j ai eu chevals de troie avec msn
Dernière réponse : dans Sécurité
j ai eut chevals de troie avec msn je les supprime mais tout les jours j en chope au moins 2, j ai supprime mes contacts msn je ne sius pas tranquille car il m arrive de faire achats sur internet j ai avast comme anti-virus est ce qu il ai assez performent
Autres pages sur : chevals troie msn
Lassé par la pub ? Créez un compte
Un bonjour ?
Télécharge Hijackthis (de Merjin).
Dézippe-le dans un dossier ou sur ton Bureau.
Lance l'application (Hijackthis.exe) :
- Choisis l'option "Do a system scan and save a logfile"
- Le Bloc-Notes s'ouvre, poste son contenu :
Edition / Sélectionner tout
Edition / Copier
Clique-Droit / Coller dans ta réponse
AIDE : Tuto en vidéo sur Hijackthis
Télécharge Hijackthis (de Merjin).
Dézippe-le dans un dossier ou sur ton Bureau.
Lance l'application (Hijackthis.exe) :
- Choisis l'option "Do a system scan and save a logfile"
- Le Bloc-Notes s'ouvre, poste son contenu :
AIDE : Tuto en vidéo sur Hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 14:59:42, on 08/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\CATHER~1\LOCALS~1\Temp\Rar$EX00.188\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [Á³# L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [_Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jh...
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: system32 - {18E99EDB-3502-456B-B158-F14266C9E69B} - sysprinters.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
Scan saved at 14:59:42, on 08/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\CATHER~1\LOCALS~1\Temp\Rar$EX00.188\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [Á³# L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [_Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jh...
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: system32 - {18E99EDB-3502-456B-B158-F14266C9E69B} - sysprinters.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
Re,
Télécharge MSNFix.zip ([#ff0000]!aur3n7[/#f]) sur ton Bureau.
Décompresse-le sur ton bureau (Clique-Droit/Extraire tout).
Ouvre le dossier MSNFix puis double-clique sur MSNFix.bat.
- Exécute l'option R.
-- Si l'infection est détectée, presse une touche pour lancer le nettoyage.
[#ff0000]Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations.
Dans ce cas il suffit de redémarrer l'ordinateur manuellement.[/#f]
Poste le rapport situé dans le dossier MSNFix.
Le nom du rapport correspond au moment de sa création : date_heure.log
->Fiche complète<-
&
Désinstalle correctement Avast! pour le remplacer par Antivir.
Télécharge MSNFix.zip ([#ff0000]!aur3n7[/#f]) sur ton Bureau.
Décompresse-le sur ton bureau (Clique-Droit/Extraire tout).
Ouvre le dossier MSNFix puis double-clique sur MSNFix.bat.
- Exécute l'option R.
-- Si l'infection est détectée, presse une touche pour lancer le nettoyage.
[#ff0000]Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations.
Dans ce cas il suffit de redémarrer l'ordinateur manuellement.[/#f]
Poste le rapport situé dans le dossier MSNFix.
Le nom du rapport correspond au moment de sa création : date_heure.log
->Fiche complète<-
&
Désinstalle correctement Avast! pour le remplacer par Antivir.
Logfile of HijackThis v1.99.1
Scan saved at 14:59:42, on 08/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\CATHER~1\LOCALS~1\Temp\Rar$EX00.188\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [Á³# L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [_Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jh...
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: system32 - {18E99EDB-3502-456B-B158-F14266C9E69B} - sysprinters.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
Scan saved at 14:59:42, on 08/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\CATHER~1\LOCALS~1\Temp\Rar$EX00.188\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [Á³# L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [_Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jh...
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: system32 - {18E99EDB-3502-456B-B158-F14266C9E69B} - sysprinters.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
j ai desinstaller avast et mis antivir j ai fait un scan
AntiVir PersonalEdition Classic
Report file date: dimanche 8 juillet 2007 17:46
Scanning for 740715 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Catherine
Computer name: CHARUAUD
Version information:
BUILD.DAT : 248 14437 Bytes 31/05/2007 16:59:00
AVSCAN.EXE : 7.0.4.15 282664 Bytes 20/04/2007 11:37:14
AVSCAN.DLL : 7.0.4.4 33832 Bytes 27/03/2007 11:31:54
LUKE.DLL : 7.0.4.11 143400 Bytes 27/03/2007 11:26:04
LUKERES.DLL : 7.0.4.0 10280 Bytes 19/03/2007 11:18:59
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58
ANTIVIR1.VDF : 6.37.1.151 4303360 Bytes 23/02/2007 13:09:01
ANTIVIR2.VDF : 6.38.0.214 729600 Bytes 12/04/2007 13:09:02
ANTIVIR3.VDF : 6.38.0.225 50688 Bytes 16/04/2007 13:09:02
AVEWIN32.DLL : 7.4.0.12 2404864 Bytes 13/04/2007 13:04:24
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
AVPREF.DLL : 7.0.2.1 24616 Bytes 27/03/2007 11:31:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVPACK32.DLL : 7.3.0.8 360488 Bytes 27/03/2007 07:48:28
AVREG.DLL : 7.0.1.2 31784 Bytes 15/03/2007 08:05:08
AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 27/03/2007 11:16:05
AVARKT.DLL : 1.0.0.17 278568 Bytes 02/05/2007 10:32:26
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 13/03/2007 09:46:18
RCTEXT.DLL : 7.0.45.0 86056 Bytes 19/03/2007 11:42:42
Configuration settings for the scan:
Jobname..........................: Windows System Directory
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\setupprf.dat
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: dimanche 8 juillet 2007 17:46
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'Watch.exe' - '1' Module(s) have been scanned
Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
Scan process 'Toaster.exe' - '1' Module(s) have been scanned
Scan process 'ComComp.exe' - '1' Module(s) have been scanned
Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
Scan process 'WgaTray.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'SyncManager.exe' - '1' Module(s) have been scanned
Scan process 'NkbMonitor.exe' - '1' Module(s) have been scanned
Scan process 'Voxsync.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'MSCamSvc.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'SAgent2.exe' - '1' Module(s) have been scanned
Scan process 'eEBSvc.exe' - '1' Module(s) have been scanned
Scan process 'dslmon.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
Scan process 'vVX1000.exe' - '1' Module(s) have been scanned
Scan process 'E_S10IC2.EXE' - '1' Module(s) have been scanned
Scan process 'tfswctrl.exe' - '1' Module(s) have been scanned
Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
Scan process 'WinPatrol.exe' - '1' Module(s) have been scanned
Scan process 'AGRSMMSG.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'LVComS.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ashServ.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
51 processes with 51 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '29' files ).
Starting the file scan:
Begin scan in 'C:\WINDOWS\system32'
End of the scan: dimanche 8 juillet 2007 17:48
Used time: 02:16 min
The scan has been done completely.
171 Scanning directories
5250 Files were scanned
0 viruses and/or unwanted programs were found
0 classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
5250 Files not concerned
7 Archives were scanned
0 Warnings
0 Notes
0 Hidden objects were found
AntiVir PersonalEdition Classic
Report file date: dimanche 8 juillet 2007 17:46
Scanning for 740715 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Catherine
Computer name: CHARUAUD
Version information:
BUILD.DAT : 248 14437 Bytes 31/05/2007 16:59:00
AVSCAN.EXE : 7.0.4.15 282664 Bytes 20/04/2007 11:37:14
AVSCAN.DLL : 7.0.4.4 33832 Bytes 27/03/2007 11:31:54
LUKE.DLL : 7.0.4.11 143400 Bytes 27/03/2007 11:26:04
LUKERES.DLL : 7.0.4.0 10280 Bytes 19/03/2007 11:18:59
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58
ANTIVIR1.VDF : 6.37.1.151 4303360 Bytes 23/02/2007 13:09:01
ANTIVIR2.VDF : 6.38.0.214 729600 Bytes 12/04/2007 13:09:02
ANTIVIR3.VDF : 6.38.0.225 50688 Bytes 16/04/2007 13:09:02
AVEWIN32.DLL : 7.4.0.12 2404864 Bytes 13/04/2007 13:04:24
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
AVPREF.DLL : 7.0.2.1 24616 Bytes 27/03/2007 11:31:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVPACK32.DLL : 7.3.0.8 360488 Bytes 27/03/2007 07:48:28
AVREG.DLL : 7.0.1.2 31784 Bytes 15/03/2007 08:05:08
AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 27/03/2007 11:16:05
AVARKT.DLL : 1.0.0.17 278568 Bytes 02/05/2007 10:32:26
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 13/03/2007 09:46:18
RCTEXT.DLL : 7.0.45.0 86056 Bytes 19/03/2007 11:42:42
Configuration settings for the scan:
Jobname..........................: Windows System Directory
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\setupprf.dat
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: dimanche 8 juillet 2007 17:46
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'Watch.exe' - '1' Module(s) have been scanned
Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
Scan process 'Toaster.exe' - '1' Module(s) have been scanned
Scan process 'ComComp.exe' - '1' Module(s) have been scanned
Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
Scan process 'WgaTray.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'SyncManager.exe' - '1' Module(s) have been scanned
Scan process 'NkbMonitor.exe' - '1' Module(s) have been scanned
Scan process 'Voxsync.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'MSCamSvc.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'SAgent2.exe' - '1' Module(s) have been scanned
Scan process 'eEBSvc.exe' - '1' Module(s) have been scanned
Scan process 'dslmon.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
Scan process 'vVX1000.exe' - '1' Module(s) have been scanned
Scan process 'E_S10IC2.EXE' - '1' Module(s) have been scanned
Scan process 'tfswctrl.exe' - '1' Module(s) have been scanned
Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
Scan process 'WinPatrol.exe' - '1' Module(s) have been scanned
Scan process 'AGRSMMSG.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'LVComS.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ashServ.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
51 processes with 51 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '29' files ).
Starting the file scan:
Begin scan in 'C:\WINDOWS\system32'
End of the scan: dimanche 8 juillet 2007 17:48
Used time: 02:16 min
The scan has been done completely.
171 Scanning directories
5250 Files were scanned
0 viruses and/or unwanted programs were found
0 classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
5250 Files not concerned
7 Archives were scanned
0 Warnings
0 Notes
0 Hidden objects were found
MSN_Fix 1.333
C:\Documents and Settings\Catherine\Bureau
Fix exécuté le 08/07/2007 - 18:10:32,79 By Catherine
mode normal
************************ Fichiers suspects
/!\ ces fichiers nécessitent un avis expérimenté avant toute intervention
------------------------------------------------------------------------
Auteur : !aur3n7 Contact: http://246694.aceboard.fr
------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
C:\Documents and Settings\Catherine\Bureau
Fix exécuté le 08/07/2007 - 18:10:32,79 By Catherine
mode normal
************************ Fichiers suspects
/!\ ces fichiers nécessitent un avis expérimenté avant toute intervention
------------------------------------------------------------------------
Auteur : !aur3n7 Contact: http://246694.aceboard.fr
------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
J'aimerais vérifier qq chose :
Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
Double clique sur SDFix.exe et choisis Install pour l'extraire sur le Bureau.
Redémarre en mode sans échec
Ouvre le dossier SDFix qui vient d'être créé à la racine de ton dique dur (C:) et double clique sur RunThis.bat pour lancer le script.
Appuie sur Y pour commencer le processus de nettoyage.
Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
Appuie sur une touche pour redémarrer le PC.
Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis.
Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
Double clique sur SDFix.exe et choisis Install pour l'extraire sur le Bureau.
Redémarre en mode sans échec
SDFix: Version 1.90
Run by Catherine on 08/07/2007 at 19:38
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\CATHER~1\Bureau\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Missing Security Center Service
Restoring Missing SharedAccess Service
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\DOCUME~1\CATHER~1\LOCALS~1\Temp\aax1F.tmp.exe - Deleted
C:\DOCUME~1\CATHER~1\LOCALS~1\Temp\aax36.tmp.exe - Deleted
C:\DOCUME~1\CATHER~1\LOCALS~1\Temp\uninstall.exe - Deleted
C:\WINDOWS\system32\cmd.com - Deleted
C:\WINDOWS\system32\ping.com - Deleted
C:\WINDOWS\system32\regedit.com - Deleted
C:\WINDOWS\system32\sysprinters.dll - Deleted
C:\WINDOWS\system32\tasklist.com - Deleted
C:\WINDOWS\system32\tracert.com - Deleted
Removing Temp Files...
ADS Check:
Checking C:\WINDOWS
C:\WINDOWS
No streams found.
Checking C:\WINDOWS\system32
C:\WINDOWS\system32
No streams found.
Checking C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Checking C:\WINDOWS\system32\ntoskrnl.exe
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\LimeWirePro\\LimeWire.exe"="C:\\Program Files\\LimeWirePro\\LimeWire.exe:*
isabled:LimeWire""C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"="C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe:*:Enabled:LifeCam.exe"
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"="C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe:*:Enabled:LifeExp.exe"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
Remaining Files:
---------------
Backups Folder: - C:\DOCUME~1\CATHER~1\Bureau\SDFix\backups\backups.zip
Files with Hidden Attributes:
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
Finished
Logfile of HijackThis v1.99.1
Scan saved at 20:02:26, on 08/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [Á³# L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [_Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jh...
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
Scan saved at 20:02:26, on 08/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [Á³# L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [_Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jh...
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
Re,
Fix les lignes en italique ci-dessous avec Hijackthis : AIDE EN IMAGES
O4 - HKLM\..\Run: [ Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKLM\..\Run: [Á³# L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\xcuoevt.exe
O4 - HKCU\..\Run: [_Windows] C:\WINDOWS\WinSecurity\services.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolb [...] jhtml?p=ZN
O9 - Extra button: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
Fix les lignes en italique ci-dessous avec Hijackthis : AIDE EN IMAGES
O4 - HKLM\..\Run: [ Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKLM\..\Run: [Á³# L"h'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\xcuoevt.exe
O4 - HKCU\..\Run: [_Windows] C:\WINDOWS\WinSecurity\services.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolb [...] jhtml?p=ZN
O9 - Extra button: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Carnival Casino - {776883A9-1EA8-4d8f-88B7-AA652FEF01A7} - C:\Casino\Carnival Casino\casino.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
Logfile of HijackThis v1.99.1
Scan saved at 21:27:44, on 08/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
C:\WINDOWS\SoftwareDistribution\Download\5827f0d5b6f0c14f7890727de1bd0621\update\update.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [_Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
Scan saved at 21:27:44, on 08/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
C:\WINDOWS\SoftwareDistribution\Download\5827f0d5b6f0c14f7890727de1bd0621\update\update.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [_Windows] C:\WINDOWS\WinSecurity\services.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
bonjour je te joins le rapportLogfile of HijackThis v1.99.1
Scan saved at 17:22:12, on 09/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
Scan saved at 17:22:12, on 09/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
voila mon analyse virale j ai trou
AntiVir PersonalEdition Classic
Report file date: lundi 9 juillet 2007 18:24
Scanning for 874288 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Catherine
Computer name: CHARUAUD
Version information:
BUILD.DAT : 247 14437 Bytes 10/05/2007 11:55:00
AVSCAN.EXE : 7.0.4.15 282664 Bytes 20/04/2007 11:37:14
AVSCAN.DLL : 7.0.4.4 33832 Bytes 27/03/2007 11:31:54
LUKE.DLL : 7.0.4.11 143400 Bytes 27/03/2007 11:26:04
LUKERES.DLL : 7.0.4.0 10280 Bytes 19/03/2007 11:18:59
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58
ANTIVIR1.VDF : 6.38.1.170 5569024 Bytes 21/05/2007 18:05:18
ANTIVIR2.VDF : 6.39.0.115 1186304 Bytes 08/07/2007 15:46:40
ANTIVIR3.VDF : 6.39.0.121 58880 Bytes 09/07/2007 15:46:40
AVEWIN32.DLL : 7.4.0.39 2482688 Bytes 08/07/2007 18:05:20
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
AVPREF.DLL : 7.0.2.1 24616 Bytes 27/03/2007 11:31:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVPACK32.DLL : 7.3.0.13 360488 Bytes 08/07/2007 18:05:21
AVREG.DLL : 7.0.1.2 31784 Bytes 15/03/2007 08:05:08
AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 27/03/2007 11:16:05
AVARKT.DLL : 1.0.0.17 278568 Bytes 02/05/2007 10:32:26
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 13/03/2007 09:46:18
RCTEXT.DLL : 7.0.45.0 86056 Bytes 19/03/2007 11:42:42
Configuration settings for the scan:
Jobname..........................: Local Hard Disks
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\alldiscs.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: lundi 9 juillet 2007 18:24
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'Watch.exe' - '1' Module(s) have been scanned
Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
Scan process 'Toaster.exe' - '1' Module(s) have been scanned
Scan process 'ComComp.exe' - '1' Module(s) have been scanned
Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'WgaTray.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'SyncManager.exe' - '1' Module(s) have been scanned
Scan process 'NkbMonitor.exe' - '1' Module(s) have been scanned
Scan process 'Voxsync.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'MSCamSvc.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'SAgent2.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'eEBSvc.exe' - '1' Module(s) have been scanned
Scan process 'dslmon.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
Scan process 'vVX1000.exe' - '1' Module(s) have been scanned
Scan process 'E_S10IC2.EXE' - '1' Module(s) have been scanned
Scan process 'tfswctrl.exe' - '1' Module(s) have been scanned
Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
Scan process 'WinPatrol.exe' - '1' Module(s) have been scanned
Scan process 'AGRSMMSG.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'LVComS.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
51 processes with 51 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '29' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Catherine\cmqphv.exe
[0] Archive type: RAR SFX (self extracting)
--> install.exe
[DETECTION] Is the Trojan horse TR/VB.aqc
[INFO] The file was deleted!
C:\Documents and Settings\Catherine\cvarkg.exe
[0] Archive type: RAR SFX (self extracting)
--> install.exe
[DETECTION] Is the Trojan horse TR/VB.aqc
[INFO] The file was deleted!
C:\Documents and Settings\Catherine\jkdjqe.exe
[0] Archive type: RAR SFX (self extracting)
--> install.exe
[DETECTION] Is the Trojan horse TR/VB.aqc
[INFO] The file was deleted!
C:\Documents and Settings\Catherine\mhqzwy.exe
[DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Bifrose.NU Backdoor server programs
[INFO] The file was deleted!
C:\Documents and Settings\Catherine\wubcle.exe
[0] Archive type: RAR SFX (self extracting)
--> install.exe
[DETECTION] Is the Trojan horse TR/VB.aqc
[INFO] The file was deleted!
C:\Documents and Settings\Catherine\Bureau\SDFix\backups\backups.zip
[0] Archive type: ZIP
--> backups/sysprinters.dll
[DETECTION] Contains signature of the worm WORM/IRCBot.24040
[INFO] The file was deleted!
C:\install\install.exe
[DETECTION] Is the Trojan horse TR/VB.aqc
[INFO] The file was deleted!
End of the scan: lundi 9 juillet 2007 18:53
Used time: 28:30 min
The scan has been done completely.
3627 Scanning directories
101999 Files were scanned
7 viruses and/or unwanted programs were found
0 classified as suspicious:
7 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
101992 Files not concerned
1529 Archives were scanned
1 Warnings
1 Notes
0 Hidden objects were found
ver 7 virus
AntiVir PersonalEdition Classic
Report file date: lundi 9 juillet 2007 18:24
Scanning for 874288 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Catherine
Computer name: CHARUAUD
Version information:
BUILD.DAT : 247 14437 Bytes 10/05/2007 11:55:00
AVSCAN.EXE : 7.0.4.15 282664 Bytes 20/04/2007 11:37:14
AVSCAN.DLL : 7.0.4.4 33832 Bytes 27/03/2007 11:31:54
LUKE.DLL : 7.0.4.11 143400 Bytes 27/03/2007 11:26:04
LUKERES.DLL : 7.0.4.0 10280 Bytes 19/03/2007 11:18:59
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58
ANTIVIR1.VDF : 6.38.1.170 5569024 Bytes 21/05/2007 18:05:18
ANTIVIR2.VDF : 6.39.0.115 1186304 Bytes 08/07/2007 15:46:40
ANTIVIR3.VDF : 6.39.0.121 58880 Bytes 09/07/2007 15:46:40
AVEWIN32.DLL : 7.4.0.39 2482688 Bytes 08/07/2007 18:05:20
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
AVPREF.DLL : 7.0.2.1 24616 Bytes 27/03/2007 11:31:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVPACK32.DLL : 7.3.0.13 360488 Bytes 08/07/2007 18:05:21
AVREG.DLL : 7.0.1.2 31784 Bytes 15/03/2007 08:05:08
AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 27/03/2007 11:16:05
AVARKT.DLL : 1.0.0.17 278568 Bytes 02/05/2007 10:32:26
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 13/03/2007 09:46:18
RCTEXT.DLL : 7.0.45.0 86056 Bytes 19/03/2007 11:42:42
Configuration settings for the scan:
Jobname..........................: Local Hard Disks
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\alldiscs.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: lundi 9 juillet 2007 18:24
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'Watch.exe' - '1' Module(s) have been scanned
Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
Scan process 'Toaster.exe' - '1' Module(s) have been scanned
Scan process 'ComComp.exe' - '1' Module(s) have been scanned
Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'WgaTray.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'SyncManager.exe' - '1' Module(s) have been scanned
Scan process 'NkbMonitor.exe' - '1' Module(s) have been scanned
Scan process 'Voxsync.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'MSCamSvc.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'SAgent2.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'eEBSvc.exe' - '1' Module(s) have been scanned
Scan process 'dslmon.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
Scan process 'vVX1000.exe' - '1' Module(s) have been scanned
Scan process 'E_S10IC2.EXE' - '1' Module(s) have been scanned
Scan process 'tfswctrl.exe' - '1' Module(s) have been scanned
Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
Scan process 'WinPatrol.exe' - '1' Module(s) have been scanned
Scan process 'AGRSMMSG.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'LVComS.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
51 processes with 51 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '29' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Catherine\cmqphv.exe
[0] Archive type: RAR SFX (self extracting)
--> install.exe
[DETECTION] Is the Trojan horse TR/VB.aqc
[INFO] The file was deleted!
C:\Documents and Settings\Catherine\cvarkg.exe
[0] Archive type: RAR SFX (self extracting)
--> install.exe
[DETECTION] Is the Trojan horse TR/VB.aqc
[INFO] The file was deleted!
C:\Documents and Settings\Catherine\jkdjqe.exe
[0] Archive type: RAR SFX (self extracting)
--> install.exe
[DETECTION] Is the Trojan horse TR/VB.aqc
[INFO] The file was deleted!
C:\Documents and Settings\Catherine\mhqzwy.exe
[DETECTION] Contains a signature of the (dangerous) backdoor program BDS/Bifrose.NU Backdoor server programs
[INFO] The file was deleted!
C:\Documents and Settings\Catherine\wubcle.exe
[0] Archive type: RAR SFX (self extracting)
--> install.exe
[DETECTION] Is the Trojan horse TR/VB.aqc
[INFO] The file was deleted!
C:\Documents and Settings\Catherine\Bureau\SDFix\backups\backups.zip
[0] Archive type: ZIP
--> backups/sysprinters.dll
[DETECTION] Contains signature of the worm WORM/IRCBot.24040
[INFO] The file was deleted!
C:\install\install.exe
[DETECTION] Is the Trojan horse TR/VB.aqc
[INFO] The file was deleted!
End of the scan: lundi 9 juillet 2007 18:53
Used time: 28:30 min
The scan has been done completely.
3627 Scanning directories
101999 Files were scanned
7 viruses and/or unwanted programs were found
0 classified as suspicious:
7 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
101992 Files not concerned
1529 Archives were scanned
1 Warnings
1 Notes
0 Hidden objects were found
ver 7 virus
bonjour je te met le rappoLogfile of HijackThis v1.99.1
Scan saved at 16:11:11, on 10/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
rt
Scan saved at 16:11:11, on 10/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
rt
trouver un virus je te poste un autre rapportLogfile of HijackThis v1.99.1
Scan saved at 19:53:10, on 10/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
Scan saved at 19:53:10, on 10/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
bonjour je poste dernier rapport de hijackthis et antivirLogfile of HijackThis v1.99.1
Scan saved at 14:56:45, on 14/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
AntiVir PersonalEdition Classic
Report file date: samedi 14 juillet 2007 09:04
Scanning for 879305 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Catherine
Computer name: CHARUAUD
Version information:
BUILD.DAT : 247 14437 Bytes 10/05/2007 11:55:00
AVSCAN.EXE : 7.0.4.15 282664 Bytes 20/04/2007 11:37:14
AVSCAN.DLL : 7.0.4.4 33832 Bytes 27/03/2007 11:31:54
LUKE.DLL : 7.0.4.11 143400 Bytes 27/03/2007 11:26:04
LUKERES.DLL : 7.0.4.0 10280 Bytes 19/03/2007 11:18:59
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58
ANTIVIR1.VDF : 6.38.1.170 5569024 Bytes 21/05/2007 18:05:18
ANTIVIR2.VDF : 6.39.0.115 1186304 Bytes 08/07/2007 15:46:40
ANTIVIR3.VDF : 6.39.0.128 133120 Bytes 10/07/2007 13:56:32
AVEWIN32.DLL : 7.4.0.39 2482688 Bytes 08/07/2007 18:05:20
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
AVPREF.DLL : 7.0.2.1 24616 Bytes 27/03/2007 11:31:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVPACK32.DLL : 7.3.0.13 360488 Bytes 08/07/2007 18:05:21
AVREG.DLL : 7.0.1.2 31784 Bytes 15/03/2007 08:05:08
AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 27/03/2007 11:16:05
AVARKT.DLL : 1.0.0.17 278568 Bytes 02/05/2007 10:32:26
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 13/03/2007 09:46:18
RCTEXT.DLL : 7.0.45.0 86056 Bytes 19/03/2007 11:42:42
Configuration settings for the scan:
Jobname..........................: Local Drives
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\alldrives.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: E:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: samedi 14 juillet 2007 09:04
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'Watch.exe' - '1' Module(s) have been scanned
Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
Scan process 'Toaster.exe' - '1' Module(s) have been scanned
Scan process 'ComComp.exe' - '1' Module(s) have been scanned
Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SyncManager.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'NkbMonitor.exe' - '1' Module(s) have been scanned
Scan process 'Voxsync.exe' - '1' Module(s) have been scanned
Scan process 'dslmon.exe' - '1' Module(s) have been scanned
Scan process 'WgaTray.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
Scan process 'vVX1000.exe' - '1' Module(s) have been scanned
Scan process 'E_S10IC2.EXE' - '1' Module(s) have been scanned
Scan process 'tfswctrl.exe' - '1' Module(s) have been scanned
Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
Scan process 'WinPatrol.exe' - '1' Module(s) have been scanned
Scan process 'AGRSMMSG.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'LVComS.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'MSCamSvc.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'SAgent2.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'eEBSvc.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
49 processes with 49 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'F:\'
[NOTE] In the drive 'F:\' no data medium is inserted!
Boot sector 'G:\'
[NOTE] In the drive 'G:\' no data medium is inserted!
Boot sector 'H:\'
[NOTE] In the drive 'H:\' no data medium is inserted!
Boot sector 'I:\'
[NOTE] In the drive 'I:\' no data medium is inserted!
Starting to scan the registry.
The registry was scanned ( '29' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
Begin scan in 'F:\'
Search path F:\ could not be opened!
Le périphérique n'est pas prêt.
Begin scan in 'G:\'
Search path G:\ could not be opened!
Le périphérique n'est pas prêt.
Begin scan in 'H:\'
Search path H:\ could not be opened!
Le périphérique n'est pas prêt.
Begin scan in 'I:\'
Search path I:\ could not be opened!
Le périphérique n'est pas prêt.
Begin scan in 'D:\'
Search path D:\ could not be opened!
Le périphérique n'est pas prêt.
Begin scan in 'E:\'
Search path E:\ could not be opened!
Le périphérique n'est pas prêt.
End of the scan: samedi 14 juillet 2007 09:32
Used time: 27:53 min
The scan has been done completely.
3637 Scanning directories
102529 Files were scanned
0 viruses and/or unwanted programs were found
0 classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
102529 Files not concerned
1523 Archives were scanned
1 Warnings
1 Notes
0 Hidden objects were found
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\PhishingFilter
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\index.dat
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\WRHZY279
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\0000050574_000000000000000434451[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\001[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\0662d7c9[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1009_conso_AL[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\100x100_numeriques_0406[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1042639286[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1057324408[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1100847480158080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1100851817228080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1101440747298080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1101446603738080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1101466054858080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1200732819998080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1200814514668080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\120097602845_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\120_09mar[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1246405563@Top,Bottom,Bottom2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1300740963468080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1300755408198080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1300854100738080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\130090640011_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1301324241858080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1317091494@Right2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1369479443@Top,Bottom,Bottom2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1400798708738080_4[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1400815072058080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\15000mp80[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1500866521868080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1500868843248080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1501325432938080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1501386117998080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\15[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1647_bandeau_1[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1647_embed[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1647_embed[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1647_embed[3].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1667318660@Top,Bottom,Bottom2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\170074573971[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1700746112488080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1700746137478080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1701232750748080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1701232764718080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1701292256618080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1800805958428080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\18230758@Top[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1838282616@Top[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1851003362@Top,Bottom,Bottom2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1877526874-flexible_buttons[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1891154553@Right2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1900777075678080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1900919463058080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1x1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2000732729398080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2001271907778080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2105374152[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2200755656838080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2200756247068080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2200778849068080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\22102147846[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\22102147846[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\234x60_ebay_mobiles[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\242007490886[9].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\24_bottom_left[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500775393378080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500775402078080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500775409768080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500775425268080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500775437058080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500809912738080_2[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501090992288080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501171238198080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501181715278080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501268038558080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501278493758080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501393296868080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2600798679428080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2600825008148080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2601053288608080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\26820[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\269978-11-besoin-aide-trojan[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\270059855381[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2700849399638080_5[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2700856795828080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2700856797118080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2701004786928080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2701427970888080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2800748315678080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2800748417738080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2800749305988080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2800767984918080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[4].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[5].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[6].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2900763371738080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2900794699128080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2901088040018080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2[7].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3000769148758080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3149E0B0BE252EB32FADE5FAF781[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3200767757798080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3200768109558080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3200799724038080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3200899041718080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3200937039818080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3300819154298080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3301014001808080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3357658490[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\35366333666236363433383063373230[3]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\36521[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\440x198_generic_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\445190782_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\463625_32FAA55A-7BC5-44BC-95EC-9FC017F63057[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\553933980_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\578x85_th19_roaming_05[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\589744239[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\5b8d_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\64B73B21A0151455458D85236D877B[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\652111859[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\6640_P106_av[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\665566728_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\67A6AD66E224A9ADB8D397F3538FC[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\698570194[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\6B1ABEC0D7B38A834FFD3D2851B17[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\7032_P034_bv[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\703987679_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\70B385332504923DA43D5CBD744C7[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\720401273[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\720970045_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\721066874_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\728x90-2[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\728x90-2[2].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\799889555_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\7a3a_1_b[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\7[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\821805981_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\83FCAD2883B29C1590AFA11814E01[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\84260-858-0-QUESTIONS-CONCERNANT-GROUPE[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\86_0[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\951470010[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\953869438[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\9607813908[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\977100812_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\977129576_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\981475022_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\981495660_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\9881B35B44F776291B5C12DF239F[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\988311316_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\;sz=300x250;ord=4152032479721578[2].5
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\A2283190A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\A2444291A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\A2469332A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\A2484412A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\A2493845A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\abhd;sz=1x1;ord=2966900456187587[2]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\aboutme-small[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ab_active[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\accueil_rov_o[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\addlive[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\adimage[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ads[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ajout_panier[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\alertspanel_en[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\almeida_[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\al[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\anim-diaporama[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\AntivirusOrdi[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\apo_300x250_voyages_Croisieres_101106[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\arrow_red[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ARTICLE_318_SMALL[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ARTICLE_337_SMALL[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ASPIRE-5102__new[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\avec_Google2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\B2361126;sz=728x90;ord=705773575[2]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\back_left[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\banner[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bas[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\BBF2EB2D452A4A7EF44C8B3AA2D50[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bddpost[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg-mesDicussions[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg_allcontent[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg_block_univ[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg_container[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg_right_bottom[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\biggrin[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\blank[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bloc1_070320[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\blockMonIDN_top[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\blog[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\boite_bg[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bord_haut[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\brochett[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\btn_ok[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\btn_ok_a[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\btn_rest_normal[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\buscador_bottom[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\buyer;tn=3;to=h;tr=1;!cat=statichp;tw=760;ta=center;szs=234x60,234x60,234x60;ord=1176193736078;[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\c0[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\c490_top[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA0T2F0D.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA0T8PSN.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA0XWT0V.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ca1d_1_b[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA23KDY7.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA2FCPER.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA2UH4KI.com%2Fforum%2F&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=41&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA32KZZ9.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA3IKRZ1.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA3QKZV1.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA45YTS5.com%2Fforum%2F269986-11-chevals-troie%23t209031®ion=default&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=4&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA4P2N45.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA5OWN9L.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA67GXQZ.html®ion=default&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=20&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA6N67MX.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA7Y69F3.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA7YQ13N.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA891CGD.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAA6KDUE.html&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=12&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAA7K5GP.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAANK1UD.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAARGHU3.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAAV4DYV.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CACL1XGO.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CADCOZT9.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cadre_coin_gauche_bas[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAE7Y3AR.html®ion=default&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=3&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAEVONFG.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAEZOTQ3.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAFGD1J8.gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAFQEH7R.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAFUKRFH.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAG0S9S3.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGH2V89.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGH8LG3.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGLC1OR.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGNXB6M.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGPW94N.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGXST0B.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGXYZ0H.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAI7CXU7.gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAIDNEPH.HTM
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAINE3IH.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAJMAX7F.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAKHEBWH.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAKLK1C7.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CALGEDP3.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CALW7I73.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\campaign_postxmas_2_234x60[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CANAWRF1.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CANMXG5T.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAO6RPT4.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAO96709.jsp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAOFYX2D.html®ion=default&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=4&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAP04359.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAPSG7DL.gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAQJEBMH.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAQTK7Y1.com%2Fforum%2F269986-11-chevals-troie%23t209340®ion=default&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=12&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CARQ0RV5.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\carreblock[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cart_actu_toutes_actus[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAS967WP.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAT0V6FJ.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAT4A1DB.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CATDJBAK.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cat_bullet_down[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAU74DQF.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAUN45EZ.jsp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAURGTMB.com%2Fmembres%2F&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=17&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAYBKH6J.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAYFSXIF.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAZAGRRL.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cb[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cel_encard3[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cel_guide1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cel_recommande3[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cel_tab1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\chan_pollservice[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CheckCnx[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\choisiradh[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\chunks[1].jsp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\clear[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cm[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\coche[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\coche_off[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CommonFunc[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Common[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Common[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Common[3].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Common[4].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\communaute_teaser1[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\comm_tit_bonplan[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\corner_famille[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\countgo[3].asp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\countgo[4].asp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\css_pp_header[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\c[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\c_encard2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\c_encard_produit2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\d539_1_b[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dans-le-fond-du-car.skyrock[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dcp;dcopt=ist;sz=275x300;tile=1;ord=1172744991843;[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\DCS000048_6F4H[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\default[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[3].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[4].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[5].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[6].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[7].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\degrade_bas_menu_gauche[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\depeche_d20070220[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dg.specificclick[2].html
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dom-drag[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dot[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\drapeau_uk[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Dscn0036[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Dscn0937[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\DSCN2343[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\DSC_0482-115[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dynamic_body[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\e89e_2[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ebay_logo_tab[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ebuyclub3[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Elastic1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\eliotManager[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ENFallback[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ensemble-noir-bonnetC-115[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ep_more_actions[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\error[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\esflag[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\es[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\expedition_comparateur_maga[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\extra_index_droite_fd_2[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\F8F3C1D297EC55AB7D98CBB2391D20[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\face-over[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\favicon[1].ico
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\favicon[4].ico
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fb[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fd_menu[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\femmes___lingerie;cat=11450;cat=11514;dcopt=ist;tcat=64123;items=21558;sz=440x198;tile=5;ord=1176123719968;[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\FFBBDEEB4828B1DBE19847BBABBB0[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\filters[1].bin
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\flagn1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\flecheregime[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fleche_puce[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fluxlc.orange[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fond_header[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fond_header[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\formIE[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\forum[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\foto_acc[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\foto_bas_gauche[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ftrRt_140x53[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\func_200706222110[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\F_cb_18_BlobMemo_2[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\gallery[2].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GetAttachment[3].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GetAttachment[4].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GetAttachment[5].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GetAttachment[6].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\gifstats[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\gifstats[4].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GlobalNav_SignInEbay_e519i4906500_fr_FR_s[2].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\global[14].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GTL_SiteGeneric[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\guidetv[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\haut[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hdrNoLogo_310x90[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\HeaderGradientImage[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\helpdoc[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[10].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[11].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[12].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[13].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[14].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[15].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[16].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[17].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[4].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[5].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[6].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[7].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[8].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[9].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\homeicon16[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Homepage__DESKTOP[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Homepage__SHARED[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hotels[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hpim0155[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icohome2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icon13[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icon2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icon_eek[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icon_mini_message[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icozip2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ico_check[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ic_concoursConnoisseur[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ic_outilregime[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\idTGV_mars07_300x250[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ieminwidth[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ie[2].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\illustre_actualite[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\im5[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\imgTabCorner_25x25[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\imp[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[1].aspx
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[3].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[4].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[5].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\index[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\index[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\index[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\index[3].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\intro[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\inv[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ips_menu_html[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ircbotacd-myalbum2007[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ishow1[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ishow22[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ishow22[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\i_contacts[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\i_spelling[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\i_you[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[2].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[3].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[4].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[6].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[8].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jsldlc[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\kazoo.shopmarking[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\KdoExcep_a500_07_07[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\keywords;kw=dolce+gabbana;cat=11450;cat=11533;cat=64133;dcopt=ist;tcat=64135;items=94;sz=440x198;tile=5;ord=1183880757515;[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\LCD72XM[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\lesbestmatchfoot.skyrock[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\li-mg-medicaments[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Light2[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\lingerieb584038[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\linter_coinhg[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\liste_bas[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\li_sharing[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\logo-antanao-ebay[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\logo[1].bmp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\loisirs[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\M1107062A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\maps[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\medicaments[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Medtronic-Fev07-Megasky01-160x600[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\menu-default[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\menu_pret_perso[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\menu_prevoyance[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\meteo;sz=1x1;ord=7851101348593292[2]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\meter[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\meter[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\meter[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\mg-obesite-zoom[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\mirror_clubic[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\mn[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\moins2[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\mon_idn_fleche_up[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\motorola_z3_60x80[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\mozcompat[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\msft[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\msft[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\MSFT_pos[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\msinfohss[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\MSNEditStrings[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\myworldIEFixes_e5191fr[2].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\nav1_on[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\nav_top_layer_bottom_1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\newspix_133_04[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\non[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\non_dispo[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\nouveaute_ccp.MainCol.0007.ImageRef[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Nuits_gratuitesTropiques_234x60[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\nutrition-obesite[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\o02[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\oeuvre[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\offre.meaban728x90[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ongletsearch[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\onglet_3[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\onglet_off_gauche[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\over1[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\o[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\p140986-4[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0006[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0007[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0016[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0016[2].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0017[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0019[2].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0024[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0025[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0027[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0036[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0045[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pantacourt-dore2-115[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\paypal-icon[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\phone[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\photo-147258[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\photo-thumb-138602[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\picto-75[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\picto-podcast-beige[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\picto_imprimer[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\picto_search[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pipe-fff[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pipe[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pixel_transparent[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\plan_acces[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\plusoff_23x17[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Position_62_0[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pourelles[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\produit2_bloc_h_g[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\prototype[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\proxy_bb_cm[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\proxy_bb_cm[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pub_black[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\puce-listing-tiret[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\puce[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\puce_home_encard[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\p_mq_add[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\quelque_chose_pour_toi[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Questionpourunchampion[1].pps
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\r1_c1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ratestar_filled2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ReadMessageLight[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ReadMessageLight[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\red_arrow_down[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\removal_tool(1)[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\reportages[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\report[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\results[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\rtm[4]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\rtm[5]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\rtm[7]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\rtm[8]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\S%C3%A9curit%C3%A9[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\sas[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\savedsearchoption_e5192fr[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\savoir_plus[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\sc_press[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\sdctag2[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[10].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[11].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[12].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[13].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[14].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[15].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[16].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[17].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[18].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[19].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[1].xml
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[20].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[21].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[22].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[23].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[24].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[25].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[26].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[27].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[28].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[29].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[2].xml
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[30].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[31].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[32].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[33].
Scan saved at 14:56:45, on 14/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\Voxsync.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Orange\Logiciel de Synchronisation Orange\SyncManager.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Toolbar Wanadoo - {4E7BD74F-2B8D-469E-8FB0-B921F5DBF922} - C:\PROGRA~1\WANADO~2\WANADO~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [asFOmZYP] C:\WINDOWS\xcuoevt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 3)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (Copie 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (Copie 2)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Mon agenda personnel Etam.lnk = C:\Program Files\Agenda Etam\calendrier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
O4 - Global Startup: Logiciel de Synchronisation Orange.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?0d3695dd571e42acb425842d4c6725e8
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\WANADOO_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.0_03\bin\npjpi140_03.dll (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSig...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photobox.fr/discount/clients/uploader_v2.2.0...
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://frgoldenriviera.microgaming.com/frgoldenriviera...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
AntiVir PersonalEdition Classic
Report file date: samedi 14 juillet 2007 09:04
Scanning for 879305 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Catherine
Computer name: CHARUAUD
Version information:
BUILD.DAT : 247 14437 Bytes 10/05/2007 11:55:00
AVSCAN.EXE : 7.0.4.15 282664 Bytes 20/04/2007 11:37:14
AVSCAN.DLL : 7.0.4.4 33832 Bytes 27/03/2007 11:31:54
LUKE.DLL : 7.0.4.11 143400 Bytes 27/03/2007 11:26:04
LUKERES.DLL : 7.0.4.0 10280 Bytes 19/03/2007 11:18:59
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58
ANTIVIR1.VDF : 6.38.1.170 5569024 Bytes 21/05/2007 18:05:18
ANTIVIR2.VDF : 6.39.0.115 1186304 Bytes 08/07/2007 15:46:40
ANTIVIR3.VDF : 6.39.0.128 133120 Bytes 10/07/2007 13:56:32
AVEWIN32.DLL : 7.4.0.39 2482688 Bytes 08/07/2007 18:05:20
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
AVPREF.DLL : 7.0.2.1 24616 Bytes 27/03/2007 11:31:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVPACK32.DLL : 7.3.0.13 360488 Bytes 08/07/2007 18:05:21
AVREG.DLL : 7.0.1.2 31784 Bytes 15/03/2007 08:05:08
AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 27/03/2007 11:16:05
AVARKT.DLL : 1.0.0.17 278568 Bytes 02/05/2007 10:32:26
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 13/03/2007 09:46:18
RCTEXT.DLL : 7.0.45.0 86056 Bytes 19/03/2007 11:42:42
Configuration settings for the scan:
Jobname..........................: Local Drives
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\alldrives.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: E:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: samedi 14 juillet 2007 09:04
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'Watch.exe' - '1' Module(s) have been scanned
Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
Scan process 'Toaster.exe' - '1' Module(s) have been scanned
Scan process 'ComComp.exe' - '1' Module(s) have been scanned
Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SyncManager.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'NkbMonitor.exe' - '1' Module(s) have been scanned
Scan process 'Voxsync.exe' - '1' Module(s) have been scanned
Scan process 'dslmon.exe' - '1' Module(s) have been scanned
Scan process 'WgaTray.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
Scan process 'vVX1000.exe' - '1' Module(s) have been scanned
Scan process 'E_S10IC2.EXE' - '1' Module(s) have been scanned
Scan process 'tfswctrl.exe' - '1' Module(s) have been scanned
Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
Scan process 'WinPatrol.exe' - '1' Module(s) have been scanned
Scan process 'AGRSMMSG.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'LVComS.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'MSCamSvc.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'SAgent2.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'eEBSvc.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
49 processes with 49 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'F:\'
[NOTE] In the drive 'F:\' no data medium is inserted!
Boot sector 'G:\'
[NOTE] In the drive 'G:\' no data medium is inserted!
Boot sector 'H:\'
[NOTE] In the drive 'H:\' no data medium is inserted!
Boot sector 'I:\'
[NOTE] In the drive 'I:\' no data medium is inserted!
Starting to scan the registry.
The registry was scanned ( '29' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
Begin scan in 'F:\'
Search path F:\ could not be opened!
Le périphérique n'est pas prêt.
Begin scan in 'G:\'
Search path G:\ could not be opened!
Le périphérique n'est pas prêt.
Begin scan in 'H:\'
Search path H:\ could not be opened!
Le périphérique n'est pas prêt.
Begin scan in 'I:\'
Search path I:\ could not be opened!
Le périphérique n'est pas prêt.
Begin scan in 'D:\'
Search path D:\ could not be opened!
Le périphérique n'est pas prêt.
Begin scan in 'E:\'
Search path E:\ could not be opened!
Le périphérique n'est pas prêt.
End of the scan: samedi 14 juillet 2007 09:32
Used time: 27:53 min
The scan has been done completely.
3637 Scanning directories
102529 Files were scanned
0 viruses and/or unwanted programs were found
0 classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
102529 Files not concerned
1523 Archives were scanned
1 Warnings
1 Notes
0 Hidden objects were found
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\PhishingFilter
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\index.dat
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\WRHZY279
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\0000050574_000000000000000434451[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\001[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\0662d7c9[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1009_conso_AL[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\100x100_numeriques_0406[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1042639286[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1057324408[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1100847480158080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1100851817228080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1101440747298080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1101446603738080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1101466054858080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1200732819998080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1200814514668080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\120097602845_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\120_09mar[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1246405563@Top,Bottom,Bottom2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1300740963468080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1300755408198080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1300854100738080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\130090640011_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1301324241858080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1317091494@Right2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1369479443@Top,Bottom,Bottom2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1400798708738080_4[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1400815072058080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\15000mp80[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1500866521868080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1500868843248080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1501325432938080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1501386117998080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\15[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1647_bandeau_1[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1647_embed[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1647_embed[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1647_embed[3].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1667318660@Top,Bottom,Bottom2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\170074573971[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1700746112488080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1700746137478080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1701232750748080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1701232764718080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1701292256618080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1800805958428080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\18230758@Top[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1838282616@Top[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1851003362@Top,Bottom,Bottom2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1877526874-flexible_buttons[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1891154553@Right2[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1900777075678080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1900919463058080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1x1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\1[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2000732729398080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2001271907778080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2105374152[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2200755656838080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2200756247068080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2200778849068080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\22102147846[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\22102147846[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\234x60_ebay_mobiles[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\242007490886[9].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\24_bottom_left[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500775393378080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500775402078080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500775409768080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500775425268080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500775437058080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2500809912738080_2[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501090992288080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501171238198080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501181715278080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501268038558080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501278493758080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2501393296868080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2600798679428080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2600825008148080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2601053288608080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\26820[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\269978-11-besoin-aide-trojan[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\270059855381[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2700849399638080_5[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2700856795828080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2700856797118080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2701004786928080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2701427970888080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2800748315678080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2800748417738080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2800749305988080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2800767984918080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[4].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[5].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\282007190882[6].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2900763371738080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2900794699128080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2901088040018080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\2[7].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3000769148758080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3149E0B0BE252EB32FADE5FAF781[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3200767757798080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3200768109558080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3200799724038080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3200899041718080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3200937039818080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3300819154298080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3301014001808080_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\3357658490[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\35366333666236363433383063373230[3]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\36521[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\440x198_generic_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\445190782_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\463625_32FAA55A-7BC5-44BC-95EC-9FC017F63057[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\553933980_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\578x85_th19_roaming_05[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\589744239[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\5b8d_1[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\64B73B21A0151455458D85236D877B[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\652111859[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\6640_P106_av[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\665566728_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\67A6AD66E224A9ADB8D397F3538FC[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\698570194[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\6B1ABEC0D7B38A834FFD3D2851B17[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\7032_P034_bv[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\703987679_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\70B385332504923DA43D5CBD744C7[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\720401273[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\720970045_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\721066874_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\728x90-2[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\728x90-2[2].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\799889555_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\7a3a_1_b[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\7[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\821805981_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\83FCAD2883B29C1590AFA11814E01[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\84260-858-0-QUESTIONS-CONCERNANT-GROUPE[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\86_0[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\951470010[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\953869438[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\9607813908[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\977100812_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\977129576_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\981475022_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\981495660_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\9881B35B44F776291B5C12DF239F[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\988311316_small[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\;sz=300x250;ord=4152032479721578[2].5
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\A2283190A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\A2444291A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\A2469332A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\A2484412A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\A2493845A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\abhd;sz=1x1;ord=2966900456187587[2]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\aboutme-small[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ab_active[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\accueil_rov_o[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\addlive[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\adimage[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ads[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ajout_panier[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\alertspanel_en[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\almeida_[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\al[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\anim-diaporama[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\AntivirusOrdi[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\apo_300x250_voyages_Croisieres_101106[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\arrow_red[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ARTICLE_318_SMALL[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ARTICLE_337_SMALL[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ASPIRE-5102__new[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\avec_Google2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\B2361126;sz=728x90;ord=705773575[2]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\back_left[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\banner[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bas[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\BBF2EB2D452A4A7EF44C8B3AA2D50[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bddpost[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg-mesDicussions[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg_allcontent[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg_block_univ[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg_container[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bg_right_bottom[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\biggrin[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\blank[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bloc1_070320[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\blockMonIDN_top[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\blog[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\boite_bg[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\bord_haut[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\brochett[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\btn_ok[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\btn_ok_a[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\btn_rest_normal[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\buscador_bottom[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\buyer;tn=3;to=h;tr=1;!cat=statichp;tw=760;ta=center;szs=234x60,234x60,234x60;ord=1176193736078;[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\c0[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\c490_top[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA0T2F0D.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA0T8PSN.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA0XWT0V.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ca1d_1_b[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA23KDY7.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA2FCPER.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA2UH4KI.com%2Fforum%2F&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=41&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA32KZZ9.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA3IKRZ1.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA3QKZV1.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA45YTS5.com%2Fforum%2F269986-11-chevals-troie%23t209031®ion=default&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=4&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA4P2N45.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA5OWN9L.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA67GXQZ.html®ion=default&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=20&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA6N67MX.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA7Y69F3.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA7YQ13N.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CA891CGD.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAA6KDUE.html&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=12&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAA7K5GP.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAANK1UD.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAARGHU3.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAAV4DYV.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CACL1XGO.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CADCOZT9.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cadre_coin_gauche_bas[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAE7Y3AR.html®ion=default&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=3&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAEVONFG.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAEZOTQ3.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAFGD1J8.gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAFQEH7R.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAFUKRFH.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAG0S9S3.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGH2V89.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGH8LG3.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGLC1OR.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGNXB6M.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGPW94N.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGXST0B.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAGXYZ0H.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAI7CXU7.gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAIDNEPH.HTM
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAINE3IH.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAJMAX7F.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAKHEBWH.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAKLK1C7.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CALGEDP3.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CALW7I73.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\campaign_postxmas_2_234x60[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CANAWRF1.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CANMXG5T.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAO6RPT4.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAO96709.jsp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAOFYX2D.html®ion=default&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=4&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAP04359.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAPSG7DL.gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAQJEBMH.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAQTK7Y1.com%2Fforum%2F269986-11-chevals-troie%23t209340®ion=default&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=12&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CARQ0RV5.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\carreblock[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cart_actu_toutes_actus[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAS967WP.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAT0V6FJ.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAT4A1DB.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CATDJBAK.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cat_bullet_down[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAU74DQF.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAUN45EZ.jsp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAURGTMB.com%2Fmembres%2F&cc=100&flash=9&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=120&u_his=17&u_java=true
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAYBKH6J.swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAYFSXIF.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CAZAGRRL.htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cb[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cel_encard3[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cel_guide1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cel_recommande3[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cel_tab1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\chan_pollservice[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CheckCnx[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\choisiradh[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\chunks[1].jsp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\clear[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\cm[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\coche[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\coche_off[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\CommonFunc[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Common[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Common[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Common[3].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Common[4].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\communaute_teaser1[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\comm_tit_bonplan[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\corner_famille[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\countgo[3].asp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\countgo[4].asp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\css_pp_header[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\c[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\c_encard2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\c_encard_produit2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\d539_1_b[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dans-le-fond-du-car.skyrock[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dcp;dcopt=ist;sz=275x300;tile=1;ord=1172744991843;[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\DCS000048_6F4H[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\default[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[3].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[4].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[5].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[6].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Default[7].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\degrade_bas_menu_gauche[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\depeche_d20070220[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dg.specificclick[2].html
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dom-drag[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dot[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\drapeau_uk[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Dscn0036[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Dscn0937[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\DSCN2343[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\DSC_0482-115[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\dynamic_body[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\e89e_2[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ebay_logo_tab[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ebuyclub3[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Elastic1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\eliotManager[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ENFallback[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ensemble-noir-bonnetC-115[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ep_more_actions[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\error[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\esflag[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\es[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\expedition_comparateur_maga[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\extra_index_droite_fd_2[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\F8F3C1D297EC55AB7D98CBB2391D20[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\face-over[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\favicon[1].ico
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\favicon[4].ico
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fb[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fd_menu[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\femmes___lingerie;cat=11450;cat=11514;dcopt=ist;tcat=64123;items=21558;sz=440x198;tile=5;ord=1176123719968;[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\FFBBDEEB4828B1DBE19847BBABBB0[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\filters[1].bin
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\flagn1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\flecheregime[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fleche_puce[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fluxlc.orange[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fond_header[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\fond_header[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\formIE[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\forum[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\foto_acc[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\foto_bas_gauche[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ftrRt_140x53[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\func_200706222110[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\F_cb_18_BlobMemo_2[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\gallery[2].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GetAttachment[3].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GetAttachment[4].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GetAttachment[5].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GetAttachment[6].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\gifstats[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\gifstats[4].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GlobalNav_SignInEbay_e519i4906500_fr_FR_s[2].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\global[14].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\GTL_SiteGeneric[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\guidetv[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\haut[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hdrNoLogo_310x90[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\HeaderGradientImage[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\helpdoc[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[10].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[11].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[12].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[13].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[14].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[15].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[16].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[17].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[4].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[5].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[6].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[7].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[8].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hit[9].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\homeicon16[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Homepage__DESKTOP[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Homepage__SHARED[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hotels[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\hpim0155[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icohome2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icon13[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icon2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icon_eek[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icon_mini_message[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\icozip2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ico_check[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ic_concoursConnoisseur[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ic_outilregime[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\idTGV_mars07_300x250[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ieminwidth[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ie[2].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\illustre_actualite[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\im5[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\imgTabCorner_25x25[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\imp[1]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[1].aspx
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[3].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[4].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\InboxLight[5].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\index[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\index[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\index[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\index[3].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\intro[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\inv[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ips_menu_html[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ircbotacd-myalbum2007[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ishow1[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ishow22[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ishow22[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\i_contacts[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\i_spelling[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\i_you[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[2].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[3].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[4].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[6].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jp[8].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\jsldlc[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\kazoo.shopmarking[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\KdoExcep_a500_07_07[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\keywords;kw=dolce+gabbana;cat=11450;cat=11533;cat=64133;dcopt=ist;tcat=64135;items=94;sz=440x198;tile=5;ord=1183880757515;[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\LCD72XM[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\lesbestmatchfoot.skyrock[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\li-mg-medicaments[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Light2[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\lingerieb584038[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\linter_coinhg[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\liste_bas[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\li_sharing[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\logo-antanao-ebay[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\logo[1].bmp
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\loisirs[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\M1107062A[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\maps[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\medicaments[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Medtronic-Fev07-Megasky01-160x600[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\menu-default[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\menu_pret_perso[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\menu_prevoyance[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\meteo;sz=1x1;ord=7851101348593292[2]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\meter[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\meter[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\meter[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\mg-obesite-zoom[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\mirror_clubic[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\mn[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\moins2[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\mon_idn_fleche_up[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\motorola_z3_60x80[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\mozcompat[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\msft[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\msft[3].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\MSFT_pos[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\msinfohss[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\MSNEditStrings[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\myworldIEFixes_e5191fr[2].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\nav1_on[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\nav_top_layer_bottom_1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\newspix_133_04[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\non[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\non_dispo[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\nouveaute_ccp.MainCol.0007.ImageRef[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Nuits_gratuitesTropiques_234x60[1].swf
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\nutrition-obesite[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\o02[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\oeuvre[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\offre.meaban728x90[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ongletsearch[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\onglet_3[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\onglet_off_gauche[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\over1[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\o[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\p140986-4[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0006[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0007[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0016[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0016[2].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0017[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0019[2].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0024[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0025[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0027[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0036[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\page-0045[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pantacourt-dore2-115[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\paypal-icon[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\phone[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\photo-147258[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\photo-thumb-138602[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\picto-75[1].jpg
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\picto-podcast-beige[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\picto_imprimer[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\picto_search[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pipe-fff[2].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pipe[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pixel_transparent[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\plan_acces[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\plusoff_23x17[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Position_62_0[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pourelles[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\produit2_bloc_h_g[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\prototype[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\proxy_bb_cm[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\proxy_bb_cm[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\pub_black[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\puce-listing-tiret[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\puce[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\puce_home_encard[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\p_mq_add[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\quelque_chose_pour_toi[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\Questionpourunchampion[1].pps
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\r1_c1[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ratestar_filled2[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ReadMessageLight[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\ReadMessageLight[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\red_arrow_down[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\removal_tool(1)[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\reportages[1].png
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\report[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\results[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\rtm[4]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\rtm[5]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\rtm[7]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\rtm[8]
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\S%C3%A9curit%C3%A9[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\sas[1].css
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\savedsearchoption_e5192fr[2].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\savoir_plus[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\sc_press[1].gif
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\sdctag2[1].js
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[10].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[11].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[12].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[13].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[14].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[15].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[16].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[17].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[18].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[19].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[1].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[1].xml
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[20].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[21].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[22].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[23].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[24].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[25].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[26].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[27].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[28].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[29].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[2].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[2].xml
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[30].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[31].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[32].htm
C:\DOCUME~1\CATHER~1\LOCALS~1\TEMPOR~1\Content.IE5\2Z9PNX7Z\search[33].
Lassé par la pub ? Créez un compte
- Contenus similaires :
Tags :
- ForumLogiciel gratuit cheval de troie
- ForumInfection par cheval de troie vundo.k
- ForumCheval de troie startpage ksf
- ForumHelp cheval de troie
- ForumChevale de troie
- ForumCheval de troie sur mac
- ForumSupprimer les chevaux de troie
- ForumCheval de troie tr dldr
- ForumCheval troie
- ForumCheval de troie
- Voir plus