Se connecter avec
S'enregistrer | Connectez-vous

Nouvel assaut du virus "Nokia 19"[résolu]

Dernière réponse : dans Sécurité
Lassé par la pub ? Créez un compte

Bon ok// je reprend:
J'ai attrapé com beaucoup d'autre avant moi le virus "Nokia 19"
Dc com jai remarqué qu'il ne se contente pas d'infecter mn ordi ,il s'auto envoi a mes contactes Msn, j'ai alor cherchè un moyen rapide sur ce forum pour savoir comment s'endébarrasser convenablement
J'ai ainsi suivi les instructions donné a quelqu'un qui avait le mm problèm


Ma preoccupation a moi est que j'ai besoin que quelqu'un voi mes rapports d'analyze afin de m'informer de ce kil en ai


Sè assez clair nn??:D 

Voila le rapport d'Hijackthis:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:57:40, on 05/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\X'nBeep 1.1\XnBeep.exe
C:\Program Files\Pando Networks\Pando\Pando.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe
C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\Hermes\Bureau\Utilitaires\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ci/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\lsass.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7411F8BA-29A3-3216-9DE7-024AC0AAB9F6} - C:\WINDOWS\System32\viyjhai.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10111} - C:\Program Files\TrueDownloader\truedownloaderie.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Adssite Toolbar - {41C29B07-6F91-4966-91BE-2E2841643C83} - C:\Program Files\Adssite Advanced Toolbar\toolbar.dll (file missing)
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [antihost] C:\WINDOWS\system32\ahr.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LBTWiz.exe] C:\WINDOWS\LBTWiz.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1148.exe 61A847B5BBF72813339F30466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\RunOnce: [MessengerPlusLiveUninstall] "C:\DOCUME~1\Hermes\LOCALS~1\Temp\MsgPlusUninstall.exe" /Cleanup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [X'nBeep] C:\Program Files\X'nBeep 1.1\XnBeep.exe
O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - HKCU\..\Run: [TrueDownloaderAutoStart] C:\Program Files\TrueDownloader\TrueDownloader.exe /silent
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Outil de détection de support de Cyber-shot Viewer.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: Reboot.exe
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Toolbar.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?611557c71b9f4b36b7268c86543e5259
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?611557c71b9f4b36b7268c86543e5259
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0835BC90-6ABC-4F52-A103-4FC3A61F2C33} (A18X Control) - http://www.albatross18.com/season2/cabs/A18X.ocx
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts...
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.ca...
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgsta...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://incredimailintl.oberon-media.com/online/online2/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://agbouuuuuu.spaces.live.com/PhotoUpload/MsnPUpld....
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) - http://www.rockyou.com/RockYouImageUploader.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/install...
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FE88AD7-F786-4FF7-BD3C-D7525390D43B}: NameServer = 213.150.193.1,213.150.201.25
O17 - HKLM\System\CS1\Services\Tcpip\..\{0FE88AD7-F786-4FF7-BD3C-D7525390D43B}: NameServer = 213.150.193.1,213.150.201.25
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 12421 bytes

bonsoir

Télécharge MSNFix.zip (!aur3n7[/#f]) sur ton Bureau.
Décompresse-le sur ton bureau (Clique-Droit/Extraire tout).
[#ff0000]
Il est indispensable que l'outil soit executé à partir du bureau.


Ouvre le dossier MSNFix puis double-clique sur MSNFix.bat.
- Exécute l'option R.
-- Si l'infection est détectée, presse une touche pour lancer le nettoyage.

[#ff0000]Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations.
Dans ce cas il suffit de redémarrer l'ordinateur manuellement.[/#f]

Poste le rapport situé dans le dossier MSNFix.
Le nom du rapport correspond au moment de sa création : date_heure.log

->Tutorial de Malekal<-

Re :) 
Voici le rapport de MSNfix:

MSNFix 1.562

C:\Documents and Settings\Hermes\Bureau\MSNFix
Fix exécuté le 05/11/2007 - 20:58:12,84 By Hermes
mode normal

************************ Recherche les fichiers présents

Aucun Fichier trouvé

************************ Recherche les dossiers présents

... C:\Program Files\Fichiers communs\Carlson\




************************ Suppression des fichiers



************************ Suppression des dossiers

.. OK ... C:\Program Files\Fichiers communs\Carlson\


************************ Nettoyage du registre



************************ Fichiers suspects

Aucun Fichier trouvé


Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 05112007_21074948.zip


------------------------------------------------------------------------
Auteur : !aur3n7 Contact: http://changelog.fr
------------------------------------------------------------------------

--------------------------------------------- END ---------------------------------------------

ok

Télécharge SDFix(créé par AndyManchesta) et sauvegarde le sur ton Bureau.
***Si le lien ne fonctionne pas, essaie celui-ci : http://download.bleepingcomputer.com/andymanchesta/SDFi... ***

Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
  • Redémarre ton ordinateur
  • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
  • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
  • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
  • Choisis ton compte.
    Déroule la liste des instructions ci-dessous :
  • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
  • Appuie sur Y pour commencer le processus de nettoyage.
  • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
  • Appuie sur une touche pour redémarrer le PC.
  • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
  • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
  • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
  • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
  • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

    Bjr :) 

    Voici le rapport de SDFix

    catchme 0.3.1253 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-11-10 06:42:17
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    scanning hidden files ...

    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\00\112-{9D35705E-E6A0-487F-B411-1789426E8705}-v100-{9D35705E-E6A0-487F-B411-1789426E8705}-v112-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 642 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\00\112-{9D35705E-E6A0-487F-B411-1789426E8705}-v100-{9D35705E-E6A0-487F-B411-1789426E8705}-v112-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 72 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\01\101-{9D35705E-E6A0-487F-B411-1789426E8705}-v101-{9D35705E-E6A0-487F-B411-1789426E8705}-v101-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 96 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\01\103-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v101-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v103-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 45588 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\01\103-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v101-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v103-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3342 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\01\103-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v101-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v103-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5096 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\01\13-{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}-v1-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\03\110-{9D35705E-E6A0-487F-B411-1789426E8705}-v103-{9D35705E-E6A0-487F-B411-1789426E8705}-v110-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 822 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\03\110-{9D35705E-E6A0-487F-B411-1789426E8705}-v103-{9D35705E-E6A0-487F-B411-1789426E8705}-v110-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 88 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\40\40-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v40-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v40-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 52536 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\40\40-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v40-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v40-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3846 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\40\40-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v40-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v40-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5896 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\41\41-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v41-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 56928 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\41\41-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v41-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4242 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\41\41-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v41-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6320 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\75\75-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v75-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v75-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 53562 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{6039796C-F7AB-DE0C-99A1-DFB9E58334DA}\75\75-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v75-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v75-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6016 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\cissoumar@hotmail.com\DFSR\Staging\CS{BFC53924-101E-F2C2-AA57-011244E0FB17}\01\11-{BFC53924-101E-F2C2-AA57-011244E0FB17}-v1-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\01\132-{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}-v1-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v132-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\33\134-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v133-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v134-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 44166 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\33\134-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v133-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v134-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3234 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\33\134-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v133-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v134-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4920 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\48\1148-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1148-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1148-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 38064 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\48\1148-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1148-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1148-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2874 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\48\1148-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1148-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1148-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4464 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\68\1068-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1068-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1068-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 107652 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\68\1068-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1068-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1068-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 7608 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\68\1068-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1068-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1068-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 12008 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\69\1069-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1069-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1069-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 47928 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\69\1069-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1069-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1069-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3468 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\69\1069-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1069-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1069-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5496 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\70\161-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1070-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 48900 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\70\161-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1070-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v161-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5408 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\71\162-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1071-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v162-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 51006 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\71\162-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1071-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v162-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5768 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\72\1072-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1072-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1072-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 44958 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\72\1072-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1072-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1072-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3342 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\72\1072-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1072-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1072-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5184 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\73\1073-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1073-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1073-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3128 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\ergisjohnson@hotmail.com\DFSR\Staging\CS{39EA9B6C-8DF4-8F80-51EA-91303A7B2585}\74\1074-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1074-{CD7F9434-E13B-4BFB-A285-AEA34006623A}-v1074-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4096 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\henry-michell@hotmail.com\DFSR\Staging\CS{A003108F-C104-8504-DECE-CD720AD23178}\01\83-{A003108F-C104-8504-DECE-CD720AD23178}-v1-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v83-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\henry-michell@hotmail.com\DFSR\Staging\CS{A003108F-C104-8504-DECE-CD720AD23178}\84\84-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v84-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v84-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 47874 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\henry-michell@hotmail.com\DFSR\Staging\CS{A003108F-C104-8504-DECE-CD720AD23178}\84\84-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v84-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v84-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3414 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\henry-michell@hotmail.com\DFSR\Staging\CS{A003108F-C104-8504-DECE-CD720AD23178}\84\84-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v84-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v84-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5304 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\01\42-{1292A833-ABFA-0E97-149B-A121CBE40B95}-v1-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\45\45-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v45-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v45-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 984 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\45\45-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v45-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v45-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 128 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\49\49-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v49-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v49-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1380 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\49\49-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v49-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v49-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 160 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\54\54-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v54-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1074 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\54\54-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v54-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 120 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\56\56-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v56-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 120 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\56\56-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v56-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 128 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\57\57-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v57-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1254 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\57\57-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v57-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 144 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\74\74-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v74-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v74-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 27498 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\74\74-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v74-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v74-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2028 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassi93@hotmail.com\DFSR\Staging\CS{1292A833-ABFA-0E97-149B-A121CBE40B95}\74\74-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v74-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v74-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3096 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassiwilliam3@hotmail.com\DFSR\Staging\CS{C2E2F3AD-DE1D-D15A-8D9D-EA3019AE245F}\83\170-{284D5D76-AC2F-4982-BB9C-E62C1AA40940}-v83-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v170-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1490736 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\kouassiwilliam3@hotmail.com\DFSR\Staging\CS{C2E2F3AD-DE1D-D15A-8D9D-EA3019AE245F}\83\170-{284D5D76-AC2F-4982-BB9C-E62C1AA40940}-v83-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v170-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 165888 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\maryaste92@hotmail.com\DFSR\Staging\CS{DD5A4E85-F74E-383E-0355-043A7D473856}\01\12-{DD5A4E85-F74E-383E-0355-043A7D473856}-v1-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\maryaste92@hotmail.com\DFSR\Staging\CS{DD5A4E85-F74E-383E-0355-043A7D473856}\76\76-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v76-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v76-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 49710 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\maryaste92@hotmail.com\DFSR\Staging\CS{DD5A4E85-F74E-383E-0355-043A7D473856}\76\76-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v76-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v76-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3288 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\maryaste92@hotmail.com\DFSR\Staging\CS{DD5A4E85-F74E-383E-0355-043A7D473856}\76\76-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v76-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v76-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5536 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\maryaste92@hotmail.com\DFSR\Staging\CS{DD5A4E85-F74E-383E-0355-043A7D473856}\77\77-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v77-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v77-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 60996 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\maryaste92@hotmail.com\DFSR\Staging\CS{DD5A4E85-F74E-383E-0355-043A7D473856}\77\77-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v77-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v77-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4242 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\maryaste92@hotmail.com\DFSR\Staging\CS{DD5A4E85-F74E-383E-0355-043A7D473856}\77\77-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v77-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v77-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6824 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\nfabien2100@hotmail.com\DFSR\Staging\CS{89C8869D-45EF-5503-34F8-1677B2A06C4B}\01\136-{89C8869D-45EF-5503-34F8-1677B2A06C4B}-v1-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v136-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\nfabien2100@hotmail.com\DFSR\Staging\CS{89C8869D-45EF-5503-34F8-1677B2A06C4B}\37\142-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v137-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v142-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 27498 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\nfabien2100@hotmail.com\DFSR\Staging\CS{89C8869D-45EF-5503-34F8-1677B2A06C4B}\37\142-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v137-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v142-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2028 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\nfabien2100@hotmail.com\DFSR\Staging\CS{89C8869D-45EF-5503-34F8-1677B2A06C4B}\37\142-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v137-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v142-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3096 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\nfabien2100@hotmail.com\DFSR\Staging\CS{89C8869D-45EF-5503-34F8-1677B2A06C4B}\40\148-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v140-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v148-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 104556 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\nfabien2100@hotmail.com\DFSR\Staging\CS{89C8869D-45EF-5503-34F8-1677B2A06C4B}\40\148-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v140-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v148-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 7356 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\nfabien2100@hotmail.com\DFSR\Staging\CS{89C8869D-45EF-5503-34F8-1677B2A06C4B}\40\148-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v140-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v148-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 11720 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\nfabien2100@hotmail.com\DFSR\Staging\CS{89C8869D-45EF-5503-34F8-1677B2A06C4B}\44\153-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v144-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 55164 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\nfabien2100@hotmail.com\DFSR\Staging\CS{89C8869D-45EF-5503-34F8-1677B2A06C4B}\44\153-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v144-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6120 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\nfabien2100@hotmail.com\DFSR\Staging\CS{89C8869D-45EF-5503-34F8-1677B2A06C4B}\54\157-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v154-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 53562 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\katchinhermes@hotmail.fr\SharingMetadata\nfabien2100@hotmail.com\DFSR\Staging\CS{89C8869D-45EF-5503-34F8-1677B2A06C4B}\54\157-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v154-{6D8EE41E-EE4A-4F62-91BA-B948169E269B}-v157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6016 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\34\134-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v134-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v134-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 52410 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\34\134-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v134-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v134-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5768 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\00\100-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v100-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v100-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 28722 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\00\100-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v100-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v100-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3208 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\01\101-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v101-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v101-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 61068 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\01\101-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v101-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v101-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6768 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\01\30-{FC89350B-72BA-3F32-6FBE-D8264E23B878}-v1-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\02\102-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v102-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v102-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 49710 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\02\102-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v102-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v102-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5536 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\03\103-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v103-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v103-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 41538 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\03\103-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v103-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v103-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4672 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\04\104-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v104-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v104-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 49008 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\04\104-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v104-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v104-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5424 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\05\105-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v105-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v105-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 48666 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\05\105-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v105-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v105-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5688 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\06\106-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v106-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v106-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 54318 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\06\106-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v106-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v106-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6120 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\07\107-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v107-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v107-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 13998 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\07\107-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v107-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v107-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1552 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\08\108-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v108-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v108-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 47460 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\08\108-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v108-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v108-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5312 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\09\109-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v109-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v109-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 47802 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\09\109-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v109-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v109-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5672 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\10\110-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v110-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v110-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 53436 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\10\110-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v110-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v110-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6008 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\11\125-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v111-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v125-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 60690 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\11\125-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v111-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v125-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6784 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\23\123-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v123-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v123-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 59880 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\23\123-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v123-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v123-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6640 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\24\124-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v124-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v124-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 35076 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\24\124-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v124-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v124-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3904 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\26\126-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v126-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v126-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 22134 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\26\126-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v126-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v126-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2416 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\27\127-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v127-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v127-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 47064 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\27\127-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v127-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v127-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5256 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\28\128-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v128-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v128-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 44472 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\28\128-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v128-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v128-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5368 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\29\129-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v129-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v129-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 101046 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\29\129-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v129-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v129-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 11208 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\30\130-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v130-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v130-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 24870 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\30\130-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v130-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v130-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2792 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\31\31-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v31-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 44472 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\31\31-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v31-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3198 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\31\31-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v31-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5368 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\32\132-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v132-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v132-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 46398 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\32\132-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v132-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v132-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5168 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\32\32-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v32-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 30720 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\32\32-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v32-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2244 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\32\32-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v32-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3400 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\33\133-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v133-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v133-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 31026 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\33\133-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v133-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v133-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3400 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\35\135-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v135-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v135-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 31170 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\35\135-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v135-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v135-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3456 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\36\136-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v136-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v136-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 48612 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\36\136-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v136-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v136-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5360 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\37\137-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v137-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v137-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 34932 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\37\137-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v137-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v137-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3864 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\38\138-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v138-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v138-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 45498 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\38\138-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v138-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v138-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5088 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\39\139-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v139-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v139-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 39612 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\39\139-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v139-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v139-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4416 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\40\140-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v140-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v140-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 73398 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\40\140-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v140-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v140-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8224 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\46\146-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v146-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v146-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 21324 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\46\146-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v146-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v146-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2384 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\47\147-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v147-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v147-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 19092 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\47\147-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v147-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v147-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2120 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\48\148-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v148-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v148-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 22620 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\48\148-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v148-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v148-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2552 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\49\149-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v149-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v149-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 21630 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\49\149-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v149-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v149-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2400 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\50\150-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v150-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v150-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 21594 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\50\150-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v150-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v150-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2400 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\51\151-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v151-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 25716 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\51\151-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v151-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v151-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2800 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\52\152-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v152-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v152-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 21468 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\52\152-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v152-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v152-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2344 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\53\153-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v153-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 25302 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\53\153-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v153-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v153-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2744 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\54\154-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v154-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v154-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 15168 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\54\154-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v154-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v154-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1704 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\55\155-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v155-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 19380 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\55\155-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v155-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v155-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2136 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\56\156-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v156-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v156-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 21810 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\56\156-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v156-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v156-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2416 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\57\157-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v157-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 16860 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\57\157-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v157-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v157-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1888 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\58\158-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v158-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v158-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 20928 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\58\158-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v158-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v158-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2320 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\59\159-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v159-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v159-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 22440 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouassihermes@hotmail.com\SharingMetadata\anienjoy@hotmail.fr\DFSR\Staging\CS{FC89350B-72BA-3F32-6FBE-D8264E23B878}\59\159-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v159-{7CD20495-A67A-4E83-9D1D-7D3ED9075EEC}-v159-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2464 bytes hidden from API
    C:\Documents and Settings\Hermes\Local Settings\Application Data\Microsoft\Messenger\kouas

    Re
    et le nouveau rapport d'Hijackthis

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:44:45, on 10/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\Explorer.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Spyware Doctor\svcntaux.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Spyware Doctor\swdsvc.exe
    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
    C:\Program Files\Spyware Doctor\SDTrayApp.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\X'nBeep 1.1\XnBeep.exe
    C:\Program Files\Pando Networks\Pando\Pando.exe
    C:\WINDOWS\system32\sistray.exe
    C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
    C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe
    C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\Hermes\Bureau\Utilitaires\HijackThis.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ci/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\lsass.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {7411F8BA-29A3-3216-9DE7-024AC0AAB9F6} - C:\WINDOWS\System32\viyjhai.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10111} - C:\Program Files\TrueDownloader\truedownloaderie.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Adssite Toolbar - {41C29B07-6F91-4966-91BE-2E2841643C83} - C:\Program Files\Adssite Advanced Toolbar\toolbar.dll (file missing)
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
    O4 - HKLM\..\Run: [antihost] C:\WINDOWS\system32\ahr.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [X'nBeep] C:\Program Files\X'nBeep 1.1\XnBeep.exe
    O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
    O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
    O4 - HKCU\..\Run: [TrueDownloaderAutoStart] C:\Program Files\TrueDownloader\TrueDownloader.exe /silent
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Outil de détection de support de Cyber-shot Viewer.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    O4 - Startup: Reboot.exe
    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
    O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe
    O4 - Startup: Y'z Toolbar.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?611557c71b9f4b36b7268c86543e5259
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?611557c71b9f4b36b7268c86543e5259
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: {0835BC90-6ABC-4F52-A103-4FC3A61F2C33} (A18X Control) - http://www.albatross18.com/season2/cabs/A18X.ocx
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts...
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.ca...
    O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgsta...
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://incredimailintl.oberon-media.com/online/online2/...
    O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://agbouuuuuu.spaces.live.com/PhotoUpload/MsnPUpld....
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) - http://www.rockyou.com/RockYouImageUploader.cab
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/install...
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0FE88AD7-F786-4FF7-BD3C-D7525390D43B}: NameServer = 213.150.193.1,213.150.201.25
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0FE88AD7-F786-4FF7-BD3C-D7525390D43B}: NameServer = 213.150.193.1,213.150.201.25
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

    --
    End of file - 11793 bytes

    bonjour

    tu as mal utilisé SDFix, il faut que tu recommences en suivant exactement la procédure, de plus, tu devras poster le rapport en entier .
    le début ressemblera à ça:
    Citation :
    SDFix: Version 1.113

    Run by Administrateur on 07/11/2007 at 09:24

    Microsoft Windows XP [version 5.1.2600]

    Running From: C:\DOCUME~1\ADMINI~1\Bureau\NOUVEA~1\SDFix

    Safe Mode:

    Daccord

    Voila le rapport de SDFix:




    SDFix: Version 1.113

    Run by Hermes on 10/11/2007 at 15:45

    Microsoft Windows XP [version 5.1.2600]

    Running From: C:\SDFix

    Safe Mode:
    Checking Services:


    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Rebooting...


    Normal Mode:
    Checking Files:

    Trojan Files Found:

    C:\Program Files\Fichiers communs\Yazzle1162OinUninstaller.exe - Deleted



    Removing Temp Files...

    ADS Check:

    C:\WINDOWS
    No streams found.

    C:\WINDOWS\system32
    No streams found.

    C:\WINDOWS\system32\svchost.exe
    No streams found.

    C:\WINDOWS\system32\ntoskrnl.exe
    No streams found.



    Final Check:

    catchme 0.3.1253 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-11-10 15:59:03
    Windows 5.1.2600 Service Pack 2 NTFS

    detected NTDLL code modification:
    ZwClose

    scanning hidden processes ...

    IPC error: 2 Le fichier spécifié est introuvable.
    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0


    Remaining Services:
    ------------------



    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:D isabled:Yahoo! Messenger"
    "C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
    "C:\\Program Files\\Microsoft Games\\Motocross Madness 2 Trial\\mcm2.exe"="C:\\Program Files\\Microsoft Games\\Motocross Madness 2 Trial\\mcm2.exe:*:D isabled:Microsoft© Motocross Madness 2"
    "C:\\Program Files\\Morpheus\\Morpheus.exe"="C:\\Program Files\\Morpheus\\Morpheus.exe:*:Enabled:M5Shell"
    "C:\\Program Files\\devolo\\informer\\devinf.exe"="C:\\Program Files\\devolo\\informer\\devinf.exe:*:Enabled:MicroLink Informer"
    "C:\\Program Files\\Pando Networks\\Pando\\pando.exe"="C:\\Program Files\\Pando Networks\\Pando\\pando.exe:*:Enabled:p ando"
    "C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
    "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Messenger"
    "C:\\Program Files\\Eidos Interactive\\Pyro Studios\\Praetorians\\Praetorians.exe"="C:\\Program Files\\Eidos Interactive\\Pyro Studios\\Praetorians\\Praetorians.exe:*:D isabled:p raetorians"
    "C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:D isabled:Microsoft DirectPlay Helper"
    "C:\\Documents and Settings\\Hermes\\Bureau\\Fichiers inutilis‚s\\New Emule\\emule.exe"="C:\\Documents and Settings\\Hermes\\Bureau\\Fichiers inutilis‚s\\New Emule\\emule.exe:*:D isabled:eMule"
    "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
    "C:\\Documents and Settings\\Hermes\\Bureau\\Utilitaires\\Emule Extreme\\emule.exe"="C:\\Documents and Settings\\Hermes\\Bureau\\Utilitaires\\Emule Extreme\\emule.exe:*:D isabled:eMule"
    "C:\\Documents and Settings\\Hermes\\Bureau\\racer053b4\\racer.exe"="C:\\Documents and Settings\\Hermes\\Bureau\\racer053b4\\racer.exe:*:Enabled:racer"
    "D:\\racer053b4\\racer.exe"="D:\\racer053b4\\racer.exe:*:Enabled:racer"
    "D:\\Spring\\spring.exe"="D:\\Spring\\spring.exe:*:Enabled:spring"
    "D:\\Nouveau dossier\\tremulous.exe"="D:\\Nouveau dossier\\tremulous.exe:*:Enabled:tremulous"
    "C:\\Program Files\\Motorola\\Software Update\\msu.exe"="C:\\Program Files\\Motorola\\Software Update\\msu.exe:*:Enabled:msu"
    "C:\\Program Files\\Magentic\\bin\\MgImp.exe"="C:\\Program Files\\Magentic\\bin\\MgImp.exe:*:Enabled:Magentic"
    "C:\\Program Files\\Magentic\\bin\\Magentic.exe"="C:\\Program Files\\Magentic\\bin\\Magentic.exe:*:Enabled:Magentic"
    "C:\\Program Files\\Magentic\\bin\\MgApp.exe"="C:\\Program Files\\Magentic\\bin\\MgApp.exe:*:Enabled:Magentic"
    "C:\\Program Files\\Internet Download Manager\\IDMan.exe"="C:\\Program Files\\Internet Download Manager\\IDMan.exe:*:Enabled:Internet Download Manager (IDM)"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\\Documents and Settings\\Hermes\\Bureau\\Packmatronic 1.0 CrystalXP.exe"="C:\\Documents and Settings\\Hermes\\Bureau\\Packmatronic 1.0 CrystalXP.exe:*:Enabled:Messenger Content Installer"
    "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:D isabled:eMule"
    "C:\\Documents and Settings\\Hermes\\Bureau\\Fichiers inutilis‚s\\Emule Extreme\\emule.exe"="C:\\Documents and Settings\\Hermes\\Bureau\\Fichiers inutilis‚s\\Emule Extreme\\emule.exe:*:D isabled:eMule"
    "D:\\GOA\\Gunbound\\GunBound.gme"="D:\\GOA\\Gunbound\\GunBound.gme:*:D isabled:GunBound"
    "C:\\Documents and Settings\\Hermes\\Bureau\\GOA\\Gunbound\\GunBound.gme"="C:\\Documents and Settings\\Hermes\\Bureau\\GOA\\Gunbound\\GunBound.gme:*:D isabled:GunBound"
    "C:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"="C:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe:*:D isabled:iMesh"
    "C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:D isabled:IncrediMail"
    "C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:D isabled:IncrediMail"
    "C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"="C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:D isabled:IncrediMail"
    "C:\\Documents and Settings\\Hermes\\Bureau\\incredimail_install.exe"="C:\\Documents and Settings\\Hermes\\Bureau\\incredimail_install.exe:*:D isabled:IncrediMail Installer"
    "C:\\Program Files\\Xfire\\xfire.exe"="C:\\Program Files\\Xfire\\xfire.exe:*:D isabled:Xfire"
    "C:\\Documents and Settings\\Hermes\\Bureau\\Nouveau dossier\\RocketRacer\\RocketRacer.exe"="C:\\Documents and Settings\\Hermes\\Bureau\\Nouveau dossier\\RocketRacer\\RocketRacer.exe:*:Enabled:RocketRacer"
    "C:\\WINDOWS\\system32\\rtcshare.exe"="C:\\WINDOWS\\system32\\rtcshare.exe:*:Enabled:p artage de l'application RTC"
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
    "C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Ex‚cuter une DLL en tant qu'application"
    "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

    Remaining Files:
    ---------------

    File Backups: - C:\SDFix\backups\backups.zip

    Files with Hidden Attributes:

    Fri 2 Feb 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
    Tue 16 Oct 2007 24,064 ...H. --- "C:\Documents and Settings\Hermes\Bureau\~WRL0038.tmp"
    Tue 16 Oct 2007 26,624 ...H. --- "C:\Documents and Settings\Hermes\Bureau\~WRL3536.tmp"
    Tue 16 Oct 2007 26,112 ...H. --- "C:\Documents and Settings\Hermes\Bureau\~WRL3886.tmp"
    Mon 22 Jul 2002 418,816 ...HR --- "C:\WINDOWS\system32\Tools\All.exe"
    Fri 19 Jul 2002 390,144 ...HR --- "C:\WINDOWS\system32\Tools\Change.exe"
    Fri 19 Jul 2002 574,464 ...HR --- "C:\WINDOWS\system32\Tools\CheckPath.exe"
    Tue 20 Aug 2002 430,592 ...HR --- "C:\WINDOWS\system32\Tools\Counter.exe"
    Tue 23 Jul 2002 390,656 ...HR --- "C:\WINDOWS\system32\Tools\DelFolders.exe"
    Fri 22 Nov 2002 399,872 ...HR --- "C:\WINDOWS\system32\Tools\DirectSetup.exe"
    Fri 19 Jul 2002 388,096 ...HR --- "C:\WINDOWS\system32\Tools\RegClean.exe"
    Fri 19 Jul 2002 388,608 ...HR --- "C:\WINDOWS\system32\Tools\Regexe.exe"
    Mon 2 Dec 2002 431,616 ...HR --- "C:\WINDOWS\system32\Tools\Restart.exe"
    Fri 19 Jul 2002 388,096 ...HR --- "C:\WINDOWS\system32\Tools\RunRegexe.exe"
    Tue 13 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
    Wed 26 Sep 2007 128,704,971 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\778fd2fc3fe6b905e366b5ddbba384c8\BIT1.tmp"
    Wed 4 Oct 2006 3,072,000 A..H. --- "C:\Documents and Settings\Hermes\Application Data\U3\temp\Launchpad Removal.exe"
    Fri 2 Feb 2007 4,348 ...H. --- "C:\Documents and Settings\Hermes\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
    Fri 2 Feb 2007 20 A..H. --- "C:\Documents and Settings\Hermes\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
    Fri 2 Feb 2007 9,656 A.SH. --- "C:\Documents and Settings\Hermes\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
    Fri 7 Sep 2007 3,324,919 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\e858426bd5ad6e5e6df8fd258cdb8155\download\BIT8.tmp"

    Finished!

    Et celui de Hijackthis:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:06:24, on 10/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Spyware Doctor\svcntaux.exe
    C:\Program Files\Spyware Doctor\swdsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Spyware Doctor\SDTrayApp.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\X'nBeep 1.1\XnBeep.exe
    C:\Program Files\Pando Networks\Pando\Pando.exe
    C:\WINDOWS\system32\sistray.exe
    C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
    C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Documents and Settings\Hermes\Bureau\Utilitaires\HijackThis.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ci/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {7411F8BA-29A3-3216-9DE7-024AC0AAB9F6} - C:\WINDOWS\System32\viyjhai.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10111} - C:\Program Files\TrueDownloader\truedownloaderie.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Adssite Toolbar - {41C29B07-6F91-4966-91BE-2E2841643C83} - C:\Program Files\Adssite Advanced Toolbar\toolbar.dll (file missing)
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
    O4 - HKLM\..\Run: [antihost] C:\WINDOWS\system32\ahr.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [X'nBeep] C:\Program Files\X'nBeep 1.1\XnBeep.exe
    O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
    O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
    O4 - HKCU\..\Run: [TrueDownloaderAutoStart] C:\Program Files\TrueDownloader\TrueDownloader.exe /silent
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Outil de détection de support de Cyber-shot Viewer.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    O4 - Startup: Reboot.exe
    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
    O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe
    O4 - Startup: Y'z Toolbar.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?611557c71b9f4b36b7268c86543e5259
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?611557c71b9f4b36b7268c86543e5259
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: {0835BC90-6ABC-4F52-A103-4FC3A61F2C33} (A18X Control) - http://www.albatross18.com/season2/cabs/A18X.ocx
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts...
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.ca...
    O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgsta...
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://incredimailintl.oberon-media.com/online/online2/...
    O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://agbouuuuuu.spaces.live.com/PhotoUpload/MsnPUpld....
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) - http://www.rockyou.com/RockYouImageUploader.cab
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/install...
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0FE88AD7-F786-4FF7-BD3C-D7525390D43B}: NameServer = 213.150.193.1,213.150.201.25
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0FE88AD7-F786-4FF7-BD3C-D7525390D43B}: NameServer = 213.150.193.1,213.150.201.25
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

    --
    End of file - 11771 bytes

    re
    Citation :
    Merci pour votre aide //même si je sais que je vous fatigue!!!

    pas de problème :) 

    ~ Télécharge Clean de Malekal
    http://www.malekal.com/download/clean.zip

    Enregistre-le sur ton bureau et dézippe-le
    Cela va créer un dossier clean.
    Double-clic sur ce dossier clean, tu y trouveras dedans plusieurs fichiers.
    Double-clic sur clean.cmd.
    Un menu va apparaître, choisis l'option 1 en appuyant sur la touche 1 de ton clavier.
    Clean va travailler.
    Poste le contenu du rapport généré en C:\rapport_clean.txt.

    Re:) 
    Le rapport de CLean:

    10/11/2007 a 21:03:01,73

    *** Recherche des fichiers dans C:

    *** Recherche des fichiers dans C:\WINDOWS\

    *** Recherche des fichiers dans C:\WINDOWS\system32
    "C:\WINDOWS\Downloaded Program Files\CONFLICT.1" FOUND

    *** Recherche des fichiers dans C:\Program Files
    "C:\Program Files\Adssite Advanced Toolbar\" FOUND
    "C:\Program Files\Adssite Games Collection\" FOUND
    "C:\Program Files\Adverts\" FOUND
    "C:\Program Files\GameHouse\" FOUND
    "C:\Program Files\Viewpoint\" FOUND

    ok

    ~Télécharge OTMoveIt (d'OldTimer). Sauvegarde-le sur ton Bureau.

    ~Lance Hijackthis “Do a system scan only”.
    Coche les lignes qui suivent si encore présentes et uniquement celles-là.

    O2 - BHO: (no name) - {7411F8BA-29A3-3216-9DE7-024AC0AAB9F6} - C:\WINDOWS\System32\viyjhai.dll (file missing)
    O3 - Toolbar: Adssite Toolbar - {41C29B07-6F91-4966-91BE-2E2841643C83} - C:\Program Files\Adssite Advanced Toolbar\toolbar.dll (file missing)
    O4 - HKLM\..\Run: [antihost] C:\WINDOWS\system32\ahr.exe
    O4 - Startup: Reboot.exe
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/n [...] 0.15-3.cab
    O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/ga [...] n11USA.cab
    O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://agbouuuuuu.spaces.live.com/ [...] nPUpld.cab
    O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) - http://www.rockyou.com/RockYouImageUploader.cab


    Clique sur Fix checked (en bas à gauche)


    Sélectionne TOUS les emplacements en gras ci-dessous :

    C:\Program Files\Adssite Advanced Toolbar
    C:\Program Files\Adssite Games Collection
    C:\Program Files\Adverts
    C:\Program Files\GameHouse
    C:\Program Files\Viewpoint
    C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Reboot.exe
    C:\WINDOWS\system32\ahr.exe


    ---> Clique-droit puis Copier (ou Ctrl+C)

    Double-clique sur OTMoveIt.exe afin de le lancer.
    Fais un Clique-droit sur le cadre de gauche puis choisis Coller (ou Ctrl+V).
    Clique maintenant sur [#ff0000]MoveIt![/#f]

    [#ff0000]Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.[/#f]

    Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
    Le nom du rapport correspond au moment de sa création : date_heure.log

    ->Informations sur le logiciel<-






    Re
    aaah ok:) 
    Voila le rapport de OT_MoveIt:


    C:\Program Files\Adssite Advanced Toolbar moved successfully.
    C:\Program Files\Adssite Games Collection moved successfully.
    C:\Program Files\Adverts moved successfully.
    C:\Program Files\GameHouse\Collapse moved successfully.
    C:\Program Files\GameHouse moved successfully.
    C:\Program Files\Viewpoint\Viewpoint Media Player\Resources moved successfully.
    C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents moved successfully.
    C:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents moved successfully.
    C:\Program Files\Viewpoint\Viewpoint Media Player\Components moved successfully.
    C:\Program Files\Viewpoint\Viewpoint Media Player moved successfully.
    C:\Program Files\Viewpoint moved successfully.
    File/Folder C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Reboot.exe not found.
    File/Folder C:\WINDOWS\system32\ahr.exe not found.

    Created on 11/12/2007 20:51:27

    Bjr
    Voila:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 09:36:24, on 15/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Safe mode with network support

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Spyware Doctor\svcntaux.exe
    C:\Program Files\Spyware Doctor\swdsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Documents and Settings\Hermes\Bureau\Utilitaires\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ci/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: ads_optimizer - {9C8A568E-4201-478a-8536-526CF371D2E2} - C:\WINDOWS\system32\nszD.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10111} - C:\Program Files\TrueDownloader\truedownloaderie.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [X'nBeep] C:\Program Files\X'nBeep 1.1\XnBeep.exe
    O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
    O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
    O4 - HKCU\..\Run: [TrueDownloaderAutoStart] C:\Program Files\TrueDownloader\TrueDownloader.exe /silent
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Outil de détection de support de Cyber-shot Viewer.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
    O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe
    O4 - Startup: Y'z Toolbar.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?611557c71b9f4b36b7268c86543e5259
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?611557c71b9f4b36b7268c86543e5259
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: {0835BC90-6ABC-4F52-A103-4FC3A61F2C33} (A18X Control) - http://www.albatross18.com/season2/cabs/A18X.ocx
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.ca...
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://incredimailintl.oberon-media.com/online/online2/...
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/install...
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0FE88AD7-F786-4FF7-BD3C-D7525390D43B}: NameServer = 213.150.193.1,213.150.201.25
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0FE88AD7-F786-4FF7-BD3C-D7525390D43B}: NameServer = 213.150.193.1,213.150.201.25
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

    --
    End of file - 9252 bytes

    bonsoir

    ta désinfection dure depuis 11 jours...
    en 1 jours ou deux on aurait tout regler, là, plus tu attends, plus tu te prends de nouvelles infections....



    Citation :
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 09:36:24, on 15/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Safe mode with network support


    un log en mode sans echec de hiajckthis ne me montre pas tout.

    1

    ~Lance Hijackthis “Do a system scan only”.
    Coche les lignes qui suivent si encore présentes et uniquement celles-là.

    O2 - BHO: ads_optimizer - {9C8A568E-4201-478a-8536-526CF371D2E2} - C:\WINDOWS\system32\nszD.dll


    Clique sur Fix checked (en bas à gauche)

    2

    Sélectionne TOUS les emplacements en gras ci-dessous :

    C:\WINDOWS\system32\nszD.dll

    ---> Clique-droit puis Copier (ou Ctrl+C)

    Double-clique sur OTMoveIt.exe afin de le lancer.
    Fais un Clique-droit sur le cadre de gauche puis choisis Coller (ou Ctrl+V).
    Clique maintenant sur [#ff0000]MoveIt![/#f]

    [#ff0000]Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.[/#f]

    Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
    Le nom du rapport correspond au moment de sa création : date_heure.log

    ->Informations sur le logiciel<-

    3
    reposte un log hijackthis en mode normal cette fois.







    Desolé :sweat:  :sarcastic:  :cry: 

    Voila en tout cas le rapport de OT_MoveiT:

    File/Folder C:\WINDOWS\system32\nszD.dll not found.

    Created on 11/16/2007 20:27:43


    Et celui d'Hijackthis:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:32:12, on 16/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0013)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Spyware Doctor\svcntaux.exe
    C:\Program Files\Spyware Doctor\swdsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Spyware Doctor\SDTrayApp.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\X'nBeep 1.1\XnBeep.exe
    C:\Program Files\Pando Networks\Pando\Pando.exe
    C:\WINDOWS\system32\sistray.exe
    C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
    C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe
    C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\Hermes\Bureau\Utilitaires\HijackThis.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ci/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10111} - C:\Program Files\TrueDownloader\truedownloaderie.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [X'nBeep] C:\Program Files\X'nBeep 1.1\XnBeep.exe
    O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
    O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
    O4 - HKCU\..\Run: [TrueDownloaderAutoStart] C:\Program Files\TrueDownloader\TrueDownloader.exe /silent
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Outil de détection de support de Cyber-shot Viewer.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
    O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe
    O4 - Startup: Y'z Toolbar.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?611557c71b9f4b36b7268c86543e5259
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?611557c71b9f4b36b7268c86543e5259
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: {0835BC90-6ABC-4F52-A103-4FC3A61F2C33} (A18X Control) - http://www.albatross18.com/season2/cabs/A18X.ocx
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.ca...
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://incredimailintl.oberon-media.com/online/online2/...
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/install...
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0FE88AD7-F786-4FF7-BD3C-D7525390D43B}: NameServer = 213.150.193.1,213.150.201.25
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0FE88AD7-F786-4FF7-BD3C-D7525390D43B}: NameServer = 213.150.193.1,213.150.201.25
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

    --
    End of file - 10826 bytes
    Lassé par la pub ? Créez un compte
    Tom's guide dans le monde