31997\exe4jlib.jar
\Documents and Settings\Guillaume\Local Settings\Temp\e4jAB.tmp_dir32003
\Documents and Settings\Guillaume\Local Settings\Temp\e4jAB.tmp_dir32003\exe4jlib.jar
\Documents and Settings\Guillaume\Local Settings\Temp\e4jAC.tmp_dir32003
\Documents and Settings\Guillaume\Local Settings\Temp\e4jAD.tmp_dir32003
\Documents and Settings\Guillaume\Local Settings\Temp\e4jAD.tmp_dir32003\exe4jlib.jar
\Documents and Settings\Guillaume\Local Settings\Temp\e4jB4.tmp_dir32287
\Documents and Settings\Guillaume\Local Settings\Temp\hsperfdata_Guillaume
\Documents and Settings\Guillaume\Local Settings\Temp\jusched.log
\Documents and Settings\Guillaume\Local Settings\Temp\WLTB Custom Button Feeds
\Documents and Settings\Guillaume\Local Settings\Temp\WLTB Custom Button Feeds\microsoft.msn.mymsn.btn upgrade status
\Documents and Settings\Guillaume\Local Settings\Temp\WLTB Custom Button Feeds\microsoft.windowslive.addbtn.btn upgrade status
\Documents and Settings\Guillaume\Local Settings\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 0
\Documents and Settings\Guillaume\Local Settings\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn upgrade status
\Documents and Settings\Guillaume\Local Settings\Temp\_avast4_
\Documents and Settings\Guillaume\Local Settings\Temp\~DFA23F.tmp
\Documents and Settings\Guillaume\Local Settings\Temp\~DFAAD5.tmp
\Documents and Settings\Guillaume\Local Settings\Temp\~DFAAE5.tmp
\Documents and Settings\Guillaume\Local Settings\Temp\~DFC8FD.tmp
\Documents and Settings\Guillaume\Local Settings\Temp\~DFC90B.tmp
\Documents and Settings\Guillaume\Menu Démarrer\Programmes
\Documents and Settings\Guillaume\Mes documents\Ma musique\Music
\Documents and Settings\Guillaume\Mes documents\Ma musique\Music\Plus 44 - When Your Heart Stops Beating
\Documents and Settings\Guillaume\Mes documents\Ma musique\Music\Plus 44 - When Your Heart Stops Beating\Thumbs.db
\Documents and Settings\Guillaume\Mes documents\Ma musique\Music\The Used - Lies For The Liars
\Documents and Settings\Guillaume\Mes documents\Ma musique\Music\The Used - Lies For The Liars\01-the_used-the_ripper.mp3
\Documents and Settings\Guillaume\Mes documents\Ma musique\Music\The Used - Lies For The Liars\05-the_used-hospital.mp3
\Documents and Settings\Guillaume\Mes documents\Ma musique\Music\The Used - Lies For The Liars\10-the_used-liar_liar_(burn_in_hell).mp3
\Documents and Settings\Guillaume\Mes documents\Ma musique\Music\The Used - Lies For The Liars\11-the_used-smother_me.mp3
\Documents and Settings\Guillaume\Mes documents\Ma musique\Music\The Used - Lies For The Liars\Thumbs.db
\Documents and Settings\Guillaume\Mes documents\Ma musique\Music\Thumbs.db
\Documents and Settings\Guillaume\Mes documents\Mes dossiers de partage.lnk
\Documents and Settings\Guillaume\NTUSER.DAT
\Documents and Settings\Guillaume\ntuser.dat.LOG
\Documents and Settings\Guillaume\ntuser.ini
\Documents and Settings\Guillaume\Programmes
\Documents and Settings\Guillaume\Programmes\Cool Edit Pro
\Documents and Settings\Guillaume\Programmes\Cool Edit Pro\Cool Edit Pro 2.0 Full + Plugins + Crack
\Documents and Settings\Guillaume\Programmes\SDFix\apps
\Documents and Settings\Guillaume\SendTo
\Documents and Settings\LocalService\Local Settings\desktop.ini
\Documents and Settings\LocalService\NTUSER.DAT
\Documents and Settings\LocalService\ntuser.dat.LOG
\Documents and Settings\NetworkService\Local Settings\desktop.ini
\Documents and Settings\NetworkService\NTUSER.DAT
\Documents and Settings\NetworkService\ntuser.dat.LOG
\hiberfil.sys
\MATLAB6p5\bin\win32
\pagefile.sys
\sqmdata01.sqm
\sqmdata02.sqm
\sqmdata03.sqm
\sqmdata04.sqm
\sqmnoopt01.sqm
\sqmnoopt02.sqm
\sqmnoopt03.sqm
\sqmnoopt04.sqm
\WINDOWS
\WINDOWS\0.log
\WINDOWS\bootstat.dat
\WINDOWS\Debug\PASSWD.LOG
\WINDOWS\ModemLog_Conexant HDA D110 MDC V.92 Modem.txt
\WINDOWS\pchealth\helpctr\DataColl
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3646.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3648.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3650.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3652.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3654.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3656.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3657.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3658.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3660.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3662.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3664.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3666.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3667.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3668.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3670.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3672.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3673.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3674.xml
\WINDOWS\pchealth\helpctr\DataColl\CollectedData_3675.xml
\WINDOWS\pchealth\helpctr\DataColl\history_db.xml
\WINDOWS\SchedLgU.Txt
\WINDOWS\security\logs
\WINDOWS\security\logs\scecomp.old
\WINDOWS\setupact.log
\WINDOWS\setupapi.log
\WINDOWS\setuperr.log
\WINDOWS\system32
\WINDOWS\system32\CONFIG.NT
\WINDOWS\system32\dla\DLA.INI
\WINDOWS\system32\drivers
\WINDOWS\system32\ias
\WINDOWS\system32\Status.MPF
\WINDOWS\system32\winjks32.dll
\WINDOWS\Tasks\SA.DAT
\WINDOWS\Temp
\WINDOWS\Temp\Historique
\WINDOWS\Temp\Perflib_Perfdata_7fc.dat
\WINDOWS\Temp\T30DebugLogFile.txt
\WINDOWS\Temp\teredo.txt
\WINDOWS\Temp\win1.tmp
\WINDOWS\Temp\win10.tmp
\WINDOWS\Temp\win100.tmp
\WINDOWS\Temp\win101.tmp
\WINDOWS\Temp\win102.tmp
\WINDOWS\Temp\win103.tmp
\WINDOWS\Temp\win104.tmp
\WINDOWS\Temp\win105.tmp
\WINDOWS\Temp\win106.tmp
\WINDOWS\Temp\win107.tmp
\WINDOWS\Temp\win108.tmp
\WINDOWS\Temp\win109.tmp
\WINDOWS\Temp\win10A.tmp
\WINDOWS\Temp\win10B.tmp
\WINDOWS\Temp\win10C.tmp
\WINDOWS\Temp\win10D.tmp
\WINDOWS\Temp\win10E.tmp
\WINDOWS\Temp\win10F.tmp
\WINDOWS\Temp\win11.tmp
\WINDOWS\Temp\win110.tmp
\WINDOWS\Temp\win111.tmp
\WINDOWS\Temp\win112.tmp
\WINDOWS\Temp\win113.tmp
\WINDOWS\Temp\win114.tmp
\WINDOWS\Temp\win115.tmp
\WINDOWS\Temp\win116.tmp
\WINDOWS\Temp\win117.tmp
\WINDOWS\Temp\win118.tmp
\WINDOWS\Temp\win119.tmp
\WINDOWS\Temp\win11A.tmp
\WINDOWS\Temp\win11B.tmp
\WINDOWS\Temp\win11C.tmp
\WINDOWS\Temp\win11D.tmp
\WINDOWS\Temp\win11E.tmp
\WINDOWS\Temp\win11F.tmp
\WINDOWS\Temp\win12.tmp
\WINDOWS\Temp\win120.tmp
\WINDOWS\Temp\win121.tmp
\WINDOWS\Temp\win122.tmp
\WINDOWS\Temp\win123.tmp
\WINDOWS\Temp\win124.tmp
\WINDOWS\Temp\win125.tmp
\WINDOWS\Temp\win126.tmp
\WINDOWS\Temp\win127.tmp
\WINDOWS\Temp\win128.tmp
\WINDOWS\Temp\win129.tmp
\WINDOWS\Temp\win12A.tmp
\WINDOWS\Temp\win12B.tmp
\WINDOWS\Temp\win12C.tmp
\WINDOWS\Temp\win12D.tmp
\WINDOWS\Temp\win12E.tmp
\WINDOWS\Temp\win12F.tmp
\WINDOWS\Temp\win13.tmp
\WINDOWS\Temp\win130.tmp
\WINDOWS\Temp\win131.tmp
\WINDOWS\Temp\win132.tmp
\WINDOWS\Temp\win133.tmp
\WINDOWS\Temp\win134.tmp
\WINDOWS\Temp\win135.tmp
\WINDOWS\Temp\win136.tmp
\WINDOWS\Temp\win137.tmp
\WINDOWS\Temp\win138.tmp
\WINDOWS\Temp\win139.tmp
\WINDOWS\Temp\win13A.tmp
\WINDOWS\Temp\win13B.tmp
\WINDOWS\Temp\win13C.tmp
\WINDOWS\Temp\win13D.tmp
\WINDOWS\Temp\win13E.tmp
\WINDOWS\Temp\win13F.tmp
\WINDOWS\Temp\win14.tmp
\WINDOWS\Temp\win140.tmp
\WINDOWS\Temp\win141.tmp
\WINDOWS\Temp\win142.tmp
\WINDOWS\Temp\win143.tmp
\WINDOWS\Temp\win144.tmp
\WINDOWS\Temp\win145.tmp
\WINDOWS\Temp\win146.tmp
\WINDOWS\Temp\win147.tmp
\WINDOWS\Temp\win148.tmp
\WINDOWS\Temp\win149.tmp
\WINDOWS\Temp\win14A.tmp
\WINDOWS\Temp\win14B.tmp
\WINDOWS\Temp\win14C.tmp
\WINDOWS\Temp\win14D.tmp
\WINDOWS\Temp\win14E.tmp
\WINDOWS\Temp\win14F.tmp
\WINDOWS\Temp\win15.tmp
\WINDOWS\Temp\win150.tmp
\WINDOWS\Temp\win151.tmp
\WINDOWS\Temp\win152.tmp
\WINDOWS\Temp\win153.tmp
\WINDOWS\Temp\win154.tmp
\WINDOWS\Temp\win155.tmp
\WINDOWS\Temp\win156.tmp
\WINDOWS\Temp\win157.tmp
\WINDOWS\Temp\win158.tmp
\WINDOWS\Temp\win159.tmp
\WINDOWS\Temp\win15A.tmp
\WINDOWS\Temp\win15B.tmp
\WINDOWS\Temp\win15C.tmp
\WINDOWS\Temp\win15D.tmp
\WINDOWS\Temp\win15E.tmp
\WINDOWS\Temp\win15F.tmp
\WINDOWS\Temp\win16.tmp
\WINDOWS\Temp\win160.tmp
\WINDOWS\Temp\win161.tmp
\WINDOWS\Temp\win162.tmp
\WINDOWS\Temp\win163.tmp
\WINDOWS\Temp\win164.tmp
\WINDOWS\Temp\win165.tmp
\WINDOWS\Temp\win166.tmp
\WINDOWS\Temp\win167.tmp
\WINDOWS\Temp\win168.tmp
\WINDOWS\Temp\win169.tmp
\WINDOWS\Temp\win16A.tmp
\WINDOWS\Temp\win16B.tmp
\WINDOWS\Temp\win16C.tmp
\WINDOWS\Temp\win16D.tmp
\WINDOWS\Temp\win16E.tmp
\WINDOWS\Temp\win16F.tmp
\WINDOWS\Temp\win17.tmp
\WINDOWS\Temp\win170.tmp
\WINDOWS\Temp\win171.tmp
\WINDOWS\Temp\win172.tmp
\WINDOWS\Temp\win173.tmp
\WINDOWS\Temp\win174.tmp
\WINDOWS\Temp\win175.tmp
\WINDOWS\Temp\win176.tmp
\WINDOWS\Temp\win177.tmp
\WINDOWS\Temp\win178.tmp
\WINDOWS\Temp\win179.tmp
\WINDOWS\Temp\win17A.tmp
\WINDOWS\Temp\win17B.tmp
\WINDOWS\Temp\win17C.tmp
\WINDOWS\Temp\win17D.tmp
\WINDOWS\Temp\win17E.tmp
\WINDOWS\Temp\win17F.tmp
\WINDOWS\Temp\win18.tmp
\WINDOWS\Temp\win180.tmp
\WINDOWS\Temp\win181.tmp
\WINDOWS\Temp\win182.tmp
\WINDOWS\Temp\win183.tmp
\WINDOWS\Temp\win184.tmp
\WINDOWS\Temp\win185.tmp
\WINDOWS\Temp\win186.tmp
\WINDOWS\Temp\win187.tmp
\WINDOWS\Temp\win188.tmp
\WINDOWS\Temp\win189.tmp
\WINDOWS\Temp\win18A.tmp
\WINDOWS\Temp\win18B.tmp
\WINDOWS\Temp\win18C.tmp
\WINDOWS\Temp\win18D.tmp
\WINDOWS\Temp\win18E.tmp
\WINDOWS\Temp\win18F.tmp
\WINDOWS\Temp\win19.tmp
\WINDOWS\Temp\win190.tmp
\WINDOWS\Temp\win191.tmp
\WINDOWS\Temp\win192.tmp
\WINDOWS\Temp\win193.tmp
\WINDOWS\Temp\win194.tmp
\WINDOWS\Temp\win195.tmp
\WINDOWS\Temp\win196.tmp
\WINDOWS\Temp\win197.tmp
\WINDOWS\Temp\win198.tmp
\WINDOWS\Temp\win199.tmp
\WINDOWS\Temp\win19A.tmp
\WINDOWS\Temp\win19B.tmp
\WINDOWS\Temp\win19C.tmp
\WINDOWS\Temp\win19D.tmp
\WINDOWS\Temp\win19E.tmp
\WINDOWS\Temp\win19F.tmp
\WINDOWS\Temp\win1A.tmp
\WINDOWS\Temp\win1A0.tmp
\WINDOWS\Temp\win1A1.tmp
\WINDOWS\Temp\win1A2.tmp
\WINDOWS\Temp\win1A3.tmp
\WINDOWS\Temp\win1A4.tmp
\WINDOWS\Temp\win1A5.tmp
\WINDOWS\Temp\win1A6.tmp
\WINDOWS\Temp\win1A7.tmp
\WINDOWS\Temp\win1A8.tmp
\WINDOWS\Temp\win1A9.tmp
\WINDOWS\Temp\win1AA.tmp
\WINDOWS\Temp\win1AB.tmp
\WINDOWS\Temp\win1AC.tmp
\WINDOWS\Temp\win1AD.tmp
\WINDOWS\Temp\win1AE.tmp
\WINDOWS\Temp\win1AF.tmp
\WINDOWS\Temp\win1B.tmp
\WINDOWS\Temp\win1B0.tmp
\WINDOWS\Temp\win1B1.tmp
\WINDOWS\Temp\win1B2.tmp
\WINDOWS\Temp\win1B3.tmp
\WINDOWS\Temp\win1B4.tmp
\WINDOWS\Temp\win1B5.tmp
\WINDOWS\Temp\win1B6.tmp
\WINDOWS\Temp\win1B7.tmp
\WINDOWS\Temp\win1B8.tmp
\WINDOWS\Temp\win1B9.tmp
\WINDOWS\Temp\win1BA.tmp
\WINDOWS\Temp\win1BB.tmp
\WINDOWS\Temp\win1BC.tmp
\WINDOWS\Temp\win1BD.tmp
\WINDOWS\Temp\win1BE.tmp
\WINDOWS\Temp\win1BF.tmp
\WINDOWS\Temp\win1C0.tmp
\WINDOWS\Temp\win1C1.tmp
\WINDOWS\Temp\win1C2.tmp
\WINDOWS\Temp\win1C3.tmp
\WINDOWS\Temp\win1C4.tmp
\WINDOWS\Temp\win1C5.tmp
\WINDOWS\Temp\win1C6.tmp
\WINDOWS\Temp\win1C7.tmp
\WINDOWS\Temp\win1C8.tmp
\WINDOWS\Temp\win1C9.tmp
\WINDOWS\Temp\win1CA.tmp
\WINDOWS\Temp\win1CB.tmp
\WINDOWS\Temp\win1CC.tmp
\WINDOWS\Temp\win1CD.tmp
\WINDOWS\Temp\win1CE.tmp
\WINDOWS\Temp\win1CF.tmp
\WINDOWS\Temp\win1D0.tmp
\WINDOWS\Temp\win1D1.tmp
\WINDOWS\Temp\win1D2.tmp
\WINDOWS\Temp\win1D3.tmp
\WINDOWS\Temp\win1D4.tmp
\WINDOWS\Temp\win1D5.tmp
\WINDOWS\Temp\win1D6.tmp
\WINDOWS\Temp\win1D7.tmp
\WINDOWS\Temp\win1D8.tmp
\WINDOWS\Temp\win1D9.tmp
\WINDOWS\Temp\win1DA.tmp
\WINDOWS\Temp\win1DB.tmp
\WINDOWS\Temp\win1DC.tmp
\WINDOWS\Temp\win1DD.tmp
\WINDOWS\Temp\win1DE.tmp
\WINDOWS\Temp\win1DF.tmp
\WINDOWS\Temp\win1E0.tmp
\WINDOWS\Temp\win1E1.tmp
\WINDOWS\Temp\win1E2.tmp
\WINDOWS\Temp\win1E3.tmp
\WINDOWS\Temp\win1E4.tmp
\WINDOWS\Temp\win1E5.tmp
\WINDOWS\Temp\win1E6.tmp
\WINDOWS\Temp\win1E7.tmp
\WINDOWS\Temp\win1E8.tmp
\WINDOWS\Temp\win1E9.tmp
\WINDOWS\Temp\win1EA.tmp
\WINDOWS\Temp\win1EB.tmp
\WINDOWS\Temp\win1EC.tmp
\WINDOWS\Temp\win1ED.tmp
\WINDOWS\Temp\win1EE.tmp
\WINDOWS\Temp\win1EF.tmp
\WINDOWS\Temp\win1F0.tmp
\WINDOWS\Temp\win1F1.tmp
\WINDOWS\Temp\win1F2.tmp
\WINDOWS\Temp\win1F3.tmp
\WINDOWS\Temp\win1F4.tmp
\WINDOWS\Temp\win1F5.tmp
\WINDOWS\Temp\win1F6.tmp
\WINDOWS\Temp\win1F7.tmp
\WINDOWS\Temp\win1F8.tmp
\WINDOWS\Temp\win1F9.tmp
\WINDOWS\Temp\win1FA.tmp
\WINDOWS\Temp\win1FB.tmp
\WINDOWS\Temp\win1FC.tmp
\WINDOWS\Temp\win1FD.tmp
\WINDOWS\Temp\win1FE.tmp
\WINDOWS\Temp\win1FF.tmp
\WINDOWS\Temp\win2.tmp
\WINDOWS\Temp\win20.tmp
\WINDOWS\Temp\win200.tmp
\WINDOWS\Temp\win201.tmp
\WINDOWS\Temp\win202.tmp
\WINDOWS\Temp\win203.tmp
\WINDOWS\Temp\win204.tmp
\WINDOWS\Temp\win205.tmp
\WINDOWS\Temp\win206.tmp
\WINDOWS\Temp\win207.tmp
\WINDOWS\Temp\win208.tmp
\WINDOWS\Temp\win209.tmp
\WINDOWS\Temp\win20A.tmp
\WINDOWS\Temp\win20B.tmp
\WINDOWS\Temp\win20C.tmp
\WINDOWS\Temp\win20D.tmp
\WINDOWS\Temp\win20E.tmp
\WINDOWS\Temp\win20F.tmp
\WINDOWS\Temp\win21.tmp
\WINDOWS\Temp\win210.tmp
\WINDOWS\Temp\win211.tmp
\WINDOWS\Temp\win212.tmp
\WINDOWS\Temp\win213.tmp
\WINDOWS\Temp\win214.tmp
\WINDOWS\Temp\win215.tmp
\WINDOWS\Temp\win216.tmp
\WINDOWS\Temp\win217.tmp
\WINDOWS\Temp\win218.tmp
\WINDOWS\Temp\win219.tmp
\WINDOWS\Temp\win21A.tmp
\WINDOWS\Temp\win21B.tmp
\WINDOWS\Temp\win21C.tmp
\WINDOWS\Temp\win21D.tmp
\WINDOWS\Temp\win21E.tmp
\WINDOWS\Temp\win21F.tmp
\WINDOWS\Temp\win22.tmp
\WINDOWS\Temp\win220.tmp
\WINDOWS\Temp\win221.tmp
\WINDOWS\Temp\win222.tmp
\WINDOWS\Temp\win223.tmp
\WINDOWS\Temp\win224.tmp
\WINDOWS\Temp\win225.tmp
\WINDOWS\Temp\win226.tmp
\WINDOWS\Temp\win227.tmp
\WINDOWS\Temp\win228.tmp
\WINDOWS\Temp\win229.tmp
\WINDOWS\Temp\win22A.tmp
\WINDOWS\Temp\win22B.tmp
\WINDOWS\Temp\win22C.tmp
\WINDOWS\Temp\win22D.tmp
\WINDOWS\Temp\win22E.tmp
\WINDOWS\Temp\win22F.tmp
\WINDOWS\Temp\win230.tmp
\WINDOWS\Temp\win231.tmp
\WINDOWS\Temp\win232.tmp
\WINDOWS\Temp\win233.tmp
\WINDOWS\Temp\win234.tmp
\WINDOWS\Temp\win235.tmp
\WINDOWS\Temp\win236.tmp
\WINDOWS\Temp\win237.tmp
\WINDOWS\Temp\win238.tmp
\WINDOWS\Temp\win239.tmp
\WINDOWS\Temp\win23A.tmp
\WINDOWS\Temp\win23B.tmp
\WINDOWS\Temp\win23C.tmp
\WINDOWS\Temp\win23D.tmp
\WINDOWS\Temp\win23E.tmp
\WINDOWS\Temp\win23F.tmp
\WINDOWS\Temp\win24.tmp
\WINDOWS\Temp\win240.tmp
\WINDOWS\Temp\win241.tmp
\WINDOWS\Temp\win242.tmp
\WINDOWS\Temp\win243.tmp
\WINDOWS\Temp\win244.tmp
\WINDOWS\Temp\win245.tmp
\WINDOWS\Temp\win246.tmp
\WINDOWS\Temp\win247.tmp
\WINDOWS\Temp\win248.tmp
\WINDOWS\Temp\win249.tmp
\WINDOWS\Temp\win24A.tmp
\WINDOWS\Temp\win24B.tmp
\WINDOWS\Temp\win24C.tmp
\WINDOWS\Temp\win24D.tmp
\WINDOWS\Temp\win24E.tmp
\WINDOWS\Temp\win24F.tmp
\WINDOWS\Temp\win25.tmp
\WINDOWS\Temp\win250.tmp
\WINDOWS\Temp\win251.tmp
\WINDOWS\Temp\win252.tmp
\WINDOWS\Temp\win253.tmp
\WINDOWS\Temp\win254.tmp
\WINDOWS\Temp\win255.tmp
\WINDOWS\Temp\win256.tmp
\WINDOWS\Temp\win257.tmp
\WINDOWS\Temp\win258.tmp
\WINDOWS\Temp\win259.tmp
\WINDOWS\Temp\win25A.tmp
\WINDOWS\Temp\win25B.tmp
\WINDOWS\Temp\win25C.tmp
\WINDOWS\Temp\win25D.tmp
\WINDOWS\Temp\win25E.tmp
\WINDOWS\Temp\win25F.tmp
\WINDOWS\Temp\win26.tmp
\WINDOWS\Temp\win260.tmp
\WINDOWS\Temp\win261.tmp
\WINDOWS\Temp\win262.tmp
\WINDOWS\Temp\win263.tmp
\WINDOWS\Temp\win264.tmp
\WINDOWS\Temp\win265.tmp
\WINDOWS\Temp\win266.tmp
\WINDOWS\Temp\win267.tmp
\WINDOWS\Temp\win268.tmp
\WINDOWS\Temp\win269.tmp
\WINDOWS\Temp\win26A.tmp
\WINDOWS\Temp\win26B.tmp
\WINDOWS\Temp\win26C.tmp
\WINDOWS\Temp\win26D.tmp
\WINDOWS\Temp\win26E.tmp
\WINDOWS\Temp\win26F.tmp
\WINDOWS\Temp\win270.tmp
\WINDOWS\Temp\win271.tmp
\WINDOWS\Temp\win272.tmp
\WINDOWS\Temp\win273.tmp
\WINDOWS\Temp\win274.tmp
\WINDOWS\Temp\win275.tmp
\WINDOWS\Temp\win276.tmp
\WINDOWS\Temp\win277.tmp
\WINDOWS\Temp\win278.tmp
\WINDOWS\Temp\win279.tmp
\WINDOWS\Temp\win27A.tmp
\WINDOWS\Temp\win27B.tmp
\WINDOWS\Temp\win27C.tmp
\WINDOWS\Temp\win27D.tmp
\WINDOWS\Temp\win27E.tmp
\WINDOWS\Temp\win27F.tmp
\WINDOWS\Temp\win280.tmp
\WINDOWS\Temp\win281.tmp
\WINDOWS\Temp\win282.tmp
\WINDOWS\Temp\win283.tmp
\WINDOWS\Temp\win284.tmp
\WINDOWS\Temp\win285.tmp
\WINDOWS\Temp\win286.tmp
\WINDOWS\Temp\win287.tmp
\WINDOWS\Temp\win288.tmp
\WINDOWS\Temp\win289.tmp
\WINDOWS\Temp\win28A.tmp
\WINDOWS\Temp\win28B.tmp
\WINDOWS\Temp\win28C.tmp
\WINDOWS\Temp\win28D.tmp
\WINDOWS\Temp\win28E.tmp
\WINDOWS\Temp\win28F.tmp
\WINDOWS\Temp\win290.tmp
\WINDOWS\Temp\win291.tmp
\WINDOWS\Temp\win292.tmp
\WINDOWS\Temp\win293.tmp
\WINDOWS\Temp\win294.tmp
\WINDOWS\Temp\win295.tmp
\WINDOWS\Temp\win296.tmp
\WINDOWS\Temp\win297.tmp
\WINDOWS\Temp\win298.tmp
\WINDOWS\Temp\win299.tmp
\WINDOWS\Temp\win29A.tmp
\WINDOWS\Temp\win29B.tmp
\WINDOWS\Temp\win29C.tmp
\WINDOWS\Temp\win29D.tmp
\WINDOWS\Temp\win29E.tmp
\WINDOWS\Temp\win29F.tmp
\WINDOWS\Temp\win2A.tmp
\WINDOWS\Temp\win2A0.tmp
\WINDOWS\Temp\win2A1.tmp
\WINDOWS\Temp\win2A2.tmp
\WINDOWS\Temp\win2A3.tmp
\WINDOWS\Temp\win2A4.tmp
\WINDOWS\Temp\win2A5.tmp
\WINDOWS\Temp\win2A6.tmp
\WINDOWS\Temp\win2A7.tmp
\WINDOWS\Temp\win2A8.tmp
\WINDOWS\Temp\win2A9.tmp
\WINDOWS\Temp\win2AA.tmp
\WINDOWS\Temp\win2AB.tmp
\WINDOWS\Temp\win2AC.tmp
\WINDOWS\Temp\win2AD.tmp
\WINDOWS\Temp\win2AE.tmp
\WINDOWS\Temp\win2AF.tmp
\WINDOWS\Temp\win2B.tmp
\WINDOWS\Temp\win2B0.tmp
\WINDOWS\Temp\win2B1.tmp
\WINDOWS\Temp\win2B2.tmp
\WINDOWS\Temp\win2B3.tmp
\WINDOWS\Temp\win2B4.tmp
\WINDOWS\Temp\win2B5.tmp
\WINDOWS\Temp\win2B6.tmp
\WINDOWS\Temp\win2B7.tmp
\WINDOWS\Temp\win2B8.tmp
\WINDOWS\Temp\win2B9.tmp
\WINDOWS\Temp\win2BA.tmp
\WINDOWS\Temp\win2BB.tmp
\WINDOWS\Temp\win2BC.tmp
\WINDOWS\Temp\win2BD.tmp
\WINDOWS\Temp\win2BE.tmp
\WINDOWS\Temp\win2BF.tmp
\WINDOWS\Temp\win2C.tmp
\WINDOWS\Temp\win2C0.tmp
\WINDOWS\Temp\win2C1.tmp
\WINDOWS\Temp\win2C2.tmp
\WINDOWS\Temp\win2C3.tmp
\WINDOWS\Temp\win2C4.tmp
\WINDOWS\Temp\win2C5.tmp
\WINDOWS\Temp\win2C6.tmp
\WINDOWS\Temp\win2C7.tmp
\WINDOWS\Temp\win2C8.tmp
\WINDOWS\Temp\win2C9.tmp
\WINDOWS\Temp\win2CA.tmp
\WINDOWS\Temp\win2CB.tmp
\WINDOWS\Temp\win2CC.tmp
\WINDOWS\Temp\win2CD.tmp
\WINDOWS\Temp\win2CE.tmp
\WINDOWS\Temp\win2CF.tmp
\WINDOWS\Temp\win2D0.tmp
\WINDOWS\Temp\win2D1.tmp
\WINDOWS\Temp\win2D2.tmp
\WINDOWS\Temp\win2D3.tmp
\WINDOWS\Temp\win2D4.tmp
\WINDOWS\Temp\win2D5.tmp
\WINDOWS\Temp\win2D6.tmp
\WINDOWS\Temp\win2D7.tmp
\WINDOWS\Temp\win2D8.tmp
\WINDOWS\Temp\win2D9.tmp
\WINDOWS\Temp\win2DA.tmp
\WINDOWS\Temp\win2DB.tmp
\WINDOWS\Temp\win2DC.tmp
\WINDOWS\Temp\win2DD.tmp
\WINDOWS\Temp\win2DE.tmp
\WINDOWS\Temp\win2DF.tmp
\WINDOWS\Temp\win2E0.tmp
\WINDOWS\Temp\win2E1.tmp
\WINDOWS\Temp\win2E2.tmp
\WINDOWS\Temp\win2E3.tmp
\WINDOWS\Temp\win2E4.tmp
\WINDOWS\Temp\win2E5.tmp
\WINDOWS\Temp\win2E6.tmp
\WINDOWS\Temp\win2E7.tmp
\WINDOWS\Temp\win2E8.tmp
\WINDOWS\Temp\win2E9.tmp
\WINDOWS\Temp\win2EA.tmp
\WINDOWS\Temp\win2EB.tmp
\WINDOWS\Temp\win2EC.tmp
\WINDOWS\Temp\win2ED.tmp
\WINDOWS\Temp\win2EE.tmp
\WINDOWS\Temp\win2EF.tmp
\WINDOWS\Temp\win2F0.tmp
\WINDOWS\Temp\win2F1.tmp
\WINDOWS\Temp\win2F2.tmp
\WINDOWS\Temp\win2F3.tmp
\WINDOWS\Temp\win2F4.tmp
\WINDOWS\Temp\win2F5.tmp
\WINDOWS\Temp\win2F6.tmp
\WINDOWS\Temp\win2F7.tmp
\WINDOWS\Temp\win2F8.tmp
\WINDOWS\Temp\win2F9.tmp
\WINDOWS\Temp\win2FA.tmp
\WINDOWS\Temp\win2FB.tmp
\WINDOWS\Temp\win2FC.tmp
\WINDOWS\Temp\win2FD.tmp
\WINDOWS\Temp\win2FE.tmp
\WINDOWS\Temp\win2FF.tmp
\WINDOWS\Temp\win3.tmp
\WINDOWS\Temp\win300.tmp
\WINDOWS\Temp\win301.tmp
\WINDOWS\Temp\win302.tmp
\WINDOWS\Temp\win303.tmp
\WINDOWS\Temp\win304.tmp
\WINDOWS\Temp\win305.tmp
\WINDOWS\Temp\win306.tmp
\WINDOWS\Temp\win307.tmp
\WINDOWS\Temp\win308.tmp
\WINDOWS\Temp\win309.tmp
\WINDOWS\Temp\win30A.tmp
\WINDOWS\Temp\win30B.tmp
\WINDOWS\Temp\win30C.tmp
\WINDOWS\Temp\win30D.tmp
\WINDOWS\Temp\win30E.tmp
\WINDOWS\Temp\win30F.tmp
\WINDOWS\Temp\win310.tmp
\WINDOWS\Temp\win311.tmp
\WINDOWS\Temp\win312.tmp
\WINDOWS\Temp\win313.tmp
\WINDOWS\Temp\win314.tmp
\WINDOWS\Temp\win315.tmp
\WINDOWS\Temp\win316.tmp
\WINDOWS\Temp\win317.tmp
\WINDOWS\Temp\win318.tmp
\WINDOWS\Temp\win319.tmp
\WINDOWS\Temp\win31A.tmp
\WINDOWS\Temp\win31B.tmp
\WINDOWS\Temp\win31C.tmp
\WINDOWS\Temp\win31D.tmp
\WINDOWS\Temp\win31E.tmp
\WINDOWS\Temp\win31F.tmp
\WINDOWS\Temp\win320.tmp
\WINDOWS\Temp\win321.tmp
\WINDOWS\Temp\win322.tmp
\WINDOWS\Temp\win323.tmp
\WINDOWS\Temp\win324.tmp
\WINDOWS\Temp\win325.tmp
\WINDOWS\Temp\win326.tmp
\WINDOWS\Temp\win327.tmp
\WINDOWS\Temp\win328.tmp
\WINDOWS\Temp\win329.tmp
\WINDOWS\Temp\win32A.tmp
\WINDOWS\Temp\win32B.tmp
\WINDOWS\Temp\win32C.tmp
\WINDOWS\Temp\win32D.tmp
\WINDOWS\Temp\win32E.tmp
\WINDOWS\Temp\win32F.tmp
\WINDOWS\Temp\win330.tmp
\WINDOWS\Temp\win331.tmp
\WINDOWS\Temp\win332.tmp
\WINDOWS\Temp\win333.tmp
\WINDOWS\Temp\win334.tmp
\WINDOWS\Temp\win335.tmp
\WINDOWS\Temp\win336.tmp
\WINDOWS\Temp\win337.tmp
\WINDOWS\Temp\win338.tmp
\WINDOWS\Temp\win339.tmp
\WINDOWS\Temp\win33A.tmp
\WINDOWS\Temp\win33B.tmp
\WINDOWS\Temp\win33C.tmp
\WINDOWS\Temp\win33D.tmp
\WINDOWS\Temp\win33E.tmp
\WINDOWS\Temp\win33F.tmp
\WINDOWS\Temp\win34.tmp
\WINDOWS\Temp\win340.tmp
\WINDOWS\Temp\win341.tmp
\WINDOWS\Temp\win342.tmp
\WINDOWS\Temp\win343.tmp
\WINDOWS\Temp\win344.tmp
\WINDOWS\Temp\win345.tmp
\WINDOWS\Temp\win346.tmp
\WINDOWS\Temp\win347.tmp
\WINDOWS\Temp\win348.tmp
\WINDOWS\Temp\win349.tmp
\WINDOWS\Temp\win34A.tmp
\WINDOWS\Temp\win34B.tmp
\WINDOWS\Temp\win34C.tmp
\WINDOWS\Temp\win34D.tmp
\WINDOWS\Temp\win34E.tmp
\WINDOWS\Temp\win34F.tmp
\WINDOWS\Temp\win35.tmp
\WINDOWS\Temp\win350.tmp
\WINDOWS\Temp\win351.tmp
\WINDOWS\Temp\win352.tmp
\WINDOWS\Temp\win353.tmp
\WINDOWS\Temp\win354.tmp
\WINDOWS\Temp\win355.tmp
\WINDOWS\Temp\win356.tmp
\WINDOWS\Temp\win357.tmp
\WINDOWS\Temp\win358.tmp
\WINDOWS\Temp\win359.tmp
\WINDOWS\Temp\win35A.tmp
\WINDOWS\Temp\win35B.tmp
\WINDOWS\Temp\win35C.tmp
\WINDOWS\Temp\win35D.tmp
\WINDOWS\Temp\win35E.tmp
\WINDOWS\Temp\win35F.tmp
\WINDOWS\Temp\win36.tmp
\WINDOWS\Temp\win360.tmp
\WINDOWS\Temp\win361.tmp
\WINDOWS\Temp\win362.tmp
\WINDOWS\Temp\win363.tmp
\WINDOWS\Temp\win364.tmp
\WINDOWS\Temp\win365.tmp
\WINDOWS\Temp\win366.tmp
\WINDOWS\Temp\win367.tmp
\WINDOWS\Temp\win368.tmp
\WINDOWS\Temp\win369.tmp
\WINDOWS\Temp\win36A.tmp
\WINDOWS\Temp\win36B.tmp
\WINDOWS\Temp\win36C.tmp
\WINDOWS\Temp\win36D.tmp
\WINDOWS\Temp\win36E.tmp
\WINDOWS\Temp\win36F.tmp
\WINDOWS\Temp\win370.tmp
\WINDOWS\Temp\win371.tmp
\WINDOWS\Temp\win372.tmp
\WINDOWS\Temp\win373.tmp
\WINDOWS\Temp\win374.tmp
\WINDOWS\Temp\win375.tmp
\WINDOWS\Temp\win376.tmp
\WINDOWS\Temp\win377.tmp
\WINDOWS\Temp\win378.tmp
\WINDOWS\Temp\win379.tmp
\WINDOWS\Temp\win37A.tmp
\WINDOWS\Temp\win37B.tmp
\WINDOWS\Temp\win37C.tmp
\WINDOWS\Temp\win37D.tmp
\WINDOWS\Temp\win37E.tmp
\WINDOWS\Temp\win37F.tmp
\WINDOWS\Temp\win380.tmp
\WINDOWS\Temp\win381.tmp
\WINDOWS\Temp\win382.tmp
\WINDOWS\Temp\win383.tmp
\WINDOWS\Temp\win384.tmp
\WINDOWS\Temp\win385.tmp
\WINDOWS\Temp\win386.tmp
\WINDOWS\Temp\win387.tmp
\WINDOWS\Temp\win388.tmp
\WINDOWS\Temp\win389.tmp
\WINDOWS\Temp\win38A.tmp
\WINDOWS\Temp\win38B.tmp
\WINDOWS\Temp\win38C.tmp
\WINDOWS\Temp\win38D.tmp
\WINDOWS\Temp\win38E.tmp
\WINDOWS\Temp\win38F.tmp
\WINDOWS\Temp\win39.tmp
\WINDOWS\Temp\win390.tmp
\WINDOWS\Temp\win391.tmp
\WINDOWS\Temp\win392.tmp
\WINDOWS\Temp\win393.tmp
\WINDOWS\Temp\win394.tmp
\WINDOWS\Temp\win395.tmp
\WINDOWS\Temp\win396.tmp
\WINDOWS\Temp\win397.tmp
\WINDOWS\Temp\win398.tmp
\WINDOWS\Temp\win399.tmp
\WINDOWS\Temp\win39A.tmp
\WINDOWS\Temp\win39B.tmp
\WINDOWS\Temp\win39C.tmp
\WINDOWS\Temp\win39D.tmp
\WINDOWS\Temp\win39E.tmp
\WINDOWS\Temp\win39F.tmp
\WINDOWS\Temp\win3A.tmp
\WINDOWS\Temp\win3A0.tmp
\WINDOWS\Temp\win3A1.tmp
\WINDOWS\Temp\win3A2.tmp
\WINDOWS\Temp\win3A3.tmp
\WINDOWS\Temp\win3A4.tmp
\WINDOWS\Temp\win3A5.tmp
\WINDOWS\Temp\win3A6.tmp
\WINDOWS\Temp\win3A7.tmp
\WINDOWS\Temp\win3A8.tmp
\WINDOWS\Temp\win3A9.tmp
\WINDOWS\Temp\win3AA.tmp
\WINDOWS\Temp\win3AB.tmp
\WINDOWS\Temp\win3AC.tmp
\WINDOWS\Temp\win3AD.tmp
\WINDOWS\Temp\win3AE.tmp
\WINDOWS\Temp\win3AF.tmp
\WINDOWS\Temp\win3B.tmp
\WINDOWS\Temp\win3B0.tmp
\WINDOWS\Temp\win3B1.tmp
\WINDOWS\Temp\win3B2.tmp
\WINDOWS\Temp\win3B3.tmp
\WINDOWS\Temp\win3B4.tmp
\WINDOWS\Temp\win3B5.tmp
\WINDOWS\Temp\win3B6.tmp
\WINDOWS\Temp\win3B7.tmp
\WINDOWS\Temp\win3B8.tmp
\WINDOWS\Temp\win3B9.tmp
\WINDOWS\Temp\win3BA.tmp
\WINDOWS\Temp\win3BB.tmp
\WINDOWS\Temp\win3BC.tmp
\WINDOWS\Temp\win3BD.tmp
\WINDOWS\Temp\win3BE.tmp
\WINDOWS\Temp\win3BF.tmp
\WINDOWS\Temp\win3C0.tmp
\WINDOWS\Temp\win3C1.tmp
\WINDOWS\Temp\win3C2.tmp
\WINDOWS\Temp\win3C3.tmp
\WINDOWS\Temp\win3C4.tmp
\WINDOWS\Temp\win3C5.tmp
\WINDOWS\Temp\win3C6.tmp
\WINDOWS\Temp\win3C7.tmp
\WINDOWS\Temp\win3C8.tmp
\WINDOWS\Temp\win3C9.tmp
\WINDOWS\Temp\win3CA.tmp
\WINDOWS\Temp\win3CB.tmp
\WINDOWS\Temp\win3CC.tmp
\WINDOWS\Temp\win3CD.tmp
\WINDOWS\Temp\win3CE.tmp
\WINDOWS\Temp\win3CF.tmp
\WINDOWS\Temp\win3D0.tmp
\WINDOWS\Temp\win3D1.tmp
\WINDOWS\Temp\win3D2.tmp
\WINDOWS\Temp\win3D3.tmp
\WINDOWS\Temp\win3D4.tmp
\WINDOWS\Temp\win3D5.tmp
\WINDOWS\Temp\win3D6.tmp
\WINDOWS\Temp\win3D7.tmp
\WINDOWS\Temp\win3D8.tmp
\WINDOWS\Temp\win3D9.tmp
\WINDOWS\Temp\win3DA.tmp
\WINDOWS\Temp\win3DB.tmp
\WINDOWS\Temp\win3DC.tmp
\WINDOWS\Temp\win3DD.tmp
\WINDOWS\Temp\win3DE.tmp
\WINDOWS\Temp\win3DF.tmp
\WINDOWS\Temp\win3E0.tmp
\WINDOWS\Temp\win3E1.tmp
\WINDOWS\Temp\win3E2.tmp
\WINDOWS\Temp\win3E3.tmp
\WINDOWS\Temp\win3E4.tmp
\WINDOWS\Temp\win3E5.tmp
\WINDOWS\Temp\win3E6.tmp
\WINDOWS\Temp\win3E7.tmp
\WINDOWS\Temp\win3E8.tmp
\WINDOWS\Temp\win3E9.tmp
\WINDOWS\Temp\win3EA.tmp
\WINDOWS\Temp\win3EB.tmp
\WINDOWS\Temp\win3EC.tmp
\WINDOWS\Temp\win3ED.tmp
\WINDOWS\Temp\win3EE.tmp
\WINDOWS\Temp\win3EF.tmp
\WINDOWS\Temp\win3F0.tmp
\WINDOWS\Temp\win3F1.tmp
\WINDOWS\Temp\win3F2.tmp
\WINDOWS\Temp\win3F3.tmp
\WINDOWS\Temp\win3F4.tmp
\WINDOWS\Temp\win3F5.tmp
\WINDOWS\Temp\win3F6.tmp
\WINDOWS\Temp\win3F7.tmp
\WINDOWS\Temp\win3F8.tmp
\WINDOWS\Temp\win3F9.tmp
\WINDOWS\Temp\win3FA.tmp
\WINDOWS\Temp\win3FB.tmp
\WINDOWS\Temp\win3FC.tmp
\WINDOWS\Temp\win3FD.tmp
\WINDOWS\Temp\win3FE.tmp
\WINDOWS\Temp\win3FF.tmp
\WINDOWS\Temp\win4.tmp
\WINDOWS\Temp\win40.tmp
\WINDOWS\Temp\win400.tmp
\WINDOWS\Temp\win401.tmp
\WINDOWS\Temp\win402.tmp
\WINDOWS\Temp\win403.tmp
\WINDOWS\Temp\win404.tmp
\WINDOWS\Temp\win405.tmp
\WINDOWS\Temp\win406.tmp
\WINDOWS\Temp\win407.tmp
\WINDOWS\Temp\win408.tmp
\WINDOWS\Temp\win409.tmp
\WINDOWS\Temp\win40A.tmp
\WINDOWS\Temp\win40B.tmp
\WINDOWS\Temp\win40C.tmp
\WINDOWS\Temp\win40D.tmp
\WINDOWS\Temp\win40E.tmp
\WINDOWS\Temp\win40F.tmp
\WINDOWS\Temp\win41.tmp
\WINDOWS\Temp\win410.tmp
\WINDOWS\Temp\win411.tmp
\WINDOWS\Temp\win412.tmp
\WINDOWS\Temp\win413.tmp
\WINDOWS\Temp\win414.tmp
\WINDOWS\Temp\win415.tmp
\WINDOWS\Temp\win416.tmp
\WINDOWS\Temp\win417.tmp
\WINDOWS\Temp\win418.tmp
\WINDOWS\Temp\win419.tmp
\WINDOWS\Temp\win41A.tmp
\WINDOWS\Temp\win41B.tmp
\WINDOWS\Temp\win41C.tmp
\WINDOWS\Temp\win41D.tmp
\WINDOWS\Temp\win41E.tmp
\WINDOWS\Temp\win41F.tmp
\WINDOWS\Temp\win420.tmp
\WINDOWS\Temp\win421.tmp
\WINDOWS\Temp\win422.tmp
\WINDOWS\Temp\win423.tmp
\WINDOWS\Temp\win424.tmp
\WINDOWS\Temp\win425.tmp
\WINDOWS\Temp\win426.tmp
\WINDOWS\Temp\win427.tmp
\WINDOWS\Temp\win428.tmp
\WINDOWS\Temp\win429.tmp
\WINDOWS\Temp\win42A.tmp
\WINDOWS\Temp\win42B.tmp
\WINDOWS\Temp\win42C.tmp
\WINDOWS\Temp\win42D.tmp
\WINDOWS\Temp\win42E.tmp
\WINDOWS\Temp\win42F.tmp
\WINDOWS\Temp\win43.tmp
\WINDOWS\Temp\win430.tmp
\WINDOWS\Temp\win431.tmp
\WINDOWS\Temp\win432.tmp
\WINDOWS\Temp\win433.tmp
\WINDOWS\Temp\win434.tmp
\WINDOWS\Temp\win435.tmp
\WINDOWS\Temp\win436.tmp
\WINDOWS\Temp\win437.tmp
\WINDOWS\Temp\win438.tmp
\WINDOWS\Temp\win439.tmp
\WINDOWS\Temp\win43A.tmp
\WINDOWS\Temp\win43B.tmp
\WINDOWS\Temp\win43C.tmp
\WINDOWS\Temp\win43D.tmp
\WINDOWS\Temp\win43E.tmp
\WINDOWS\Temp\win43F.tmp
\WINDOWS\Temp\win44.tmp
\WINDOWS\Temp\win440.tmp
\WINDOWS\Temp\win441.tmp
\WINDOWS\Temp\win442.tmp
\WINDOWS\Temp\win443.tmp
\WINDOWS\Temp\win444.tmp
\WINDOWS\Temp\win445.tmp
\WINDOWS\Temp\win446.tmp
\WINDOWS\Temp\win447.tmp
\WINDOWS\Temp\win448.tmp
\WINDOWS\Temp\win449.tmp
\WINDOWS\Temp\win44A.tmp
\WINDOWS\Temp\win44B.tmp
\WINDOWS\Temp\win44C.tmp
\WINDOWS\Temp\win44D.tmp
\WINDOWS\Temp\win44E.tmp
\WINDOWS\Temp\win44F.tmp
\WINDOWS\Temp\win45.tmp
\WINDOWS\Temp\win450.tmp
\WINDOWS\Temp\win451.tmp
\WINDOWS\Temp\win452.tmp
\WINDOWS\Temp\win453.tmp
\WINDOWS\Temp\win454.tmp
\WINDOWS\Temp\win455.tmp
\WINDOWS\Temp\win456.tmp
\WINDOWS\Temp\win457.tmp
\WINDOWS\Temp\win458.tmp
\WINDOWS\Temp\win459.tmp
\WINDOWS\Temp\win45A.tmp
\WINDOWS\Temp\win45B.tmp
\WINDOWS\Temp\win45C.tmp
\WINDOWS\Temp\win45D.tmp
\WINDOWS\Temp\win45E.tmp
\WINDOWS\Temp\win45F.tmp
\WINDOWS\Temp\win46.tmp
\WINDOWS\Temp\win460.tmp
\WINDOWS\Temp\win461.tmp
\WINDOWS\Temp\win462.tmp
\WINDOWS\Temp\win463.tmp
\WINDOWS\Temp\win464.tmp
\WINDOWS\Temp\win465.tmp
\WINDOWS\Temp\win466.tmp
\WINDOWS\Temp\win467.tmp
\WINDOWS\Temp\win468.tmp
\WINDOWS\Temp\win469.tmp
\WINDOWS\Temp\win46A.tmp
\WINDOWS\Temp\win46B.tmp
\WINDOWS\Temp\win46C.tmp
\WINDOWS\Temp\win46D.tmp
\WINDOWS\Temp\win46E.tmp
\WINDOWS\Temp\win46F.tmp
\WINDOWS\Temp\win470.tmp
\WINDOWS\Temp\win471.tmp
\WINDOWS\Temp\win472.tmp
\WINDOWS\Temp\win473.tmp
\WINDOWS\Temp\win474.tmp
\WINDOWS\Temp\win475.tmp
\WINDOWS\Temp\win476.tmp
\WINDOWS\Temp\win477.tmp
\WINDOWS\Temp\win478.tmp
\WINDOWS\Temp\win479.tmp
\WINDOWS\Temp\win47A.tmp
\WINDOWS\Temp\win47B.tmp
\WINDOWS\Temp\win47C.tmp
\WINDOWS\Temp\win47D.tmp
\WINDOWS\Temp\win47E.tmp
\WINDOWS\Temp\win47F.tmp
\WINDOWS\Temp\win48.tmp
\WINDOWS\Temp\win480.tmp
\WINDOWS\Temp\win481.tmp
\WINDOWS\Temp\win482.tmp
\WINDOWS\Temp\win483.tmp
\WINDOWS\Temp\win484.tmp
\WINDOWS\Temp\win485.tmp
\WINDOWS\Temp\win486.tmp
\WINDOWS\Temp\win487.tmp
\WINDOWS\Temp\win488.tmp
\WINDOWS\Temp\win489.tmp
\WINDOWS\Temp\win48A.tmp
\WINDOWS\Temp\win48B.tmp
\WINDOWS\Temp\win48C.tmp
\WINDOWS\Temp\win48D.tmp
\WINDOWS\Temp\win48E.tmp
\WINDOWS\Temp\win48F.tmp
\WINDOWS\Temp\win490.tmp
\WINDOWS\Temp\win491.tmp
\WINDOWS\Temp\win492.tmp
\WINDOWS\Temp\win493.tmp
\WINDOWS\Temp\win494.tmp
\WINDOWS\Temp\win495.tmp
\WINDOWS\Temp\win496.tmp
\WINDOWS\Temp\win497.tmp
\WINDOWS\Temp\win498.tmp
\WINDOWS\Temp\win499.tmp
\WINDOWS\Temp\win49A.tmp
\WINDOWS\Temp\win49B.tmp
\WINDOWS\Temp\win49C.tmp
\WINDOWS\Temp\win49D.tmp
\WINDOWS\Temp\win4A.tmp
\WINDOWS\Temp\win4A0.tmp
\WINDOWS\Temp\win4A1.tmp
\WINDOWS\Temp\win4A2.tmp
\WINDOWS\Temp\win4A3.tmp
\WINDOWS\Temp\win4A4.tmp
\WINDOWS\Temp\win4A5.tmp
\WINDOWS\Temp\win4A6.tmp
\WINDOWS\Temp\win4A7.tmp
\WINDOWS\Temp\win4A8.tmp
\WINDOWS\Temp\win4A9.tmp
\WINDOWS\Temp\win4AA.tmp
\WINDOWS\Temp\win4AB.tmp
\WINDOWS\Temp\win4AC.tmp
\WINDOWS\Temp\win4AD.tmp
\WINDOWS\Temp\win4AE.tmp
\WINDOWS\Temp\win4AF.tmp
\WINDOWS\Temp\win4B.tmp
\WINDOWS\Temp\win4B3.tmp
\WINDOWS\Temp\win4C.tmp
\WINDOWS\Temp\win4C0.tmp
\WINDOWS\Temp\win4C7.tmp
\WINDOWS\Temp\win4D.tmp
\WINDOWS\Temp\win4E.tmp
\WINDOWS\Temp\win4F.tmp
\WINDOWS\Temp\win5.tmp
\WINDOWS\Temp\win50.tmp
\WINDOWS\Temp\win51.tmp
\WINDOWS\Temp\win52.tmp
\WINDOWS\Temp\win53.tmp
\WINDOWS\Temp\win54.tmp
\WINDOWS\Temp\win55.tmp
\WINDOWS\Temp\win56.tmp
\WINDOWS\Temp\win57.tmp
\WINDOWS\Temp\win59.tmp
\WINDOWS\Temp\win6.tmp
\WINDOWS\Temp\win62.tmp
\WINDOWS\Temp\win67.tmp
\WINDOWS\Temp\win6C.tmp
\WINDOWS\Temp\win70.tmp
\WINDOWS\Temp\win75.tmp
\WINDOWS\Temp\winB5.tmp
\WINDOWS\Temp\winBC.tmp
\WINDOWS\Temp\winC0.tmp
\WINDOWS\Temp\winC1.tmp
\WINDOWS\Temp\winC2.tmp
\WINDOWS\Temp\winC3.tmp
\WINDOWS\Temp\winC4.tmp
\WINDOWS\Temp\winC5.tmp
\WINDOWS\Temp\winC6.tmp
\WINDOWS\Temp\winC7.tmp
\WINDOWS\Temp\winC8.tmp
\WINDOWS\Temp\winC9.tmp
\WINDOWS\Temp\winCA.tmp
\WINDOWS\Temp\winCB.tmp
\WINDOWS\Temp\winCC.tmp
\WINDOWS\Temp\winCD.tmp
\WINDOWS\Temp\winCE.tmp
\WINDOWS\Temp\winCF.tmp
\WINDOWS\Temp\winD0.tmp
\WINDOWS\Temp\winD1.tmp
\WINDOWS\Temp\winD2.tmp
\WINDOWS\Temp\winD3.tmp
\WINDOWS\Temp\winD4.tmp
\WINDOWS\Temp\winD5.tmp
\WINDOWS\Temp\winD6.tmp
\WINDOWS\Temp\winD7.tmp
\WINDOWS\Temp\winD8.tmp
\WINDOWS\Temp\winD9.tmp
\WINDOWS\Temp\winDA.tmp
\WINDOWS\Temp\winDB.tmp
\WINDOWS\Temp\winDC.tmp
\WINDOWS\Temp\winDD.tmp
\WINDOWS\Temp\winDE.tmp
\WINDOWS\Temp\winDF.tmp
\WINDOWS\Temp\winE0.tmp
\WINDOWS\Temp\winE1.tmp
\WINDOWS\Temp\winE2.tmp
\WINDOWS\Temp\winE3.tmp
\WINDOWS\Temp\winE4.tmp
\WINDOWS\Temp\winE5.tmp
\WINDOWS\Temp\winE6.tmp
\WINDOWS\Temp\winE7.tmp
\WINDOWS\Temp\winE8.tmp
\WINDOWS\Temp\winE9.tmp
\WINDOWS\Temp\winEA.tmp
\WINDOWS\Temp\winEB.tmp
\WINDOWS\Temp\winEC.tmp
\WINDOWS\Temp\winED.tmp
\WINDOWS\Temp\winEE.tmp
\WINDOWS\Temp\winEF.tmp
\WINDOWS\Temp\winF0.tmp
\WINDOWS\Temp\winF1.tmp
\WINDOWS\Temp\winF2.tmp
\WINDOWS\Temp\winF3.tmp
\WINDOWS\Temp\winF4.tmp
\WINDOWS\Temp\winF5.tmp
\WINDOWS\Temp\winF6.tmp
\WINDOWS\Temp\winF7.tmp
\WINDOWS\Temp\winF8.tmp
\WINDOWS\Temp\winF9.tmp
\WINDOWS\Temp\winFA.tmp
\WINDOWS\Temp\winFB.tmp
\WINDOWS\Temp\winFC.tmp
\WINDOWS\Temp\winFD.tmp
\WINDOWS\Temp\winFE.tmp
\WINDOWS\Temp\winFF.tmp
\WINDOWS\Temp\WLTB Custom Button Feeds
\WINDOWS\Temp\WLTB Custom Button Feeds\microsoft.msn.mymsn.btn upgrade status
\WINDOWS\Temp\WLTB Custom Button Feeds\microsoft.windowslive.addbtn.btn upgrade status
\WINDOWS\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 0
\WINDOWS\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn upgrade status
\WINDOWS\Temp\_avast4_
\WINDOWS\Temp\_avast4_\Webshlock.txt
\WINDOWS\wiadebug.log
\WINDOWS\wiaservc.log
\WINDOWS\WindowsUpdate.log


Liste des derniers fichies modifies/crees dans windir\system32
C:\WINDOWS\System32/drivers\secuity_center_logo.gif -->22/05/2007 17:52:06
C:\WINDOWS\System32/drivers\remove_spyware_button.gif -->22/05/2007 17:52:06
C:\WINDOWS\System32/drivers\icon_warning.gif -->22/05/2007 17:52:06
C:\WINDOWS\System32/drivers\header_bg.gif -->22/05/2007 17:52:06
C:\WINDOWS\System32/drivers\close_icon.gif -->22/05/2007 17:52:06
C:\WINDOWS\System32/drivers\alert_icon.gif -->22/05/2007 17:52:06
C:\WINDOWS\System32/drivers\aswmon.sys -->30/04/2007 17:41:55

C:\WINDOWS\System32\CONFIG.NT -->25/05/2007 23:09:21
C:\WINDOWS\System32\Status.MPF -->25/05/2007 22:57:18
C:\WINDOWS\System32\winjks32.dll -->25/05/2007 14:51:41
C:\WINDOWS\System32\FNTCACHE.DAT -->25/05/2007 2:02:12
C:\WINDOWS\System32\perfh00C.dat -->25/05/2007 1:55:44
C:\WINDOWS\System32\perfc00C.dat -->25/05/2007 1:55:44
C:\WINDOWS\System32\perfh009.dat -->25/05/2007 1:55:43
C:\WINDOWS\System32\perfc009.dat -->25/05/2007 1:55:43
C:\WINDOWS\System32\lfd32.ini -->21/05/2007 13:26:56
C:\WINDOWS\System32\gtv_sd.bin -->21/05/2007 13:26:56
C:\WINDOWS\System32\aswBoot.exe -->30/04/2007 17:46:10
C:\WINDOWS\System32\AvastSS.scr -->30/04/2007 17:35:28
C:\WINDOWS\System32\msi.dll -->18/04/2007 18:14:18
C:\WINDOWS\System32\KGyGaAvL.sys -->18/04/2007 8:15:53
C:\WINDOWS\System32\68BEA66E75.sys -->18/04/2007 8:15:48
C:\WINDOWS\System32\LexFiles.ulf -->15/04/2007 19:34:45
C:\WINDOWS\System32\wpa.dbl -->13/04/2007 18:48:09
C:\WINDOWS\System32\PerfStringBackup.INI -->11/04/2007 11:01:52
C:\WINDOWS\System32\SampleGrabber.ax -->22/03/2007 5:48:18
C:\WINDOWS\System32\756EA6BE68.sys -->20/03/2007 1:40:47
C:\WINDOWS\System32\winsrv.dll -->17/03/2007 15:44:47
C:\WINDOWS\System32\xpsp3res.dll -->9/03/2007 13:51:20
C:\WINDOWS\System32\user32.dll -->8/03/2007 17:37:50
C:\WINDOWS\System32\mf3216.dll -->8/03/2007 17:37:50
C:\WINDOWS\System32\gdi32.dll -->8/03/2007 17:37:50

C:\WINDOWS\0.log -->25/05/2007 23:03:54
C:\WINDOWS\ModemLog_Conexant HDA D110 MDC V.92 Modem.txt -->25/05/2007 23:03:49
C:\WINDOWS\WindowsUpdate.log -->25/05/2007 23:03:46
C:\WINDOWS\wiadebug.log -->25/05/2007 23:03:46
C:\WINDOWS\wiaservc.log -->25/05/2007 23:03:45
C:\WINDOWS\bootstat.dat -->25/05/2007 23:03:16
C:\WINDOWS\SchedLgU.Txt -->25/05/2007 23:02:24
C:\WINDOWS\setupapi.log -->25/05/2007 22:58:00
C:\WINDOWS\setuperr.log -->25/05/2007 16:36:02
C:\WINDOWS\setupact.log -->25/05/2007 16:36:02
C:\WINDOWS\Sti_Trace.log -->25/05/2007 4:40:24
C:\WINDOWS\win.ini -->20/05/2007 14:03:29
C:\WINDOWS\system.ini -->20/05/2007 14:03:29
C:\WINDOWS\matlab.ini -->17/05/2007 10:42:55
C:\WINDOWS\installer.exe -->17/05/2007 2:45:58


Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est D090-9B45

Répertoire de C:\WINDOWS\system32

05/08/2004 13:00 6.144 csrss.exe
1 fichier(s) 6.144 octets
0 Rép(s) 45.719.457.792 octets libres

Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est D090-9B45

Répertoire de C:\WINDOWS\Downloaded Program Files

16/04/2007 14:56 <REP> .
16/04/2007 14:56 <REP> ..
20/08/2004 11:36 65 desktop.ini
25/07/2002 19:13 24.576 dwusplay.dll
25/07/2002 19:13 196.608 dwusplay.exe
10/06/2005 11:44 417.792 isusweb.dll
4 fichier(s) 639.041 octets

Total des fichiers listés :
4 fichier(s) 639.041 octets
2 Rép(s) 45.719.457.792 octets libres

Recherche de rootkit! (Merci S!Ri)

Recherche d'infections connues

Export des clefs sensibles..

Liste des fichiers en exception sur le pare-feu XP SP2

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Disabled:LimeWire"
"C:\\Program Files\\Hummingbird\\Connectivity\\11.00\\Exceed\\exceed.exe"="C:\\Program Files\\Hummingbird\\Connectivity\\11.00\\Exceed\\exceed.exe:*:Enabled:X Server for Windows 2000/XP/2003"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\Program Files\\Dassault Systemes\\B15\\intel_a\\code\\bin\\CNEXT.exe"="C:\\Program Files\\Dassault Systemes\\B15\\intel_a\\code\\bin\\CNEXT.exe:*:Enabled:CATIA"
"C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PreGui_ogl.exe"="C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PreGui_ogl.exe:*:Enabled:PreGui_ogl"
"C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PreEngine.exe"="C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PreEngine.exe:*:Enabled:PreEngine"
"C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PostGui_ogl.exe"="C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PostGui_ogl.exe:*:Enabled:PostGui_ogl"
"C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PostEngine.exe"="C:\\Program Files\\Ansys Inc\\CFX\\CFX-10.0\\bin\\winnt\\PostEngine.exe:*:Enabled:PostEngine"
"C:\\Program Files\\Java\\j2re1.4.2_07\\bin\\java.exe"="C:\\Program Files\\Java\\j2re1.4.2_07\\bin\\java.exe:*:Enabled:java"
"C:\\DOCUME~1\\GUILLA~1\\LOCALS~1\\Temp\\win55.tmp.exe"="C:\\DOCUME~1\\GUILLA~1\\LOCALS~1\\Temp\\win55.tmp.exe:*:Enabled:win55.tmp"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\WINDOWS\\TEMP\\win42.tmp.exe"="C:\\WINDOWS\\TEMP\\win42.tmp.exe:*:Enabled:win42.tmp"

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"

Export de la clef SharedTaskScheduler

[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

Rechercher adresses sensibles dans le fichier HOSTS...







Répondre à blinkgreen

Il y a aussi un fichier appelé catchme sur mon bureau suite à l'exécution de DiagHelp. Si ca peut vous etre utile, voici son contenu :


catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-26 10:32:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCGCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\gaetleleu@hotmail.com\DFSR\Staging\CS{06436DAB-D817-C9A3-2D95-83D668666413}\01\10-{06436DAB-D817-C9A3-2D95-83D668666413}-v1-{D9B08CF4-68C2-4C40-B84C-1B9D776B2AA2}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\gaetleleu@hotmail.com\DFSR\Staging\CS{06436DAB-D817-C9A3-2D95-83D668666413}\11\11-{D9B08CF4-68C2-4C40-B84C-1B9D776B2AA2}-v11-{D9B08CF4-68C2-4C40-B84C-1B9D776B2AA2}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3201726 bytes hidden from API
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\gaetleleu@hotmail.com\DFSR\Staging\CS{06436DAB-D817-C9A3-2D95-83D668666413}\11\11-{D9B08CF4-68C2-4C40-B84C-1B9D776B2AA2}-v11-{D9B08CF4-68C2-4C40-B84C-1B9D776B2AA2}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 225120 bytes hidden from API
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\gaetleleu@hotmail.com\DFSR\Staging\CS{06436DAB-D817-C9A3-2D95-83D668666413}\11\11-{D9B08CF4-68C2-4C40-B84C-1B9D776B2AA2}-v11-{D9B08CF4-68C2-4C40-B84C-1B9D776B2AA2}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.3 15744 bytes hidden from API
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\gaetleleu@hotmail.com\DFSR\Staging\CS{06436DAB-D817-C9A3-2D95-83D668666413}\11\11-{D9B08CF4-68C2-4C40-B84C-1B9D776B2AA2}-v11-{D9B08CF4-68C2-4C40-B84C-1B9D776B2AA2}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 355480 bytes hidden from API

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 5

Répondre à blinkgreen

Re

Rien de visible dans ce rapport.

Fais une analyse antivirus en ligne sur Panda
http://www.pandasoftware.com/activ [...] ncipal.htm
Désactive temporairement Avast, car ils ne s'aiment pas.

Colle son rapport ici.

------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_

Question idiote peut-être, mais comment faire pour désactiver avast. Car je l'ai juste quitté et il n'est plus dans ma barre des taches mais quand je fais le scan en ligne j'ai une fenêtre du même type que celle que j'expliquais avant avec WinAgent et alors le scan s'arrête...

Répondre à blinkgreen

Re

Si tu ne l'as plus dans la bare des tâches, on change.

BitDefender
http://www.bitdefender.fr/scan8/ie.html

------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_

J'ai également un problème avec ce scan en ligne. Après avoir installé le contrôle ActiveX, j'ai une fenêtre disant :

this website is not authorized to host this ActiveX control
Please report it to the webmaster of the website or report it to BitDefender

Répondre à blinkgreen

PS : j'ai toujours ce foutu Win32Dial machin qui rvient toute les 5 min...

Répondre à blinkgreen

Salut, ca fait longtemps que je n'ai plus eu de tes nouvelles... C'est pas grave je comprends que t'es pas toujours derrière ton écran, en plus on est dimanche et t'as déjà été là tous les jours pour moi.

En résumé, le scan de BitDefender ne marche toujours pas. Mais j'ai refait un scan de KasperSky parce que j'en avais marre de ce Win32 Dialer et ca a marché ! J'ai l'impression que j'ai encore pas mal de crasses. En plus il vient de m'arriver un truc bizarre je sais pas si ca a quelque chose a voir. Ma touche shift était inversée (c'est-à-dire que quand mon shift lock était activé ca écrivait en minuscule et quand il ne l'était pas, ca écrivait en majuscule) et quand je sélectionnait un objet dans le panneau de configuration tous les objets précédents étaient aussi sélectionnées. Je savais pas sélectionné un élément particulier si il était en plein milieu de la liste !J'ai redémarré mon ordi et maintenant c'est parti. Enfin soit, à bientot et voici le rapport de Kaspersky :


KASPERSKY ON-LINE SCANNER REPORT
Sunday, May 27, 2007 6:28:49 PM
Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version : 5.0.83.0
Dernière mise à jour de la base antivirus Kaspersky : 27/05/2007
Enregistrements dans la base antivirus Kaspersky : 330541


Paramètres d'analyse
Analyser avec la base antivirus suivante étendue
Analyser les archives vrai
Analyser les bases de messagerie vrai

Cible de l'analyse Poste de travail
C:\
E:\

Statistiques de l'analyse
Total d'objets analysés 240526
Nombre de virus trouvés 12
Nombre d'objets infectés 25 / 0
Nombre d'objets suspects 1
Durée de l'analyse 01:25:32

Nom de l'objet infecté Nom du virus Dernière action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare L'objet est verrouillé ignoré

C:\Documents and Settings\All Users\Application Data\SingleClick Systems\HomeNet Manager\Logs\hnm_svc.log L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Mozilla\Firefox\Profiles\kvdk0zul.default\cert8.db L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Mozilla\Firefox\Profiles\kvdk0zul.default\formhistory.dat L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Mozilla\Firefox\Profiles\kvdk0zul.default\history.dat L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Mozilla\Firefox\Profiles\kvdk0zul.default\key3.db L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Mozilla\Firefox\Profiles\kvdk0zul.default\parent.lock L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\call256.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\callmember256.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\chat512.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\chatmsg1024.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\chatmsg256.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\chatmsg32768.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\chatmsg512.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\contactgroup256.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\index2.dat L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\profile4096.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\user1024.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\user16384.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\user256.dbb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Cookies\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\BVRP Software\NetWaiting\MoHlog.txt L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\Logs\Dfsr.log L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\pending.dat L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\Working\database_72D0_90CF_D090_9B45\dfsr.db L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\Working\database_72D0_90CF_D090_9B45\fsr.log L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\Working\database_72D0_90CF_D090_9B45\fsrtmp.log L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\Working\database_72D0_90CF_D090_9B45\tmp.edb L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Windows Live Contacts\gpochet13@hotmail.com\real\members.stg L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Windows Live Contacts\gpochet13@hotmail.com\shadow\members.stg L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Mozilla\Firefox\Profiles\kvdk0zul.default\Cache\_CACHE_001_ L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Mozilla\Firefox\Profiles\kvdk0zul.default\Cache\_CACHE_002_ L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Mozilla\Firefox\Profiles\kvdk0zul.default\Cache\_CACHE_003_ L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Application Data\Mozilla\Firefox\Profiles\kvdk0zul.default\Cache\_CACHE_MAP_ L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Historique\History.IE5\MSHist012007052720070528\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Temp\clclean.0001.dir.0000\~efe2.tmp L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Temp\~DF2346.tmp L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Temp\~DF2354.tmp L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Temp\~DF3E66.tmp L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Temp\~DF3E74.tmp L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Temp\~DFFA82.tmp L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\Local Settings\Temporary Internet Files\Content.IE5\852R8L6R\xc60[1].exe Infecté : Trojan.Win32.Agent.qt ignoré

C:\Documents and Settings\Guillaume\Local Settings\Temporary Internet Files\Content.IE5\C9IV41QF\antzom[1].exe Infecté : Trojan.Win32.Agent.qt ignoré

C:\Documents and Settings\Guillaume\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\NTUSER.DAT L'objet est verrouillé ignoré

C:\Documents and Settings\Guillaume\ntuser.dat.LOG L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré

C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré

C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré

C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat L'objet est verrouillé ignoré

C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db L'objet est verrouillé ignoré

C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int L'objet est verrouillé ignoré

C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws L'objet est verrouillé ignoré

C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log L'objet est verrouillé ignoré

C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log L'objet est verrouillé ignoré

C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt L'objet est verrouillé ignoré

C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP220\A0110358.exe Infecté : Trojan-Downloader.Win32.Small.cul ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP220\A0110381.exe Infecté : Trojan-Downloader.Win32.Small.cul ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP221\A0116440.exe Infecté : not-virus:Hoax.Win32.Renos.fn ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP226\A0117533.exe Infecté : Trojan-Downloader.Win32.Small.cul ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP226\A0118560.dll Infecté : not-a-virus:AdTool.Win32.WhenU.i ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP226\A0118561.exe Infecté : not-a-virus:AdTool.Win32.WhenU.i ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP226\A0125688.exe Infecté : not-a-virus:RiskTool.Win32.PsKill.k ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP226\A0125755.exe Infecté : Trojan-Downloader.Win32.Alphabet.b ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP226\A0125758.exe Infecté : Trojan-Downloader.Win32.Small.cul ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP226\A0125765.exe Infecté : Trojan-Downloader.Win32.Alphabet.b ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP226\A0125770.exe Infecté : Trojan-Downloader.Win32.Small.cul ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP226\A0125850.exe/stream/data0006 Infecté : Trojan-Downloader.Win32.Zlob.btr ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP226\A0125850.exe/stream Infecté : Trojan-Downloader.Win32.Zlob.btr ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP226\A0125850.exe NSIS: infecté - 2 ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP227\A0132989.exe Infecté : not-a-virus:RiskTool.Win32.PsKill.k ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP227\A0133000.exe Infecté : not-a-virus:AdWare.Win32.Virtumonde.bq ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP227\A0133002.exe/data.rar/keygen.exe Infecté : not-a-virus:AdWare.Win32.Virtumonde.bq ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP227\A0133002.exe/data.rar/patch.exe Infecté : Trojan.Win32.Dialer.qn ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP227\A0133002.exe/data.rar/crack.exe Infecté : Trojan.Win32.Inject.br ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP227\A0133002.exe/data.rar/install.exe Infecté : Trojan-Downloader.Win32.Small.eqn ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP227\A0133002.exe/data.rar Infecté : Trojan-Downloader.Win32.Small.eqn ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP227\A0133002.exe RarSFX: infecté - 5 ignoré

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP229\change.log L'objet est verrouillé ignoré

C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré

C:\WINDOWS\installer.exe Suspect : Packed.Win32.Morphine.a ignoré

C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré

C:\WINDOWS\SoftwareDistribution\EventCache\{F5E9E392-35B7-4FBB-87D3-E000CA76BB2D}.bin L'objet est verrouillé ignoré

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré

C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré

C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré

C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\Antivirus.Evt L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\DEFAULT L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\SOFTWARE L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\SYSTEM L'objet est verrouillé ignoré

C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré

C:\WINDOWS\system32\drivers\sptd.sys L'objet est verrouillé ignoré

C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré

C:\WINDOWS\system32\winjks32.dll Infecté : Trojan.Win32.Dialer.qn ignoré

C:\WINDOWS\Temp\Perflib_Perfdata_1a4.dat L'objet est verrouillé ignoré

C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré

C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré

C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré

Analyse terminée.

Répondre à blinkgreen

Bonjour



$$ Supprime les fichiers/dossiers incriminés

C:\WINDOWS\ installer.exe
C:\WINDOWS\ system32\winjks32.dll


$$ Lance le nettoyage avec CCleaner.



$$ Clique sur Démarrer - Clic droit sur le Poste de Travail - Propriétés - Restauration du systéme - Cocher la case Désactiver la restauration du systéme et cliquer sur Appliquer.

Puis redémarrer l'ordinateur et faire l'opération inverse en décochant la case Désactiver la restauration systéme.


$$ Télécharge Combofix.exe (par sUBs) sur ton Bureau
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Double clique combofix.exe et suis les invites.
Lorsque le scan sera complété, un rapport apparaîtra.

Copie/colle ce rapport dans ta prochaine réponse avec un nouveau HijackThis.

------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_

Ok. Je ferai ca demain matin parce que la je vais aller dormir... Merci d etre revenu !

Répondre à blinkgreen

Impossible de supprimer le fichier dll. Voici le rapport de ComboFix puis le nouveau HiJackThis :


"Guillaume" - 2007-05-29 11:41:50 Service Pack 2
ComboFix 07-05.27.V - Running from: "C:\Documents and Settings\Guillaume\Bureau\"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\winjks32.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


((((((((((((((((((((((((((((((( Files Created from 2007-04-28 to 2007-05-29 ))))))))))))))))))))))))))))))))))


2007-05-27 18:20 206 --a------ C:\WINDOWS\g58565609.exe
2007-05-27 16:47 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-05-27 01:36 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-05-26 23:47 <REP> d-------- C:\WINDOWS\system32\ActiveScan
2007-05-25 23:01 95,872 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-05-25 23:01 94,552 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-05-25 23:01 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-05-25 23:01 745,600 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-05-25 23:01 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-05-25 23:01 26,888 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-05-25 23:01 23,416 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-05-25 23:01 <REP> d-------- C:\Program Files\Alwil Software
2007-05-25 14:47 <REP> d-------- C:\DOCUME~1\GUILLA~1\APPLIC~1\Sonic
2007-05-25 14:44 <REP> d-------- C:\DOCUME~1\GUILLA~1\APPLIC~1\Leadertech
2007-05-25 13:05 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-05-25 02:15 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-05-25 02:13 <REP> d-------- C:\Program Files\Yahoo!
2007-05-25 02:13 <REP> d-------- C:\Program Files\CCleaner
2007-05-25 01:59 <REP> d-------- C:\DOCUME~1\GUILLA~1\APPLIC~1\Hummingbird
2007-05-24 20:21 <REP> dr------- C:\Documents and Settings\Guillaume\Download
2007-05-24 20:21 <REP> dr------- C:\DOCUME~1\GUILLA~1\Download
2007-05-24 18:34 8,676 --a------ C:\dnsbak.reg
2007-05-24 16:56 0 -rahs---- C:\MSDOS.SYS
2007-05-24 16:56 0 -rahs---- C:\IO.SYS
2007-05-24 14:04 15,876 --a------ C:\Program Files\wsgyvsbff.exe
2007-05-24 11:25 15,876 --a------ C:\Program Files\bewwo.exe
2007-05-21 13:26 12 --a------ C:\WINDOWS\system32\gtv_sd.bin
2007-05-20 13:48 <REP> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Hummingbird
2007-05-20 13:46 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-05-20 13:46 <REP> dr------- C:\DOCUME~1\ADMINI~1\Mes documents
2007-05-20 13:46 <REP> dr------- C:\DOCUME~1\ADMINI~1\Menu D‚marrer
2007-05-20 13:46 <REP> dr------- C:\DOCUME~1\ADMINI~1\Favoris
2007-05-20 13:46 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisinage r‚seau
2007-05-20 13:46 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisinage d'impression
2007-05-20 13:46 <REP> d--h----- C:\DOCUME~1\ADMINI~1\ModŠles
2007-05-20 13:46 <REP> d-------- C:\DOCUME~1\ADMINI~1\Bureau
2007-05-20 13:46 <REP> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-05-20 13:46 <REP> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Intel
2007-05-20 13:46 <REP> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Corel
2007-05-20 03:33 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2007-05-10 10:55 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-05-29 09:42:31 -------- d-----w C:\DOCUME~1\GUILLA~1\APPLIC~1\Skype
2007-05-28 19:04:19 -------- d-----w C:\DOCUME~1\GUILLA~1\APPLIC~1\OpenOffice.org2
2007-05-28 12:58:32 6,632 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-05-28 12:58:30 56 --sh--r C:\WINDOWS\system32\68BEA66E75.sys
2007-05-27 23:34:54 -------- d-----w C:\DOCUME~1\GUILLA~1\APPLIC~1\Azureus
2007-05-27 10:08:47 -------- d-----w C:\DOCUME~1\GUILLA~1\APPLIC~1\U3
2007-05-26 21:40:40 -------- d-----w C:\Program Files\Webteh
2007-05-24 23:55:44 64,886 ----a-w C:\WINDOWS\system32\perfc00C.dat
2007-05-24 23:55:44 447,134 ----a-w C:\WINDOWS\system32\perfh00C.dat
2007-05-24 23:46:53 -------- d-----w C:\Program Files\LimeWire
2007-05-15 19:38:53 -------- d-----w C:\Program Files\Dl_cats
2007-04-20 13:18:18 -------- d-----w C:\Program Files\Xilisoft
2007-04-20 13:15:05 -------- d-----w C:\Program Files\Movavi Video Converter 5.3
2007-04-20 13:15:05 -------- d-----w C:\Program Files\MOVAVI
2007-04-20 13:10:03 -------- d-----w C:\Program Files\Blaze Media Pro
2007-04-19 09:45:17 -------- d-----w C:\Program Files\Azureus
2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-15 17:40:50 -------- d-----w C:\Program Files\Dell AIO 810
2007-04-15 17:33:19 -------- d-----w C:\Program Files\Jasc Software Inc
2007-04-15 17:33:19 -------- d-----w C:\DOCUME~1\GUILLA~1\APPLIC~1\Jasc Software Inc
2007-04-15 17:32:25 -------- d-----w C:\Program Files\Fichiers communs\Jasc Software Inc
2007-04-15 17:31:45 -------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-04-15 13:46:08 -------- d-----w C:\Program Files\a-squared Free
2007-04-15 13:07:25 -------- d-----w C:\DOCUME~1\GUILLA~1\APPLIC~1\Lavasoft
2007-04-14 15:26:42 -------- d-----w C:\Program Files\ffdshow
2007-04-14 15:11:52 -------- d-----w C:\Program Files\Dell Network Assistant
2007-04-14 15:07:12 -------- d-----w C:\Program Files\Movie Maker
2007-03-19 23:40:47 88 --sh--r C:\WINDOWS\system32\756EA6BE68.sys
2007-03-17 13:44:47 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:37:50 578,560 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:37:50 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:37:50 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 15:33:58 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 10:28]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04]
{5CA3D70E-1895-11CF-8E15-001234567890}=C:\WINDOWS\system32\dla\tfswshx.dll [2004-12-06 02:05]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-07-07 12:29]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\Windows Live Toolbar\msntb.dll [2006-10-11 00:26]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe" [2005-01-15 12:24]
"SigmatelSysTrayApp"="stsystra.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 12:48]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2006-04-06 15:58]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 12:55]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 12:56]
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 11:51]
"MBMon"="CTMBHA.DLL" [2006-03-03 04:18 C:\WINDOWS\system32\CTMBHA.DLL]
"VoiceCenter"="C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" [2006-01-02 10:13]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 21:29]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 02:02]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-10 00:34]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 16:24]
"dlcgmon.exe"="C:\Program Files\Dell AIO 810\dlcgmon.exe" [2005-10-20 20:42]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2006-10-07 14:20]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 16:16]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting.exe" [2003-09-10 03:24]
"SetDefaultMIDI"="MIDIDef.exe" []
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 19:23]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2006-07-29 19:34]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-08-14 18:39]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 16:13]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18a9b3ad-9f94-11db-8d71-001422f9ddbe}]
AutoRun\command- F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{96bdbc54-cd7b-11db-8d9d-001422f9ddbe}]
AutoRun\command- H:\Launch.exe


Contents of the 'Scheduled Tasks' folder
2007-04-14 14:23:30 C:\WINDOWS\tasks\Recherche de virus de McAfee.com - Mon ordinateur (DHY5TD2J-Guillaume).job
2007-05-29 00:30:01 C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job

********************************************************************

catchme 0.3.681 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-29 11:48:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2007-05-29 11:50:26 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-29 11:50

--- E O F ---






Logfile of HijackThis v1.99.1
Scan saved at 11:52:18, on 29/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\clclean.0001
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell AIO 810\dlcgmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\dlcgcoms.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.204\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://english.ircfast.com/index.php?rvs=hompag
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dlcgmon.exe] "C:\Program Files\Dell AIO 810\dlcgmon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/229?176774bdf545422c9411324edd84addd
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/230?176774bdf545422c9411324edd84addd
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/re [...] oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activ [...] asinst.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: ANSYS FLEXlm license manager - Macrovision Corporation - C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlcg_device - - C:\WINDOWS\system32\dlcgcoms.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Répondre à blinkgreen

Bonjour

Combofix a supprimé le fichier résistant.

Hijackthis est propre.

As tu encore des dysfonctionnements ?

------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_

Depuis que j'ai exécuté combofix, je n'ai plus la fenetre du Win32 Dialer qui revient tout le temps. Mais j'ai refait un scan Kaspersky et il m'a encore trouvé des virus dans le répertoire C:\Program Files et dans C:\Qoobox\Quarantine\C\Windows\System32.
J'ai réussi à les supprimer dans l'explorateur et j'ai refait immédiatement après un scan Kaspersky. Apparement il resterait 3 fichier infevtés dans le c:\Systeme Volume Information\restore... mais je ne trouve pas ce dossier dans l'explorateur donc je sais pas les virer. Voici donc le rapport du dernier Kaspersky :


KASPERSKY ON-LINE SCANNER REPORT
Tuesday, May 29, 2007 5:19:24 PM
Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version : 5.0.83.0
Dernière mise à jour de la base antivirus Kaspersky : 29/05/2007
Enregistrements dans la base antivirus Kaspersky : 333800
Paramètres d'analyse
Analyser avec la base antivirus suivante étendue
Analyser les archives vrai
Analyser les bases de messagerie vrai
Cible de l'analyse Poste de travail
C:\
E:\
Statistiques de l'analyse
Total d'objets analysés 228926
Nombre de virus trouvés 2
Nombre d'objets infectés 3 / 0
Nombre d'objets suspects 0
Durée de l'analyse 01:21:21

Nom de l'objet infecté Nom du virus Dernière action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\SingleClick Systems\HomeNet Manager\Logs\hnm_svc.log L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\call256.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\callmember256.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\chat512.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\chatmsg1024.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\chatmsg256.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\chatmsg32768.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\chatmsg512.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\contactgroup256.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\index2.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\profile4096.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\user1024.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\user16384.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Application Data\Skype\gaetleleu\user256.dbb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\BVRP Software\NetWaiting\MoHlog.txt L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\Logs\Dfsr.log L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\pending.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\Working\database_72D0_90CF_D090_9B45\dfsr.db L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\Working\database_72D0_90CF_D090_9B45\fsr.log L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\Working\database_72D0_90CF_D090_9B45\fsrtmp.log L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Messenger\gpochet13@hotmail.com\SharingMetadata\Working\database_72D0_90CF_D090_9B45\tmp.edb L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Windows Live Contacts\gpochet13@hotmail.com\real\members.stg L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Application Data\Microsoft\Windows Live Contacts\gpochet13@hotmail.com\shadow\members.stg L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Historique\History.IE5\MSHist012007052920070530\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Temp\clclean.0001.dir.0001\~efe2.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Temp\~DF2A34.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Temp\~DF2A59.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Temp\~DF7502.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Temp\~DF7510.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\Guillaume\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt L'objet est verrouillé ignoré
C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP1\A0000011.dll Infecté : Trojan.Win32.Dialer.qn ignoré
C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP1\A0000076.exe Infecté : not-virus:Hoax.Win32.Renos.hr ignoré
C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP1\A0000077.exe Infecté : not-virus:Hoax.Win32.Renos.hr ignoré
C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP1\change.log L'objet est verrouillé ignoré
C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\Antivirus.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\DEFAULT L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SOFTWARE L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SYSTEM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\drivers\sptd.sys L'objet est verrouillé ignoré
C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
C:\WINDOWS\Temp\Perflib_Perfdata_140.dat L'objet est verrouillé ignoré
C:\WINDOWS\Temp\_avast4_\Webshlock.txt L'objet est verrouillé ignoré
C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
Analyse terminée.

Répondre à blinkgreen

Re


Il s'agit du système de restauration.

Clique sur Démarrer - Clic droit sur le Poste de Travail - Propriétés - Restauration du systéme - Cocher la case Désactiver la restauration du systéme et cliquer sur Appliquer.

Puis redémarrer l'ordinateur et faire l'opération inverse en décochant la case Désactiver la restauration systéme.


As tu encore des dysfonctionnements ?

------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_

Ok je viens de le faire. Non je n'ai plus aucuns dysfonctionnements !! Merci pour tout en tout cas parce que je suis resté avec un ordi complètement infecté pendant plusieurs semaines et j'ai pensé à formatter plein de fois jusqu'à ce que je découvre ce site...

Répondre à blinkgreen

Re

Encore une petite chose.
Dénonce ton infection pour faire condamner les auteurs.
Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être le plus nombreux possibles, alors rends compte de ton infection :
- Voir les règles du forum : http://www.malwarecomplaints.info/viewtopic.php?t=5
- Après t'être enregistré à l'aide du bouton en haut se nommant "Register"
Si tu as plus de 13 ans, choisir : "I Agree to these terms and am over or exactly 13 years of age"
Si tu as moins, clique sur : "I Agree to these terms and am under 13 years of age"

Tu as alors sous forme de liste un sujet par type d'infection (Look2Me, Smitfraud, SpywareQuake etc..).
La tienne =
Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas par quoi tu étais infecté(e), crée un message dans le sujet Autres infections conforme au règle du forum (age, ville, département etc..)
Indique aussi le nom du Forum qui t'a aidé.
---> http://www.malwarecomplaints.info/viewforum.php?f=10

Plus d'informations ici
http://forum.zebulon.fr/index.php?showtopic=88688

------------------------------ Le meilleur antivirus, c'est vous
Vous avez un problème ? Créez votre propre post !
Répondre à chercheur_
Tom's Guide > Forum > Sécurité - Virus > [RESOLU] aide svp ne sais plus quoi faire PC multiplement infecté !!!
Aller à :

Il y a 1506 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.

Attention

Vous allez répondre sur un sujet resté inactif pendant plus de 6 mois.
Assurez-vous d'apporter des éléments nouveaux à la discussion avant de poursuivre.

Répondre Annuler
Liens